yan Profile picture
Oct 13, 2021 4 tweets 3 min read Read on X
i…. just received a children’s book about a rabbit who travels back in time to medieval europe and gets everyone hyped about blockchain ImageImageImageImage
some of the blockchain applications that the poor bunny serfs come up with: ImageImageImageImage
not impressed Image
anyway! you can get the book from amazon.com/Sphinxing-Rabb…. it may or may not be satire. ImageImage

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with yan

yan Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @bcrypt

Apr 11
in january 2023, i had a simple ultrasound done at SimonMed. they sent me 4 bills totaling $5137 for it.

after a year of emails and phone calls, they finally admitted today that i only owed $140.53 and are mailing me a refund check!

here's how i did it 🧵 Image
2/ the first bill they sent was for $484.92, which i paid promptly. a few months later they sent a bill for $3378.69! i contacted my insurance and they sent me an updated EOB saying i only owed an additional $140.53.
3/ i emailed simonmed and attached the EOB. they said they would look into it. shortly after i got a new bill for $140.53 in the mail which i paid.

then i noticed the 484.92 amount wasn't counted in my insurance deductible so i contacted my insurance asking why
Read 10 tweets
Mar 6, 2022
when reading text in a non-native language & wondering how it's pronounced, u can enter this in devtools to have the browser pronounce it:

u=new SpeechSynthesisUtterance(getSelection().toString());u.lang='ru-RU';speechSynthesis.speak(u)

(replace 'ru-RU' with any BCP 47 tag)
assuming you've highlighted the text you want pronounced
in case u were wondering, the context menu text-to-speech feature doesn't work for this use case :)
Read 6 tweets
Sep 14, 2020
my friend sophie got fired from her job at Facebook and turned down a $64,000 severance package in order to leak this, so u better read it. buzzfeednews.com/article/craigs…
my biggest takeaway from this article is that FB could be doing a lot more to prevent politically-motivated bot activity, but they choose not to because they don't see any immediate revenue or PR benefit from doing so.
clarification: in order to leak this *internally* at Facebook
Read 4 tweets
Apr 9, 2020
why is it not common knowledge that u can make perfect japanese-style croissants from scratch with like 20min of effort?? thx @MimeeXu for enlightening me

(recipe in thread👇)
1/ mix 400g bread flour & 6g salt

microwave 240g milk for 30s
dissolve 8g dry yeast in it
add 50g honey
add 40g softened butter
mix together

mix wet mix into dry mix to form a well-combined dough

cover and rest overnight in fridge
2/
1. form 12 balls of dough
2. roll each dough as shown below, wrapping a piece of butter and pinch of salt at the center of each roll
3. lay rolls on parchment paper and rest for 40min in a slightly warm place (ex: warming drawer of oven, or an oven with the light on)
Read 6 tweets
May 8, 2019
1/ in this thread i'll summarize some differences between SameSite=Lax (Chrome's new proposed default policy; see mikewest.github.io/cookie-increme… for more technical details) and third party cookie blocking (Brave's default policy unless user turns it off for a site)
2/ SameSite=Lax is more strict than 3p cookie blocking in the sense that it also blocks requests using unsafe HTTP methods. For instance if X contains a form that POSTs to Y, cookies to Y would be blocked by SameSite=Lax but not most 3p cookie block implementations AFAIK
3/ SameSite=Lax is less strict than 3p cookie blocking in the sense that a site can override it with SameSite=None. But unless a site does that, both SameSite=Lax and 3p cookie blocking will block 3rd party cookies on subresource requests.
Read 4 tweets
May 11, 2018
Signal Desktop just pushed out a fix for a remote XSS vuln: github.com/signalapp/Sign…

demo:
a lot of @electronjs devs have the attitude that their app doesn't need sandboxing or keeping up-to-date with Chromium bc "it doesn't execute untrusted code". the problem is that falls apart as soon as you get XSS. github.com/signalapp/Sign…

(at least Signal has sandboxing)
"should i build this as a web app or use Electron?"
the difficulty gap between XSS and full RCE is much smaller in Electron compared to a browser like up-to-date Chrome, so plz make it a web app if u care about good things
Read 6 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(