Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Borealid
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
Borealid
4mo ago
The interior of the house is a private space. Things under your clothes are too. Revealing either of these things through whatever technology is a search. The standard is whether something expected to be private is revealed. What your eyes
62.
▲
by
Borealid
5mo ago
No, looking up your face in a list of faces is searching FOR you, not searching you. Searching you means taking an inventory of the items on your person. It does not mean looking at you. In some cases, imaging you can be a "search"
63.
▲
by
Borealid
5mo ago
> Note that absent reasonable articulable suspicion of a crime, law enforcement in the US cannot legally forcibly identify people. Could you cite a source for this? If a law enforcement officer personally recognizes someone's face,
64.
▲
by
Borealid
5mo ago
This is actually how it works in India with "e-mandates". In order to set up a recurring bill the merchant must get a "mandate" from the customer, which involves them approving the amount/frequency/term of the
65.
▲
by
Borealid
5mo ago
> All metaphysical positions are ultimately unfalsifiable This is not true, there are many metaphysical positions that are falsifiable. For example, "anything shaped like an apple is an apple" is a metaphysical position. It def
66.
▲
by
Borealid
5mo ago
The only purpose of SEV is to protect a guest against the person who controls the hypervisor. So this is a threat against SEV.
67.
▲
by
Borealid
5mo ago
A "threat actor" can be a company employee who is intentionally permitted to update internal documentation, but not intentionally permitted to change the behavior of an LLM whose context window includes that documentation. I think
68.
▲
by
Borealid
5mo ago
They are copied from a thumb drive the person applying the exploit creates.
69.
▲
by
Borealid
5mo ago
With PIV, the private keys are stored inside the smartcard (a Yubikey is just one type of smartcard) and don't leave it. They're used for encryption/decryption by the host. Yes, it's generally sound, and is the primary m
70.
▲
by
Borealid
5mo ago
It does not. The files are copied to the recovery image, not the machine's encrypted drives.
71.
▲
by
Borealid
5mo ago
If Microsoft wanted a backdoor, there is no need to hide it in the official Windows Recovery Environment image. Just sign an alternate version of the recovery environment that doesn't bother displaying a login screen. Done - you can ac
72.
▲
by
Borealid
5mo ago
I don't think any of the attacks being discussed are actually attacks on the TPM's own threat model. I think they're attacks on Windows' measured boot approach.
73.
▲
by
Borealid
5mo ago
> That's not how it works. The KEK is not stored inside the TPM, but encrypted/decrypted by the TPM. No, the KEK is stored inside the TPM, and the DEK is decrypted by it. If you have three layers (two KEKs, one encrypted with t
74.
▲
by
Borealid
5mo ago
I gave three ways in which encrypting a disk using a TPM provides advantages over encrypting the disk using a secret password. Encrypting the disk using a secret password provides advantages over encrypting the disk using a public password.
75.
▲
by
Borealid
5mo ago
That does not match up with the way this exploit works. An un-exploited system is booted with a modified version of the Windows Recovery Environment. Like I said, I think the not-well-described problem here is that (effectively) the lock sc
76.
▲
by
Borealid
5mo ago
There are two ways to "use a PIN". Since there's a ton of misunderstanding in this thread, I'm going to go into how disk encryption works conceptually. First, there's a symmetric key to encrypt blocks on the disk. S
77.
▲
by
Borealid
5mo ago
Their strategy WAS GamePass - get a bunch of users accumulating huge collections of inexpensive-but-high-value games, paid for via a subscription (rented), that are only playable on Windows (enforced via Microsoft's own software and an
78.
▲
by
Borealid
5mo ago
Wireguard has no key distribution mechanism. You can use software like Headscale/Tailscale/Netbird on top.
79.
▲
by
Borealid
5mo ago
That site doesn't mention that when DNSSec is absent, the behaviour of SSH is identical to what happens if you hadn't used the SSHFP record at all, except that for unsophisticated attackers it also displays "no matching host
80.
▲
by
Borealid
5mo ago
Believe it or not, email service providers actually exist. Rollernet.us is a good one. They have excellent deliverability, reasonable prices, and everything you could want related to email. They have a few minor other services, like DNS man
81.
▲
by
Borealid
5mo ago
I recommend reading the description of the option `VerifyHostKeyDns` in the `ssh_config` man page. If set to `yes`, you get automatic trust-on-first-use (no user prompt) if you use DNSSec, and you get the current asking-the-user behavior if
82.
▲
by
Borealid
5mo ago
SSH has *ANOTHER* built-in solution, in the form of the SSHFP DNS record. If the DNS record for the host has an SSHFP (SSH FingerPrint) record, SSH will compare it to the retrieved public key(s) and refuse the connection if there is a misma
83.
▲
by
Borealid
5mo ago
There is already plenty of open hardware, it's just not this-year's-top-performance. In the category of ~1-3 years' performance lag you get Rockchip and friends, which are closed hardware that allows open computation. See com
84.
▲
by
Borealid
5mo ago
If the task is ill-defined, then it's a bit unfair to make it sound like the problem is that an LLM can't be configured to do something, if a human would have an equally hard time with the same task. The statement "it's
85.
▲
by
Borealid
5mo ago
> Because that’s what I am seeing emerge from the various efforts to build LLM safety tools. Something having not been obtained so far is not a logical argument it is impossible to obtain that thing. > LLM != human? They don’t even us
86.
▲
by
Borealid
5mo ago
> If you make an LLM more safe, you are going to shift the weight for defensive actions as well. > > There’s no physical way to assign weights to have one and not the other. Do you think a human is capable of providing assistance w
87.
▲
by
Borealid
5mo ago
I think someone exercising their legal rights, such as their right to enter a business open to the public and their right to free speech inside that establishment, in a way that harms the business should be something a business can "pu
88.
▲
by
Borealid
5mo ago
A limited account is allowed access to all prior purchases. It can even download those purchases again (incurring costs on Valve's part without paying anything). I don't believe anything was rescinded in the situation being discus
89.
▲
by
Borealid
5mo ago
I think there's a line between retaliating against someone, and refusing to help them in the future. I do not believe that refusing to do business with an individual, where your business provides a non-life-critical service, is retalia
90.
▲
by
Borealid
6mo ago
This is a bogus analogy leaidng to a bogus conclusion. If something points to the needle in the haytack (saying "this haystack has a needle positioned eighteen centimeters from the top and three left of center"), it's much ea
More ›