Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DanielDent
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
DanielDent
10y ago
Ubiquity gear around the 1Gbps rate isn't anywhere close to $18-20k. And for very short links, there are projects like http://koruza.net/ which use standard (cheap) 1Gbps or 10Gbps media converters for free space optic
92.
▲
by
DanielDent
10y ago
While I don't believe this type of thinking about IP addresses represents a sustainable approach to an open internet, https://www.maxmind.com/en/geoip2-anonymous-ip-database and/or https://www.maxm
93.
▲
by
DanielDent
10y ago
60ghz, 80ghz, and higher frequencies (i.e. free space optics operating at or near the visible light spectrum) change the story considerably. As frequency goes up and wavelengths get pencil thin, issues like "do I have clear line of sig
94.
▲
by
DanielDent
10y ago
This is a really interesting 'real world' anecdote. Do you know of any related data available publicly? i.e. "on our network, X bits in Y terabytes end up with undetected corruption, meaning that approximately Z% of downloads
95.
▲
by
DanielDent
10y ago
While I agree a credit card might theoretically offer recourse, in practice I think what would happen is I would end up locked out of my iTunes account and I would discover that all my past "purchases" would be better described as
96.
▲
by
DanielDent
10y ago
But it's crippled. I didn't want to waste my time evaluating a product other than the one which was interesting to me.
97.
▲
by
DanielDent
10y ago
I tried within hours. And tried again multiple times with intervals on the order of weeks.
98.
▲
by
DanielDent
10y ago
Much easier to just load a root CA certificate - this use case is explicitly supported and does not require maintaining a browser fork & compile infrastructure. But "just" doing either of these things turns out not to be simpl
99.
▲
by
DanielDent
10y ago
I believe nossl was intended as a concession for schools that believe in censorship. It makes it relatively easy to configure things so Google doesn't go over SSL so that your existing MITM boxes which censor continue to function as be
100.
▲
by
DanielDent
10y ago
I bought Veertu through the Mac app store on an early 2009 MacBook Pro. The CPU instructions used for native virtualization are not enabled on the machine. Despite not being compatible with the machine on which I was purchasing, and despite
101.
▲
by
DanielDent
10y ago
Interesting, thanks for pointing that out. This code is such a good example of the potential value of formal verification tools for crypto primitives.
102.
▲
by
DanielDent
10y ago
Pretty sure there are planes which are quieter than some bitcoin miners...
103.
▲
by
DanielDent
10y ago
That fits with my understanding. What I don't know is how this interacts with the acceleration functionality the chip has. For instance, do the instructions end up being "please do sha256 on this data", or are they closer to
104.
▲
by
DanielDent
10y ago
Did you compare performance to SHA512? Despite being a theoretically more secure/"harder" algorithm, on 64 bit platforms it can sometimes be faster than SHA256. If you don't want to use 512 bits, using 256 bits of the ou
105.
▲
by
DanielDent
10y ago
To be fair, OpenStack doesn't exactly have a reputation of "just working". It's really more a framework for building infrastructure. That's why there are entire consultancies and OS distributions to help people succ
106.
▲
by
DanielDent
10y ago
Well, all the IPv6 privacy mechanism does is rotate the /64 suffix. My /64 prefix hadn't changed. From a reputation/risk modelling standpoint, it's usually correct to view a /64 of v6 as a /32 of v4 (i.e.
107.
▲
by
DanielDent
10y ago
"but keep doing stateful tracking of outbound connections just like a NAT would, and drop everything else on the floor" Here are two important behaviours which come with "just like a NAT would". 1) UPNP - a protocol whic
108.
▲
by
DanielDent
10y ago
There's a reasonable argument to be made that router-based firewalls shouldn't be necessary for a home user to have a secure configuration. If it's not safe to expose a service to the internet, it's also not safe to have
109.
▲
by
DanielDent
10y ago
I'm unaware of any precedent... I could certainly see people getting upset, but I don't think they'd have solid grounds. The interesting thing is that I actually am considering setting up a WPAD entry on a domain where I am
110.
▲
by
DanielDent
10y ago
Anything less than 2048 bit is probably a poor choice these days. NIST recommended that RSA-1024 be considered deprecated for use after 2010. The trouble with RSA is that you end up needing to increase to pretty large key lengths to have si
111.
▲
by
DanielDent
10y ago
I wonder how much of a role https://www.toosheh.org/ plays in this decision. Toosheh buys satellite time (funding source: intentionally ambiguous) to transmit curated western media to Iranians.
112.
▲
by
DanielDent
10y ago
HN uses Cloudflare (a YC company) and could turn IPv6 on for free with a single click. But that may not represent the full story for them. Internal moderation and anti-spam may need updating to be compatible with running on two different ne
113.
▲
by
DanielDent
10y ago
Even Apple got bit by this issue. They sold an Airport home router which by default provided full v6 connectivity. They were promptly lambasted in the press for "putting their users at risk by not having a proper firewall!". :( Th
114.
▲
by
DanielDent
10y ago
And there are actually some use cases where NAT66 may make sense (various multi-homing and re-numbering avoidance scenarios). I think the jury is still out. I think we'll see lots of NAT66, but for completely different reasons than we&
115.
▲
by
DanielDent
10y ago
I have heard rumours that, although this is what they state, they actually in practice do assign the entire /64 to the machine. Not sure if this is true and I have not tested it myself. I see it largely as an attempt to do market segme
116.
▲
by
DanielDent
10y ago
DO's v6 needs work. They block port 25, and they don't even assign an entire /64 to a machine, which breaks SLAAC and whole bunch of useful ways of using v6.
117.
▲
by
DanielDent
10y ago
It is, however, only 1024 bit RSA for now.
118.
▲
by
DanielDent
10y ago
The way I think about IPv6 is that it's an entire second network which happens to frequently coexist on the same layer 1 and layer 2 equipment. That said, I think there's often a strong argument for only using IPv6 for the interna
119.
▲
by
DanielDent
10y ago
SGC certificates were entirely a result of bizarre US export restrictions.
120.
▲
by
DanielDent
10y ago
It's been a while since I read the Mythical Man Month, but as I recall his answer to your point is to look at things through the perspective of systems and subsystems. While Linus is responsible for the overall Linux kernel/system
More ›