Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Genbox
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
Genbox
2y ago
Pretty interesting solution. At least it removes many of the errors stemming from reading keys over the phone, etc., but it also proclaims to remove the risk of distributing BitLocker keys - but that's precisely what they did - just in
32.
▲
by
Genbox
2y ago
Research deals with theory. Not everything in research is immediately practical. Lots of engineering, tweaking, and testing goes into market-ready products. This announcement is an achievement for science, not a consumer-ready product.
33.
▲
by
Genbox
2y ago
What's really annoying me today is the security holes Microsoft is adding – by design – into Windows. I mean of course Microsoft Recall. This delightful AI addition to the next generation of Windows PCs would have taken regular snapsh
34.
▲
by
Genbox
2y ago
Link to paper: https://www.usenix.org/system/files/login/articles/login_dec...
35.
▲
by
Genbox
2y ago
People don't consider adversarial inputs when building scripts, which is one of the main reasons why I started a company to build an incident response platform in 2018. I was handling security incidents on a large scale with tools that
36.
▲
by
Genbox
2y ago
The project links to [1], which is absolutely amazing as well. [1] https://bbycroft.net/llm
37.
▲
by
Genbox
2y ago
Even non-cryptographic hashes must provide some sort of security against attacks. Let's say we use a weak hash function in an open addressing hash-map - if I can calculate a set of inputs that will all collide in the hash-map, then it
38.
▲
by
Genbox
2y ago
I've done some security testing against this hash function. Does anyone want to follow up and see if they can extend the attacks I describe[1]? [1] https://github.com/ogxd/gxhash/issues/25
39.
▲
by
Genbox
2y ago
A web interface for the Infini-gram engine can be found here: https://huggingface.co/spaces/liujch1998/infini-gram
40.
▲
by
Genbox
2y ago
It references Box2D as the physics engine, but it seems to be a JavaScript port of Box2D. I'm unfamiliar with the JavaScript ports, but if it is a copy of one of the existing ports, the port should be referenced instead.
41.
▲
by
Genbox
3y ago
Google has developed several non-cryptographic hash functions. CityHash, FarmHash, and HighwayHash come to mind. BigQuery provides FarmHash next to the MD5 and SHA-family of cryptographic hash functions. Who knows, maybe they use FarmHash t
42.
▲
by
Genbox
3y ago
It is the primary failsafe for Microsoft 365 accounts to store the BitLocker recovery key with your Microsoft account. The other failsafes are printing the key or storing it on an external device. One can easily obtain the recovery key on a
43.
▲
by
Genbox
3y ago
I love the low level .NET stuff Michael Strehovsky makes. Microsoft has built a feature-rich and easy-to-use environment, but it makes .NET developers think there is only one way to use it: create csproj and call dotnet build. But underneat
44.
▲
by
Genbox
3y ago
Great article Ken. I love the chip/die pictures.
45.
▲
by
Genbox
3y ago
He is very skilled and a pleasure to watch. His restorations make the items better than the original. The Datsun project is a bit boring as I'm not a car guy, but I'm impressed that he manages to keep the level of craftsmanship hi
46.
▲
by
Genbox
3y ago
Does anyone here remember .kkrieger? the first-person shooter in a 97 kb file. The demoscene was comprised of some truly talented people.
47.
▲
by
Genbox
3y ago
Code correctness is a lost art. I requirement to think in abstractions is what scares a lot of devs to avoid it. The higher abstraction language (formal specs) focus on a dedicated language to describe code, whereas lower abstractions (code
48.
▲
by
Genbox
3y ago
I get that this guy tries to take a perspective based on error reporting, but it really has nothing to do with the difference between interpreted and compiled. I've built a scripting language with a full lexer and parser. It is capable
49.
▲
by
Genbox
3y ago
Like the article says, the author did test against an open addressing hash table. He also addressed the resize requirements in the first paragraph, which makes rehashing not a concern.
50.
▲
by
Genbox
3y ago
> don't tell yourself it's only good for hashing. The hash function[1] takes an arbitrary input and generate (in this case) a 32bit integer. This is nessecary to index values that are not integers (such as byte arrays or string
51.
▲
by
Genbox
3y ago
Also, technically bcrypt is not a general hash algorithm, but rather a password-hash construction. Where SHA1 and MD5 are primitives that can be used in arbitrary crypt constructions, bcrypt is already a construction specialized for passwor
52.
▲
by
Genbox
3y ago
Immutability and thread-safety are two different things. There are no thread-safety guarantees made by the JVM or the runtime for the String type, and I suspect your bug report will get the same answer. You are right that there is an expeca
53.
▲
by
Genbox
3y ago
Making the 99% case faster at the cost of making the 1% case slower, is a speedup.
54.
▲
by
Genbox
3y ago
The climate is changing for the worse due to humans. However, the article has a selection bias: In recent days, as the Earth has reached its highest average temperatures in recorded history, scientists have made a bolder claim: It may well
55.
▲
by
Genbox
3y ago
It is just me, or does the article date say "07/11/2023"? Someone goofed.
56.
▲
by
Genbox
3y ago
I've done my best to research this and I'm unable to find any numbers on the matter besides one app developers miscalculation of 20 mio. for billions of requests. I can however find official documentation that backs up what the ad
57.
▲
by
Genbox
3y ago
They are called similarity digests or sometimes "fuzzyhashing". For generic files there are Context Triggered Piecewise Hashing (CTPH), Trend Micro Locality Sensitive Hash (TLSH) and Similary Digest Hash (SDHash)
58.
▲
by
Genbox
3y ago
How devs can work with code that breaks at 80 characters in this day and age is beyond me.
59.
▲
by
Genbox
3y ago
I'm not making general claims about the use of memory exploitation - only questioning the statement that they are not widely used. With more than 500 forensics cases with my name on it, and a substantial amount of them being RCE based,
60.
▲
by
Genbox
3y ago
I work in the field and I'm not entirely sure about the cardinality of types of attacks. On one hand, there are password spaying, RDP bruteforces, email attachments, social engineering etc. On the other we have BlueKeep, ZeroLogon and
More ›