Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Tharre
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
Tharre
7mo ago
The word "temporarily" isn't mentioned anywhere on that page, and that's already a very different claim to "Brave is about to shut down MV2". And the MV2 support is not specific to those 4 extensions, the host
32.
▲
by
Tharre
7mo ago
> Tweaking user-hostile OSes into user-friendly ones is impressive, but not sustainable. Even worse, it slowing us down from leaving Android entirely. Not sustainable as opposed to what, exactly? Developing and maintaining a completely d
33.
▲
by
Tharre
7mo ago
> Seniors come from juniors. If you want seniors, you must let the juniors write the code. Companies know this as well, but this is a prisoner dilemma type situation for them. A company can skip out on juniors, and instead offer to pay s
34.
▲
by
Tharre
8mo ago
I never said that passkeys can be phished, I said they don't solve this problem, but yeah. Locking the front door while leaving the back door wide open, as they say. But unless you can convince people to go into the bank counter every
35.
▲
by
Tharre
8mo ago
With banks, typically a combination of your account number, pin and some confirmation code sent via email or SMS. And of course unregistering your previous device. Not sure where you're going with this though?
36.
▲
by
Tharre
8mo ago
This is just a variant of the "complicated unlocking mechanism" I was talking about. It still screws over everything not coming from the play store because the installation process for them essentially becomes a huge hassel, that
37.
▲
by
Tharre
8mo ago
> do not control the signing key which is ultimately used to associate app <-> domain <-> passkey, and they do not control the system credentials service which checks this association. You're assuming the attacker must g
38.
▲
by
Tharre
8mo ago
I understand how passkeys work. You don't need the legitimate app's credentials, we're talking about phishing attacks, you're trying to bring the victim to giving you access/control to their account without them rea
39.
▲
by
Tharre
8mo ago
Fully hardware-based disk encryption with key management. Or live captions. Or a far better java runtime with superior memory management. Or a million other things. But even your own example works, just because you dislike camera filters, d
40.
▲
by
Tharre
8mo ago
Read my previous comment again. Passkeys are nice, but they don't solve the problem that's being discussed here.
41.
▲
by
Tharre
8mo ago
I'm going to assume you're referring to auth codes, especially the ones sent via SMS? In which case yes, banks should definitely stop using those but that alone doesn't solve the overarching issue. The next step is simply tha
42.
▲
by
Tharre
8mo ago
There simply isn't a known solution to this problem. If you give users the ability to install unverified apps, then bad actors can trick them into installing bad ones that steal their auth codes and whatnot. If you want to disallow cer
43.
▲
by
Tharre
8mo ago
It's a question of what tradeoffs you're willing to make. If you're making a professional product then sure, but I've checked the chips you suggested and the cheapest one available on JLCPCB seems to be the LPC1820FB at
44.
▲
by
Tharre
8mo ago
> And that's objective. I don't think you understand what that word means. Regardless, your opinion (and mine) is irrelevant. People want at least some of the features of modern android, and any alternative lacking those is not
45.
▲
by
Tharre
8mo ago
> They have instead hand picked exactly 4 manifest v2 extensions (AdGuard, NoScript, uBlock Origin, and uMatrix) and have hard-coded special support for them. They quite literally say in https://brave.com/blog/brave-
46.
▲
by
Tharre
8mo ago
Who else is going to maintain and develop it? It's the same issue as with Chrome, even if you force Google to give it to some other company, they're all just as bad. And it's too big and too costly to maintain for anyone else
47.
▲
by
Tharre
8mo ago
> and when Google pushed manifest v3 changes to block ad-blockers every single one of them was affected. That's just objectively wrong, both Brave and Opera still support manifest v2 and are committed to continue doing so for the fo
48.
▲
by
Tharre
8mo ago
> * Chip design pays better than software in many cases and many places (US and UK included; Where are these companies? All you ever hear from the hardware side of things are that the tools suck, everyone makes you sign NDAs for everythi
49.
▲
by
Tharre
8mo ago
Probably not for much longer though. Several countries, including mine, have already banned SMS 2FA for banking, and it's likely that that will be implemented for all of Europe in the near future, possibly with PSD3. Not that SMS 2FA w
50.
▲
by
Tharre
8mo ago
The question is what generated that TOTP code. The banks must ensure that they "are independent, in that the breach of one does not compromise the reliability of the others," as article 4(30) states. That text is vague as hell, bu
51.
▲
by
Tharre
8mo ago
> Not in Spain. I can access my bank's website but I can't do anything without their bank app. I don't know about Spain specifically, but as far as I understand it no bank in the European Economic Area + UK should allow ba
52.
▲
by
Tharre
8mo ago
> a zero-day in the closed source firmware from Qualcomm will probably screw you anyway. All the devices that GrapheneOS supports implement a clear separation of the baseband and the CPU in the form of SMMU, ARMs version of IOMMU. So a z
53.
▲
by
Tharre
8mo ago
Those would have the user agent "ChatGPT-User" though, and I barely see those. The majority comes from "GPTBot" like in my excerpt above, which makes it pretty clear that it's used for some sort of training: "G
54.
▲
by
Tharre
8mo ago
There are a bit too many IPs to list but from my logs they're always of the form 74.7.2XX.* for GPTBot, matching OpenAIs published ip ranges[0]. So yes, they are definitely running scrapers that are this badly written. Also old scraper
55.
▲
by
Tharre
8mo ago
> Does anyone know what's the deal with these scrapers, or why they're attributed to AI? You don't really need to guess, it's obvious from the access logs. I realize not everyone runs their own server, so here are a c
56.
▲
by
Tharre
9mo ago
You can probably already get that if you order a somewhat significant amount of chips directly from Raspberry Pi. They seem to already have everything required for it, it's literally just setting a bit differently during factory progra
57.
▲
by
Tharre
9mo ago
The TPM itself can actually be discrete, as long as you have a root-of-trust inside the CPU with a unique secret. Derive a secret from the unique secret and the hash of the initial bootcode the CPU is running like HMAC(UDS, hash(program)) a
58.
▲
by
Tharre
9mo ago
If that's a concern, you can lock the OTP either permanently or with a password, before you hand them out. Or just use the older RP2040. But I don't think that "targeting the education market" is accurate in the first pl
59.
▲
by
Tharre
10mo ago
It's worth noting that strcpy() isn't just bad from a security perspective, on any CPU that's not completely ancient it's bad from a performance perspective as well. Take the best case scenario, copying a string where th
60.
▲
by
Tharre
10mo ago
Not true, see "Extensions from Lua 5.2" here: https://luajit.org/extensions.html
More ›