Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
XMPPwocky
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
XMPPwocky
2y ago
Yes, a few hours ago. I used no cypher.
62.
▲
by
XMPPwocky
2y ago
i cracked it by considering (rot13) gur "prafbefuvc" shapgvbaf nf na benpyr - fbzr "vaabprag" guvatf ner yvxryl gb trg erwrpgrq jura gurl ner fvzvyne gb, be va fbzr jnl gbhpu ba, guvatf gur zbqry vf gelvat gb uvqr.
63.
▲
by
XMPPwocky
2y ago
Ah, of course, that makes sense- thanks for the answer!
64.
▲
by
XMPPwocky
2y ago
I'm not a cryptographer- what's the attack/failure mode of "standard HSM key recovery, but the 'PIN' sent to each realm is actually HMAC(some_identifier_for_each_realm, PIN), and each realm stores just one shar
65.
▲
by
XMPPwocky
3y ago
if you patch out the CRC check in the binary with echo -ne "\x90\x90" | dd if=/dev/stdin of=tsac bs=1 seek=23914 conv=notrunc you can corrupt the compressed files with very interesting results: https://meow.s
66.
▲
by
XMPPwocky
3y ago
> can't exactly use GPS time for synchronization if you're measuring GPS interference Can other GNSSes (Galileo/BeiDou/GLONASS/etc) give usable timestamps? Seems like it'd be tricky for a jammer to target al
67.
▲
by
XMPPwocky
4y ago
Modern terminals are not supposed to allow things like this (though there are bugs!) There's historically been stuff like "type the window title as if it was text entered on the keyboard"; since you can set the window title
68.
▲
by
XMPPwocky
4y ago
That's nothing- run `curl https://xmppwocky.net/curlme.txt ` on, say, OS X Terminal.app (and a lot of Linux terminal emulators, too) and your terminal window will do things like steal focus, maximize and minimize repeat
69.
▲
by
XMPPwocky
4y ago
I think I can do a decent job of steel-manning this- I might be a bit unfair because I think it's rather morally reprehensible and deeply harmful (and also suspect these are only the stated motives of folks pushing this idea), but I
70.
▲
by
XMPPwocky
4y ago
You seem to be describing something like a classic P2P content-distribution system - BitTorrent w/ magnet links, IPFS, CoralCDN, etc. Could you explain a bit more what part of your proposal would be incompatible with those existing sys
71.
▲
by
XMPPwocky
4y ago
This video seems to confuse semiconductors with "materials with a negative thermal coefficient of resistivity". Saying "this gets more conductive as you heat it up" does not a semiconductor make, as far as I understand.
72.
▲
by
XMPPwocky
4y ago
https://i.imgur.com/VDUs5Ej.png seems like a fairly standard prompt
73.
▲
by
XMPPwocky
4y ago
https://socraticmodels.github.io/ seems somewhat related, using a LLM as the top-level model.
74.
▲
by
XMPPwocky
4y ago
at least one of the RCE vulns seems to be exploitable even without connecting to any network (reachable via probe response handling).
75.
▲
by
XMPPwocky
5y ago
and why should anybody else trust her? well, if she just says "actually, I'm right and the science is wrong", nobody should! Anybody can say that, regardless of whether they're right or not. I could say that! if she sa
76.
▲
by
XMPPwocky
5y ago
"how does someone in her position know they're right and the research is wrong, and not the reverse?" This is where you pull out the rusty ol' tools of Figuring Things Out From Evidence, which mostly boil down to: come u
77.
▲
by
XMPPwocky
5y ago
sure thing! talking to a large number of folks right now and generally have a lot of outlets for My Bullshit, but I might pop in at some point. p.s. on the registration form, my brain expected "username, email, password" and not &
78.
▲
by
XMPPwocky
5y ago
Exactly! That's a good expression of the underlying point- that's why we've got to be annoying in private . It's a scalability issue. If everybody posted stuff like this on HN, it'd be hard to talk about actual tec
79.
▲
by
XMPPwocky
5y ago
Exactly!!! It shouldn't be terrifying, and everybody "knows" that. But that doesn't help if you have a weird PTSD reaction to the idea of "questioning your own beliefs and then changing them" because you'r
80.
▲
by
XMPPwocky
5y ago
Ah, shoot, no, sorry, my paws slipped on the keyboard and I accidentally typed that out. Crap. Weird that it's so coherent, but I guess, hey, it's not impossible that /dev/urandom could output that exact string. (Of cour
81.
▲
by
XMPPwocky
5y ago
Of course it is, what sort of sincere statement wouldn't be? Are you satire?
82.
▲
by
XMPPwocky
5y ago
1. yes, "decent human beings" (which don't exist) don't think like that, because it's not ideal to believe things that are not predictive of future expected sense-data. Sorry. 2. People don't deserve to be sile
83.
▲
by
XMPPwocky
5y ago
fwiw these are wrong opinions, not "wrong" opinions. the people who are clueful about things and have already understood enough about social engineering to understand those issues just don't have the dopamine to explain it to
84.
▲
by
XMPPwocky
5y ago
If a person can't even deal with the vague threat of somebody "silencing" them, they're likely to be too scared of thinking to be worth talking to. They don't "deserve to be silenced" any more than a spa
85.
▲
by
XMPPwocky
5y ago
> Being able to quickly register new "throw-away" accounts is useful for those with the "right" opinion, and because of the fingerprinting and tracking, useless to those with the "wrong" opinion. Nah, anybod
86.
▲
by
XMPPwocky
5y ago
Depending on what you want to do with it, there's always https://github.com/cannadayr/git-sqlite
87.
▲
by
XMPPwocky
5y ago
"There's an inherent physics limitation when trying to strap a whole human body to the side of something small (and generally depicted as being strapped on your back, Bobba Fett style). The center of mass is off." While obvio
88.
▲
by
XMPPwocky
5y ago
Two things- one, as a sibling comment's mentioned, it absolutely includes implementation of cryptographic primitives too. There are quite a few subtle bugs (mostly, but not entirely, side-channels) that end up being utterly catastrophi
89.
▲
by
XMPPwocky
5y ago
Offensive or defensive? For offensive (at least in the non-classified space), major players include e.g. Riscure. A fun historical quirk about chip-level security is that most of the experienced people and firms have at least some ties to c
90.
▲
by
XMPPwocky
5y ago
I'm trying to read this charitably but can't. As far as I can tell, they're describing the concept of "fuse some keys into chips" (and/or "use a PUF"?) and "do secure boot". Where's the
More ›