Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ZoFreX
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
ZoFreX
9y ago
I would have to read their source code to answer that question (I know almost nothing about 1Password). Some password managers just call a PGP executable. Others are assembling crypto primitives into larger pieces and making choices like &q
32.
▲
by
ZoFreX
9y ago
This is off-topic. We are talking about security vs obscurity in the context of cryptography libraries.
33.
▲
by
ZoFreX
9y ago
As I said I'm not a fan of the phrase "don't roll your own crypto". I don't disagree that that (obviously!) prevents new crypto libraries being written. But if you're going to do it, you damn well do it right,
34.
▲
by
ZoFreX
9y ago
Game companies are a great example because: 1) they invest 6 or 7 figures in this (piracy prevention is big money) 2) they still get it wrong 3) they not only get it wrong, they get in wrong in ways that teenagers still in high school can b
35.
▲
by
ZoFreX
9y ago
> In some cases, security through obscurity works well in practice. This is not one of those cases. Absolutely not. I'm moderately competent at finding security bugs in things, but I doubt I could find any in OpenSSL. I am confident
36.
▲
by
ZoFreX
9y ago
I am terrified that I do not consider myself competent enough to write a crypto library, and yet there isn't a single mention - in this article, nor at the time of writing the comments here on Hacker News - of many of the pitfalls I kn
37.
▲
by
ZoFreX
9y ago
I think it's important to recognise how good - and effective - data protection laws are in some countries. The biggest challenge is US companies flagrantly ignoring them. In other words, the main thing holding Europe back from protecti
38.
▲
by
ZoFreX
9y ago
> just like every other store This is illegal in many countries, so waving it off as "everyone does it" is not only morally weak, but factually inaccurate.
39.
▲
by
ZoFreX
9y ago
For RHEL/Centos/Fedora (the only ones there I would call "major") you have to enable a separate repo, which isn't really the same as being in the official repos.
40.
▲
by
ZoFreX
9y ago
I think it's fair to say that anyone releasing software written in Rust on Debian right now has extra work to do, and is likely to be treading new ground.
41.
▲
by
ZoFreX
9y ago
For Debian at least, cargo isn't even in stable yet AFAIK. And even then, having the compiler and package manager available is a step along the way, but insufficient. Anything non-trivial depends on libraries, which with C programs are
42.
▲
by
ZoFreX
9y ago
Is it really the time, yet, to start advocating for rewrites in Rust? Worth considering for new projects, definitely. Using to write new components of existing projects, maybe. But rewriting existing work? I'm concerned if we start pus
43.
▲
by
ZoFreX
9y ago
Thank you for sharing that link, I've been looking for resources for gently improving my ASM skills and this looks perfect!
44.
▲
by
ZoFreX
9y ago
I had no idea, that's really interesting!
45.
▲
by
ZoFreX
9y ago
I don't really know assembly (other than a little RISC) and I breezed through HRM, but I still had a lot of fun with it. There's some real charm and humour wrapped around its programming puzzles, unlike most games of its ilk. The
46.
▲
by
ZoFreX
9y ago
If you like this you might also like the games "Human Resource Machine" and "TIS-100", which both give a similarly visual insight into how computers work.
47.
▲
by
ZoFreX
9y ago
This definition of TDD either supposes that it is possible to write software with zero bugs using TDD, or that your project ceases to be TDD as soon as a bug is discovered, or any other change is required. I propose this definition is not v
48.
▲
by
ZoFreX
9y ago
But Ruby Koans is a tutorial on Ruby, not on TDD.
49.
▲
by
ZoFreX
9y ago
I'm more of a learning by doing person. Here's three exercises that you'll learn a lot doing: 1) https://www.ssllabs.com/ssltest/ - try to get an A+. It's not important to in most cases in practice,
50.
▲
by
ZoFreX
9y ago
I'm not sure how much that adds though because at the time of them writing that, there was a lot of speculation online that it was NK based on some shared code. That argument was baseless, the amount of shared code was far too small an
51.
▲
by
ZoFreX
9y ago
If they wanted to find vulnerable ssh daemons it would be much faster and easier to scan the web than wait for people to enter their details here. Or to put it another way: if you're worried that your SSH is vulnerable, fix it. Don
52.
▲
by
ZoFreX
9y ago
(this is purely about the OCSP server outage, others have commented on the issuance server outage) In most cases, clients ignore any failure to contact the OCSP servers. This means that: 1) OCSP servers aren't an additional point of fa
53.
▲
by
ZoFreX
9y ago
There's some really great advice here from others. I'll add what I personally needed to learn: I got comfortable with the small subset of the language I knew, and then used those tools to try to tackle all problems. I eschewed som
54.
▲
by
ZoFreX
9y ago
If I could go back in time and give myself advice it would be: 0) Nothing is too hard to do, no matter how much those doing it might seem like towering titans many levels above you, or how out of your reach it may seem. Nothing is too hard,
55.
▲
by
ZoFreX
9y ago
Huh, that's a really useful tip, thank you.
56.
▲
by
ZoFreX
9y ago
True, I was a little unfair on you :) Still, I see the software you're using as much a part of the problem as Windows here. Needing weeks of solid up-time to complete something is a challenge and doesn't seem like a realistic assu
57.
▲
by
ZoFreX
9y ago
My point is that by connecting your machine to the internet it ceases to be solely a question of "your machine" and "your rights". There are other systems on the network too and you have a certain amount of responsibilit
58.
▲
by
ZoFreX
9y ago
> If someone needs to skip an update on their own machine and their own network that is their right. And if you want your machine to DDoS Playstation Network that's your right too, right? And if I want my kid to get measles and spre
59.
▲
by
ZoFreX
9y ago
> I once had to turn off updates on all laptops in my workplace so we could use the internet. In such a situation you can dramatically reduce the bandwidth required by setting up an update server. There's no need for every laptop to
60.
▲
by
ZoFreX
9y ago
> No mention that disabling Microsoft update trend is a logical answer No, it isn't. Disabling update isn't a logical answer to _anything_ except "what's the best way to get malware". If you don't want Micro
More ›