Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alcari
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
alcari
11y ago
The usual term is "Chinese Wall" [1]. [1] https://en.wikipedia.org/wiki/Chinese_wall
32.
▲
by
alcari
11y ago
It's something that has already changed. This is only happening because the iPhone in question is a 5C, which doesn't have a Secure Enclave.
33.
▲
by
alcari
11y ago
If you can run the app on a jailbroken/rooted device, it's fairly easy to beat certificate pinning in a few different ways. Two that come to mind are: * find the certificate file in the app and replace it with your own. * hook the
34.
▲
by
alcari
11y ago
OpenZFS was forked from the original Sun/Solaris ZFS code base, which Sun made available regularly. It's still CDDL.
35.
▲
by
alcari
11y ago
No, and it effectively never will be. See: http://open-zfs.org/wiki/FAQ#Do_you_plan_to_release_OpenZFS_...
36.
▲
by
alcari
11y ago
A statute of limitations prevents you from charging someone with a crime once some period of time elapses. It says nothing about how long you have to prove your case in court. That's more likely to run afoul of the right to a speedy tr
37.
▲
by
alcari
11y ago
They're acting as cache, to hide the latency to your RAM. They're implementing increasingly niche instructions that speed up ever smaller sets of programs. They're mostly sitting idle, because power usage hasn't fallen a
38.
▲
by
alcari
11y ago
That's a classic canary trap. [0] [0] https://en.wikipedia.org/wiki/Canary_trap
39.
▲
FE-Schrift – forgery-impeding typeface
(en.wikipedia.org)
143 points
by
alcari
11y ago
|
27 comments
40.
▲
by
alcari
11y ago
Additionally, old versions will expire, so there's a limit to how far back you can keep someone, even if you continuously intercept the update attempts.
41.
▲
by
alcari
11y ago
Maybe it changed at some point (8?), or my memory's fuzzy. I haven't looked at it in several years. Either way, trusting a root CA generally looks far less threatening than the self-signed certificate warnings.
42.
▲
by
alcari
11y ago
It's scary how easy it is to add new roots on all major platforms. You just click on the CA link and get a response with the appropriate MIME type back, then: * Windows gives you a helpful little wizard wherein you click "next&quo
43.
▲
by
alcari
11y ago
Don't fall back. If you don't have a reasonable enough environment to get a PRNG, you should halt and complain very loudly. As for actually generating random numbers, here's a good explanation from 'tptacek: http:/
44.
▲
by
alcari
11y ago
People use DSA for the same reasons they use RC4, 3DES, and MD5: that's what the other party's 10 year old legacy platform that will never be updated supports.
45.
▲
by
alcari
11y ago
They probably just said that because it's ZFS, and didn't look at the upstream. IIRC, Nexenta pulls from Illumos like all the other ZFS-based storage vendors.
46.
▲
by
alcari
11y ago
`rm` is definitely one of them, it's just suppressed by the `-f` flag. (examples from Ubuntu) $ touch foo $ chmod -w foo $ rm foo rm: remove write-protected regular empty file ‘foo’? There's also the immutable
47.
▲
by
alcari
11y ago
That's an Economist thing. They feel that "what is written is more important than who writes it"[0]. [0]: http://www.economist.com/blogs/economist-explains/2013/09/ec...
48.
▲
by
alcari
11y ago
Sure, but that doesn't help in the context of zfs send, which serializes at the filesystem level for transport. The stream is still going to be in plain text. In fact, Oracle's ZFS still sends the stream decrypted and decompressed
49.
▲
by
alcari
11y ago
Nobody outside of Oracle supports encrypted ZFS, and that's probably not going to change any time soon (I'd love to be wrong, though).
50.
▲
by
alcari
11y ago
I seem to recall this being on HN a few months ago: https://github.com/shazow/ssh-chat
51.
▲
by
alcari
11y ago
That method's mentioned in the article. See the section 'The Obvious Problem'.
52.
▲
Liquid Mirror Telescope
(en.wikipedia.org)
1 points
by
alcari
11y ago
|
0 comments
53.
▲
by
alcari
12y ago
Black Forest Games is still around, and making Giana Sisters games.
54.
▲
Enough with the Salts: Updates on Secure Password Schemes
(chargen.matasano.com)
16 points
by
alcari
12y ago
|
0 comments
55.
▲
Ditto Blocks – The Amazing Tape Repellent (2006)
(blogs.oracle.com)
6 points
by
alcari
12y ago
|
0 comments
56.
▲
by
alcari
12y ago
The ZFS crypto implementation (which isn't really available outside Oracle's Solaris) uses AES-GCM, which solves the authentication problem.
57.
▲
by
alcari
12y ago
This brings back some memories, but not the ones everyone else seems to have: I'd spent several hours (at least) looking at MSDN docs, various DLLs on my system, and the contents of the Windows SDK trying to figure out how to get an ol
58.
▲
by
alcari
12y ago
Give those shares votes, and let shareholder interests define value for you.
59.
▲
by
alcari
12y ago
The problem isn't necessarily with the intentions of the people running the site. It could be an attacker altering the site to steal the information.
60.
▲
by
alcari
12y ago
One-time pads are still secure because the decryption process will produce every plaintext the same length as the ciphertext, and you'll have no way of knowing which one was correct.
More ›