Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
als0
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
181.
▲
by
als0
3y ago
Bus sniffing can be mitigated by encrypting communications using the TPM's in-built parameter encryption capabilities.
182.
▲
by
als0
3y ago
Here is the thread about ARM https://github.com/chipsec/chipsec/issues/461
183.
▲
by
als0
3y ago
I wonder why they are launching their own tool instead of enhancing CHIPSEC, which already has a large community https://github.com/chipsec/chipsec
184.
▲
by
als0
3y ago
True but there is no security testing framework that can analyse TF implementations. It seems like something that ought to be done by the CHIPSEC open source project, but they don't seem to have resources.
185.
▲
by
als0
3y ago
> These were prone to (relatively primitive) bus sniffing attacks, where you would hook up a Logic Analyzer to the bus, watch a regular boot procedure grab the disk key, and then use software like Dislocker to extract all data from a USB
186.
▲
by
als0
3y ago
TPM is more or less an API specification. The specification is fine but people are worried about implementation backdoors and pre-provisioned keys. It should be possible to have an open source public trustable implementation that anyone can
187.
▲
by
als0
3y ago
It's worth mentioning that standalone TPM chips from Infineon and others are a lot more hardened than Intel or AMD's fTPMs. Infineon's TPMs are tested against fault injection attack, package removal, side channels and so on.
188.
▲
by
als0
3y ago
Not got a reference but one of the new Lenovo ARM laptops claims to have 26 hour battery life. If true then that's pretty compelling.
189.
▲
by
als0
3y ago
Does anyone else remember when Ubuntu releases felt...significant? Since 12.04 changes have felt incremental.
190.
▲
RC: A New Shell for Unix
(drewdevault.com)
13 points
by
als0
3y ago
|
1 comments
191.
▲
Writing Helios drivers in the Mercury driver environment
(drewdevault.com)
3 points
by
als0
4y ago
|
0 comments
192.
▲
by
als0
4y ago
Last time I tried, you had to disable UEFI secure boot to get PopOS to start. And then follow some complex steps to self sign all those components. Regular Ubuntu (and Debian) does not need any of this.
193.
▲
by
als0
4y ago
But no secure boot support.
194.
▲
Why Kids Aren’t Falling in Love with Reading
(theatlantic.com)
1 points
by
als0
4y ago
|
1 comments
195.
▲
by
als0
4y ago
Blinded peer review at least enforces some degree of impartiality and anonymity, though obviously challenging in practice.
196.
▲
by
als0
4y ago
Looking at https://plaudit.pub and trying to understand it. It seems like a technical solution trying to solve a social problem (which I dare say is impossible). There's too much politics in academia for researchers to obje
197.
▲
All travelers to the UK will need pre-authorization by 2025
(cnbc.com)
43 points
by
als0
4y ago
|
79 comments
198.
▲
by
als0
4y ago
> Oh, and that 500-line shell script probably ends up being a 5000-line Python monster anyway. This is an important distinction, and probably why I still make shell scripts. I've found utilities like `shellcheck` invaluable for maki
199.
▲
by
als0
4y ago
YubiKey already supports those scenarios, I think.
200.
▲
by
als0
4y ago
That would be the right priority. Double the battery would make it even more competitive with Nintendo.
201.
▲
by
als0
4y ago
> Decades of exploits have me convinced that microkernels are the only real path towards security. Not necessarily. Check out the CHERI project, which has a reasonably good handle on exploits https://www.cl.cam.ac.uk/rese
202.
▲
by
als0
4y ago
I would suppose their pricing model is not competitive.
203.
▲
by
als0
4y ago
Agreed. It feels like a huge amount of effort for little reward, especially because it does not eliminate all the possibilities.
204.
▲
by
als0
4y ago
> This is exactly what I see happening. AMD will have to move to RISC-V to stay competitive The year is 2259. The name of the place is Babylon 5.
205.
▲
by
als0
4y ago
Why would AMD do that today though? They are in a privileged position to have an x86 license and zillions of customers asking for an x86. AMD once made some ARM chips and realised they didn’t need to.
206.
▲
Classical virtualization rules applied to RISC-style atomics
(axio.ms)
11 points
by
als0
4y ago
|
0 comments
207.
▲
by
als0
4y ago
> There isn't as much pressure in tech to deliver low level results quickly. This isn't my experience. Companies producing hardware or devices tend to think hardware-first. Any firmware or software that needs to be developed is
208.
▲
by
als0
4y ago
Getting internal server error on some Git repos too. "Git Operations - Degraded"
209.
▲
by
als0
4y ago
I think you raise the right point. I remember reading about how the team was burned out. > What was the atmosphere like during the final days of coding? I think there was a lot of panicking going on. But it was still very organised, ther
210.
▲
by
als0
4y ago
Projects like this is why I come to Hacker News.
More ›