Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
amirmc
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
181.
▲
Not-quite-so-broken TLS
(nqsb.io)
34 points
by
amirmc
11y ago
|
6 comments
182.
▲
by
amirmc
11y ago
I'm not sure your final disadvantage really applies. If we accept that most deployments to the cloud (eg. EC2) are essentially single-purpose VMs, then Xen is already scheduling resources this way (& presumably well enough).
183.
▲
by
amirmc
11y ago
Each different Unikernel approach has its benefits and trade-offs. Rumprun lets you 'unikernelize' legacy software using well-established OS components (eg out of NetBSD) -- but you're still exposed to classes of bugs and pot
184.
▲
Rumprun Tutorial: Serve a static website as a Unikernel
(github.com)
50 points
by
amirmc
11y ago
|
12 comments
185.
▲
by
amirmc
11y ago
Sadly, no. Anyone who's studied human emotion know that the dichotomy doesn't make sense (especially if studying the neural basis of emotions [1]). I hope this movie will help to shift some of that mindset. [1] My PhD was the int
186.
▲
by
amirmc
11y ago
If the opinion of the dead didn't matter, Wills would be pointless. In this scenario, if you don't want the living to access your phone, then just state that.
187.
▲
by
amirmc
11y ago
"If you can get $200 million from private sources, then yeah, I don’t want my company under the scrutiny of the unwashed masses who don’t understand my business," said Danielle Morrill" Wow. I get that private money is eas
188.
▲
by
amirmc
11y ago
My point is that I don't believe any of the dynamics would actually change. White hats would still report issues (they're not necessarily doing it for the money) and nefarious types will still trade/sell exploits.
189.
▲
by
amirmc
11y ago
Your comment seems to conflate 'our', 'us' and 'we' with the drug companies themselves. There should be more to such negotiations than just whatever is in the (self)interest of US-based drug companies. That all
190.
▲
by
amirmc
11y ago
Isn't that pretty much what we have already with things like openSSL? Find an exploit and suddenly you've exposed everyone. I don't think public bounties would change any of the dynamics around this situation.
191.
▲
by
amirmc
11y ago
edwintorok is comparing s2n with the OCaml-TLS stack. See the links at the end of his comment (and the one below) https://github.com/mirleft
192.
▲
by
amirmc
11y ago
> It's interesting, but isn't 10BTC($2500) prize too low to tell us anything about how secure is this ? No amount of prize money can ever really tell you how secure something is. We knew this before we announced it (see ba
193.
▲
by
amirmc
11y ago
Yup, I totally agree with your points. However, I also feel there's some 'fun' factor here too -- and we hoped to appeal to it. By having the entire code base available, it also reduces the need for reverse engineering that o
194.
▲
by
amirmc
11y ago
We're aware that bounties can't demonstrate security (mentioned early on in the post). However, putting such items out there and inviting review helps to stress-test the stack. Right now, unikernels aren't in major production
195.
▲
by
amirmc
11y ago
I wonder that you're forgetting that this is an entire VM. Including all the other bits necessary to function, such as a networking stack, web server, etc. it's not really fair to compare it with just OpenSSL this way. It shou
196.
▲
by
amirmc
11y ago
Yeah, we thought these were pretty cute. Almost a social engineering attack.
197.
▲
by
amirmc
11y ago
This is a follow-up to a post back in February. The Piñata was originally meant to run for about a month but the team has kept it running much longer (it's still going). HN discussion when the Pinata was released: https://n
198.
▲
Reviewing the Bitcoin Piñata
(mirage.io)
73 points
by
amirmc
11y ago
|
14 comments
199.
▲
MirageOS v2.5 with full TLS support
(mirage.io)
115 points
by
amirmc
11y ago
|
9 comments
200.
▲
by
amirmc
11y ago
This reasoning makes no sense to me. It's like: Alice: "Doing X will prevent bugs like Y!" Bob: "Oh, but it does nothing for bugs like Z. I just won't bother at all, then". Why would you not want to try and
201.
▲
CueKeeper Internals: Experiences with Irmin, React, TyXML and IndexedDB
(roscidus.com)
10 points
by
amirmc
11y ago
|
0 comments
202.
▲
by
amirmc
11y ago
I find that view to be a little harsh. It demeans all those people who choose to work for organisations that can't/don't generally pay as much but are driven by other purposes (eg NGOs).
203.
▲
by
amirmc
11y ago
Popular sentiment isn't really a sensible thing to compare with. Most people have no idea how technology works nor a proper understanding of what they're actually exposing themselves to. Products like this would be great if they
204.
▲
by
amirmc
11y ago
You're correct that patio11 didn't say that but I think it's helpful to remind people that the power law still exists. It's really easy to fall into the trap of survivorship bias and I'm sure there are plenty of fol
205.
▲
by
amirmc
11y ago
This was written about 5-6 months before the sexual harassment claims, lawsuit, investigation, and the later departure of one of the cofounders. My take on this is that lack of 'management' might seem like fun but there's a r
206.
▲
by
amirmc
11y ago
To be fair, this article also mentions the increase in height.
207.
▲
by
amirmc
11y ago
With the above in mind, here's the text of the original post ( https://www.craigmurray.org.uk/archives/2015/06/five-reasons... ). Five Reasons the MI6 Story is a Lie The Sunday Times has a story claiming
208.
▲
by
amirmc
11y ago
and immediately following this article https://www.craigmurray.org.uk/archives/2015/06/cyber-attack... : The site is under a strong denial of service attack from a bot trying to crash it by overloading with m
209.
▲
by
amirmc
11y ago
There are also more links/resources on the OCaml website. http://ocaml.org/learn/books.html
210.
▲
by
amirmc
11y ago
That was wonderful. Thank you for sharing.
More ›