Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aomix
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
aomix
3y ago
Finding things on the internet can be really hard without reddit. SEO spam has gotten really good at making Google searches useless unless you add “reddit” on the end. Then it’s exactly what you need.
62.
▲
by
aomix
3y ago
I think the idea of using their new libTLS api alongside it was there early on. Adding "easier, foolproof api => even fewer bugs" to the mix. But that didn't seem to get much uptake.
63.
▲
by
aomix
4y ago
These messages come in waves for me. Maybe it is strategy that if I get them constantly I'll tune them out but 5+ over the course of a couple days once a month might trick me? Occasionally they are very determined to get a response and
64.
▲
by
aomix
5y ago
I found the beep on lost (in this case, "lost" but not in a malicious way) tags to be pretty quiet or just not distinctive. While taking care of a friends cat with an airtag in the collar I kept thinking I was hearing a car down t
65.
▲
by
aomix
6y ago
Not really the same thing but I'm blood type O- and do the "Power Red" donation at Red Cross events. I have two units of blood taken out and the red cells and plasma are separated so the plasma can be returned along with sali
66.
▲
by
aomix
7y ago
Would a local DoH server making going between different networks a little clunky? I have unbound handling dns at home but the old way lets the network define where to get dns information and/or allow for multiple options. Seems like Fi
67.
▲
by
aomix
7y ago
The PROT_WRITE tweak is interesting. Being able to enforce a bit of Write XOR Execute behavior in Write OR Execute arenas is nifty. It took this change for me to read into W^X and exactly what it entailed because my naive understanding was
68.
▲
by
aomix
7y ago
Most of the LibreSSL changes were removing features or platform support so I don't know how many of their changes were desired or applicable to OpenSSL.
69.
▲
by
aomix
8y ago
Microsoft dual signs at the moment with SHA1 and 2. SHA1 is used by older versions of Windows and SHA2 by newer versions. This flips a switch so older versions of Windows use SHA2 too.
70.
▲
by
aomix
8y ago
As others have mentioned, TLS 1.3 is not yet supported. But a little bit of context for that decision as of early last year. https://github.com/libressl-portable/portable/issues/228#iss... We will support 1.3
71.
▲
by
aomix
8y ago
My manager pointed out this to me shortly after the video blew up. As soon as he saw the video he suspected something was up but it took him less than half an hour after work that day to track down a shocking amount of information about th
72.
▲
by
aomix
8y ago
I've read horror stories about bad sysadmin jobs but users not using a system as intended don't usually have a body count as a result.
73.
▲
by
aomix
8y ago
Tiny nit. An unveil pledge promise was added so pledging without it is the same as unveil(null, null).
74.
▲
by
aomix
8y ago
It's cool ROP attacks are being mitigated from two directions in OpenBSD. The amount of useful gadgets are being reduced by efforts detailed here AND gadget rich libraries are being relinked at boot or upgrade time. So even if a ROP at
75.
▲
by
aomix
8y ago
I'm really liking OpenBSD as a router for those reasons but it's certainly more work intensive. I'd argue not that much but as soon as you start telling people to ssh into a box and fire up vi you've justifiably lost mos
76.
▲
by
aomix
8y ago
Unveil is programmatic so the developer can restrict the software to only perform expected behaviors. Like the earlier pledge(2) call OpenBSD introduced a few versions ago. A piece of software may have far more access to the filesystem than
77.
▲
by
aomix
8y ago
OpenBSD's filesystem restriction utility is starting to be implemented in the base system. This first large commit from Theo de Raadt is intended to give an example of the intended usage of unveil(2).
78.
▲
OpenBSD – unveil(2) usage in base
(marc.info)
2 points
by
aomix
8y ago
|
4 comments
79.
▲
by
aomix
8y ago
I don't think the unveil(0,0) call to disable/ignore further calls is intuitive. But I'm not sure how you would improve on it beyond creating an unveil_disable() call.
80.
▲
by
aomix
9y ago
Why isn't a basic version of proof of work a reasonable approximation of that for the time being? Ex. to provide a review you must also provide a value that when postpended to your review gives a hash containing some properties that sc
81.
▲
by
aomix
9y ago
I appreciate OpenBSD. Among other things their focus on making APIs that are impossible to misuse and hacking down the scope of a problem to the bone result in a lot of interesting products. Basically if you have to consult anything beyond
82.
▲
by
aomix
9y ago
I worked at a distributor throughout college and the week a drug went generic was party time. The company would ship more of a recently genericized drug in that week than they had until that point. Dropping to ~25% the original price is the
83.
▲
by
aomix
9y ago
These kind of classes are structs with busy work attached. At work I feel a little guilty when I delete them over the course of refactoring but if no processing on the incoming and outgoing data is necessary then public fields are better in
84.
▲
by
aomix
9y ago
It's weirdly impressive that you still find wide, systemic misuse of random number generators in professional products. But maybe un-use is a better term for not using one where appropriate. In a Def Con talk Dan Kaminsky described it
85.
▲
by
aomix
9y ago
From discussions about this it seems like the consensus is that the nature of neutrinos would kill any attempt to make this method of communication scale. But boy it would cool to have straight line communication between any two points on e
86.
▲
by
aomix
9y ago
Even following the OpenBSD mailing lists I didn't realize all the anti ROP features they put into this release. The big idea is that popular attack surfaces are randomly relinked at boot/upgrade/run time. Now now the kernel,
87.
▲
by
aomix
9y ago
Unless there is a strong mandate from the top to take time for maintaining and reviewing code I'd say absolutely. Even if those were in place I'd say a strong maybe. Ignoring competency some people just have wildly divergent ways
88.
▲
by
aomix
9y ago
I appreciate the ruthless design choices behind Go. Crafting a language so there are as few ways as possible, and preferably one, to solve a problem must be beautiful at a large scale organization. In my experience java codebases in big com
89.
▲
by
aomix
9y ago
That number seems stupendous but I don't know enough to know that. My very casual understanding was that 100G was state of the art.
90.
▲
by
aomix
9y ago
Or least if you drink most of the six pack you stop caring about taste. Unlike Soylent. Disclaimer: I drink Soylent's Coffiest every morning.
More ›