Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aprescott
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
aprescott
13y ago
The strings and documentation don't make it too easy to distinguish, but the docs do explicitly distinguish between aDH and ADH. I think "DH" includes any and every cipher that might use DH, but there's a good chance tha
32.
▲
by
aprescott
13y ago
I indeed managed to get a B without trying to mitigate against BEAST (d). The trouble does seem to be that RC4 isn't vulnerable to BEAST, but it's not desirable because of its other vulnerabilities. Since BEAST was fixed in TLS 1.
33.
▲
by
aprescott
13y ago
> Note that ECDH and DH are different authentication mechanisms: these require special certificates and offer no forward-secrecy. I contacted the author about this, but I don't think this is correct. The OpenSSL ciphers documentat
34.
▲
by
aprescott
13y ago
I think you missed the "[/sarcasm]"!
35.
▲
by
aprescott
13y ago
The presentation on the vulnerability, from the two Microsoft employees, for those interested: http://rump2007.cr.yp.to/15-shumow.pdf Amusingly, from the PDF: > WHAT WE ARE NOT SAYING: > NIST intentionally put a back
36.
▲
by
aprescott
13y ago
> Very few people compile the Windows binaries from source; it is exceedingly difficult to generate binaries from source that match the binaries provided by Truecrypt (due to compiler options, etc.) I don't know if Tor considers its
37.
▲
Did NSA Put a Secret Backdoor in New Encryption Standard? (2007)
(wired.com)
187 points
by
aprescott
13y ago
|
32 comments
38.
▲
by
aprescott
13y ago
I believe homomorphic encryption would address this.
39.
▲
by
aprescott
13y ago
This seems to be straight from Wikipedia and then wrapped in a while loop: https://en.wikipedia.org/wiki/Netcat#Setting_up_a_one-shot_w... netcat's cool, but the post could've gone a bit further. If it's
40.
▲
by
aprescott
13y ago
The difficulty of relying on the same name for separate ideas. :)
41.
▲
by
aprescott
13y ago
Not necessarily refuting what you're saying, but here's an interesting take on "purely by chance" from Buffett, by analogy of coin flipping and getting a run of heads: http://www.tilsonfunds.com/superinve
42.
▲
by
aprescott
13y ago
I'm not an investor but I've read both of Graham's main books. I don't think value investing in the Graham sense would lead you to a company as big as Apple, and certainly not with the company's stock as 75% of a po
43.
▲
by
aprescott
13y ago
You can at least look at the difference each second, when the figures update.
44.
▲
by
aprescott
13y ago
If the start of this post put you off because it sounds arrogant, please keep reading. It is an intentional setup to highlight the core point, which I think is in this paragraph: But the environment matters a lot less than the fact that wh
45.
▲
by
aprescott
13y ago
I don't think this is true. MIT explicitly allows sublicensing, meaning you can essentially just change the license on any derivative. The copyright notice needs to remain, though.
46.
▲
by
aprescott
13y ago
The trouble with this is that you now have to switch "commented" to "active" and vice versa, when I think the aim was to have a single-char switch (although the syntax is pretty horrible, to be honest).
47.
▲
by
aprescott
13y ago
This seems to be a common complaint, and the response seems to frequently be: you don't need to replace all your food intake. 50% of the time you eat you might find it tedious and boring, so you can leave the other 50% for pleasurable eatin
48.
▲
How Jason Rohrer Won The Game Design Challenge
(rockpapershotgun.com)
2 points
by
aprescott
14y ago
|
0 comments
49.
▲
by
aprescott
14y ago
I followed this to a geometer's compass at 29.14,129.19, but there doesn't seem to be any other coordinates. (One before that was at 24.3775,124.1555.)
50.
▲
by
aprescott
14y ago
Damn you, Poe! :(
51.
▲
by
aprescott
14y ago
I don't really understand this approach. Won't the false positive rate be close to 100%? Humans are going to get the captcha right every time. If it's supposed to be a honeypot system, the input should be hidden from human users to avoid th
52.
▲
The Price of Wine
(blog.priceonomics.com)
8 points
by
aprescott
14y ago
|
0 comments
53.
▲
by
aprescott
14y ago
As I said, it's doable with scripts and whatnot, but transparent and built into git would be awesome. I see it as something you just set up on a remote repository server. No need to make N developers aware of it, or aware of the script, or
54.
▲
by
aprescott
14y ago
You know what I want? Transparent failover somehow baked into git remotes. you <--> (X <--> Y) If you push to and pull from X, and X should be unavailable, automatically start using Y. When X is pushed to, check wit
55.
▲
Digging Around In The Google Graveyard
(blog.priceonomics.com)
1 points
by
aprescott
14y ago
|
0 comments
56.
▲
by
aprescott
14y ago
Unless an employee contract says otherwise, the default copyright position is that all work done is part of "work-for-hire".[1] There are a few reasons for this, and Joel Spolsky covered them pretty well.[2] [1]: http://en.wikipedia.org/wi
57.
▲
by
aprescott
14y ago
Speak to them and get an exemption, even on a case-by-case basis. Those ideas need to not die out, and you might find that being able to give life to them makes you simply a better employee.
58.
▲
by
aprescott
14y ago
It maybe isn't simple enough for Joe Blow to use (yet?), but I started working on Serif[1] specifically to get away from having to manage the filesystem, without losing the simplicity of everything just being files. Having a web interface t
59.
▲
by
aprescott
14y ago
Not only that, in Ocean's Eleven they don't just place bets, they break into a vault, so the only similarity with the film seems to be that a camera feed was involved.
60.
▲
by
aprescott
14y ago
Here's something similar that is cumbersome to stop, but not so disastrous: yes 'yes yes&' | sh
More ›