Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bri3d
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
bri3d
3mo ago
> A vulnerability can’t leak your key if the TPM doesn’t know the entire key and relies on the user to supply the missing parts of the key in the form of a PIN. First off: I agree with your thesis, BitLocker with PIN is Just Fine, equiva
62.
▲
by
bri3d
3mo ago
For the system drive they seem to really strongly prefer PIN, which also doesn't have the problems linked above. I was going to use PIN as my example but didn't want to explain another set of recent BitLocker conspiracy theories y
63.
▲
by
bri3d
3mo ago
Having dealt with FileVault in this context, it's also frustrating; it's really common to have it fail to follow the logged-in user's credentials, and if you use any kind of federated login, you will frequently get users with
64.
▲
by
bri3d
3mo ago
The issues you linked with BitLocker are obvious properties of BitLocker-with-SecureBoot-only architecture. If you configure Linux that way, you get similar issues (for example, it's pretty easy to mis-configure TPM sealed disk encrypt
65.
▲
by
bri3d
3mo ago
It’s less a question of people and more one of "Why doesn't a hardware company want to give away their IP design documentation?"
66.
▲
by
bri3d
3mo ago
For "copter" style drones, 3D printing is basically a "noob" meme at this point; everyone thinks it's a good idea, tries it, and realizes that it's actually really hard and doesn't work. Copter-style drone
67.
▲
by
bri3d
3mo ago
Low end and most open source stuff will use a PID inner loop for “fast path” control (stabilization) and either a second PID loop or something a little better (Kalman filter etc) for the slow path (position / path hold). Higher end stu
68.
▲
by
bri3d
3mo ago
Most filament based printed frames end up with really nasty resonance; it’s possible to engineer damping around the issue with some clever 3D design if the parameters of the prints are measured, but overall 3D printing copter frames doesn’t
69.
▲
by
bri3d
3mo ago
Ahh, thanks for the correction, it's the window manager that's closed (lipstick-jolla-home). Regardless, I will stand by my statement that a fully open-source build of AOSP is significantly more complete and useful than a fully op
70.
▲
by
bri3d
3mo ago
> It's still more open than AOSP I don't think this is true at all? AOSP is completely open source modulo driver blobs (which Sailfish has too) and Google services. One can make a fully functional system, modulo drivers, out of
71.
▲
by
bri3d
4mo ago
> Somehow hardware giants like Dell, HP, SuperMicro, etc didn't make a product like this, even at their peak in 2000s or during cloud boom in 2010s. Not so sure about this one. HCI (Hyperconverged) rack units (where storage and com
72.
▲
by
bri3d
4mo ago
No? The article extensively discusses the use of XOrg. With that said, the Wine graphics abstractions are a lot better now and there are many working backends (winex11, winemac, winewayland, winehaiku, etc.)
73.
▲
by
bri3d
4mo ago
The default reference firmware for the nRF52840 Desktop Dongle does this. https://github.com/nrfconnect/sdk-nrf/blob/main/applications...
74.
▲
by
bri3d
4mo ago
I am not aware of this being a regulatory matter in any state, California included. Retailers choose not to carry them because they are expensive to ship due to their hazardous materials classification and an attractive theft / crime t
75.
▲
by
bri3d
4mo ago
Microsoft is the trusted party because they convinced hardware manufacturers to install their keys by default; that's it. A lot of commercial/industrial/pre-branded OEM hardware comes without Microsoft's keys, they'
76.
▲
by
bri3d
4mo ago
(not the parent poster, but same setup): Is it better than UI Protect? No, but you can make it about the same. I have the same popular setup (Frigate) although I just use ONNX on an 11th-gen Intel CPU instead of a Coral (unless you are tryi
77.
▲
by
bri3d
4mo ago
Yes? These things directly follow one another: VW are obsessed with letter-of-the-law compliance, so things like end-runs around test routines are obvious solutions. And VW didn't single-handedly destroy the diesel market; economics an
78.
▲
by
bri3d
4mo ago
The historical data is aggregated in some "cloud" rather than in the car, but if you want to collect and aggregate the data locally, you can still, for now at least. Car Scanner Pro and ABRP (A Better Route Planner) are both reall
79.
▲
by
bri3d
4mo ago
> Out of curiosity, do they not pressurize the cargo hold? Well, the DC-3 is a fun example, because it wasn't pressurized to start with. But no, normally converted freight aircraft are fully pressurized; it's more expensive and
80.
▲
by
bri3d
4mo ago
That's VW AG "MIB" - a lot of these units had fixed per-infotainment-model root passwords and a shell service exposed over SSH or Telnet, so one could dump the flash memory directly from the board and crack the password hashe
81.
▲
by
bri3d
4mo ago
I'm hoping this comment is a joke? It's kind of nonsensical. > I wish other car makers were as reasonable as Honda here. I doubt they did this on purpose. > No "evil valet" with half a brain cell would waste time h
82.
▲
by
bri3d
4mo ago
Hyundai head units at one point used an RSA key you got by googling “RSA key” (no joke: https://programmingwithstyle.com/posts/howihackedmycar/ ), an honestly even more amazing mistake since it required effort rat
83.
▲
by
bri3d
4mo ago
AMD Software Engineers giving AMD Stupid Gaming Accessory Software Engineers access to a signing system backed by PSP seems like a much worse outcome than trusting HTTPS, really. Like, there are definitely intelligent and secure ways to do
84.
▲
by
bri3d
4mo ago
Actual write-up rather than overwrought YouTube drama: https://mrbruh.com/amd2/ A non-default-installation set of AMD tools (Ryzen Master and probably others) had an auto-updater which used HTTP instead of HTTPS. It&#x
85.
▲
by
bri3d
4mo ago
I used the usual stack of HomeAssistant, Frigate, and a bazillion glue connectors to consolidate devices that were previously cloud apps on my phone. For example, previously I used the Frigate web UI over VPN to access my cameras, but I ins
86.
▲
by
bri3d
4mo ago
Why does everyone focus on this aspect? Why is this surprising? Do people think that 100% or even 20% of Twitter employees were SREs? Do you think that most large applications are kept alive by constant manual toil from SREs? (ok, ok some a
87.
▲
by
bri3d
4mo ago
I've always wanted my own VW diagnostic tool suite, and between tooling that was released in public on GitHub ( https://github.com/kartoffelpflanze/ODIS-project-explorer ) and my own research from years ago, it alw
88.
▲
by
bri3d
4mo ago
LLM rant aside, I think this comment is built on a fundamental misunderstanding of what this is. This kind of runtime is an advanced debugging tool for exploring extreme edge cases in a repeatable way, not the thing you’d run your productio
89.
▲
by
bri3d
4mo ago
It’s a post-boot authentication bypass exploit. Any post-boot authentication bypass exploit against TPM-only sealed BitLocker effectively bypasses it. The user doesn’t have a key to start with in this setup, just the machine. This exploit i
90.
▲
by
bri3d
4mo ago
For a hobbyist, they're quite nice for "I want to SSH into a thing, write my tools on Linux, and still have access to SPI / I2C / GPIO, USB, and whatever hats can plug into that." The Hat form factor, while not tech
More ›