Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
btrask
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
181.
▲
Hard Sci-Fi
(bentrask.com)
2 points
by
btrask
10y ago
|
0 comments
182.
▲
Symbolic execution in vuln research (2015)
(lcamtuf.blogspot.com)
2 points
by
btrask
10y ago
|
0 comments
183.
▲
Static analysis tools for security (2015)
(dwheeler.com)
1 points
by
btrask
10y ago
|
0 comments
184.
▲
by
btrask
10y ago
If your summary is accurate (haven't read the paper yet), I don't think this works, because if you don't have a proper quorum, you can't know that the leader is still valid at the time of an event. It might've been
185.
▲
The CFAA: Giving More Power to Networks Instead of End Users
(continuations.com)
1 points
by
btrask
10y ago
|
0 comments
186.
▲
by
btrask
10y ago
The problem is that the user's data itself needs to be conflict-free. For example, no programming language models its source code as a CRDT, so DVCSes will always produce merge conflicts (or worse, silently broken merges). CRDTs are a
187.
▲
by
btrask
10y ago
I developed a "general purpose" JSON-based CRDT[1] as a part of my content addressing system project. The idea was to have an "append-only tree", where subtrees could be used by individual applications for different purp
188.
▲
JavaScript continent and the callback pyramids of hell
(boxbase.org)
1 points
by
btrask
10y ago
|
0 comments
189.
▲
by
btrask
10y ago
Fair enough. :)
190.
▲
by
btrask
10y ago
In the context of sharing public keys, I'd say you merely need authentication. Web of Trust being one possible mechanism. This isn't a particularly advanced topic. Relevant to my original post, information about whether the connec
191.
▲
by
btrask
10y ago
I said trusted, not encrypted. I wasn't talking about private keys at all. I think I understand the issues involved. Thanks though.
192.
▲
by
btrask
10y ago
Users/user agents need to know whether to expect a connection to be secure. Unfortunately, you can't necessarily trust any random link you follow to reliably tell you. If I can get you to use HTTP when you should've used HT
193.
▲
by
btrask
10y ago
I've got a simple way of implementing Rust's borrow checker in C. It's based on always nulling out old pointers rather than letting them dangle. Functions that take ownership of an argument demand a pointer-to-pointer, and th
194.
▲
by
btrask
10y ago
LSM trees are ideal for posting lists, because every time you add a new document, you need to touch potentially hundreds of different lists. LSM trees are able to batch all of these writes together. That's why Google originally develop
195.
▲
by
btrask
10y ago
What is the argument in favor of specifically allowing casting away const of pointers?
196.
▲
CRDT notes (2015)
(github.com)
18 points
by
btrask
10y ago
|
0 comments
197.
▲
by
btrask
10y ago
This is a very long and very good blog series that I highly recommend. (One note, it's from 2013.) The funniest part is this post, which complains about code duplication: https://ayende.com/blog/162853/reviewi
198.
▲
by
btrask
10y ago
If you're still curious, I dug this up: https://news.ycombinator.com/item?id=9734842 It sounds like WebAssembly is in a weird position, where it can be (relatively) directly translated to machine code, or more heavily
199.
▲
by
btrask
10y ago
License out portions of its own technology. It'd be worth billions.
200.
▲
by
btrask
10y ago
My own project, https://hash-archive.org , is intended to help with this to some degree. The idea is to provide a 3rd party source for cryptographic hashes of files on the web. Recent Show HN: https://news.ycombinator.
201.
▲
by
btrask
10y ago
I think your concern about "what if the sandbox can do too much" is reasonable. My only suggestion is to try out Qubes for a while. It requires some adaption, but it's definitely possible to use securely (edit: obviously limi
202.
▲
by
btrask
10y ago
I think it's worth distinguishing two problems with pledge: 1. It's likely to have bugs because it's mixed with a constantly changing kernel and can't be proven correct 2. It isn't fine-grained enough If pledge were
203.
▲
by
btrask
10y ago
The idea is to separate security out so that new features and spec changes don't impact it. The necessary features of the sandbox are defined by the hardware, which doesn't change very fast. Everything else can be done inside the
204.
▲
by
btrask
10y ago
The difference is priorities. By separating them, your OS can be fast and featureful, and your sandbox can be secure. Better yet if there are several competing, portable sandboxes, so you can choose the best OS and best sandbox separately.
205.
▲
by
btrask
10y ago
Yes, that is a good question. I think OpenBSD's pledge(2) is a good model for what a simple and useful privilege interface can enforce (although there is room for improvement). To some extent, this is a question of what the requirement
206.
▲
by
btrask
10y ago
> That's not how it works, is it? If we want to minimize X * Y and we currently have X = 50 and Y = 5, it's much more efficient to focus on bringing Y down. I guess I see 0 as the asymptote. Like if you're already at 99.99
207.
▲
by
btrask
10y ago
A better analogy is Android permissions. These days you can fake them and apps mostly still work, right?
208.
▲
by
btrask
10y ago
It doesn't require consensus or standardization. NaCl, for example, runs in userspace on several platforms. If you had a sandbox that supported all of the necessary features, you could compile any open source browser for it easily (or
209.
▲
by
btrask
10y ago
The idea is that Rust (or something like it) is genuinely necessary to address it, because the necessary API is complex, as you say.
210.
▲
by
btrask
10y ago
Put the browser in a VM/sandbox, yes. tl;dr: Right now there is a competition between features and security, and security is losing. By separating them, they wouldn't need to compete, and we could have both. It isn't a good i
More ›