Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chc4
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
by
chc4
2y ago
You are wrong. NIST recommendations outline both deterministic or RBG-based construction. The 2^32 invocation limit is only for random nonce or if your deterministic construction is less than 96bits. Lots of people are doing random nonces
122.
▲
by
chc4
2y ago
Oops, I did not, thank you!
123.
▲
by
chc4
2y ago
You just do rounds of fixed sets of parties, like Ethereum proof of stake does. The set of nodes in each round are then needed to be 2/3rds honest. They then have Sybil resistance in each round as identities aren't free, since you
124.
▲
by
chc4
2y ago
In case you haven't seen, there was actually a quantum algorithm on preprint recently for solving some class of learning with errors problems in polynomial time. https://eprint.iacr.org/2024/555
125.
▲
by
chc4
2y ago
This is a Byzantine agreement protocol. By definition it is a construction taking into account malicious nodes: that is what Byzantine agreement means. Table 1 says that this algorithm, like all the rest except one in the table, has fault t
126.
▲
by
chc4
2y ago
Sorry, they're reimplementations, not full 1:1 ports from Javascript to Lua. Roblox is also a full game engine. All game scripts are already in Lua and the developers are already using Lua in their games. Their GUI engine is in-house a
127.
▲
by
chc4
2y ago
I'm under the impression they've been using the game GUI engine to drive the mobile app since 2018 or so - or at least I remember seeing things about it from way back then.
128.
▲
by
chc4
2y ago
People have been using Roact and Rodux (Roblox Lua rewrites of React and Redux) to drive in-game GUIs for years. Roblox's GUI system is essentially a DOM, so doing stateful updates to the game objects quickly becomes extremely painful
129.
▲
by
chc4
2y ago
I'm not sure anyone is really surprised by this. Apple for example likewise calls out that you are at risk of an attacker using timing attacks to construct an authentication oracle for PAC, which is much more explicit about when exactl
130.
▲
by
chc4
2y ago
I applied to TripleByte in 2019. I passed the interview, they sent me some swag, and then had my profile "go live" for a week(?). I didn't get a single interested company, and then they took my profile down and said I can try
131.
▲
by
chc4
2y ago
Squandered, along with things like "commit massive tax fraud that caused several executives to go to jail and be forced to pay millions of dollars of fees"
132.
▲
by
chc4
2y ago
Yes, it's extremely sad :( He was a giant in the Ruby and Truffle communities, and TruffleRuby was a monumental work for both projects.
133.
▲
by
chc4
2y ago
Truffle/Graal is also able to do some insanely cool things related to optimizing across FFI boundries: if you have a Java program that uses the Truffle javascript engine for scripting, Truffle is able to do JIT optimization transparent
134.
▲
by
chc4
2y ago
Well, sort of. There definitely have been bugs in Binder related to it incorrectly mapping physical pages, which it needs to be doing as part of its core behavior, and is essentially a logic bug with memory safety implications that Rust fun
135.
▲
by
chc4
2y ago
Fuchsia's kernel is written in C++. It's much more a microkernel design, and so device drivers usually run as userspace processes and some of them are Rust, but the core kernel is not written in a memory safe language.
136.
▲
by
chc4
2y ago
The theory behind EmDrive is based on his quantized inertia theory. I was under the impression he was the original proposer of the idea. It looks like it was instead proposed by someone else in 2006; however McCulloch submitted a paper in 2
137.
▲
by
chc4
2y ago
The main reason, as far as I'm aware, is because McCulloch then went on to claim to invent several thrusters (EmDrive, most notably) derived from the effect that break normal conservation of momentum.
138.
▲
by
chc4
2y ago
This just seems like a very specific way of implementing tree matching? Top-down graph matching instruction selection implementations look a lot like this if you squint (apply labels to child nodes, then have rules that fire on simple trees
139.
▲
by
chc4
2y ago
24bit integers and floats, no array datatype, and a maximum 4GB heap of nodes are very harse restrictions, especially for any workloads that would actually want to be running on a GPU. The limitations in the HVM2 whitepaper about unsound ev
140.
▲
by
chc4
2y ago
You can (and people do) do graph coloring on SSA form, just the same as you can do linear scan without SSA. SSA helps graph coloring, in fact, thanks to the discovery that the interference graph of SSA values is chordal and the consequenc
141.
▲
by
chc4
2y ago
Starting a paragraph about how to "safely" remove safeguards, and then tongue-in-cheek joking about Rust, kind of looks worse when your very first example isn't safe and liable to segfault even before the "proverbial gun
142.
▲
by
chc4
2y ago
CreateProcess the victim with CREATE_SUSPENDED, do whatever code patching, then ResumeThread it. Pretty sure you can even CreateRemoteThread into the victim for DLL injection, since it just suspends the primary thread, and then patch &quo
143.
▲
by
chc4
2y ago
IMO You should just stick some programs in Ghidra/Godbolt and see what they emit, especially for small individual snippets whenever you think "I want to do X, what's the best way of doing it". There really isn't muc
144.
▲
by
chc4
2y ago
LLL lattice reduction is the same algorithm that can be used for cracking PuTTY keys from biased nonces from the CVE a few days ago. 'tptacek explained a bit about the attack (and links to a cryptopals problem for it, which I can almos
145.
▲
by
chc4
2y ago
Right, in case it wasn't clear to readers this isn't a bad thing. Lots of people use games because they're good analogs for other programs and evocatively show fuzzing exploration progress. Not being the first to point a fuzz
146.
▲
by
chc4
2y ago
A lot of fuzzers use Mario or other simple games as an internal testcase. I'm aware of a hypervisor fuzzer from 2016 that did it, and I'm positive there are others (both before and since). Hell, tom7 has a fuzzer for exploring pro
147.
▲
by
chc4
3y ago
I have had the exact opposite experience: clang constantly gives me much better error messages than GCC, implementations of some warnings or errors catch more cases, and clang-tidy is able to do much better static analysis.
148.
▲
by
chc4
3y ago
It's really not enough to just say that a GC gave you more pointers = it has worse cache locality. Compacting GC almost always has better cache utilization than malloc, because heap fragmentation over long-running programs will waste
149.
▲
by
chc4
3y ago
I was horrified to learn that PowerPC uses an "inverted page table", which is essentially just a TLB implemented as a hash table. If the requested page isn't resident in the inverted page table it delivers an interrupt, where
150.
▲
by
chc4
3y ago
AI might also make unicorns real and usher in world peace, while we're wishing for things.
More ›