Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cipherboy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
cipherboy
3y ago
> Yeah, alright then. As far as I'm aware, Scalr is not directly participating in or precipitating the fork at this time [0]. This was started by groups working on OpenHorizon and EdgeX Foundary (two Linux Foundation projects under
62.
▲
by
cipherboy
3y ago
It is in FIPS 186-5 which is a very recent standard. Likely the underlying implementation has not undergone recertification to include it, as NIST has quite the backlog for FIPS certifications. See: https://nvlpubs.nist.gov/
63.
▲
by
cipherboy
3y ago
Chrome 119.0.6045.163 (Official Build) (64-bit) on Android 14 worked for me, but Firefox Nightly Mobile 122.0a1 didn't. I've built other apps with Tone JS that work fine in Firefox (outside of a few pops as the complexity increase
64.
▲
by
cipherboy
3y ago
Perhaps a more apt term would be freeware. The BUSL is not OSI approved and places restrictions around usage, in an effort to sell some product or service off of a project and prohibit competition. It is not free as in beer either, if you h
65.
▲
by
cipherboy
3y ago
If anyone does start an open Vault fork, I'd be interested in contributing as I get time. Edit to add: https://github.com/hashicorp/vault/graphs/contributors?from=...
66.
▲
by
cipherboy
3y ago
Note for whatever it is worth that the Homebrew-owned version rebuilds these from source -- https://github.com/Homebrew/homebrew-core/pull/139538/files#... . This is also typical in the Linux packaging ec
67.
▲
by
cipherboy
3y ago
Nomad, along with the rest of Hashicorp's flagship products, transitioned to the BUSL-1.1: https://github.com/hashicorp/nomad/blob/main/LICENSE
68.
▲
by
cipherboy
4y ago
This isn't fair to the OP. > > That is, take some data and manipulate it until it has the same MD5 as a different piece of data. > Second sentence is false - that's called a preimage attack. It's actually rather poor
69.
▲
by
cipherboy
4y ago
IBM has done this as well.
70.
▲
by
cipherboy
4y ago
Wouldn't that just be because OP's comment appeared on the article, which was posted ~1h ago, and the Google result link is to the article, not the comment directly, hence has the earlier timestamp?
71.
▲
by
cipherboy
4y ago
Does this impact most distros? I'd imagine Python and PHP's native crypto bindings would be replaced with OpenSSL which should have assembly variants of SHA-3.
72.
▲
by
cipherboy
4y ago
Copyright claims are a form of content moderation, by preventing reuse of content that others own. But it can still be weaponized to prevent legitimate resubmissions of parallel works, that can potentially deplatform legitimate users, depen
73.
▲
by
cipherboy
4y ago
The poster isn't claiming that this is a valid DMCA suit. Nearly everyone who is at a mildly decent level and has posted their own recordings of classical musical to YouTube have received these claims _in their Copyright section_. YouT
74.
▲
by
cipherboy
4y ago
I believe 384 has the same problem: most CAs use RSA-2048/SHA-256 signatures and very few do 2048/384 (which this certificate is doing), especially on demand (ACME has no parameter to control hash function selection by the request
75.
▲
by
cipherboy
4y ago
Yeah there's a GitHub repo behind this and there's comments from past times it has expired. Essentially it requires a public CA to issue an EV cert for them, which is hard to maintain and rotate. I think Mozilla and DigiCert worke
76.
▲
by
cipherboy
4y ago
https://developers.redhat.com/blog/2021/04/16/broadening-com... Red Hat seems to have a =3
77.
▲
by
cipherboy
4y ago
The middle of the list had a media disclosure without any auth via the image API. That would mean running a publicly accessible instance would be ill advised if you can about the privacy of what you host. Plex on the other hand somewhat enc
78.
▲
by
cipherboy
4y ago
Correct; after the newer seeding policies have taken affect, many have punted to the OS/app for seeding. See https://csrc.nist.gov/CSRC/media/projects/cryptographic-modu... -- the entropy input is plaint
79.
▲
by
cipherboy
4y ago
Every major Linux distro ships FIPS crypto libraries that seed from the Linux kernel; the source is available.
80.
▲
by
cipherboy
4y ago
Sorry, reading NIST is worse than reading tea leaves and I don't actively participate in the IETF TLS mailing lists enough to say any more than the next person :-) Just stating that the process (NIST to enterprise customer) takes time
81.
▲
by
cipherboy
4y ago
Ah sorry, correct.
82.
▲
by
cipherboy
4y ago
OP does have a point though, especially with DJB's thoughts (and others) on the matter. https://nitter.net/hashbreaker?lang=en For FIPS in particular, they've first gotta sunset the traditional algorithms for anyo
83.
▲
by
cipherboy
4y ago
As a fun fact, you can also run: $ systemctl --user enable --now podman.socket $ export DOCKER_HOST=unix:///run/user/$UID/podman/podman.sock and get a rootless, Docker-compatible socket. If yo
84.
▲
by
cipherboy
4y ago
Nah, no op code. You just open a regular connection and then terminate it. This forces the TLS server to auth (as the CLI OpenSSL lacks session resumption tickets).
85.
▲
by
cipherboy
4y ago
In general, we don't actually have enough information to tell this. :-) Consider the case of an older Android client (not from TFA, but bear with me), using certs from Let's Encrypt: https://letsencrypt.org/certifi
86.
▲
by
cipherboy
4y ago
This is almost all correct, but note that the new TLSv1.3 CertificateAuthoritiesExtension is optional (MAY): https://datatracker.ietf.org/doc/html/rfc8446#section-4.2.4
87.
▲
by
cipherboy
4y ago
Strictly it isn't true that a leaf cert's validity must be capped by the parent issuer's, but I'm also surprised this worked. I suspect the intermediate is still valid though. The PKIX RFC 5280 says: https://d
88.
▲
by
cipherboy
4y ago
If you visit the site in most (desktop) browsers, you can usually click the lock icon, navigate through various intermediate steps (Firefox is Connection Secure -> View Certificate) and find details about the cert or download it (hidden
89.
▲
Learning to Play Settlers of Catan with Deep Reinforcement Learning
(settlers-rl.github.io)
3 points
by
cipherboy
4y ago
|
0 comments
90.
▲
by
cipherboy
5y ago
And to be even more pedantic, the function works because it is applied on an event listener... When null[1] is evaluated (in the right side of the || of the conditional), it produces a TypeError... which in effect (due to no catch and evalu
More ›