Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
codahale
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
codahale
16y ago
I see absolutely zero details about the actual configurations of either system. No replicability means it's just another opinion paper.
62.
▲
by
codahale
16y ago
By that token, all security advisories are just advertisements for the security researchers' services.
63.
▲
by
codahale
16y ago
That doesn't sound unreasonable, no -- at some point in the future, Scala's hash array mapped trie will be robust and highly optimized. If your plan is to wait until then, you might be able to speed things up by helping them out yourself. I
64.
▲
by
codahale
16y ago
The hash array mapped trie was committed to trunk 3 months ago and was first released in 2.8.0.RC1 (which no one uses due to various bugs) and is now available in 2.8.0.RC2 (which very few people are using due to binary incompatibility). In
65.
▲
by
codahale
16y ago
I invite you to benchmark the two. I'm also slightly confused as to why you think reusing stable, proven, and reviewed data structure implementations is a "good learning experience" as opposed to being SOP.
66.
▲
by
codahale
17y ago
I've seen java apps commonly take up a whole rack of servers, not just one Ok, and I've seen Java apps not do that. Argument by anecdote is bankrupt.
67.
▲
by
codahale
17y ago
You know, you can set a maximum heap size for JVM processes. It defaults to 1/4th of the physical memory or 1GB, whichever is the smaller.
68.
▲
by
codahale
17y ago
And yet the nerve impulses which caused the muscles in your arm to contract left your brain about 500ms before you became aware of deciding to raise your arm. ( http://www.ncbi.nlm.nih.gov/pubmed/6640273 ) Additionally, the mechanisms which
69.
▲
by
codahale
17y ago
Oh, ok. So it takes making predictions to quality as real science. Here's a real prediction, with actual confirming evidence: giving someone with a high MADRS score an SSRI will reduce their score. That's beyond seeing and naming depres
70.
▲
by
codahale
17y ago
You have got to be kidding. 150-300 years? Agriculture dates back to at least ~10,000 BC (the "Neolithic revolution"). Effective farming (i.e., not dying of starvation) requires planning for changing weather conditions. If you think Neolith
71.
▲
by
codahale
17y ago
The reason we know where Pluto will be in 9 years is that we've been watching the solar system for two thousand years. How long do you think people have been watching the weather for?
72.
▲
by
codahale
17y ago
Seriously. No one jumps all over NASA yelling about how the science "isn't in yet" when they want to send a probe out to where Pluto will be in 9 years .
73.
▲
by
codahale
17y ago
They might. I don't know. They didn't ask me for help getting it tuned.
74.
▲
by
codahale
17y ago
The bcrypt algorithm has salting built-in.
75.
▲
by
codahale
17y ago
They're two completely different things. AES is an encryption algorithm. bcrypt is a special-purpose hash algorithm. If you're confused, I'd highly recommend Practical Cryptography by Niels Furguson and Bruce Schneier: http://www.schneie
76.
▲
by
codahale
17y ago
I should have been more precise in the article. Here: A system which uses an adaptive hash function like bcrypt is ~6 orders of magnitude less effed in the event of a compromised database than a system which uses a standard hash algorithm
77.
▲
by
codahale
17y ago
Awww. :(
78.
▲
by
codahale
17y ago
You're asking about the relative merit of two hash functions, one of which allows your attacker to test a candidate password in 1 millisecond , the other of which allows the same in less than 1 nanosecond . Using the latter provides your
79.
▲
by
codahale
17y ago
Toss it up on GitHub, man.
80.
▲
by
codahale
17y ago
Uh. All of the current SHA-3 candidates are as fast or faster than SHA-1. That's one of the contest's design goals: NIST expects SHA–3 to have a security strength that is at least as good as the hash algorithms currently specified in FIPS
81.
▲
by
codahale
17y ago
He's implying that using bcrypt (and other iterative hash functions like PBKDF2 and scrypt) raises the cost of mounting a dictionary attack compared to commonly-used and -recommended hash algorithms like SHA256. Which, uh, is an objectively
82.
▲
by
codahale
17y ago
Also, you point out that "successfully discouraging your users from using a crappy password has much better repercussions." This is true, and I'm curious to know how you personally achieve this with your users, given that the vast majority[
83.
▲
by
codahale
17y ago
I'm familiar with cperciva's scrypt, and I think it's a great solution. That said, I've only seen C and Ruby bindings for it. I'd love to recommend its use over bcrypt, as memory constraints are much more expensive than computational constr
84.
▲
by
codahale
17y ago
I'm guessing you haven't read Provos and Mazières' USENIX paper. In the design considerations, they say: In general, a password algorithm, whatever its cost, should execute with near optimal efficiency in any setting in which it sees legit
85.
▲
by
codahale
17y ago
I'm curious to know why you think innovation in the security domain will come from web developers working on lolcat apps and not, say, cryptographers.
86.
▲
by
codahale
17y ago
Foiled again! Curse you, Ptacek!
87.
▲
by
codahale
17y ago
It's true. That is a ridiculous policy. They should refund him his money.
88.
▲
by
codahale
17y ago
Good god, no. Here is much better advice, in much shorter form: If you're storing a password , use bcrypt or I'll bite your thumbs off. If you're making sure something hasn't been modified by someone and you absolutely can't use a signed
89.
▲
by
codahale
17y ago
From TFA: And then some fool calling himself SoSerious posted _an article_ about how much he feels DC was an idiot. From his link: Joshua Blankenship is a designer living in Anderson, SC.
90.
▲
by
codahale
17y ago
When an "upstream" owner doesn't take patches, the usual result is that there's complete chaos and mutually incompatible forks with the same name and version information spring up. If the upstream owner doesn't accept patches the project
More ›