Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ctz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
151.
▲
by
ctz
10y ago
Linux doesn't power the smallest devices in the world. It's about two orders of magnitude too large out at the low end.
152.
▲
by
ctz
10y ago
Are you suffering from this? https://www.globalsign.com/en/customer-revocation-error/
153.
▲
by
ctz
10y ago
Lithium ion capacities are limited by the FAA to 100Wh per device, so it's not that.
154.
▲
by
ctz
10y ago
> There are no such thing and UL security requirements for IOT device. UL 2900-1.
155.
▲
by
ctz
10y ago
It could be any of these things. It could also be BT OpenReach.
156.
▲
by
ctz
10y ago
Computers is one job that comes to mind (as in human computer, one who computes).
157.
▲
by
ctz
10y ago
Well, true. But that would mainly affect availability :)
158.
▲
by
ctz
10y ago
> "Many customers in China find it important to use a domestic CA for purposes of security." That's not how the CA system works. Your security is unaffected by what CA you choose; it is invariably the minimum of all trust
159.
▲
OpenSSL Security Advisory - 26 Sep 2016
(openssl.org)
126 points
by
ctz
10y ago
|
36 comments
160.
▲
by
ctz
10y ago
There are no standard kerberos ciphersuites that use anything better than RC4/IDEA/DES/3DES: http://www.iana.org/assignments/tls-parameters/tls-parameter... . So: broken and obsolete.
161.
▲
by
ctz
10y ago
I've spent a career of 12 years writing, reviewing and breaking C in high-security products such as HSMs. I'm still to see real world, secure C. Maybe you could point me towards the numerous real world examples of people getting
162.
▲
by
ctz
10y ago
https://www.youtube.com/watch?v=pmofgf-Y3Mc&t=45 This is a promotional video produced by Uber. It clearly shows the vehicle illegally entering a crosswalk containing pedestrians. That's not a great start, and not
163.
▲
by
ctz
10y ago
Very long years or cheap iphones where you live.
164.
▲
by
ctz
10y ago
> Enter Golang... a language smaller than even ANSI C. It's readable because if you've worked with Golang for more than a week, you basically know every language construct you'll encounter. That's not really what read
165.
▲
by
ctz
10y ago
Apple is probably referring mainly to VAT and employee payroll taxes. However, the EU action is only concerned with corporation taxes. Apple confuses the issue by convolving the two.
166.
▲
by
ctz
10y ago
Your mailbox icon 'ſ' will be read aloud as 'latin small letter long s' or 'esss' if you're lucky. But I can't really tell if you're actually saying that the ability for web pages to be read alou
167.
▲
by
ctz
10y ago
It's a PRNG, so you fix the inputs and make sure the output is correct for all possible parameter sets. Matthew Green has more on this here: http://blog.cryptographyengineering.com/2014/03/how-do-you-k... (&#
168.
▲
by
ctz
10y ago
Here's the relevant commit: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commi... You'll notice that there are no tests with this commit, and no tests on other commits for the same feature. You can
169.
▲
by
ctz
10y ago
> What would be the economic incentive towards carrying out a sufficiently complex MITM attack on a blog or a newsfeed? We've already seen large scale MITM be used for political reasons: to DDOS github off the internet in retaliatio
170.
▲
High frequency security bug hunting: 120 days, 120 bugs
(shubs.io)
129 points
by
ctz
10y ago
|
24 comments
171.
▲
by
ctz
10y ago
I used to work for a company which did this, though it was 4 weeks each 4 years. It was actually mandatory: to check that that the company could function without you.
172.
▲
by
ctz
10y ago
I got a few thousand dollars of that money as a security bug bounty. OpenSSL fixed the problem quickly, but one year on still haven't accepted the regression test for the issue. It would be amusing if it wasn't so horrifying.
173.
▲
by
ctz
10y ago
Yes. Some people have confused themselves into thinking TLS is end-to-end, when it's only point-to-point. Not specific to cloudflare; Google did this for years and the NSA took advantage of that (hence the "SSL added and removed h
174.
▲
by
ctz
10y ago
There's a few problems with it. 1. client auth in TLS1.2 and earlier is done at the wrong time in the handshake. As a result the client's identity (which unlike the server identity usually identifies a user; see sibling comment w
175.
▲
by
ctz
10y ago
I'm using 'modern' here in two ways: - in reference to Mozilla's "Modern TLS" profile: https://wiki.mozilla.org/Security/Server_Side_TLS#Modern_com... - as an antonym for the unlimited bac
176.
▲
by
ctz
10y ago
This is how the DMCA works -- a provider is freed from liability if they process a valid-looking takedown request immediately. They can then notify you. You must now file a counter-notice if the request is invalid.
177.
▲
by
ctz
10y ago
That example code isn't going to run. Hyphens are illegal in python identifiers.
178.
▲
by
ctz
10y ago
> With SGX, Intel had the chance to offer a widely available security token (built in to every new CPU!) that anyone could freely program and use for their own security purposes. They blew it when they created their "launch control&
179.
▲
by
ctz
10y ago
You don't generate public exponents. Also, public exponents do not need to be prime, only relatively prime to phi(n) so inverses can be computed.
180.
▲
by
ctz
11y ago
Yes, the NSURLIsExcludedFromBackupKey file property.
More ›