Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cyphar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
cyphar
8mo ago
> So I don't think I actually have a problem with businesses handing over their customer data if there is a valid warrant or subpoena. That's the system working as intended. I disagree -- the third party doctrine that allows
92.
▲
by
cyphar
8mo ago
Actually, after my comment I took another look and it turns out that only a few months ago someone released a pure-Rust PDF renderer called hayro[1] that seems to fit exactly what I need, so I will work on finishing this bit of paperback as
93.
▲
by
cyphar
8mo ago
> Since you wrote it in Rust, I'd suggest compiling it to wasm and releasing a browser-based version That was my eventual plan for having a single GUI for everything, the only problem is that there isn't a really obvious way to
94.
▲
by
cyphar
8mo ago
Business class flights from Sydney to San Francisco cost A$6k, 6-10x as much as economy. Flights from Sydney to Europe are more like 3-4x (A$7k vs A$2k) but still ludicrously expensive. Good luck convincing your company to expense that for
95.
▲
by
cyphar
8mo ago
I wrote a project to do this a few years ago[1], it's mainly missing an automated mechanism to scan the PDFs and a GUI. Maybe you'll find it interesting. [1]: https://github.com/cyphar/paperback
96.
▲
by
cyphar
8mo ago
I must admit it was a little surreal to check my own username out of curiosity, only to find that I'm in the top 500 commenters (0.06%) on HN by word count. The really surprising thing is that I stopped commenting regularly a few years
97.
▲
by
cyphar
8mo ago
There are much better systems for splitting data than just chunking it into N chunks, the most common is Shamir Secret Sharing[1] (the main benefit being that you can construct an M-of-N scheme easily and having N-1 shards provides you ze
98.
▲
by
cyphar
8mo ago
I must admit that there is a certain sense of nostalgia I get from playing Civ 3 that I never got from any of the other Civ games, but that's probably just because it was the first Civ game I played and got really hooked on as a young
99.
▲
by
cyphar
8mo ago
> trust us we're cool guys I'm guessing you're referencing my comment, that isn't what I said. > But the team is not even willing to make promises as big as yours. Be honest, look at the comment threads for this an
100.
▲
by
cyphar
8mo ago
I am aware of that, my (personal) view is that DRM is a social issue caused by modes of behaviour and the existence or non-existence of technical measures cannot fix or avoid that problem. A lot of the concerns in this thread center on TPMs
101.
▲
by
cyphar
8mo ago
I'm really not trying to be slick, but I think it's quite difficult to convince people about anything concrete (such as precisely how this model is fundamentally different to models such as the Secure Boot PKI scheme and thus will
102.
▲
by
cyphar
8mo ago
> but the way this will be used is by corporations to lock us out into approved Linux distributions. Linux will be effectively owned by RedHat and Microsoft, the signing authority. This is basically true today with Secure Boot on modern
103.
▲
by
cyphar
8mo ago
I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on user
104.
▲
by
cyphar
9mo ago
I was under the impression that the Mickey Mouse Protection Act 1998[1] extended the copyright protection for works retroactively (though already public domain works were excluded). That being said, I guess the act had precautions to stop i
105.
▲
by
cyphar
9mo ago
As someone who has caught DB a fair number of times over the years, I think DB is most hated by Germans (who love to complain) and German locals. Maybe I've just been lucky so far, but as an Aussie it is hard to overstate the fact it i
106.
▲
by
cyphar
9mo ago
I get your point, but can you point to a sales pitch which included "exploit security flaws in Android to improve tracking"? Probably not, but we know for a fact they did that. Also, your own blog lists an leak from 2024 about a F
107.
▲
by
cyphar
10mo ago
> See also "instagram is spying on you through your microphone". It's not, but I've seen people argue that it's OK for people to believe that because it supports their general (accurate) sentiment that targeted a
108.
▲
by
cyphar
10mo ago
On paper, USDT probes are the best way for libraries (and binaries) to provide information for debugging because they can be used programmatically and have no performance overhead until they are measured but unfortunately they are not widel
109.
▲
by
cyphar
10mo ago
Maybe I'm getting too jaded but I'm struggling to be quite that charitable. The entireity of the human-written text in that comment was "From ChatGPT:" and it was formatted as though it was a slam-dunk "you're
110.
▲
by
cyphar
10mo ago
Yeah, I really have to wonder what the thought process is behind leaving such a comment. When people first started doing it I wondered if it was some kind of guerrilla outrage marketing campaign.
111.
▲
by
cyphar
10mo ago
SmartOS constructed a container-like environment using LX-branded zones, they didn't create an in-kernel equivalent to Linux's namespaces which it then nested in a zone. You're probably thinking of the KVM port to Solaris
112.
▲
by
cyphar
10mo ago
As a maintainer of runc (the runtime Docker uses), if you aren't using user namespaces (which is the case for the vast majority of users) I would consider your setup insecure. And a shocking number of tutorials recommend bind-mounting
113.
▲
by
cyphar
10mo ago
You really need to use user namespaces to get this kind of security protection -- running as root inside a container without user namespaces is not secure. Yes, breakouts often require some other bug or misconfiguration but the margin for e
114.
▲
by
cyphar
10mo ago
I just tried it from my Android phone (GrapheneOS) and it still asks to verify a phone number when trying to create an account via a web browser. (Strangely, even though it's a private browser session it just asks to confirm my numbe
115.
▲
by
cyphar
10mo ago
More than one thing can be true at once. In the case of Twitter, there is evidence that the initial implementation was meant to just be a security mechanism but later someone else noticed they had a handy database of user phone numbers and
116.
▲
by
cyphar
10mo ago
This might depend on the country you're in, but I'm quite certain I've gotten locked out of the signup flow in the past when I refused to provide a phone number.
117.
▲
by
cyphar
10mo ago
> Invite codes worked fine for Gmail Back in 2004, sure. Today, Gmail asks you for a phone number when signing up because of the spam problem.
118.
▲
by
cyphar
10mo ago
TFA mentions this option and then goes on at some length to explain that this doesn't help for transitive dependencies, which is how these attacks usually work.
119.
▲
by
cyphar
10mo ago
AV1 has been around for a decade (well, it was released 7 years ago but the Alliance for Open Media was formed a decade ago). It's fine that you haven't heard of it before (you're one of today's lucky 10,000!) but it rea
120.
▲
by
cyphar
10mo ago
So the solution is to stop doing code reviews and just YOLO-merge everything? After all, everything is fucked already, how much worse could it get? For the record, there are examples where human code review and design guidelines can lead to
More ›