Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dadrian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
dadrian
1y ago
Dave’s riffs are also stolen from disco. Which again, is fine! I love them! Source: https://youtu.be/dZCrdSC2-1I
62.
▲
by
dadrian
1y ago
I dunno why you say it isn't useful. It is inherently plaintext, but still worth authenticating. If you just used an AEAD but didn't put e.g. the session identifier or connection ID or sequence number in the AD, it would be entire
63.
▲
Is open-world design making games worse?
(dadrian.io)
12 points
by
dadrian
1y ago
|
14 comments
64.
▲
by
dadrian
1y ago
The root problem is certificate lifetimes are too long relative to the speed at which domains change, and the speed at which the PKI needs to change.
65.
▲
by
dadrian
1y ago
Yeah, but this also offers a clear exit opportunity (during the raise), and limits the "blast radius" to time-since-last-raise, rather than progress against the first four years of the company.
66.
▲
by
dadrian
1y ago
If you can't do 10 up front, you can usually reset founder vesting back every funding round to slow it down. This is fairly common.
67.
▲
by
dadrian
2y ago
You need to be a unicorn or you need to only take angel checks. This is not complicated.
68.
▲
by
dadrian
2y ago
There is literally a code-signing working group in the CA/BF. However, the browsers don't really participate in it, since it's irrelevant to browsers. This is the entire point of moving to dedicated hierarchies per use-case--
69.
▲
by
dadrian
2y ago
ARI is outside the scope of the CABF
70.
▲
by
dadrian
2y ago
What Big Tech companies are demanding 80 hours a week?
71.
▲
by
dadrian
2y ago
Maybe, but they've taken something that was effectively risk-free and added risk for absolutely no reason.
72.
▲
by
dadrian
2y ago
If they actually integrate this into randomness on their TLS servers, the only risk is that the system for getting the entropy from the lamps and waves somehow screws up, fails to parse an HTTP request or something, and accidentally seeds t
73.
▲
by
dadrian
2y ago
Yes, but head-of-line blocking is a different thing than round trips.
74.
▲
by
dadrian
2y ago
HTTP/2 already reduces roundtrips.
75.
▲
by
dadrian
2y ago
It's not clear to me that HTTP/3 is relevant to anyone who isn't already using it. It's most useful for large-scale hosting providers and video. And these people have already adopted it, and don't necessarily use ou
76.
▲
by
dadrian
2y ago
No, eIDAS 2.0 was an attempt to address the fact that the EU is not one market in ecommerce, because EU citizens don't like making cross-border orders. The approach to solving this was to attach identity information to sites, ala EV ce
77.
▲
by
dadrian
2y ago
The main limitation is the incredibly opaque and brittle nature of putting keys in DNS. We've spent a decade and a half slowly making the Web PKI more agile and more transparent by reducing key lifetimes, expanding automation support,
78.
▲
by
dadrian
2y ago
The Tor service model is equivalent to if every site used a self-signed certificate, which doesn't scale. The more feasible CA-free architecture is to have the browser operator perform domain validation and counter-sign every sites key
79.
▲
by
dadrian
2y ago
Mozilla’s list is built to reflect the needs of Firefox users, which are not the same as the needs of most non-browser programs. The availability/compatibility vs security tradeoff is not the same.
80.
▲
by
dadrian
2y ago
What actual risk are you worried about here? Mozilla changed their data policy, therefore the root store might do what...?
81.
▲
by
dadrian
2y ago
Non-browser clients shouldn't be expected to crib browser trust decisions. Also, the (presumably?) default behavior for a non-browser client consuming a browser root store, but is unaware of the constraint behavior, is to not enforce t
82.
▲
by
dadrian
2y ago
You can install uBlock Origin Lite [1], and get literally the same blocklists but with better security properties. [1]: https://chromewebstore.google.com/detail/ublock-origin-lite/...
83.
▲
by
dadrian
2y ago
https://podcasts.apple.com/us/podcast/root-causes-408-takeaw...
84.
▲
by
dadrian
2y ago
I'm with you, but the government (at least in the US and UK) should definitely be spending more time figuring out how to patch reliably, and little less on PQC.
85.
▲
by
dadrian
2y ago
I'd also add that the legality of law enforcement exploiting a server-side bug is much more of a gray area (or actually illegal), whereas there is a standard process for law enforcement or the intelligence community to get a court orde
86.
▲
by
dadrian
2y ago
pg has not moderated Hacker News, nor been operationally involved in YC, for over a decade.
87.
▲
by
dadrian
2y ago
If Government A and Government B are not equally "good" for the world, then the world is _not_ better off if everyone disclosed, since the main users of CNE are LE/IC.
88.
▲
by
dadrian
2y ago
That organization exists, and it is called the FBI.
89.
▲
by
dadrian
2y ago
It is not required by window.open semantics, you can absolutely implement site isolation even in the presence of COOP unsafe-none
90.
▲
by
dadrian
2y ago
A real false start on that baseball metaphor.
More ›