Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dadrian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
121.
▲
by
dadrian
3y ago
It doesn't matter if the JIT itself is written in a memory-safe language or not if you're exploiting miscompiled JIT output. If the machine code emitted by a JIT is wrong, it can be exploited regardless of if the JIT itself is mem
122.
▲
by
dadrian
3y ago
> There is no technological reason this is the case, but pure greed by publishers. Ah yes, because server-side infrastructure is notoriously free and cheap to run, with no ongoing operational costs, and requires no employees to maintain.
123.
▲
by
dadrian
3y ago
All this article says is that Haidt's analysis is just correlation, and then cites a single metastudy from 2019, and doesn't go on to explain what Haidt did wrong. This is despite extensive writing from Haidt that deconstructs tha
124.
▲
by
dadrian
3y ago
You look across unrelated events that you scored similarly. In aggregate, across all things you predict as having an 8% chance to happen, 8% should actually happen.
125.
▲
by
dadrian
3y ago
This is awesome. I remember back in 2006 I bought every copy of MechAssault that my local Game Stop had and hoped that one was the correct revision such that it was compatible with the Krayzie Ndure softmod exploit, and used it to install X
126.
▲
by
dadrian
3y ago
I have 3. For about 14 years, I had 1.
127.
▲
by
dadrian
3y ago
Oh, that's easy. It's because Assange committed crimes that Greenwald did not.
128.
▲
by
dadrian
3y ago
Good for them. I am however, confused by the list of accomplishments, one of which is "wrote tests". I think this goes to show that audience matters---that list looks a lot better as items on a resume at an undergrad career fair t
129.
▲
by
dadrian
3y ago
Slack's not down, you've been fired.
130.
▲
by
dadrian
3y ago
It is publicly available data from Chrome's non-URL keyed metrics system. https://transparencyreport.google.com/https/overview?hl=en
131.
▲
by
dadrian
3y ago
If there's any vendor in the sponsor list with an ulterior motive, it's Vanta.
132.
▲
by
dadrian
3y ago
If an a16z repo gets enough stars, will they invest in themselves?
133.
▲
by
dadrian
3y ago
How long until Jen Easterly is a partner at a16z? Seems like she's on a never-ending speaking tour, rather than leading an agency.
134.
▲
by
dadrian
3y ago
What do you think the government does to TLS?
135.
▲
by
dadrian
3y ago
It is already in use in WebEx.
136.
▲
by
dadrian
3y ago
Off the top of my head... - Soft-white LEDs - Data-over-headphone-jack - ZK-SNARKs - Tor - Energy-harvesting power monitors - TCP congestion control These all had government funding or were invented in government labs.
137.
▲
by
dadrian
3y ago
The peer review system is not designed to catch fraud, it's designed to catch scientific or experimental errors. Giving up on science is such a vast overgeneralization. You could take your statement and replace "manipulated resear
138.
▲
by
dadrian
3y ago
With an XOR, if you can control bits on one of the inputs, you can deterministically change one of the bits on the outputs. That is not the case with an HKDF.
139.
▲
by
dadrian
3y ago
That's backwards. Profitability at scale is about the _only_ way for a cloud provider to be profitable. There's a reason you don't see a bunch of small cloud providers, the economics only work at scale.
140.
▲
by
dadrian
3y ago
You raise money to pay for costs of running the business. If you couldn't raise money, then only people who are already extremely rich would be able to start a business of any size, let alone one that requires deploying physical hardwa
141.
▲
by
dadrian
3y ago
If you are interviewing for a senior-ish position in some specific domain, and it has a take-home, and it recommends a time limit, and you blow past that time limit because you aren't familiar with the domain, then either: - You aren&#
142.
▲
by
dadrian
3y ago
If there's one thing prohibition is known for, it's lack of crime! Wait...
143.
▲
by
dadrian
3y ago
Those billionaires don't have it in cash, either.
144.
▲
by
dadrian
3y ago
> We will continue to mark HTTP as insecure.
145.
▲
by
dadrian
3y ago
Chrome remembers certificate click-throughs for 2 weeks. That being said, there's definitely a bunch of room for improvement with local networks that we haven't quite sorted out yet.
146.
▲
by
dadrian
3y ago
Believe it or not, the title began as a placeholder title before I realized it was a Google-ism for shutting things down.
147.
▲
by
dadrian
3y ago
In (50%) of Beta, Chrome attempts HTTPS and silently falls back to HTTP on all HTTP links. We're still poking around with opt-outs, currently if you allow insecure content via Page Info / Site Controls, we stop upgrades.
148.
▲
by
dadrian
3y ago
I wonder if Bard can write a show tune about how you regret what you built, but you're taking the money anyway.
149.
▲
by
dadrian
3y ago
Almost nothing on this list is actually positive for security, and most of the applications provided are not actually substitutes. Good luck replacing Discord with Signal.
150.
▲
by
dadrian
4y ago
You can mitigate things that go wrong quicker if the default lifetimes are shorter.
More ›