Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
danarmak
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
danarmak
7y ago
The police could not exist if most people refused to help them. Arguing for people not to help the police is therefore arguing for the police to stop existing or to become less powerful or less effective. I take "not helping" to m
62.
▲
by
danarmak
7y ago
But since we lack an individually actionable way of making the police better, doesn't the argument reduce to "we should not help the police as they are now"?
63.
▲
by
danarmak
7y ago
I'm not saying "everyone" should help the police. I do think it's alright that a few companies, in specialized professions, exist to help the police (and other governmental organizations). Yes, a lot of the effect is har
64.
▲
by
danarmak
7y ago
Are you suggesting a locksmith should refuse to help the police open safes that contain too many valuables or PII inside?
65.
▲
by
danarmak
7y ago
The announcement says they have a new architecture. At the very least it's not a direct performance comparison to the same architecture implemented in Clojure. > Storm 2.0.0 introduces a new core featuring a leaner threading model,
66.
▲
by
danarmak
7y ago
> I miss Netscape days...internet wasn't a megacorp business playground :( ! You mean "this website is optimized for Internet Explorer 6" days? Or the earlier "this website is optimized for Netscape 2.0" days? I
67.
▲
by
danarmak
7y ago
Thanks, that's encouraging to hear! Although I still worry about the case where fixing the deviance would break production apps. Potentially break them, since people won't complain until you release the breaking browser versio
68.
▲
by
danarmak
7y ago
If I complain to Mozilla that they deviate from the W3C spec in some respect, will they treat that as a bug, or will they more likely say "no-one implements this, so no website uses this, so we have no reason to be the first to impleme
69.
▲
by
danarmak
7y ago
But no browser maker recognizes the W3C standard or claims to implement it, so what good is it?
70.
▲
by
danarmak
7y ago
It could also be about Github private repos, which cost money, and therefore are a business relationship. If Huawei has a private repo on Github, is Microsoft now required to delete their account?
71.
▲
by
danarmak
7y ago
Disabling HT can't be done per-process. Since per-frame browser processes need to be protected from one another, you can't even run two browser processes on the same core in HT. And scheduling a browser process while leaving the s
72.
▲
by
danarmak
7y ago
Some are there, yes, but they're insufficient to provide security. You need both them, and the microcode changes, and to disable HT. I'm not sure what if anything the software changes do alone, they may mitigate some of the
73.
▲
by
danarmak
7y ago
There aren't such mitigations to enable. There aren't even purely software kernel-level mitiations.
74.
▲
by
danarmak
7y ago
That must be recent. Good to know!
75.
▲
by
danarmak
7y ago
I meant that the "Allow personalized ads" in a Google account is on by default.
76.
▲
by
danarmak
7y ago
The problem is less with me seeing personalized ads, and more with the ad-server and/or the website getting my PII, and anyone who sees my screen or sniffs my traffic acquiring PII by observing which ads I get.
77.
▲
by
danarmak
7y ago
"Allow personalized ads" is on by default, which is iffy under the GDPR. Especially considering that, when it's enabled, they match you to your Google account even if your current browser isn't signed in to the Google ac
78.
▲
by
danarmak
7y ago
It's true that "backdoor" is sometimes used as you defined. I feel that some usage, like this article, implies a deliberate backdoor. But you're right that it's an implication and not an explicit statement. One reas
79.
▲
by
danarmak
7y ago
A backdoor is a deliberate remote-access vulnerability that the creator intended to use for illegitimate access. The same code, but intentional, is a bug and vulnerability, but not a backdoor. Same security implications, but a big differenc
80.
▲
by
danarmak
7y ago
It doesn't matter if it's a deliberate backdoor or not. It's a door, and I want to be able to close that door if I'm not using it, and Intel won't let me. Reducing attack surface is a security best practice exactly
81.
▲
by
danarmak
7y ago
Why not both? Many routers have had remote access vulnerabilities, but there's a clear reason to write about 2012-era vulns about Huawei and not some other manufacturer.
82.
▲
by
danarmak
7y ago
The NSA is probably better at domestic surveillance because it's much easier and/or cheaper than foreign surveillance. If people of the same ability level work on both, the domestic results will be better. That doesn't meant
83.
▲
by
danarmak
8y ago
You're right! I wasn't aware of that.
84.
▲
by
danarmak
8y ago
If DoH is backed by e.g. Google, won't they just end up exposing DoH on the same IP addresses serving www.google.com? Similarly, what if e.g. CloudFlare expose their DoH on all their addresses? This seems like the obvious next step for
85.
▲
by
danarmak
8y ago
> Unfortunately, on our school network, we also allow BYOD (students with their own laptops and ipads), so we will have to have some strict rules to block DoH, the same way we block proxies and vpns. How can you block DoH without doing
86.
▲
by
danarmak
8y ago
Title should mention the year, [2008].
87.
▲
by
danarmak
8y ago
> is there a more effective way to disable a cellular modem than removing its antenna? Wrap it in aluminum foil as a Faraday cage?
88.
▲
by
danarmak
8y ago
As Scott Aaronson put it[0]: > I’m not making the much stronger claim that this is the best possible use of $20 billion for science. Plausibly a thousand $20-million projects could be found that would advance our understanding of reality
89.
▲
by
danarmak
8y ago
> Since JavaScript has an especially high burden for backward compatibility you can’t really remove old cruft You can't remove features from JS runtimes (browsers or node), but you can certainly remove them from a new language versi
90.
▲
by
danarmak
8y ago
As the Git FAQ [0] says: > Git has a rename command git mv, but that is just for convenience. The effect is indistinguishable from removing the file and adding another with different name and the same content. git diff, merge, and relate
More ›