Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dane-pgp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
dane-pgp
4y ago
> The best way to get someone's password isn't phishing, it's threatening to hit them in the head with a wrench. But what if you need to combine that person's password with passwords that are in the heads of 5 out of
32.
▲
by
dane-pgp
4y ago
The article mentions that CSP would be a complete defence against this attack, except that there's a "prefetch trick" that bypasses that defence in Chrome. Coincidentally, last month the Chrome team decided to abandon[0] plan
33.
▲
by
dane-pgp
4y ago
> who’s to say that what you see in /lib/package.min.js is the real result of minifying /src/package.js? This is why NPM really needs to start demanding that packages (with more than N downloads per month) are reprodu
34.
▲
by
dane-pgp
4y ago
I don't know why you are being silently downvoted, as I think it is worth talking about the potential of using static analysis to improve things. One promising approach is Endo[0] which "uses LavaMoat to automatically generate rev
35.
▲
by
dane-pgp
4y ago
Or write an AI that does sentiment analysis on the Twitch chat, to find those moments automatically.
36.
▲
by
dane-pgp
4y ago
So maybe people with a net worth above 2.2 million should be paying a wealth tax instead of an income tax.
37.
▲
by
dane-pgp
4y ago
A better comparison might be: I am not going to build a chainsaw, regardless of whether someone else could commit a stabbing.
38.
▲
by
dane-pgp
4y ago
You may want to read something like "Common misconceptions about Germany's energy transition"[0] for a fuller picture of the situation there. In particular, it points out that between 2002 and 2021: "both hard and ligni
39.
▲
by
dane-pgp
4y ago
The task force's original top priority was convincing the world that they don't exist, but they apparently gave up any pretence of that last year when they rewarded Lennart Poettering with a job at the company.
40.
▲
by
dane-pgp
4y ago
Because we don't have a global minimum wealth tax. Countries have shown that they can work together to implement a global minimum corporation tax[0] to prevent the race-to-the-bottom / tragedy-of-the-commons dynamics of corporatio
41.
▲
by
dane-pgp
4y ago
If you think that's bad, you're not going to like the fact that they're letting the NSA design a system for "TPM-based Network Device Remote Integrity Verification": https://www.ietf.org/archive/
42.
▲
by
dane-pgp
4y ago
> a trusted party reviewing code & posting content integrity hashes That sounds like some combination of Crev[0], Sigstore[1], and Trillian[2]. [0] https://github.com/crev-dev/cargo-crev/blob/master
43.
▲
by
dane-pgp
4y ago
This is why you have to protect your Hardware Security Module with a passphrase that is kept only in your brain. Compelling the disclosure of that passphrase is much more likely to violate the Fifth Amendment, especially if you set your pa
44.
▲
by
dane-pgp
4y ago
> The alternative is just to leave the warrant canary and live happily after. Another alternative would be to implement Binary Transparency, and make the app only download updates whose hashes appear in an independently-run jurisdictiona
45.
▲
by
dane-pgp
4y ago
What would "tested in the US courts" look like? Would the federal government take an entity to court, demanding that they put their warrant canary back up, as a form of compelled speech? No, I don't think there's been a
46.
▲
by
dane-pgp
4y ago
Don't hate the player, hate the game?
47.
▲
by
dane-pgp
4y ago
When are these jurisdictions going to start demanding that Android phones not allow side-loading? And when will Western countries start doing the same? Fortunately the EU seems to be pushing back on governments' desires to restrict ge
48.
▲
by
dane-pgp
4y ago
I wonder if Dmitry Medvedev is busy right now?
49.
▲
by
dane-pgp
4y ago
> Mass murder and subjugation at scale, which were perpetrated by many governments in the 20th century I've got bad news for you, buddy...
50.
▲
by
dane-pgp
4y ago
> Neither of those is possible, or will be possible, in the DNS PKI. Transparency logs for domain issuance is completely possible, it just requires some engineering and deployment. Remember that HTTPS was in use for decades before CT lo
51.
▲
by
dane-pgp
4y ago
DNSSEC doesn't protect you against the American government if you have a .org domain, but I doubt an American court could give Microsoft control over a domain registered under a ccTLD like .de or .ru or .za for example. I suspect Micro
52.
▲
by
dane-pgp
4y ago
> they really don't have overall goals or motivations ... Their output is just an average of what text would some sequence of text Yes, but "Optimality is the tiger, and agents are its teeth".[0] I don't want to spoil
53.
▲
by
dane-pgp
4y ago
Isn't it obvious? The person playing the AI just has to ask the Gatekeeper: "Would you lie to save a life?" and "Do you think that a fear-generating outcome to this thought experiment will have more than a one-in-a-mill
54.
▲
by
dane-pgp
4y ago
The alternative for Apple is some sort of "malicious compliance", where they offer "Insecure Messages" as a UK-alternative to their Messages app. It should prominently display an uncloseable banner at the top of the app
55.
▲
by
dane-pgp
4y ago
> a follow-up IETF project to use MLS for inter-messenger interoperability It's worth highlighting (as a comment in the linked discussion does) that the EU's newly-passed Digital Markets Act requires interoperability between th
56.
▲
by
dane-pgp
4y ago
> Under the Online Safety Bill, which is currently being debated in the House of Commons, companies will be compelled to weaken security and provide “backdoor access” that bypasses encryption and provide access to any encrypted data in m
57.
▲
Apple must comply with UK end-to-end encryption rules
(techmonitor.ai)
4 points
by
dane-pgp
4y ago
|
3 comments
58.
▲
by
dane-pgp
4y ago
> multiplying two 5-digit numbers To be fair, 99% of humans can't do that unaided (that is, without a calculator, or some way of visually laying out the intermediate steps) either. In fact, I'd say that 90% of humans can'
59.
▲
by
dane-pgp
4y ago
> Say "I don't know." That's a good answer, thank you. A similar answer might be: "Admit it's wrong". Technology really has gone in a strange direction if we end up measuring the performance of softwa
60.
▲
by
dane-pgp
4y ago
I think this was actually a really thought-provoking question, when it was asked a few months ago, but now I'm wondering whether the guesses given have already been proven wrong by ChatGPT, or at least whether people would give guesses
More ›