Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dhx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
dhx
2mo ago
OSM probably has the best data on golf courses because for many courses, people have mapped each 'golf=hole' as a way, and mapped other golf course features such as 'golf=bunker', 'golf=green', etc. OSM knows o
32.
▲
by
dhx
3mo ago
Update 2: Upon checking Sentinel-2 imagery for BAH55 from 2026-03-29 to 2026-04-13 (and all later imagery) there is also visible blast damage to the roof of BAH55, which would correspond in timing to media reports about damage caused about
33.
▲
by
dhx
3mo ago
Update: IRGC published satellite imagery a few hours ago showing an impact to BAH54, apparently impacted on 2026-07-24, alongside another undated image before the impact. From a quick comparison of both images with reliable satellite imager
34.
▲
by
dhx
3mo ago
To add: The request has not yet been published by GitHub to https://github.com/github/gov-takedowns/tree/master/India/20... Also not mentioned in the project's GitHub repository yet per https:
35.
▲
by
dhx
3mo ago
AWS's 3 data centres in me-south-1 are: BAH53 (Manama): https://www.openstreetmap.org/way/1492345589 An adjoining substation to BAH53 had one of it's two main buildings damaged/destroyed about 2026-0
36.
▲
by
dhx
3mo ago
See [1] for April 2024 Clickhouse Github activity analysis of the xz backdoor. I haven't seen anyone write up a proper analysis that includes consideration of: - GitHub activity (e.g. all API actions on GitHub side including replying t
37.
▲
by
dhx
3mo ago
Title is not correct. Microsoft didn't patch a lot of this, they're reporting patches for dependencies that other people patched and Microsoft are inheriting. For example, Mariner (now branded Azure Linux) is a Microsoft-supported
38.
▲
by
dhx
3mo ago
If demographics are a problem for chipmaking in China, then it's good to compare against key chipmaking countries. To compare, 2024 (UN) fertility rates (highest-lowest):[1] US: 1.62 Japan: 1.23 China: 1.02 ROC: 0.86
39.
▲
by
dhx
3mo ago
For some recent data, see the diagram "Semiconductor foundry capacity 8" & 12" - by foundry location (in %)" at [1] for a rough idea of kWpm (thousand 300mm equivalent wafer starts per month) for key countries/r
40.
▲
by
dhx
3mo ago
My key point you are avoiding with personal attacks is: If I see another computer offer TLS named group 0x0200 (MLKEM512) as introduced by draft-ietf-tls-mlkem, do I have any assurance that the other end I'm communicating with uses con
41.
▲
by
dhx
3mo ago
It looks like recent Tenda hardware/firmware is encrypted per below examples, making it harder to audit. binwalk US_AC10V6.0si_V16.03.62.09_multi_TDE01.bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------
42.
▲
by
dhx
3mo ago
From RFC8446 (TLSv1.3) sE.4: "In general, TLS does not have specific defenses against side-channel attacks (i.e., those which attack the communications via secondary channels such as timing), leaving those to the implementation of the
43.
▲
by
dhx
3mo ago
The draft considers FIPS 203 to be normative. Therefore FIPS 203 forms part of this draft. You can't implement this draft without first implementing FIPS 203. FIPS 203 doesn't care about side channel resistance, per my other comme
44.
▲
by
dhx
3mo ago
To point out some positive examples of what RFCs should include: RFC 5288 s3 (AES-GCM): "Each value of the nonce_explicit MUST be distinct for each distinct invocation of the GCM encrypt function for any fixed key. Failure to meet this
45.
▲
by
dhx
3mo ago
This reads to me as an argument of "If you thought ECDSA was bad, wait until you see MLKEM?" ECDSA history is repeating itself again when you consider how poorly the proposed MLKEM RFC deals with side channel resistance: From draf
46.
▲
by
dhx
3mo ago
Not all cryptographers (and cryptography standards) care about real world implementation, or have the same use cases in mind for their cryptography algorithms and protocols. Almost every cryptography standard in common use treats side chann
47.
▲
by
dhx
3mo ago
To extend on this good point-- DJB is not just a mathematician looking over theoretical equations. He's also an expert in the real world _implementation_ of cryptography where most security failures can be expected to occur. For some m
48.
▲
by
dhx
3mo ago
At least in my experience for large retail chains or restaurant chains, hours on their websites are very accurate. I think where Google might benefit from calling to verify hours is, for example, where they've scraped https:/
49.
▲
by
dhx
3mo ago
See alltheplaces.xyz for continuously updated straight-from-the-primary-source opening hours of chains of shops and restaurants, public facilities such as libraries, etc. This is probably as accurate as it gets AND you have the confidence o
50.
▲
by
dhx
3mo ago
1. This is largely country-dependent with some governments being quite adamant that address data should be in the public domain, and some governments doing the opposite and selling address databases to private companies for some quick cash,
51.
▲
by
dhx
3mo ago
I change that slightly to "Good luck getting an explosive payload." The difficulty for an attacker is the explosive payload, not the delivery mechanism. If it were easy for an attacker to get an explosive payload there would be ca
52.
▲
by
dhx
4mo ago
"Fix this code" should ideally solve entire vulnerability classes, not just spot fix buffer overflows one by one. Thus it may be possible to design an LLM which can solve entire vulnerability classes and remain useful to users, bu
53.
▲
by
dhx
4mo ago
I like that it's non-serious and contains jokes throughout the user interfaces. Reminds me a little of Airline Tycoon's non-serious/joking nature, and Theme Hospital if going further back in time. It makes the game fun rather
54.
▲
by
dhx
4mo ago
Contributor for an open source scraper -- https://alltheplaces.xyz/ -- which currently has about 4700 scrapers extracting 40-someting million points of interest. The project aims to scrape location data and other general in
55.
▲
by
dhx
4mo ago
There's an example at [1] of a prompt for a HTML mockup operating system where 3 applications are requested to be "white hat tools" that show diagnostic system information. Claude Fable 5 is shown and said in the video to swi
56.
▲
by
dhx
4mo ago
Also have a look at Inform 7[1] (domain specific language for interactive fiction), specifically the "Stone" example section[2] which explains edible food and the effects different foods may have on the adventurer. It's simil
57.
▲
by
dhx
4mo ago
Agreed. My comment was to highlight that if a recipe for a soup just says "1kg squash", that could mean anything from "Cucurbita maxima subsp. maxima var. Jarrahdale"[1] through to "Cucurbita pepo subsp. pepo var. r
58.
▲
by
dhx
4mo ago
This will perhaps be overkill for what you're trying to achieve, but there is Object Process Methodology (OPM)[1] which may be inspiration for modelling recipes. It looks similar to the methodology you're using, and as an example,
59.
▲
by
dhx
4mo ago
See [1] for a demo, seemingly of an older iteration of what this paper describes. I was curious what ingredients the demo had selected (1032 available vs 1790 this paper selects) so I tried some obscure ingredients from "Organum: Natur
60.
▲
by
dhx
5mo ago
I dug into how software such as LS-DYNA could have been modified. Take for example the EOS_JWL equation at [1] (vendor website, public manual) which is implemented by LS-DYNA. This equation seemingly could be used, alongside other equations
More ›