Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlitz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
91.
▲
by
dlitz
12y ago
Let's Encrypt is scheduled to launch in mid-2015, so by later this year, the procedure to get a proper certificate will be something like: sudo apt-get install lets-encrypt lets-encrypt example.com https://lets
92.
▲
by
dlitz
12y ago
Right, which means that there will be a disproportionate number of FreeBSD developers running it. These developers have commit access to the source tree, including -STABLE and -RELEASE.
93.
▲
by
dlitz
12y ago
SSH agent forwarding should eliminate the need to do that.
94.
▲
by
dlitz
12y ago
Who said anything about doxxing? Cheap intimidation tactics aren't going to change anything. I don't care about these people's home addresses or even their contact info. I just want to know who they are so that I can avoid
95.
▲
by
dlitz
12y ago
No, I mean the individual engineers.
96.
▲
by
dlitz
12y ago
I've taken Lyft a handful of times, and in my experience, it seems like it's only the new drivers that are awkward about this---after that, they usually do a good job of reading my body language and responding appropriately. I th
97.
▲
by
dlitz
12y ago
> The tough sell is trying to show management that the alternative creates technical debt that will strangle the project if it isn't addressed If you're worried about that, then the problem is that you have someone managing a s
98.
▲
by
dlitz
12y ago
Wikipedia Zero creates a financial penalty for users who want to preserve their privacy by using Wikipedia over Tor. I wonder what folks here think about the ethics of that.
99.
▲
by
dlitz
12y ago
> Maybe I'm being too mean, but yeah, I also think a lot of the comments are pointless. Yeah, I think you're being a little mean. If you browse to that user's GitHub page, it looks like it's just somebody new who
100.
▲
by
dlitz
12y ago
Is there? The usual term for what you're describing is a "stream cipher" or a "streaming-mode cipher".
101.
▲
by
dlitz
12y ago
> You'd have to use absolute paths everywhere Ever heard of PATH_MAX and ENAMETOOLONG? You will if you're using absolute paths everywhere. Sigh
102.
▲
by
dlitz
12y ago
I doubt there's really a "new" Microsoft. They're just in the "Embrace" phase of their usual 3-step process.
103.
▲
by
dlitz
12y ago
The page doesn't load for me. My recursive resolver (unbound) just gives SERVFAIL. I did a bit of digging, and apparently you need to follow a ridiculously long CNAME chain just to resolve the domain: www.whymicrosoft.com.
104.
▲
by
dlitz
12y ago
Because COBOL is alive and well. It's not interesting , but it's far from dead. A friend of mine works on a COBOL system that's responsible for calculating pension payments for former government employees. COBOL is good en
105.
▲
by
dlitz
12y ago
> ...Qhadaffi's Libyan government would have effectively been the CA for BIT.LY. They already are, in practice. Many reputable CAs will issue certificates to anyone who can forge an MX record for a domain. With or without DNSSEC,
106.
▲
by
dlitz
12y ago
Raymond didn't answer the question; He answered a different question. The question actually asked was about why---almost 20 years later---Microsoft continues to ship new versions of Office with this inconsistency. It's like if yo
107.
▲
by
dlitz
12y ago
Speaking a language in the same way as other speakers of that language makes you easier to understand.
108.
▲
by
dlitz
12y ago
> On modern Linux kernels, /dev/urandom is Probably Safe(tm). But what about everything else? That's where it gets murkier. No. That argument is exactly why I didn't just use /dev/urandom in PyCrypto'
109.
▲
by
dlitz
12y ago
> It's impossible (or just not worth the trade-off) to make one piece of software (this time, kernel) fast for any use case imaginable. We're not nearly at the theoretical limit of what /dev/urandom can provide.
110.
▲
by
dlitz
12y ago
Most developers don't know how to make that distinction, and even savvy ones know better than to take the risk of being wrong. It's 2014. There are well-funded governments and organized crime attacking our systems. If downstream
111.
▲
by
dlitz
12y ago
Exactly. Most developers are about as good at picking RNGs as end-users are at picking passwords. We need to stop asking them to make that choice.
112.
▲
by
dlitz
13y ago
> Maybe a big name in software could go and write a modern crypto library without all the cruft of OpenSSL but for now we have to deal with it. https://xkcd.com/927/ There are very few competent FOSS crypto implemen
113.
▲
by
dlitz
13y ago
Thank you for being sane about this. Do you know if those folks are working on making /dev/ random faster*? I'd really like to see even traditionally "non-cryptographic" RNG's (e.g. rand()) just use the kerne
114.
▲
by
dlitz
13y ago
> I understand your suggestion as changing the contract to satisfy those who falsely think they actually need "/dev/random" even if they don't. Not exactly. /dev/urandom also sucks, because it's s
115.
▲
by
dlitz
13y ago
Another new IPv6 transition mechanism?
116.
▲
by
dlitz
13y ago
What should actually happen is that /dev/random and /dev/urandom should provide the exact same interface: block at boot-time until they're seeded with "sufficient" entropy, and then never block again until
117.
▲
by
dlitz
13y ago
> I don't understand how people who understand the relationship between CSPRNGs and (say) CTR mode can believe that there's merit to using /dev/random after urandom has been seeded. If I were more cynical, I'd sa
118.
▲
by
dlitz
13y ago
That's sometimes hard to do. For example, if you're here on an H-1B visa.
119.
▲
by
dlitz
13y ago
> If your documentation is a directory full of files on GitHub, I close the tab. I closed the tab after reading this.
120.
▲
by
dlitz
13y ago
The site has been around for a while. I already had an account on it from last year, because it has a nice tax calculator.
More ›