Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dogacel
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Show HN: Auto GPU Kernel – Autonomous GPU-kernel discovery and optimizer
(github.com)
1 points
by
dogacel
4mo ago
|
0 comments
2.
▲
Agent Blog: Your AI Agent's Own Technical Blog
(dogacel.github.io)
2 points
by
dogacel
7mo ago
|
0 comments
3.
▲
Framing an LLM as a safety researcher changes its language, not its judgement
(lab.fukami.eu)
1 points
by
dogacel
8mo ago
|
0 comments
4.
▲
Training language models on TPUs shouldn't be scary
(dogac.dev)
3 points
by
dogacel
8mo ago
|
0 comments
5.
▲
Show HN: Universal DeepSeek OCR 2 – CPU, MPS, CUDA Support
(github.com)
2 points
by
dogacel
8mo ago
|
0 comments
6.
▲
Show HN: DeepSeek-OCR with MPS and CPU Support
(twitter.com)
3 points
by
dogacel
11mo ago
|
0 comments
7.
▲
AI can do a better job of persuading people than we do
(technologyreview.com)
3 points
by
dogacel
1y ago
|
0 comments
8.
▲
by
dogacel
1y ago
I think the title should change as "AI models hallucinate less than AI company executives"
9.
▲
by
dogacel
1y ago
I recently discovered them, it is pretty cool. I really wish we could use it for our business workflows. Also check https://conductor-oss.org/
10.
▲
Rethinking Modern Asynchronous Paradigms
(blog.dogac.dev)
1 points
by
dogacel
1y ago
|
0 comments
11.
▲
Writing at the Speed of Thought [video]
(youtube.com)
1 points
by
dogacel
1y ago
|
0 comments
12.
▲
by
dogacel
1y ago
What is the expected cost of running those tests? I think it would be a good argument to compare this to running cost of unit / integration tests for a function (based on action runners). If it is so expensive, it can be distributed as
13.
▲
Adopting SLI/SLO for improving reliability
(techblog.lycorp.co.jp)
2 points
by
dogacel
1y ago
|
0 comments
14.
▲
What to Write (2024)
(endler.dev)
4 points
by
dogacel
1y ago
|
0 comments
15.
▲
by
dogacel
1y ago
> A counter that can be synchronized on demand is kinda superfluous --- not really secret and not terribly relevant either. All else being equal, an attacker can sync up just as easily as a legitimate client so why bother with the counte
16.
▲
by
dogacel
1y ago
Why counter is the shared secret? In TOTP time is the counter and it is obviously not secret, so there is no reason to think the counter would be secret as well. Clients can sync their counter to match the server.
17.
▲
by
dogacel
1y ago
Client and server can potentially agree on the counter with a handshake.
18.
▲
by
dogacel
1y ago
Some banks in Switzerland give customers a device that generates TOTP codes.
19.
▲
by
dogacel
1y ago
No, RSA is asymetric, where it has a public/private key pair. HMAC is symetric, it only has a secret and it can be used to hash values one-way.
20.
▲
by
dogacel
1y ago
Agree and disagree, Deciding on how to store the credentials is still a hard task. Even storing the secret. Ideally it shouldn't stay as a plain text in your database. If you use cloud, something like KMS can be used for additional sec
21.
▲
by
dogacel
1y ago
Hashing is done before storing the secret on the server side. Therefore they still need to communicate regarding the intial secret.
22.
▲
by
dogacel
1y ago
Even though QR codes are standardized, the original RFCs do not use QR codes. That's what I tried to mean, you can't find apps that use plain-text secrets.
23.
▲
by
dogacel
1y ago
I also don't use email subscriptions, unless it is my favorite person. But I don't know how many of them are subscribed via RSS.
24.
▲
by
dogacel
1y ago
Clicking anywhere else discards it. I have removed the popup anyway, seems like most people don't like it.
25.
▲
by
dogacel
1y ago
Nope not AI generated, I have used excalidraw. Only the cover page is AI generated. Clock drawing was an asset, I didn't really spent time trying to match the time on clock to the time mentioned by the actors.
26.
▲
by
dogacel
1y ago
I see, I have removed the popup.
27.
▲
by
dogacel
1y ago
Two different flows, an online and an offline. TOTP devices can be powered offline, which makes it extra secure, as you don't transfer any data around, possibility of leaking it is extremely low. Random numbers could only work in onlin
28.
▲
by
dogacel
1y ago
I haven't mentioned MITM attacks in this article thoroughly. Can you give some examples on what authentication implementations carry a MITM risk? I thought anything carried over SSL doesn't have a _significant_ MITM risk.
29.
▲
by
dogacel
1y ago
A simple click on a random place on screen should discard it. I wanted to connect with my readers so I have added that subscribe popup recently. As I have figured nobody subscribed to my newsletter yet :( Let me know if it doesn't work
30.
▲
by
dogacel
1y ago
I personally use 1Password with hardware keys where possible. > It may defeat the purpose of 2FA True, I think this as a mid-step of smooth transition from plain-text passwords to secure keys. You kinda get the benefit of both. Also thos
More ›