Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
drvdevd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
241.
▲
by
drvdevd
10y ago
I use ZFS under everything (including docker) and so I can use scheduled snapshots, backups, etc, to do the real data management, and not worry about losing data. I can use host mounts too, but I prefer to just back up and manage all of do
242.
▲
by
drvdevd
10y ago
PoC||GTFO is my favorite of late...
243.
▲
by
drvdevd
10y ago
This doesn't really answer your question directly but I find a fun exercise is to take a picture of a face and modify it (clip it, skew, morph, rotate, repeat, etc), and then see at which point Facebook will cease to recognize a face i
244.
▲
TCP-ENO: Encryption Negotiation Option
(datatracker.ietf.org)
1 points
by
drvdevd
10y ago
|
0 comments
245.
▲
by
drvdevd
10y ago
Yeah I suppose it's not really tractable to automatically infer the total behavior of a program (halting problem?)... I had some kind of weird strace like mechanism in mind.. Perhaps static analysis to see which library functions are l
246.
▲
by
drvdevd
10y ago
Disgusting.
247.
▲
by
drvdevd
10y ago
One could envision a scenario where much of that custom wiring could be auto-generated somehow (e.g.: with some kind of defaults + dynamic analysis). But the point is really - this is a distro issue and SELinux is a building block. If you
248.
▲
by
drvdevd
10y ago
This is a great idea and reminiscent of LLVM to me...
249.
▲
by
drvdevd
10y ago
It's important to understand that SELinux has ceased to be a pure-NSA development for a long time. For that matter, it has spread far beyond RedHat as well. Anyway, though I get the sentiment, SELinux is a great example of leveraging O
250.
▲
by
drvdevd
10y ago
Interesting. I'm surprised I haven't read more about the Linux kernel keyring infrastructure. Are you sure that portable openssh ssh-agent doesn't implement access to it?
251.
▲
by
drvdevd
10y ago
This is murky because the most basic UNIX isolation mechanism (UID/GID) is applied across all parts of the system: processes, files, etc. (in a nutshell). Thus, when you run some program locally, sometimes it runs as your user/gro
252.
▲
by
drvdevd
10y ago
I know it's not really what you mean, but isn't the touchbar powered by an ARM chip already and also the secure enclave?
253.
▲
by
drvdevd
10y ago
I think SELinux is convenient or inconvenient depending on context. For example on Android I find it's mostly convenient because it's been (IMO) well integrated into the system in such a way that I will only have to dig into it if
254.
▲
by
drvdevd
10y ago
I pay for GitHub and can't deny their positive role in OSS, but I also use GitLab and will happily continue (and love that they have an OSS edition). I don't think it's a binary choice. Personally I will often adopt multiple
255.
▲
by
drvdevd
10y ago
That's the kind of team I want ! All hands on deck. No lame responsibility shifters.
256.
▲
by
drvdevd
10y ago
also, maybe some people on here are perfect, but if you've used Unix for more than half your life (as I have) you've 'rm -rf'-ed some stuff. I think people who've been through disasters have a much better understand
257.
▲
by
drvdevd
10y ago
> (under heavy regulation) ... and this is where most Heroin addicts start, actually, through prescription opiate use. Once a physical addiction is formed, heroin can be a cheaper or more accessible alternative to a prescription for say,
258.
▲
by
drvdevd
10y ago
Isn't there something like, just one company in the world that makes 95% of all USB to Serial chips?
259.
▲
by
drvdevd
10y ago
This is an inspiring point of view for those of us who would like to do business internationally as well I think. Personally, I'm stuck on the idea that the Internet is capable of helping citizens transcend national barriers (and timez
260.
▲
by
drvdevd
10y ago
So you would still need a trusted cert though right for the TLS MITM? And presumably SSH is not affected any more than on the open internet? Anyway, while these may be valid attack vectors, since I started getting traffic injected by my ISP
261.
▲
by
drvdevd
10y ago
The radiation poisoning was certainly strange though. Any idea why this was done?
262.
▲
by
drvdevd
10y ago
I haven't actually looked at the code yet, but to be fair, if your connection through any VPN is completely encrypted (e.g. HTTPS only), then it's not much different to most ISPs... They can grab metadeta but this is already bein
263.
▲
by
drvdevd
10y ago
But again - the point is not to lie, technically and thus avoid commiting an actual offense. If your data is important enough to you, you probably will want to consult your lawyer before attempting such a scheme :)
264.
▲
by
drvdevd
10y ago
I think this is probably correct. But I would be sure to encrypt my device before mailing it too.
265.
▲
by
drvdevd
10y ago
Yeah perhaps this is not the best hypothetical response... I still believe there is a way to adjust such an encryption scheme to meet the ideal criteria: 1. you're not lying 2. you can't provide access 3. you're not drawing e
266.
▲
by
drvdevd
10y ago
And as in the original "scheme" -- this is a question of technicalities and (perhaps only if you're a US citizen, perhaps not), whether or not the authorities in question are willing to take it to trial and prove that you &qu
267.
▲
by
drvdevd
10y ago
I agree - basically. The scheme is designed to be a half truth essentially. One that you can mentally convince yourself of in a tight situation, which would relieve you somewhat of the need to be "tough", psychologically speaking.
268.
▲
by
drvdevd
10y ago
Well, I was being somewhat vague to avoid inserting my own story into the thread too much, but I'm going to be a first-time parent soon and I'm living in the same town I've lived in most of my life, which I often get fed up w
269.
▲
by
drvdevd
10y ago
You just told me everything I needed to hear. Thank you. [edit] being serious here -- I needed to read what you wrote.
270.
▲
by
drvdevd
10y ago
Right. The best scheme requires no bravado. You should be able to tell the truth: 1) use FDE with a LUKS-like scheme where the encryption header can be backed up and then removed (making sure you can restore it at your destination somehow
More ›