Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dvzk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
dvzk
4y ago
Sorry. I meant to write that closed source software isn’t opaque, technologically. (More opaque, yes, opaque... no.) Legally, it’s different. But closed source compilation alone doesn’t grant a program special privileges or confidentiality
62.
▲
by
dvzk
4y ago
DRM protection sometimes rears its ugly head, and that is worth objecting to, but as someone who has written unpackers and game mods, it’s rare nowadays that DRM prevents modding, unless you’re creating unethical multiplayer hacks. Code tha
63.
▲
by
dvzk
4y ago
Sometimes, yes, but not intrinsically. AOSP performs OS and app update authenticity verification via predistributed public keys, as do package managers. In theory, a phone’s firmware can be completely open source and still be unmodifiable.
64.
▲
by
dvzk
4y ago
Copyright laws are not what is stopping custom firmware projects on many devices. It’s the inability to flash non-signed firmware. Legal considerations in general have minor pragmatic relevance for modding projects that are not lazily redis
65.
▲
by
dvzk
4y ago
I think this is a good argument for the advocacy of GPL-3+ prevalence. It’s also legal, I think, to publish GPL-3 firmware source code, and to disallow custom firmware flashing, as long as the copyright is self-owned. (IIRC the provisions o
66.
▲
by
dvzk
4y ago
> Yet since then, I have personally lost control of many of the computing devices I use. No, you haven't. Or rather, you didn't lose control because of any software license. We lost control because of cryptography and enforced
67.
▲
by
dvzk
4y ago
I don’t know if I dislike GPT for making inauthentic people seem slightly more convincing, or if I like it for confirming that we have always lived among people who are essentially performative NPCs.
68.
▲
by
dvzk
4y ago
Perhaps the biggest revelation from this is that Firefox doesn't implement rebinding protection, and that CGNAT DNS responses aren't dropped by most resolvers. Host validation is preferable anyway [1] but the second problem still
69.
▲
by
dvzk
4y ago
Maybe it’s just me, but I would never go through a random certificate authority like “K Software”. Users are not cryptographically verifying the developer’s signing identity, they are trusting KSoftware’s attestation that the signed binary
70.
▲
by
dvzk
4y ago
I'm usually a strong advocate for holding citizens of democratic nations morally accountable for their nation's actions. Asking software authors to martyr and incriminate themselves on behalf of a minuscule fraction of the public,
71.
▲
by
dvzk
4y ago
What utility does that provide? In time the other provider will be issued a different warrant. The user threat model for every online service ought to include legal and illegal data seizure. Any imaginary nation which doesn't perform t
72.
▲
by
dvzk
4y ago
I was about to mention this. It’s hard for me to take any symmetric or password-based backup tools seriously. User chosen passwords are a disaster for offline encryption. Most tools also use related key input for (non-)authenticated encrypt
73.
▲
by
dvzk
4y ago
Linux and the BSDs really should have a more restricted default desktop capability model compared to macOS by now. It's a shame that Qubes is the main response we have, not because it's bad, but because it's almost necessary.
74.
▲
by
dvzk
4y ago
In most cases, yes, but that's not what the parent meant. In managed environments, it's common to not have root login access, and local privilege escalation is sometimes more critical than normal.
75.
▲
by
dvzk
4y ago
I'm not sure there is much of substance to evaluate. If we fired every technical lead who sometimes "waded into areas with no experience," issued orders, followed a conviction or two and occasionally provided disparaging feed
76.
▲
by
dvzk
4y ago
Based on the article, the private keys for peer enrollment signing are generated locally on each Tailscale client and aren't distributed at all. I don't see why you couldn't write a custom client that approves or denies new p
77.
▲
by
dvzk
4y ago
That's actually the point of this feature. Before, the key distribution server could add unauthenticated Wireguard nodes to your peer list. Now, the tailnet administrator can tell Tailscale nodes to reject new peer public keys unless t
78.
▲
by
dvzk
4y ago
As an observer since the initial release, Tarn repeatedly refused requests to compromise by expanding the team or involving a publisher. It was a genuine passion project the sort of which rarely succeed financially. I couldn't be happi
79.
▲
by
dvzk
4y ago
I started using std::shared_ptr in every project in 2008. Isn’t it late to denounce the changes now? The state of most C++ codebases is infinitely better today compared to then, partly owed to the added descriptivity.
80.
▲
by
dvzk
4y ago
If this update is like the old version, it has bundled dependencies on glibc and SDL 1.2. You can overwrite the outdated glibc libraries with symlinks to the system glibc. SDL, SDL_image, and SDL_ttf can be relinked to sdl12-compat, which i
81.
▲
by
dvzk
4y ago
Burrows are not something you need as a beginner unless you're doing something unusual. It's best to forget about the feature. For jobs, press (u)nits -> (z)oom -> (p)references -> (l)abors on your dwarves and adjust thei
82.
▲
by
dvzk
4y ago
Following up, I find it funny that this old meme comment thought orders and banking are our most trusted activities, and not our communications and data storage.
83.
▲
by
dvzk
4y ago
I trust the cryptography behind TLS. I don’t trust every website using TLS. The difference between end-to-end encryption and transport-layer encryption is the website operator can recover the plaintext. And the point of the comment I respon
84.
▲
by
dvzk
4y ago
Anyone who doubts you should run zxcvbn and more modern entropy estimators against their passwords. Our intuitions are not good. Offering password-based encryption to normal users is borderline unethical.
85.
▲
by
dvzk
4y ago
> Further complicating this math is the E2EE nature of it, so it’s not just enough to pwn a server, you’d need to also compromise the client application. The webvault is both a server and a client, and you can't not use it. As soon
86.
▲
by
dvzk
4y ago
The Bitwarden webvault infrastructure is a doomsday target. If it's compromised, no evidence of a client backdoor will exist except in the server logs. You can't avoid using it, because you need to sign into the webvault to config
87.
▲
by
dvzk
4y ago
Astronauts have spent >736,000 hours in spaceflight, risking their lives for humanity, but the parent believes a 10-minute stunt flight carrying an irrelevant passenger is all that matters. I suppose they also dislike the imaginary adore
88.
▲
by
dvzk
4y ago
Assuming that you still want offroad capability, you basically just described a cyclocross bike. And going on an ultralight tour on a modified CX bike sounds super fun!
89.
▲
by
dvzk
4y ago
Tires and rims differ substantially but you often don't need to reseat the tire bead if you remove the valve core and inject sealant through the stem. High volume hand pumps and soap can usually seat tires in place of CO2 cartridges. I
90.
▲
by
dvzk
4y ago
How feasible are tubeless setups on long tours? I'm curious. Anyone who MTBs knows about the dramatic improvement. In just the past year I would have had 50+ flats using tubes. I'm positive because I pull out thorns by the dozen.
More ›