Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eqvinox
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
121.
▲
by
eqvinox
3mo ago
Curious. Most places needing SSO also have legal retention requirements, making E2E a hard nonstarter. And most E2E users wouldn't want to rely on a SSO that could likely revoke their keys. What's your environment?
122.
▲
by
eqvinox
3mo ago
What I said was "It makes much more sense to argue there is no consensus […] can be argued even in a "60:40" situation regardless of direction". Not "there's a 60/40 split, therefore there's no consen
123.
▲
by
eqvinox
3mo ago
Anyone know if "-cpu ${CPU},vmx=off,svm=off" in QEMU is a safe workaround for this? (To disable nested virtualization on a per-VM basis. Only against exploitation from within that specific VM, obviously does nothing against users
124.
▲
by
eqvinox
3mo ago
> A single sentence of encouragement is all that is on offer from this MLKEM RFC. The draft only specifies the MLKEM binding into TLS; it'd be out of scope for it to go into detail on implementation considerations for MLKEM. Those
125.
▲
by
eqvinox
3mo ago
I can't help but note two things: * the IETF's approach predates 15 U.S.C. §4302 by more than a decade * every single case example cited is US-American scoped¹ SDOs: American Society of Mechanical Engineers, National Fire Protect
126.
▲
by
eqvinox
3mo ago
> I would maintain TLS the same way WireGuard and OpenSSH are maintained. Both have superior track records. I'm generally an opponent of all security and (especially) cryptographic standards bodies. Hmm. This doesn't entirely c
127.
▲
by
eqvinox
3mo ago
Ah I see what you were trying to say. It read to me (with " He's a cryptographer. You're describing cryptographers. ") like you were dismissing that knowledge about implementing and shipping cryptographic libraries is a
128.
▲
by
eqvinox
3mo ago
> …information RFC? He can’t stop that, right? Informational RFCs still need to pass through the IETF consensus process, changing the intended status isn't a procedural bypass. However, the authors can just publish it elsewhere, it
129.
▲
by
eqvinox
3mo ago
> whether he realizes it or not, he's operating in supremely bad faith this time. I've met him in person, once, at a CCC event about a decade ago, and as someone clueless about cryptography all I can say to that is that he cert
130.
▲
by
eqvinox
3mo ago
I do think it's fair to make an argument that DJB's expertise in practical cryptography (both in e.g. engineering against side channel attacks as well as in publishing his own libraries) gives him a reality-minded perspective/
131.
▲
by
eqvinox
3mo ago
Thanks for the link to that amazing document!
132.
▲
by
eqvinox
3mo ago
From the way DJB talks about IETF processes, it's quite clear to me though that he has little trust/belief in the IETF consensus process. I thought he said as much somewhere but can't find that right now. (It's particula
133.
▲
by
eqvinox
3mo ago
Actually… what would even be the result of the pure MLKEM document getting dropped by the IETF? I guess the entries would temporarily be marked deprecated or something, until another reference is made available somewhere, describing the sam
134.
▲
by
eqvinox
3mo ago
> […] "preliminary" in the sense that when the RFC for hybrid ECC/ML-KEM is published […] Yes, sorry, I was just covering against people nitpicking on the document status :)
135.
▲
by
eqvinox
3mo ago
> The question at hand is whether the IETF will publish an RFC documenting the ML-KEM. The IETF document only documents how and where to put the MLKEM values into TLS. MLKEM itself is specified in FIPS203 and it just references that for
136.
▲
by
eqvinox
3mo ago
From the other direction, the ITU-T has a highly regarded presentation on how to actually work with consensus procedures & establish said consensus: https://www.itu.int/en/ITU-T/tutorials/202203/Docum
137.
▲
by
eqvinox
3mo ago
DJB keeps calling the IETF consensus process "voting". That's detrimental to his own case; when there is a vote, the vote can be manipulated. It makes much more sense to argue there is no consensus, which should be quite ob
138.
▲
by
eqvinox
3mo ago
> But the short wires in a Nikon camera are not long enough to be a useful antenna. […] Everything is probably just traces on a PCB. Anyone who's had to get newly developed hardware through EMI certification in recent times can tell
139.
▲
by
eqvinox
3mo ago
> Flex or Bison generated code is also hard to maintain plus it complicates builds. This is, in all honesty, a solved problem in any reasonable build system. (And I have little patience left for people making life hard for themselves thr
140.
▲
by
eqvinox
3mo ago
> The defacto industry standard for audio ICs is I²S, an I²C-based bus optimised for audio data. Nit: I²S has nothing to do with I²C. (Most I²S chips also have an I²C interface since I²S only carries raw audio data, no sideband like volu
141.
▲
by
eqvinox
3mo ago
Annex K (which is what that is) is sufficiently unpopular as to have been under discussion to be removed from the standard. Few implementations exist, and even fewer conform to the standard (e.g. Microsoft's doesn't). https:&#x
142.
▲
by
eqvinox
3mo ago
For people interested in "less systemd" there's also the gardenhouse bits at https://git.pinkro.se/
143.
▲
by
eqvinox
3mo ago
UB (specified to be undefined) and 'plain' unspecified are not the same thing.
144.
▲
by
eqvinox
3mo ago
Feels like you missed the point. On the example of 'echo \n' - it's not defined in POSIX, therefore a script written in "POSIX shell" must simply never hit that case. TFA kinda implies you can't target POSIX sh
145.
▲
by
eqvinox
4mo ago
There's a whole bunch of other studies on this topic, as well as metastudies, and from what I can tell the problem is real. https://www.sciencedirect.com/science/article/pii/S245195882... (+ cf. its refe
146.
▲
by
eqvinox
4mo ago
> My hope is that in a couple of model generations, we'll trust AI to review MRIs the way we trust it to proofread our emails. https://www.nature.com/articles/d41586-026-01947-1 I've started asking my do
147.
▲
by
eqvinox
4mo ago
I get that there's only so many good names, but Murmur is the name of the Mumble server implementation [ https://www.mumble.info/ ], which is also communication. That makes this name collision worse than others.
148.
▲
by
eqvinox
4mo ago
I wasn't talking about a specific case, and "UI" is more than a single page. To be specific, I'm referring to the sum of text (incl. translations), graphics and layout on the entire product/application/etc. I a
149.
▲
by
eqvinox
4mo ago
> Oh, so you know several people who when presented with the dichotomy of Ethernet or fiber (because that's what the comment you replied to was about, as it put Ethernet in contrast with fiber), they'll be completely dumbfounde
150.
▲
by
eqvinox
4mo ago
"still"? It never was. If you copy a (copyrighted) UI in bulk, that's a copyright violation just like copying code in bulk. The legal metric is generally "sufficient height of creation", the actual interpretation de
More ›