Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
erights
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
erights
6y ago
Meltdown and Spectre are serious. But we need clarity on what they do and do not threaten. To address the widespread confusion on this topic, and to demonstrate a completely different approach to mitigating these, we wrote: https:/&#x
2.
▲
by
erights
6y ago
> were you one of the authors, contributors or involved in writing it? Yes, I am one of the authors of the paper. > but they don't come across as snooty dismissals. Feels more like guys on all sides trying their best. Rereading i
3.
▲
by
erights
7y ago
Hi Ping! What differences do you find most striking?
4.
▲
by
erights
7y ago
Much of my work on capabilities, from 1988 till now, can be found at https://research.google/people/author35958/ and at Agoric https://agoric.com/papers/ Agoric is bringing distributed objec
5.
▲
by
erights
7y ago
Yes, that's the paper, from 2003. Please everyone read this paper http://srl.cs.jhu.edu/pubs/SRL2003-02.pdf rather than the web page. And thanks! There's a story behind why this paper became so influential. T
6.
▲
by
erights
7y ago
ActivityPub is important. We need it to be more widely appreciated. I'm glad to see it on Hacker News. Chris Webber, one of ActivityPub's creators, suggests next steps in "OcapPub: Towards networks of consent" https:&
7.
▲
by
erights
7y ago
Thanks. The "with(proxy)" part specifically would be mine. The old Google Caja, from the EcmaScript-5 days preceding Proxies, did something similar: https://github.com/google/caja/blob/master/sr
8.
▲
by
erights
8y ago
At https://twitter.com/spudowiar/status/1069680974110306306 Saleem Rashid raises an example of this principle that is especially easy to overlook, where authority arises from one entity relying on the unchecked ve
9.
▲
by
erights
8y ago
In light of some feedback we've received on the article, some clarification is needed. The ocap (object-capabilities) approach does not by itself make systems secure. Rather, it an enormous step towards making systems secureable. Even
10.
▲
by
erights
8y ago
This npm / event-stream incident is the perfect teaching moment for POLA (Principle of Least Authority), and for the need to support least authority for JavaScript libraries. https://www.youtube.com/watch?v=9Snbss_tawI&