Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
g_p
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
g_p
2y ago
Presumably you sign the emails rather than encrypt them? Otherwise anyone who knew the public key of the server (which shouldn't be presumed secret) could send an encrypted instruction, and it would be acted upon, and past encrypted in
32.
▲
by
g_p
2y ago
An interesting idea. Another commenter pointed out the need to train staff regularly on its use. Something else that would be a challenge for your idea would be how to handle the orders of magnitude efficiencies in scaling gained from digit
33.
▲
by
g_p
2y ago
Yes, this is really hard. You could get a Solarwinds type situation where the adversary has the signing keys and ability to publish to the website. You might also find that the vendor ships a library (like libxz) as a part of their invisibl
34.
▲
by
g_p
2y ago
Out of interest, I assume this was an arm64 build of Linux? Which hypervisor or VM software did you use?
35.
▲
by
g_p
2y ago
My reading is that they really wanted the non-SE version (i.e. the full performance one with JIT) on those devices, but recognized that wasn't going to happen given the rules against using JIT. Therefore they do not seem particularly b
36.
▲
by
g_p
2y ago
Not the OP, but my understanding (admittedly a few years outdated) is that an MSP430 will, in idle, with sleep states properly set up and low power modes in use, drain a coin cell battery (e.g. CR2032) over a period of years - with the curr
37.
▲
by
g_p
2y ago
TDD networks (where the same frequency is used for downlink and uplink, but with timeslots for each) do need tight timing between cells though, but it doesn't have to be absolute - just in sync with each other so one cell doesn't
38.
▲
by
g_p
2y ago
My guess is they will retain "parts pairing" from a technical perspective, but frame it as an anti theft measure, and focus on preventing use of stolen device parts. Perhaps they'll relax the restrictions on "non first p
39.
▲
by
g_p
2y ago
The current approach (as I understand it) for Windows is to turn off measured boot for bitlocker, do the update that's likely to cause the issue, and then turn it back on again after the update has completed. Hence you'll often no
40.
▲
by
g_p
2y ago
Good question. By my understanding , in principle yes you could use ZK proofs - you can imagine it as a way to prove a certain assertion (age >= 18) in a way that isn't directly linked to other data. You sometimes see this in concep
41.
▲
by
g_p
2y ago
While there's some complexity in the details of how you'd implement the protocol and avoid replay "attacks", there are potentially ways to use Chaumian blind signatures so that an age verifying authority can (blindly) si
42.
▲
by
g_p
3y ago
You've got some other good advice in other replies on specific steps to take around infrastructure and software/ dependencies. To turn the question around a bit - you've identified the possible routes of compromise/explo
43.
▲
by
g_p
3y ago
And this is a very sensible precaution where developer environments have SSH keys and other privileged credentials available and exposed in predictable locations, ready for exfiltration over the unfiltered internet connection that developer
44.
▲
by
g_p
3y ago
That sounds like a fine that was the maximum under the pre-GDPR regime, rather than the GDPR-era penalty regime. If the offence took place before the new rules were in force, the old penalties apply, even if the case takes some time to be r
45.
▲
by
g_p
3y ago
My guess is that it's difficult to interface with the system's Bluetooth and WiFi sufficiently without a native app on any modern platform (iOS, Android, Mac, Windows, Linux) enough to create and advertise that kind of ad hoc netw
46.
▲
by
g_p
3y ago
Absolutely. Part of the challenge is that Open RAN opens up more (and new) interfaces that have to "play nice" and interoperate. Another part of the challenge is the commercial business models part - monolithic RAN vendors can int
47.
▲
by
g_p
3y ago
Yes, and yes - the LPC bus is standardized, and TPMs need to use the same protocol to enable them to be modules on the motherboard. And yes, it's only $10 or thereabouts for a logic analyzer that can decode LPC bus communications. 2019
48.
▲
by
g_p
3y ago
> This is just a data quality problem Isn't this really a process problem (i.e. a missed requirement), so that after the first instance of a queried match (for whatever reason), the unrelated death record (which will have some kind
49.
▲
by
g_p
3y ago
I believe this is coming, but (rightly) from the police investigating credible allegations of criminal wrongdoing, rather than from Government intervention. 2x fairly prominent Fujitsu people have been interviewed under caution on suspicion
50.
▲
by
g_p
3y ago
Currently, Kagi has (if you hover/click the shield icon to the right of a result) an indication of the information it knows about a website (as well as a way for you to rank it higher or lower for yourself). One of these is "ads&#
51.
▲
by
g_p
3y ago
It's worth noting that courts (in the common law system) don't generally play any kind of inquisitive role in cases - there's a presumption that both sides bring legal representation for an adversarial debate where the court
52.
▲
by
g_p
3y ago
One convenient feature if you run a third instance on a server is that you can "distrust" the server by encrypting the files you sync (this is done at share level), then only entering the decryption password on the trusted end dev
53.
▲
by
g_p
3y ago
> Outsourcing has definite limits and potentially catastrophic results - as does the demolition of corporate technical capability. A lot of what seems apparent in this case is that contractual and commercial factors weren't set up c
54.
▲
by
g_p
3y ago
Especially with the rise of the idea of "GPT stores" to share custom GPTs, this becomes an even bigger issue with those kinds of integrations. One potential mitigation might be to require them to expose all "prompt" data
55.
▲
by
g_p
3y ago
I've seen the same issue with instructions for how to configure Keycloak as an OIDC provider - given Keycloak has so many options (some of which might well be security significant), you'd almost want a step by step explicit statem
56.
▲
by
g_p
3y ago
Absolutely. One fact I recall from many years ago (so I don't know how true it is now) is that auto makers were shipping 7 year old silicon (and thus board support packages for their software). The guys working on chips and CPUs were w
57.
▲
by
g_p
3y ago
That makes good sense to exempt those kinds of readers from the soft lock. And given that's possible, it would likely make sense for some similar kind of leeway on EV charging. Not that there's likely to be any real repercussions
58.
▲
by
g_p
3y ago
Yeah - there's even some fairly capable "cloners" available on eBay for most of the common formats. I guess that the ongoing use of (derived from magnetic stripe) Wiegand interfaces mean that most can be cloned like this. The
59.
▲
by
g_p
3y ago
Makes sense and matched my understanding of the pay at pump preauth for a fixed amount. I guess the issue then becomes relying on contactless (only) without the hardware for full EMV with PIN, as then someone whose card has been used contac
60.
▲
by
g_p
3y ago
How would paying for an EV charge work like this? Would you select an amount of credit in currency (presumably via buttons on the charger?) then tap-to-pay for that amount? (I believe there are some limitations on tap-to-pay transactions to
More ›