Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
g_p
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
121.
▲
by
g_p
4y ago
Answer - probably not. But courts are very likely (in my view) to take a very very dim view of the introduction of some kind of barrack-room "AI lawyer". It will slow things down by introducing potentially spurious arguments which
122.
▲
by
g_p
4y ago
Then I imagine the defendant would risk enjoying a stretch in jail for contempt of court, for creating an unauthorized recording or live "streaming" of the court? I'm not even convinced by the idea of having a person repeat w
123.
▲
by
g_p
4y ago
> The AI lawyer tells the defendant what to say in real-time, through headphones. Yeah - and I wonder what will happen if it starts telling the defendant to say things which aren't grounded and rooted in fact, or which contradict th
124.
▲
by
g_p
4y ago
Equally though, GDPR (and predecessor or adjacent legislation) isn't specifically about cookies - common parlance is to refer to it as the "cookie law", but usually it's the ePrivacy Directive that covers cookie use, and
125.
▲
by
g_p
4y ago
> You don't see the term spyware much anymore. I suppose that is the result of almost everything being spyware now. Likewise for "adware" - it seems the rise of smartphones heralded a normalisation of practices which (on t
126.
▲
by
g_p
4y ago
Indeed - this was my first concern. How many of these local web servers are properly implementing CSP and the myriad of other protections you need to (securely) run a local web server that isn't vulnerable to CSRF from other origins et
127.
▲
by
g_p
4y ago
And as long as you don't re-use wallet addresses, your public key is effectively not revealed until the balance is zero. Since your wallet address is a sha256 hash of the public key, you would need to meaningfully break sha256 to be ab
128.
▲
by
g_p
4y ago
My understanding is that Bitcoin, used correctly , is effectively quantum safe. Since the "recipient" address of a UTXO is expressed as a hash, a user does not broadcast their public key until after they spend the funds. If you f
129.
▲
by
g_p
4y ago
Indeed, they're not one-time pads - they are symmetric authenticators where both sides hold the same seed, and iterate a PRNG or similarly iterable function every N units of time (say, 30 seconds), to give you the same new output, base
130.
▲
by
g_p
4y ago
Not generally, although precisely how this works in a passkey world remains to be seen. In the underlying webauthn technology, a non-resident key is uniquely generated for every account you have. In theory your use of the same token for mul
131.
▲
by
g_p
4y ago
In the current design of most security tokens, a PIN is not really a "something you know" factor per-se - it instead unlocks a "something you have" factor. That sounds counter-intuitive, but few (if any) security tokens
132.
▲
by
g_p
4y ago
I'd agree - technically speaking, there's no real barrier to a secure way to export from a FIDO key. HSMs have support for it - authenticate to the HSM, provide an encryption key (or public key), and receive an encrypted dump. I d
133.
▲
by
g_p
4y ago
To add to this, I also want the ability to move "ecosystem" - passkeys are "platform-backed", meaning Chrome on iOS is "iOS" as far as passkeys are concerned, and you are stuck in the iOS keychain. I want to se
134.
▲
by
g_p
4y ago
There's 2 main reasons they differ from "something you know": 1) A passkey isn't phishable, as it's a digital signature that wraps the origin domain that is requesting the passkey. That means a phishing site can
135.
▲
by
g_p
4y ago
Interestingly, it's not actually a Chromium clone - it's webkit based, but with WebExtension APIs added to give compatibility with (a growing range of) Firefox & Chrome web extensions. I am a Firefox user too, but Orion feels
136.
▲
by
g_p
4y ago
Indeed - they actually did surveys and found 70% of users wouldn't continue at $19/mo (but 30% would), so you're not alone. Since the costs in question are per search, I think they were previously considering different pricin
137.
▲
by
g_p
4y ago
I understand they're having to pay for access to crawler results, to avoid the cost of indexing and crawling the entire web (though they do some themselves).
138.
▲
by
g_p
4y ago
This is a good point as well. Ultimately any search engine has user IP address though, modulo VPN and similar technologies. For a regular user who signs into Google to use Gmail, they'll be searching while signed in anyway - no real lo
139.
▲
by
g_p
4y ago
The team behind kagi are also building a browser (Orion). One of the new features that's been teased could likely be put to use doing something like this... Think natural language input to a browser.
140.
▲
by
g_p
4y ago
Part of the challenge is getting people to see the true cost of the free services they consume. The internet today defaults to the "all you can eat buffet" post-scarcity world. The kagi team are transparent about what it actually
141.
▲
by
g_p
4y ago
Interestingly, this seems to be one of the ways their satellite based emergency services system works - using a relay station to receive messages from phones. This would suggest they already have infrastructure they could use for these feat
142.
▲
by
g_p
4y ago
If you use a remote Borg server over SSH, you can set up your authorized_keys file to enforce append-only mode on the server by defining the command to be run at login, and reject Borg requests by that SSH key which try to purge or remove d
143.
▲
by
g_p
4y ago
Kopia is pretty new, but looking through the documentation I felt it had some pretty good features that suggest it will be a good option in the future. A few highlights (for me at least): - They have implemented support for object locking a
144.
▲
by
g_p
4y ago
Thanks for your work on bupstash. To second this, there are some threat models that are often overlooked with backups. Separating the encryption and restore keys makes sense, and is a design pattern few of the modern new backup tools offer
145.
▲
by
g_p
4y ago
Interesting - I did the same on a bitwarden install just to test it, and it was instantaneous. From memory, BW has a single account key (encrypted by password) to facilitate this process, as well as a method to re-key the account (which wou
146.
▲
by
g_p
4y ago
Eek. It is quite incredible they didn't have any kind of KDF upgrade system built into the login process, under the guise of "log in again please". And presumably no prominent permanent notification of your 500 rounds of KDF
147.
▲
by
g_p
4y ago
The passwords are encrypted by a per-user key. That per-user key is derived from a password through a password based key derivation function (PBKDF). In essence, an iterative hashing function. Many users don't use "good" pass
148.
▲
by
g_p
4y ago
Understand (before you start writing code) the basic security properties that you want to deliver through use of cryptography. This is usually where most implementers fall over (including the big commercial products). To give a couple of sp
149.
▲
by
g_p
4y ago
Agreed. Also what's being overlooked by others is the inability (using dumps of "users of site X") is the ability to globally intersect that with another site. The ability to quickly find users who have an account in (list of
150.
▲
by
g_p
4y ago
According to [1], there were 5,000 client-side rounds of SHA256 in key derivation in June 2015. It does sound like a missed opportunity to have an at-login upgrade mechanism to upgrade KDF rounds that can be carried out seamlessly or near-s
More ›