Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
geogriffin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
geogriffin
6y ago
FWIW, you can write the conditional compilation example like so: fn read_keys(#[cfg(feature = "splitapple")] port: nrf52840_hal::pac::P1, #[cfg(feature = "keytron")] port:
2.
▲
by
geogriffin
6y ago
Answering my own question.. A cryptographer friend offered an answer to this question: The network operator may be the same as or colluding with the target resolver, defeating the anonymization of the proxy. Once we say we need encryption o
3.
▲
by
geogriffin
6y ago
Why encrypt the first hop? Why isn't this just plain DoH with a simple CONNECT forward proxy to 1.1.1.1, like Signal's Giphy proxy [1]? [1] https://signal.org/blog/signal-and-giphy-update/
4.
▲
by
geogriffin
6y ago
The Plundervolt [1] paper is one study in what exactly goes haywire when a processor is undervolted. They found that the computation errors induced are quite consistent and reproducible. MUL and DIV are vulnerable, and AES-NI happened to be
5.
▲
by
geogriffin
6y ago
I think it's just more clear that they are listing pronouns, especially if someone isn't familiar with the practice or in verbal speech. Also note that some people use two sets of pronouns, with equal weight, and may list them suc
6.
▲
by
geogriffin
7y ago
well.. there is CONFIG_PREEMPT and the even broader CONFIG_PREEMPT_RT in linux [1]. [1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
7.
▲
by
geogriffin
7y ago
> After our investigation, we immediately made a number of changes to this endpoint so that it could no longer return specific account names in response to queries. Does anyone know what this actually means? If the contact discovery API
8.
▲
by
geogriffin
7y ago
Phone numbers are useful for exactly the reasons you find them frustrating: stability -- as you said, everyone and everything you associate with can and will store and contact you via your phone number indefinitely -- and portability -- eve
9.
▲
by
geogriffin
7y ago
> ... do not make it explicitly clear that the final solution sends a hash-prefixed password I'm not sure if you're actually talking about something else, but the paper says: "Post-canonicalization, the server calculates a
10.
▲
by
geogriffin
7y ago
> 2. It is regularly carried on - not really, there's only one .org domain so one can't regularly sell it. You're right. I misread #2 as the inverse so misunderstood what UBI was. > 3. It is not substantially related t
11.
▲
by
geogriffin
7y ago
Well, reading the IRS guidelines on what qualifies as UBI, it seems like it might fall under that category, but I'm also not an expert, which is why I'm asking for a more qualified opinion. However, assuming it's UBI, it'
12.
▲
by
geogriffin
7y ago
I agree. Becoming and staying a non-profit is harder than you'd think. The IRS's rules are vague and subjective. This is specifically what I'm talking about: "If unrelated business income comprises a 'substantial&#x
13.
▲
by
geogriffin
7y ago
Does anyone have a clue if they'll manage to keep their 501(c)(3) status with $1.1 billion in profit for 2019? My understanding is that profits like this unrelated to their normal business activies are taxable, and may also cause the I
14.
▲
by
geogriffin
7y ago
I see your point. Especially since cost-based KDFs rely on the predicted characteristics of future hardware.
15.
▲
by
geogriffin
7y ago
I think if my password is worth 17.5 trillion CPU seconds then I'm a very lucky person...
16.
▲
by
geogriffin
7y ago
Exactly, 1000 guesses per second is probably a reasonable target to tune your KDF's difficulty to, depending on of course the application and the amount of resources you're willing to dedicate to running the KDF on every login..
17.
▲
by
geogriffin
7y ago
If passphrases are easier to remember, then it may be possible for a human to be able to recall many such passphrases at the same time. If these passphrases are used for services with any sort of auth rate-limiting, and they aren't reu
18.
▲
by
geogriffin
7y ago
Am I missing something, or is the reason most of the queries observed have low TTL because, well, they have a low TTL? IOW, the higher TTL responses would be cached downstream and so you'd see them less often. If that is the case, the
19.
▲
by
geogriffin
7y ago
Doesn't something like jemalloc basically give you this, but without pauses? Thread-local freelists for quick recycling of small allocations without synchronization.. funnily enough, jemalloc even uses some garbage collection mechanism
20.
▲
by
geogriffin
7y ago
True, and it seems as though to avoid this kind of litigation Ticketmaster simply had to disclose more information about the purpose and intent of the fees in the fine print. I also remember them changing the name "processing fee"
21.
▲
by
geogriffin
7y ago
> nothing says it has to be specifically earmarked for anything Lawsuits in the US about deceptive fees like [1] come to mind. [1] https://blog.ticketmaster.com/schlesinger-v-ticketmaster/
22.
▲
by
geogriffin
7y ago
I have ran into a couple places I needed GATs while writing abstractions, without realizing beforehand it'd lead to needing GATs. This is especially true with lifetimes, which I'm not used to thinking about as part of an abstracti
23.
▲
by
geogriffin
8y ago
Looks like pretty good code, but interesting that they only have a few dependencies and decided to implement a lot of stuff, like kernel polling, themselves rather than using the mio crate. I wonder why. They also implemented the noise hand
24.
▲
by
geogriffin
8y ago
My thought specifically was that "core networking code" is code that handles untrusted, unsolicited data potentially from the entire world, written in C, with special performance requirements that gives programmers a license to el
25.
▲
by
geogriffin
8y ago
Pretty sure it was introduced here: https://github.com/apple/darwin-xnu/commit/c10988c130af09087... In this commit a bunch of code was copy-pasted from BSD into ip_icmp.c in icmp_error() to quote IP packet da
26.
▲
by
geogriffin
8y ago
Let's be precise; that Intel is enforcing enclave Launch Control is orthogonal to the SGX mechanism itself. Launch Control is a bane to end-users, like you said, and a pain to enclave creators (I had to talk to some random business dev
27.
▲
by
geogriffin
8y ago
Agreed. > Only the CPU (silicon or microcode) can assist you in the flushing of L1 when you exit enclave mode. This seems correct, upon double-checking. The interrupt process within SGX is called Asynchronous Enclave Exit (AEX) and does
28.
▲
by
geogriffin
8y ago
It looks like Intel is pushing these security-related patches pretty hard on vendors, as this latest patch was available in late May on one IBM board Softlayer uses, and early June on another Supermicro board they use.
29.
▲
by
geogriffin
8y ago
BIOS updates are required for most SGX-related microcode updates, as the microcode has to be up-to-date before enabling the SGX feature via a MSR (which is usually done by the BIOS). This is so you can't start an enclave with old micr
30.
▲
by
geogriffin
8y ago
SGX Remote Attestation was built specifically to deal with events like this. Intel starts to reject attesting to vulnerable microcode revisions after some period following disclosure. In this case, they even postponed disclosure until patch
More ›