Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
grahamedgecombe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
grahamedgecombe
9mo ago
You can still request permission to use it for apps distributed via Google Play for a limited set of use cases: https://support.google.com/googleplay/android-developer/answ... which is then subject to Google revie
2.
▲
by
grahamedgecombe
6y ago
We've been experimenting with Azure's IPv6 support at work recently. The fact it uses NAT is insane - though we could tolerate that. Even worse is that the NAT is broken - it doesn't update the ICMPv6 checksum when it rewrite
3.
▲
by
grahamedgecombe
6y ago
In the UK it's probably already illegal under the Computer Misuse Act, as it'd fall under "unauthorised modification of computer material". I assume other countries have similar laws. That said, enforcing it is a differe
4.
▲
by
grahamedgecombe
7y ago
> "runes" like Go would be even better but codepoints are halfway there Go runes are codepoints. I think Swift is interesting, a "character" in Swift is actually a grapheme cluster.
5.
▲
by
grahamedgecombe
8y ago
I don't think `mkcert -install` requires root in all cases. The NSS trust store is stored in ~/.pki/nssdb/ and can be written to without root.
6.
▲
by
grahamedgecombe
8y ago
It's probably easier to manually merge the manifest (as they're much more human-readable) than a lock file though.
7.
▲
by
grahamedgecombe
9y ago
> But you won't be able to synthesize a RISC-V CPU. The iCE40 series consists of relatively small parts. You can fit picorv32 on an iCE40-HX8K, although admittedly you'll only get an RV32IMC core with just the user ISA.
8.
▲
by
grahamedgecombe
9y ago
The citext type automatically does case-insensitive comparisons: https://www.postgresql.org/docs/current/static/citext.html
9.
▲
by
grahamedgecombe
10y ago
> each device gets 2^64 addresses Each subnet gets 2^64 addresses. You can have multiple devices in the same subnet.
10.
▲
by
grahamedgecombe
10y ago
Chrome requires Certificate Transparency for the EV indicator to be displayed - see https://news.netcraft.com/archives/2015/08/24/thousands-shor...
11.
▲
by
grahamedgecombe
10y ago
Wildcards are in the version of the ACME spec at https://letsencrypt.github.io/acme-spec/ : > A server MAY consider a client authorized for a wildcard domain if it is authorized for the underlying domain name (withou
12.
▲
by
grahamedgecombe
10y ago
CAs are forbidden from issuing a cert for * .co.uk. The Baseline Requirements say: > The CA MUST establish and follow a documented procedure that determines if the wildcard character occurs in the first label position to the left of a &q
13.
▲
by
grahamedgecombe
10y ago
> You need to zero fill .bss section in the boot code before jumping to C code. GRUB does this for you. See this thread from a few years ago: https://news.ycombinator.com/item?id=7590790
14.
▲
by
grahamedgecombe
11y ago
Amazon bought one of the Starfield roots from GoDaddy last year: https://mobile.twitter.com/Cryptoki/status/61114541131566694...
15.
▲
by
grahamedgecombe
11y ago
use -std=gnu99 instead
16.
▲
by
grahamedgecombe
11y ago
People have been able to get SSL certs for webmail domains before, as the webmail providers hadn't blacklisted some of the emails CAs can use for domain validation by email. e.g. see http://www.entrust.com/what-happened
17.
▲
by
grahamedgecombe
11y ago
X509 extensions can be marked as critical. Certificates must be rejected if the stack encounters a critical extension it doesn't understand. (In theory at least, I haven't looked at real implementation behaviour.)
18.
▲
by
grahamedgecombe
12y ago
I get the impression that 296 is meant to be 2^96, which is exactly the same as your figure.
19.
▲
by
grahamedgecombe
12y ago
And LibreSSL also has support for ChaCha20.
20.
▲
by
grahamedgecombe
12y ago
I've just checked the GRUB source code and I think it will clear the .bss section even if it's loading an ELF file. grub-core/loader/multiboot_elfxx.c has a function named grub_multiboot_load_elf32/64 which actually
21.
▲
by
grahamedgecombe
12y ago
It's still important to test on physical hardware though, perhaps on an old spare machine you don't care about if you want to be cautious, as the virtual machines do not perfectly emulate real hardware. For example, QEMU initializ
22.
▲
by
grahamedgecombe
12y ago
It's worth pointing out there are a few bugs in James Molloy's tutorial [1], and some of the things he does in them aren't exactly best practices - for example, a few I remember are: - Disabling interrupts and paging (which a
23.
▲
by
grahamedgecombe
12y ago
> Another thing that is missing is clearing the .BSS section before passing control to the C code. It's not used at the moment, though. The Multiboot standard says that the boot loader will clear the .bss section for you - in sectio
24.
▲
by
grahamedgecombe
12y ago
There's a slight problem in this tutorial in that it assumes ESP (the stack pointer) will be defined by the boot loader to point to an appropriate location for the stack. However, the Multiboot standard states that ESP is undefined [1]
25.
▲
by
grahamedgecombe
12y ago
> losetup on a disk image doesn't (to my knowledge) detect partitions… for reasons unknown to me. You can use the kpartx command for this. This site has a good overview: http://nfolamp.wordpress.com/2010/08/
26.
▲
by
grahamedgecombe
13y ago
OCSP and CRLs allow a CA to revoke an SSL certificate (albeit with a varying degree of browser support).
27.
▲
by
grahamedgecombe
13y ago
It can work like this - see: http://wiki.squid-cache.org/Features/HTTPS#CONNECT_tunnel
28.
▲
by
grahamedgecombe
13y ago
I suspect DigitalOcean have more virtual servers per physical machine than Linode do, which is probably why they can offer cheaper prices. This means you probably won't be able to use as much CPU power and I/O (more people contend
29.
▲
by
grahamedgecombe
13y ago
The old L5520 processors they are using have 4 cores with hyperthreading, so it appears as 8 to the OS - so they don't have to have changed the host machines to present 8 cores to the VMs.
30.
▲
by
grahamedgecombe
13y ago
> The interesting thing is that linode started out as a cheaper alternative to slicehost Linode have been around since 2003. I think Slicehost was founded later than this (in 2006 according to a quick search for their name.)
More ›