Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jbangert
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
jbangert
11y ago
(author here) https://github.com/jbangert/trapcc We did get a few hypervisor crashes and the Intel architecture has all sorts of subtle behaviour that is often not modelled properly. It would be good to see someone bu
32.
▲
by
jbangert
11y ago
This comes from a restriction of almost all existing computer architectures. You have a small amount (16 on amd64) of 'variables' called registers that you can directly work with. Additional variables have to be loaded from and st
33.
▲
by
jbangert
11y ago
GC's can compact memory. Go does this for stacks, but not (yet) for heaps.
34.
▲
by
jbangert
11y ago
very broad theorems like CAP (and e.g. The halting problem) are still very useful for proving things by reduction. Instead of talking about nodes failing, you could talk about a network partition isolating just that one node (sure, the nod
35.
▲
by
jbangert
11y ago
porting regular software to FPGA's is certainly an interesting idea and many people have worked on it (google C to FPGA). Unfortunately, these solutions aren't quite what you would think, because the programming model of a micropr
36.
▲
by
jbangert
11y ago
Error messages and error recovery are to some extent red herrings. You really do not want a production system to accept wrong inputs (and especially not try to 'recover' them into a usable parse tree). This will definitely make yo
37.
▲
by
jbangert
12y ago
I think you shouldn't write parsers by hand at all and instead generate them automatically -- without semantic actions. I wrote a parser generator for tricky binary formats a few months ago - https://www.usenix.org/syst
38.
▲
by
jbangert
12y ago
Well, the ability to call a set of functions (really, to overwrite a vtable pointer with a constrained set of values - which is a table of function pointers your C++ compiler emits to handle virtual function calls) is the underlying vulnera
39.
▲
by
jbangert
12y ago
But these are very different business cases - retail banking and institutional investing have very different customers, practices, regulations, etc. So why not make these be different companies?
40.
▲
by
jbangert
12y ago
Weird, it works here. I put a copy on my webpage at http://csail.mit.edu/~julian/papers/login_nail.pdf As has been pointed out below, there are many C bindings for Protobuf (and my argument was that using somethin
41.
▲
by
jbangert
12y ago
https://github.com/irungentoo/toxcore/issues/137
42.
▲
by
jbangert
12y ago
My one experience with the Tox project was that I made a few (I thought) constructive suggestions. First, I suggested they use some form of static analysis or perhaps a 'safer' language to implement their core functionality - such
43.
▲
by
jbangert
12y ago
One issue with PEG's (and other parsers) is that it doesn't address (unbounded) count fields (or bounded count fields in an elegant manner) or offsets. This means a pure PEG can't express e.g. PDF or ZIP files. To address t
44.
▲
by
jbangert
12y ago
Without going into the metrics that these rankings use and their flaws, the German university system unfortunately focuses less on "elite" universitities, instead trying to create a good average experience, so most of the universi
45.
▲
by
jbangert
12y ago
Yes, but this is rarely enforced, especially if the minicabs don't wait in front of a hotel, but just take a slow route home (Or if as in the case of Uber, they get 'free'/unpaid time when they have no fare, as they are
46.
▲
by
jbangert
12y ago
Well, in Germany the only thing you need a taxi medallion for is waiting at taxi stands and being hailed off the street. Everything else can be done as a 'rental car with driver' (i.e. livery), which is allow to receive driving as
47.
▲
by
jbangert
12y ago
As far as malware attacks go, this seems to be pretty run-of-the-mill (no clever vulnerabilities used). The key seems to be that the automated malware dropping is adapted to all sorts of 'restricted environments' (i.e. chroot, vir
48.
▲
by
jbangert
13y ago
Well, the 10 beefy boxes will be much, much faster if your problem is not very distributable. Say, Facebook as an application shards very easily, because most users don't interact much with each other. Other applications, might have m
49.
▲
by
jbangert
13y ago
GPS relies (heavily) on the satellites knowing their own orbits, which they get from a ground station, which means the satellites would very quickly get very inaccurate (and GPS with 200km accuracy is somewhat useless).
50.
▲
by
jbangert
13y ago
However, on a technical note, 'relocatable program' usually refers to a completely different concept, namely that the programs binary has relocation entries so it can be 'relocated' and executed at any address range (thi
51.
▲
by
jbangert
13y ago
With the current implementation of SSL, there really is no point in picking one CA over another for security purposes (unless you don't trust a CA with billing, etc. data). In the typical use case of a web browser, any trusted (root) C
52.
▲
by
jbangert
14y ago
While I am not an expert on FPGA design, I believe Figures 1 and 2 are slightly exaggerated. The C program is very ad-hoc (returning a double from main is actually illegal and will lead to interesting results) and avoids all I/O, whereas th
53.
▲
by
jbangert
14y ago
This is awesome! Maybe one day we can extend it to more modern members of the x86 family (286,386) that introduced more opcodes (hence producing the complicated ISA encoding that x86 has) and operating modes (unreal mode, protected mode, SM
54.
▲
by
jbangert
14y ago
Yes, there is a cheat, it moves values from RAM to VGA ...
55.
▲
by
jbangert
14y ago
Shmoocon will release the video of the presentation in a bit, until then here is our talk at CCC http://www.youtube.com/watch?v=NGXvJ1GKBKM
56.
▲
by
jbangert
14y ago
Author here: While it is true that with the current implementation, memory access is extremely limited (essentially one DWORD per page, or about 0.1% of the available physical RAM) that limitation can certainly be avoided. For one, you coul
57.
▲
by
jbangert
14y ago
Author here: Actually, the slide 'no publically available simulator implements this correctly' is somewhat misleading (it had a follow up slide that I cut and replaced by verbal comments - I should re-add it to the PDF). What I meant is tha
58.
▲
Show HN: Game of Life in 0 CPU instructions, just in the MMU
(youtube.com)
1 points
by
jbangert
14y ago
|
0 comments
59.
▲
by
jbangert
14y ago
However, it wouldn't be impossible. I am quite sure (although I don't have a proof) that the BPF bytecode can be made turing complete, so an arbitrary program (maybe a rootkit, much more likely patches to a few kernel structures) could be i
60.
▲
by
jbangert
14y ago
SELinux does not aim to protect or harden the kernel. SELinux aims to enforce a more complicated(maybe expressive), MAC policy on the filesystem and a few related objects. The SELinux threat model is helpless against a kernel vulnerability
More ›