Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jeff_marshall
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
jeff_marshall
11y ago
So, I'm not familiar with all of the CFI protections available in clang, but is full CFI actually implemented in CLANG? Especially with C/C++, there are a lot of potential attack vectors that would need to be closed (stack smashin
62.
▲
by
jeff_marshall
11y ago
Be careful with this advice - If the TSA considers an item a firearm, local law enforcement may as well. If you are traveling to a place where firearms are restricted, you could end up facing penalties for possesion that don't discrime
63.
▲
by
jeff_marshall
11y ago
Can you comment on this a bit? It's not obvious to me how open access to this data would be intrinsicly bad, but I suppose that relies on the assumption that it's equally available to all parties (which may not (definitely not?))
64.
▲
by
jeff_marshall
11y ago
This "newspeak" with regard to government activity (and the intelligence apparatus especially) bothers me. It enables soundbites where government officials can say things like "no, we don't collect X", with essentia
65.
▲
by
jeff_marshall
11y ago
The DPDK operates (or at least it did the last time I looked) in a run to completion model for packets received. once the current batch of received packets has been processed by a thread, the DPDK run time immediately looks for more packets
66.
▲
by
jeff_marshall
11y ago
>What they should have done is ramp that shit up and figure out how to monetize the query traffic or figure out a way to decentralize their infrastructure to allow everyone to run Twitter together So, I'm genuienly curious. How do t
67.
▲
by
jeff_marshall
11y ago
Security engineering is a great book. I learned a lot about systems (as opposed to software) from the first edition. Definitely worth a read for getting the 'security mindset'. Techniques can be picked up according to the needs of
68.
▲
by
jeff_marshall
11y ago
I think we're in violent agreement. I'm a fan of the high-level approach taken by the common criteria[1], which emphasizes cataloging threats, security objectives, environmental concerns & vulnerability mitigations when desig
69.
▲
by
jeff_marshall
11y ago
Agreed. I've started poking into security for http-based things (web sites, REST api's, etc), and it's got a mostly different knowledge base from the one I've studied. Compare, for example, the CHES[1] proceedings (a goo
70.
▲
by
jeff_marshall
11y ago
This is very true. I've been involved in building systems involving cryptography for about a decade now, and having transitioned from the weeds (side channels, physical security) to the forest (secure systems architectures), I think I
71.
▲
by
jeff_marshall
11y ago
I've got to say I'm rather amused by the notion that type inference and GC are innovations of the last 20 years. Regarding now vs. the 80s, we have much better tools for making assurance cases for critical software. So much progre
72.
▲
by
jeff_marshall
11y ago
Ugh, that time window. I once had to work with a hardware team to debug a "boot issue" where we were right on the margin due to a two-phase boot process (boot initial bitstream, check journal in flash, load active bitstream) and d
73.
▲
by
jeff_marshall
11y ago
yeah, isn't that hard to get the basics by reading the docs and doing some basic experiments with explicit placement and examining the resulting bitstream. When I looked at the encryption format for the virtex 5 series it was quicker t
74.
▲
by
jeff_marshall
11y ago
Love, for the NYT? surely you jest. They've got a long way back before they have my trust, let alone my love.
75.
▲
by
jeff_marshall
11y ago
It's worse than just publishing what the administration wants. They've also demonstrated that they're willing to kill pieces that the administration wants killed (at least until they realize their reporters are just going to
76.
▲
by
jeff_marshall
11y ago
Agreed completely. I looked on post-9/11 US airport security with much frustration until I got global entry (which includes pre-check). Now, my experience is almost as good as pre-9/11 security (though I can't fly with a pock
77.
▲
by
jeff_marshall
11y ago
I sort-of disagree. If you aren't judging whether they get a correct working solution (i.e. passes some unit tests after running it through the compiler/interpreter), and actively engaging them on their thought process while they
78.
▲
by
jeff_marshall
11y ago
Not to detract from the fine work done by the sel4 folks, but there is a large gap between what they have and what DO178 C requires for level A software. Like many other bureaucratic organisations, the FAA (and other regional equivalents) h
79.
▲
by
jeff_marshall
12y ago
I would agree. I recently went through a phone interview with $BIG_COMPANY. I'm not actively looking for a job, but the opportunity was interesting (I'd be able to learn some things that aren't possible at the small companies
80.
▲
by
jeff_marshall
12y ago
XSLT is rather verbose compared to typical sed/awk syntax. While it's not quite sed/awk (there isn't a programming language per se, just simple edit/select commands) xmlstarlet can do some of the things to an xml do
81.
▲
by
jeff_marshall
12y ago
could you explain what isomorphic means in this context? what set is mapped to another set? what meaning for the set is maintained?
82.
▲
by
jeff_marshall
12y ago
Generally speaking, a macro lens just has a shorter minimum focus distance so that you can fill more of the frame with your subject. The macro lens I've got is perfectly willing to focus at infinity, and I frequently use it for other t
83.
▲
by
jeff_marshall
12y ago
No,that's completely natural (if verbose). This is from someone coming from a C background, FWIW.
84.
▲
by
jeff_marshall
12y ago
How about "Future Democracy System" or "Joint Democracy Platform" ;)
85.
▲
by
jeff_marshall
12y ago
Agreed. Within the demographic that understands the acronym (OS=Operating System or Open Source, etc.), it's likely to be confusing. Outside the demographic, it's not useful as a metaphor because they don't know have an expan
86.
▲
by
jeff_marshall
12y ago
It's less about Linux for me than about the other things I want to boot (MS is unlikely to disable Linux bootloaders on certified Windows PCs for lots of reasons). By way of example, the company where I work today produces a hypervisor
87.
▲
by
jeff_marshall
12y ago
This is true today, but it ignores the realities of many secure boot implementations. Specifically, many UEFI firmware vendors don't include the ability for the hardware owner to update the public key used to verify a bootloader signat
88.
▲
by
jeff_marshall
12y ago
Cool platform, thanks for sharing. Based on the picture, I'm pretty sure the main CPU board on my current quad is about as large as the Crazieflies whole frame :)
89.
▲
by
jeff_marshall
12y ago
Out of curiosity, what hardware are you using / drivers are you missing? Given the number of existing flight control boards with decent open source software support, I'm a little surprised that drivers are blocking you, rather tha
90.
▲
by
jeff_marshall
12y ago
I think perhaps you've forgotten all the ways to shoot yourself in the foot... C++ may be an effective language for experienced users, but it's got quite the learning curve (beginning with how exactly DO I write a correct construc
More ›