Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
johncolanduoni
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
johncolanduoni
7mo ago
Very narrow circumstances like the DMCA? I don’t think the jurisprudence is as simple as you’re making it out to be.
32.
▲
by
johncolanduoni
7mo ago
RAM is always storing something, it’s just sometimes zeros or garbage. Nothing in how DRAM timings work is sensitive to what bits are encoded in each cell.
33.
▲
by
johncolanduoni
8mo ago
Yes, but the attestation does not tell the RP anything about the browser. The whole point of the nightmare scenario above was for Google to sneak browser attestation in via passkey attestation. The browser being able to see the attestation
34.
▲
by
johncolanduoni
8mo ago
None of the password managers (including but not limited to ones built-in iOS/Android) work that way. The Apple one (and I think Google is the same) keeps the private key inside the secure enclave (security processor), but it is still
35.
▲
by
johncolanduoni
8mo ago
As I said, the attestation structurally does NOT attest to your OS or your browser that are displaying the website performing the authentication. It attests to the device that holds the passkey's key material, which is usually not your
36.
▲
by
johncolanduoni
8mo ago
That's a matter of implementing an open standard. Google hasn't done anything to prevent open source browsers and OSes from implementing it, and nothing in the spec makes it difficult for Firefox/Linux specifically AFAICT.
37.
▲
by
johncolanduoni
8mo ago
The attestation actually has nothing to do with the browser, only the holder of the passkey's key material. You can satisfy the attestation by having a passkey on your Android device and doing the normal Bluetooth flow with your Firefo
38.
▲
by
johncolanduoni
8mo ago
Most of these systems already do this, especially since very few applications have a flat encryption key hierarchy regardless of passkeys. The counterpoint would be that not everyone will set up multiple passkeys unless you require it on si
39.
▲
by
johncolanduoni
8mo ago
How many people are doing a spring cleaning of unused passkeys in their password managers? We're talking like a kilobyte of data, nobody needs to delete these things in any kind of normal circumstance. Sure, it would be great if users
40.
▲
by
johncolanduoni
8mo ago
What about this ban is anticompetitive? The only think I can think of is accusing them of dumping product (as opposed to price discrimination), in which case the remedy is going to be to making them charge the API price for everything.
41.
▲
by
johncolanduoni
9mo ago
Okay, but now you’re running a country-scale VPN service in Russia or whatever, and somebody has to pay for it. Or you have to acquire a botnet, again to handle the internet of a whole country. These are non-trivial barriers to overcome, an
42.
▲
by
johncolanduoni
9mo ago
How useful is a GPS position for theft prevention? IME cops are not interested in doing more than filing a report after a theft, even if you have a live GPS location of the item for them. Do you try and go get it yourself?
43.
▲
by
johncolanduoni
9mo ago
If they mean a real proxy, that’s even more involved - you can’t just do that with BGP configurations and will need someone running what is basically a country-wide VPN in Russia or China (which will probably be very identifiable).
44.
▲
by
johncolanduoni
9mo ago
IPs owned by Iranian entities could be blocked straightforwardly by network operators at various levels. They could probably fudge the paperwork via Russian or Chinese entities and obfuscate the routes with cooperation from Russian/Chi
45.
▲
by
johncolanduoni
9mo ago
Does the Iranian economy rely heavily on access to the global internet? They can’t trade with most of the world due to sanctions, so what in their internal economy grinds to a halt without global communications? I’m not saying I think that
46.
▲
by
johncolanduoni
9mo ago
Even if you don't have fiber all the way into your house, most cable internet terminates pretty close to the home these days. It kind of has to, since bandwidth has gone way up and as a result they can't put very many subscribers
47.
▲
by
johncolanduoni
9mo ago
But if there is a civil war, what were you going to be able to do with the USD anyway?
48.
▲
by
johncolanduoni
9mo ago
Yes, and it’s quite inefficient compared to L4 or Zircon’s IPC so it isn’t used for anything that wouldn’t work just fine over a SEQPACKET socket using SCM_RIGHTS like Linux does. Is modern Windows a microkernel because ALPC exists?
49.
▲
by
johncolanduoni
9mo ago
All the major OSes have components of the larger operating system that run in userspace and communicate via IPC, including Linux. But userspace drivers and basic system services (VFS, network stack, etc.) are very limited in their use of us
50.
▲
by
johncolanduoni
9mo ago
They're threatening to take their ball and go home. If they move all of their operations out of Italy, under what principle does Italy demand they block content globally? Should Wikipedia remove their page on Tiananmen Square because t
51.
▲
by
johncolanduoni
9mo ago
They can read the statement, and the definitions that the statement references. If everything it references is in a well-tread part of the Lean library, you can have pretty high confidence in a few minutes of going over the syntax.
52.
▲
by
johncolanduoni
9mo ago
Wow. That’s a new one. Where exactly do you think the authentication tokens you obtain using 2FA are stored?
53.
▲
by
johncolanduoni
9mo ago
A warning doesn’t help at all. The main threat model for FDE is that someone steals your device and dumps the disk. If you don’t protect the boot process somehow, then you’re just storing the encryption key next to the data. If you don’t ca
54.
▲
by
johncolanduoni
9mo ago
I mentioned XNU below. It doesn’t really count as a microkernel if you, you know, don’t actually use the microkernel part. At least for the 30 years between the FreeBSD collision and the introduction of DriverKit, which does most of its IPC
55.
▲
by
johncolanduoni
9mo ago
These are pretty much all about mandatory locking. Which giveth and taketh away in my experience. I’ve had substantially fewer weird file handling bugs in my Linux code than my Windows code. POSIX is very loosey-goosey in general, but Linux
56.
▲
by
johncolanduoni
9mo ago
That’s not my point - just that “state machine races” is a too-broad category to say much about how Rust would or wouldn’t help.
57.
▲
by
johncolanduoni
9mo ago
It depends what they mean by some of these: are the state machine race conditions logic races (which Rust won’t trivially solve) or data races? If they are data races, are they the kind of ones that Rust will catch (missing atomics/syn
58.
▲
by
johncolanduoni
9mo ago
This is I think an under-appreciated aspect, both for detractors and boosters. I take a lot more “risks” with Rust, in terms of not thinking deeply about “normal” memory safety and prioritizing structuring my code to make the logic more obv
59.
▲
by
johncolanduoni
9mo ago
What warranties? I assume you’re comparing it to ext4 and not e.g. ZFS?
60.
▲
by
johncolanduoni
9mo ago
Mach is not a very good microkernel at all, because the overhead is much higher than necessary. The L4 family’s IPC design is substantially more efficient, and that’s why they’re used in actual systems. Fuchsia/Zircon have improved on
More ›