Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
justsomeadvice0
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
justsomeadvice0
4y ago
Agreed, we can only speculate; personally I would be surprised if that was the "long-term" plan instead of just a push at the time to enforce industry best practices on its apps. My hunch would be such a move might be disruptive t
32.
▲
by
justsomeadvice0
4y ago
I believe all OP is trying to say is that Apple controls ingress nodes, which the customer connects (authenticating with iCloud) to as the first hop; the destination and content of the packets is encrypted to the second hop and cannot be de
33.
▲
by
justsomeadvice0
4y ago
I did look a bit more and it does appear LineageOS could work as a long-term alternative OS. I'm a bit hesitant after reading about some of the difficulties imposed by missing google's Playstore and "Safetynet" (sounds l
34.
▲
by
justsomeadvice0
4y ago
I am looking for such a phone so I looked into this. To make a comparison to the 6A: the Pixel 3A was released in May 2019. Just over 3 years later: it is no longer supported (no updates available) by Google in any way [1]. GrapheneOS lists
35.
▲
by
justsomeadvice0
4y ago
> And also the "minor" thing that having only one strong authenticator makes it super-easy to lose own data just in case the authenticator breaks etc. This is why I mentioned "esp with synced passkeys". WebAuthn can u
36.
▲
by
justsomeadvice0
4y ago
Yea, I'm really not sure how this is a "misery". System processes are protected for typical users to limit the blast radius of malware, among other reasons. If you are capable of debugging system processes you should be able
37.
▲
by
justsomeadvice0
4y ago
That is really cool, thanks for a detailed writeup. I try to pay attention to the WebAuthn spec and did not realize this was possible. I suspect that for most people, WebAuthn (esp with synced passkeys) is going to actually make the CI part
38.
▲
by
justsomeadvice0
4y ago
You're totally right, this is not the module I am thinking of. We used to do this exact step (yank all admins pubkeys from somewhere, and test logins with it to make an access map) in our pentests but now I am having trouble rememberin
39.
▲
by
justsomeadvice0
4y ago
Nice :) In practice I have used metasploit's `auxiliary/scanner/ssh/ssh_login_pubkey` to do this: https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_... But standalone t
40.
▲
by
justsomeadvice0
4y ago
Saw this the other day, makes sense to me. If I ran Visa, I would hire a team of engineers to come up with ways we could be making money off of future cryptocurrency transactions, if only as a hedge against people using Visa less and to qui
41.
▲
by
justsomeadvice0
4y ago
It can certainly be "or": rootkits can come from your machine's supply chain, and lie mostly dormant for many months or years before activation. Rootkits can get installed after a non-zero-day-entrypoint vector e.g. simply tr
42.
▲
by
justsomeadvice0
4y ago
This is indeed how RSA works, and is seen as a weakness of RSA, among other things it can lead to accidental oracles if you use the same key to both sign and decrypt things. To my knowledge, this is not how ECDSA works. ECDSA is "just&
43.
▲
by
justsomeadvice0
4y ago
That's prohibitively expensive for an ID, even for most Americans. Any required government IDs should be nearly if not completely subsidized. Requiring IDs in the USA has historically been used as a form of voter suppression. Texas is
44.
▲
by
justsomeadvice0
4y ago
So the big scandal, the thing to get upset about here, Elon's dramatic reveal: is that Twitter's leaders "didn't care" enough? If you listen carefully, behind the crickets, you can hear the goalposts moving.
45.
▲
by
justsomeadvice0
4y ago
Here are the parts of the statement I am disappointed with, to clarify, emphasis mine: > *This system wasn't balanced.* It was based on contacts. ... there were more channels, more ways to complain, open to the left (well, Democrats
46.
▲
by
justsomeadvice0
4y ago
tl;dr: 1. important entities like American government administrators and political candidates can report Twitter ToS violation for review via a dedicated line with a fast expected turnaround 2. the Biden laptop story was treated as misinfor
47.
▲
by
justsomeadvice0
4y ago
I think it's a good idea. I somewhat pay attention to headlines in that space, but I literally don't know of a single cryptocurrency community that has launched a successful product, outside of perhaps "platforms for trading
48.
▲
by
justsomeadvice0
4y ago
What is the point here? Wikipedia tells me: > No proof mechanism is standardized but the data model is flexible enough to support various existing cryptographic mechanisms, such as digital signatures. So why even have a standard at all?
49.
▲
by
justsomeadvice0
4y ago
We are on the same page. I do think there are some gains, although I question the use of "permissionless" blockchains (we have to remember to add this caveat now since we decided 90s tech should now be called "permissioned bl
50.
▲
by
justsomeadvice0
4y ago
TBH this is a good argument not to trust timestamp servers. AFAIK usually you just want to stick to one, and not treat a group of them interchangeably (ala the Internet Root Bundle). In any case, the owners of the repo (or email message)
51.
▲
by
justsomeadvice0
4y ago
"trustless" is not the word here... you are trusting the economic incentives of the blockchain system to remain in-tact. But I do agree with you that one could feasibly trust it "more" than a single entity protecting a k
52.
▲
by
justsomeadvice0
4y ago
Fair point, agreed I doubt mount_webdav ends up posix compliant.
53.
▲
by
justsomeadvice0
4y ago
Yep, precisely what I was referring to.
54.
▲
by
justsomeadvice0
4y ago
Alright I'll bite - why do all this blockchain hoopla instead of just using SMIME/CMS's trusted timestamp feature? That already works fine with git signatures.
55.
▲
by
justsomeadvice0
4y ago
Lots of people use permanent-ish HSM-backed keys (like yubikeys) for SSH access so I guess this saves them from distributing another key? Outside of that I agree, I don't really see the point.
56.
▲
by
justsomeadvice0
4y ago
You might look at webdav instead, which has actual existing library implementations (unlike NFSv4), supports user/pass auth (in some cases you don't want wide-open services on loopback) and is based on HTTP; that would make the wh