Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jwilkins
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
jwilkins
10y ago
If that were true, he wouldn't have built something so perfect for abuse.
2.
▲
by
jwilkins
10y ago
He now retracts, says it was poorly worded: https://twitter.com/iang_fc/status/727071298325618689
3.
▲
by
jwilkins
10y ago
/dev/urandom while entropy available is low: $ rngtest -c 200000 -b 2000 < /dev/urandom ..... rngtest: bits received from input: 4000000032 rngtest: FIPS 140-2 successes: 199848 rngtest: FIPS 140-2 fail
4.
▲
by
jwilkins
10y ago
Unpredictable and unbiased source of bytes, even on server machines and virtualized hardware at boot time.
5.
▲
by
jwilkins
11y ago
I hope that this was offered as an example of the sorts of broken thinking that justifies this sort of backdoor that eventually leaks/is discovered by others. 1. Key based backdoors are as good as it gets, but in order to be useful to
6.
▲
Https on GitHub Pages (GitHub.io) Open to MITM
(github.com)
2 points
by
jwilkins
11y ago
|
0 comments
7.
▲
by
jwilkins
11y ago
One thing I can add from my analysis is that there aren't seperate counters for files/teams/etc. there's only one. So if a given id is used by a team, it won't be used as a file id.
8.
▲
by
jwilkins
11y ago
Interestingly, I put the same bug in at HackerOne 9 months ago. It was closed as not applicable. So they had at least two independent reports of the same bug and failed to understand it, acknowledge it and then fix it. Way to go slack. If
9.
▲
by
jwilkins
11y ago
DJB's nacl or libgpgme.
10.
▲
by
jwilkins
11y ago
Why does the penny transaction have to confirm in 10 mins? Currently, and for at least a couple of years, you will likely still be able to send 0 fee transactions. The time for them to appear in a block will increase however. Have you hea
11.
▲
by
jwilkins
11y ago
Core has been moving away from failed experiments like unconfirmed transactions. (How that wasn't an obviously flawed idea in the first place is beyond me, but hey, might as well get the data..) No one in core is saying that growth is
12.
▲
by
jwilkins
12y ago
yeah, not so much: http://motherboard.vice.com/read/wire-built-by-ex-skype-empl...
13.
▲
by
jwilkins
12y ago
FWIW, direct link to cached version of gopresto page: http://webcache.googleusercontent.com/search?q=cache:K6ckHm8... here's the link the gopresto dump, from above http://rghost.net/private/5863097
14.
▲
by
jwilkins
12y ago
any reason you didn't use https://github.com/jimhester/per-directory-history
15.
▲
BrainKeys, abusing EC for deterministic ssh keys
(jwilkins.github.io)
1 points
by
jwilkins
13y ago
|
0 comments
16.
▲
by
jwilkins
13y ago
DRC is hardly a conflict free region, or if it is right this moment , it is only because the genocide was so far reaching that there is no one left causing sufficient disturbance to meet whatever bar they've set. http://en.wikipedia.org/w
17.
▲
by
jwilkins
14y ago
or cli via https://github.com/dcadenas/gmail_sender create ~/.gmail and the post's example is: gmail -t dbieber@princeton.edu -s "Automate your life: sending emails" -c "Why'd the elephant sit on the marshmallow?" plus you can hav
18.
▲
by
jwilkins
14y ago
CAPTCHA comes from "Completely Automated Public Turing test to tell Computers and Humans Apart". These tests don't fulfill that requirement. Random guessing gives you 3%, which is worse than random guessing on either the MSFT or reCAPTCHA.
19.
▲
by
jwilkins
14y ago
What do you mean by 'some of the best'? If a CAPTCHA can be solved or guessed in an automated fashion then attackers can just throw more (likely compromised) machines at the problem at little cost. 3% is awful. http://bitland.net/captcha.p