Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kroeckx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
kroeckx
5y ago
You can look at the Majority results if you want to say how many people think an option is acceptable. That ratio is also in the graph. For option 1, 203 people indicated that it's acceptable, 186 said it was unacceptable, leaving 31 t
32.
▲
by
kroeckx
5y ago
That is not enough to create a cycle. Option 7 would still beat option 4 via option 3 with 8 and via option 2 with 4 votes. Note that there is already a cycle between option 1, 3, and 4. You're right that it doesn't take that many
33.
▲
by
kroeckx
5y ago
The code does not draw lines between the options that didn't pass the quorum or majority test (drawn in pink), because they are dropped before the Schulze method is used. But it then adds the options again, to show all the options. Whe
34.
▲
by
kroeckx
6y ago
We've had code in OpenSSL written in C that was constant time until a newer version of both gcc and clang recognized (mask & a | ~mask & b) as a conditional assign and could do things like turn it into a branch. Edit: It can tu
35.
▲
by
kroeckx
6y ago
As one of the OpenSSL maintainers, I would like to move away from C and probably to rust. But the problem is that C is the most portable language, and rust's platform support just isn't close enough.
36.
▲
by
kroeckx
6y ago
I find it easiest to explain it in terms of electricity, which I assume most people here are familiar with. It acts just the same. Pressure, like voltage, is a difference. The flow rate is like the current, how much goes though. A pipe has
37.
▲
by
kroeckx
6y ago
It seems that a HGST/WD Ultastar, which is their data center drive line, has ERC disabled by default. I've now set it to the suggested 7 seconds.
38.
▲
by
kroeckx
6y ago
This not provide the same integrity as ZFS. Dm-integrity only protects against corruption on the disk itself, while ZFS attempts to provide protection against all sources of corruption, including software/firmware bugs, RAM and I/
39.
▲
by
kroeckx
6y ago
As far as I know, with netflix the quality depends on things like the platform you're watching. Even with the highest subscription plan, if you watch it in Firefox or Chrome you're limited to 720p and you now get about 500 kbit&#x
40.
▲
by
kroeckx
6y ago
That's not my experience at all. It got better when I left some large rooms. But I still regularly get things like messages that the server is offline, taking a minute before the UI shows that my message was sent, after my laptop was s
41.
▲
by
kroeckx
6y ago
The map at https://maps.s5p-pal.com/ allows you to change the date. Comparing the 30-12-2019 - 13-01-2020 data to the latest makes a huge difference in certain areas.
42.
▲
by
kroeckx
6y ago
Because in crypto, the math usually isn't mod 2^256. For instance in curve25519 you do do math mod 2^255-19, so they actually all fit in 51 bit.
43.
▲
by
kroeckx
6y ago
SHA1 is 160 bits and should have a complexity of 2^80 for collision resistance. The last paper puts a chosen-prefix collision at 2^63.4.
44.
▲
by
kroeckx
6y ago
The plan at least is that at little as possible should break. If you do find a problem, please file an issue.
45.
▲
by
kroeckx
6y ago
It's mostly about deprecating old APIs where a newer more general API is available, sometimes for more than 10 years.
46.
▲
by
kroeckx
7y ago
I think https://www.coronawiki.org/ uses that data to visualize it.
47.
▲
by
kroeckx
7y ago
A lot of time is spend on the assembler versions doing the crypto, which is why they get used by various other projects like ring, boringssl, and the Linux kernel. Less or no time is spend on improving the performance of the SSL library. Fr
48.
▲
by
kroeckx
7y ago
systemd didn't change much related to this. The seed file never got credited, at least not in Debian. So either you have the same problem on Gentoo, or Gentoo has other problems.
49.
▲
by
kroeckx
7y ago
The problem with /dev/urandom is that it's always available, even before any entropy was added. Fixing /dev/urandom to block until enough entropy is available once causes breakage like in the article. That is one of
50.
▲
by
kroeckx
7y ago
Why do you trust Intel less then any other hardware RNG you might have? Do you trust the one in the TPM? Or do you just not trust hardware to collect entropy?
51.
▲
by
kroeckx
8y ago
At least Theo has a reputation for breaking embargoes. If he wants to get notified, he should work on changing that reputation. [edit: It's probably more accurate to say that Theo doesn't want to agree to an embargo.]
52.
▲
by
kroeckx
8y ago
0-RTT / early data is supported. It is mentioned in the blog. The wiki is really a document about issues you might run into when upgrading, and 0-RTT is not such a problem. To enable 0-RTT you need to use new functions.
53.
▲
by
kroeckx
8y ago
A CDDA has 2352 bytes of main data and 96 byte of sub-channel data per sector, so a total of 2448 bytes per sector. A sector is made up of 98 sub-frames. Each such sub-frame has 24 bytes of main data, 4 bytes of C1 error correction and 4 by
54.
▲
by
kroeckx
8y ago
There are multiple ways to set it up: - Reuse the key, set up the TLSA record using the public key. Certbot really doesn't seem to support this in an automated way. It requires that you generate a CSR, but there doesn't seem to be
55.
▲
by
kroeckx
8y ago
I'm still using a self-signed certificate because I'm using DANE / DNSSEC. I don't know of any tool that can properly help me automate the rollover of a let's encrypt certificate.
56.
▲
by
kroeckx
9y ago
There are other companies like Google that first require you to set it up over SMS before they allow you to add a security token.
57.
▲
by
kroeckx
9y ago
It's not about client certificates, but it can be a reason why some software might want to do this. The return value of 1 allows the program to deal with verification errors instead of aborting the connection. You can for instance use
58.
▲
by
kroeckx
9y ago
I think there is a misunderstand of what the existing safety net is about. There are 2 error states: did the verification fail and should the connection be aborted. The safety net makes sure that if a function (the callback) says the connec
59.
▲
by
kroeckx
11y ago
I tried to be clear in when you're vulnerable and when not, so that you can decide if you're vulnerable or not. The answer in this case is "it depends, very likely not".