Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lrvick
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
121.
▲
by
lrvick
1mo ago
Those are of course just minimum viable proofs of concept for users with the CLI installed because they are succinct. Real malware could of course install the CLIs for the user helpfully or just directly access the database the next time it
122.
▲
by
lrvick
1mo ago
Policy gated secure enclaves are absolutely a thing and I have designed several of them, some of which are responsible for protecting hundreds of billions of dollars in assets for major financial institutions. To make a transaction several
123.
▲
by
lrvick
1mo ago
> Yeah, I mean, I'm just not going to do that, I tried a yubikey for a few weeks and found the convenience factor to be terrible. If you cannot be bothered to touch a device when it blinks in exchange for having defense against phis
124.
▲
by
lrvick
1mo ago
This is me talking about the UX of decrypting one password at a time with explicit consent.
125.
▲
by
lrvick
1mo ago
An optional remotely attestable secure enclave all secrets are encrypted to on first entry can however bulk encrypt secrets to a public key of each device bypassing the touch policy when adding new devices but still requiring a manual tap f
126.
▲
by
lrvick
1mo ago
The most user friendly way for someone with only one device and no external trusted screens is with the help of a recovery enclave all your secrets are encrypted to. Whenever you add a new secret, you have it encrypt a copy to ideally a sma
127.
▲
by
lrvick
1mo ago
Of course you can. Random non technical executive goes to a login page, and a popup happens on an external device like a phone or keychain dongle, watch, or any secondary display that asks "Allow aws.amazon.com root access to open brow
128.
▲
by
lrvick
1mo ago
Who needs root? You seem to be under the impression the status quo password managers are reasonably secure for anyone, technical or otherwise. Exfiltrate all plaintext credentials from 1password: op list items \ | jq -r '.[].uuid&#
129.
▲
by
lrvick
1mo ago
Every modern device under the sun ships with a hardware security module of some kind which could, if nothing else, rate limit decryptions and ensure decryptions can only happen on that machine. There are so so many hardware anchors free for
130.
▲
by
lrvick
1mo ago
It is a negligent and blatant design flaw in all popular implementations, yes. Mooltipass and Password Store are the only two password managers to do the bare minimum. That is ridiculous. Anyone who corrects this, with a good UX solution, w
131.
▲
by
lrvick
1mo ago
I really find complaints about the minimum viable placeholder malloc in musl confusing. Does anyone seriously try to use malloc-ng for performance critical use cases? Our entire linux distro is musl based BUT we swap out the default malloc
132.
▲
by
lrvick
1mo ago
So you decrypt -any- password on a system with malware, and malware gets -all- the passwords. Makes life super easy for an attacker. All they would need to do is install a wrapper for sesame that waits for the next database unlock and exfil
133.
▲
by
lrvick
1mo ago
Those are cute, but as long as they ask every single user to run their proprietary code in system memory to use the GPUs users paid for, their commitments to open source higher in the stack are a joke.
134.
▲
by
lrvick
1mo ago
It was in the uploaded tar.gz file to the releases page. The vulnerable code bypassed code review, at least for those distros that trusted the human made source snapshots more than git which was a poor choice.
135.
▲
by
lrvick
1mo ago
Sure it does, if you deterministically full source bootstrap, build, and sign the same image m-of-n places with different hardware owned by different people, all of whom only sign if everyone gets identical results, and this can be easily v
136.
▲
by
lrvick
1mo ago
> The threat actor had access to the source control so he could have just as easily put it there too. And yet they did not because that would be much much higher risk of getting caught, given lots of people pay attention to high-performa
137.
▲
by
lrvick
1mo ago
This is absolutely one of my reasons. When the internet goes down I have every line of code that built my system from zero right here.
138.
▲
by
lrvick
1mo ago
> The developer signing the build provides sufficient guarantees. There are tons of documented cases of people resorting to physical attacks to obtain valuable cryptographic signing keys stored in full in one place. https://gi
139.
▲
by
lrvick
1mo ago
The XZ attack was not in version control. It was on the human-built tar files published to Github Releases which no one reviews. Trust in a single person. Distros paranoid about supply chain attacks like stagex build directly from (ideally
140.
▲
by
lrvick
1mo ago
We almost had a major backdoor in OpenSSH deployed worldwide, caught at the 11th hour. Now imagine someone used that exploit to inject a ken-thompson-style trusting trust attack at compile-time into all builds of GCC on the build and reprod
141.
▲
by
lrvick
1mo ago
> Would love to see someone try to automate the bootstrap chain from a working C89 compiler to Rust. We did that in stagex over a year ago actually and several major orgs are using it in production. Also no dependency on libgcc. LLVM nat
142.
▲
by
lrvick
1mo ago
We full source bootstrapped our 100% deterministic, quorum-signed, LLVM/musl native, and container native distribution this way from day 1 thanks to the incredible work of this team. Bootstrappable builds unlocked stagex, which unlocks
143.
▲
by
lrvick
1mo ago
Now that Nvidia owns huggingface, I fear their days being able to support open source products are over.
144.
▲
by
lrvick
1mo ago
The pain inflicted is way worse than the cash. They now must make teens have aggressive time limits and time of day boundaries. Meta knows this means teens will leave forever to competitors and never come back as they age. That is a death s
145.
▲
by
lrvick
1mo ago
> and worked closely with external advisors, including CrowdStrike The company that was used as part of a widespread supply chain attack, and did functionally nothing to prevent it from happening again? You pick that company to help you
146.
▲
by
lrvick
1mo ago
Nvidia has closed drivers, which makes them light years behind AMD in trust. Also if we were just discussing labs, Ai2 opens ~everything with dramatically less resources than Nvidia.
147.
▲
by
lrvick
1mo ago
We use mold as the default linker in the Stagex linux distribution. It shaved hours off our full tree build time.
148.
▲
by
lrvick
1mo ago
Qwen 3.8 27b Q4_K_M w/ matching dflash drafter, 256k context, llama.cpp+dflash2, draft-n-max=5 Also using with Charmbracelet Crush with Froggerinc fixed chat templates.
149.
▲
by
lrvick
1mo ago
Convert it to an image on the fly to feed it into a vision language model and I expect it would work just fine.
150.
▲
by
lrvick
1mo ago
That may have been true a few months ago, but shit changes fast in this space! I run Qwen 3.8 27b on each of my six AMD AI PRO r9700 GPUs at 80tps decode each and they cranks for days with 256k context, doing complex kernel, compiler, debug
More ›