Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
markasoftware
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
markasoftware
1y ago
This isn't security research, it's unauthorized hacking. Monster has no vulnerability disclosure program. It's completely illegal to try and gain unauthorized access without a VDP, even if you attempt to responsibly disclose
92.
▲
by
markasoftware
1y ago
I agree, but I got the Pixel 5 instead; the 5 is actually smaller while the screen size is larger due to the curved screen corners. It also has a fingerprint sensor, unlike the 4. That being said, I still miss the squeeze-activated flashlig
93.
▲
by
markasoftware
1y ago
a bloom filter look up is by hash, and given the relatively small set of words in english, it would be pretty easy for the server to reverse the hash sent to it. Thus a bloom filter wouldn't be very private. Additionally, a typical spe
94.
▲
by
markasoftware
1y ago
nope they were both started within a year of each other. Lots of Tor fans will tell you that I2P is overly complicated. And indeed it seems to have had more vulnerabilities over the years.
95.
▲
by
markasoftware
1y ago
There's some subtlety here so my apologies for the long reply. Nym/Loopix (and I405, though it's so experimental I feel bad even talking about it) completely defeat end-to-end correlation attacks, where an attacker tries to f
96.
▲
by
markasoftware
1y ago
if I'm able to ping 8.8.8.8 in 10ms, doesn't that mean that my rtt latency to get out of the docsis-part of the network is 10ms, and that any latency beyond that will be the same regardless of docsis/fiber?
97.
▲
by
markasoftware
1y ago
It depends on your threat model. Tor is focused on hiding from small-scale passive adversaries (eg, you're in Iran and don't want the Iranian government to see what you're doing. Or your ISP. Or any single node operator). Eve
98.
▲
by
markasoftware
1y ago
tor tries very hard to bypass censorship. Have you tried the numerous Tor bridges, or the new Snowflake p2p bridge?
99.
▲
by
markasoftware
1y ago
uh have you ever tried pinging a server in your same city? It's usually substantially <30ms. I'm currently staying at a really shitty hotel that has 5mbps wifi, not to mention I'm surrounded by other rooms, and I can still
100.
▲
by
markasoftware
1y ago
this is what i don't get. How can GPT-5 ace obscure AIME problems while simultaneously falling into the trap of the most common fallacy about airfoils (despite there being copious training data calling it out as a fallacy)? And I belie
101.
▲
by
markasoftware
1y ago
it really does have that AI writing style, and these are the sorts of bugs I imagine an AI could have found...I wonder if that's what they did (though they claim it was all manual source code inspection).
102.
▲
by
markasoftware
1y ago
still, if you ask this open model to generate a fancy space invaders game with polish, and then ask the other model to generate a bare-bones space invaders game with the fewest lines of code, I think there's a good chance they'd s
103.
▲
by
markasoftware
1y ago
The space invaders game seems like a poor benchmark. Both models understood the prompt and generated valid, functional javascript. One just added more fancy graphics. It might just have "use fancy graphics" in its system prompt fo
104.
▲
by
markasoftware
1y ago
is this their attempt to pin it on Visa / other networks? Or are they claiming that they actually had a valid legal issue against steam's policies?
105.
▲
by
markasoftware
1y ago
GitHub copilot's inline completions still exist, and are nearly instant!
106.
▲
by
markasoftware
1y ago
I wonder if it's possible to run trains at higher speeds closer to each other using fixed brakes embedded near the tracks, similarly to how roller coasters often have mid-course brake runs that are only activated in emergencies when t
107.
▲
by
markasoftware
1y ago
ok, so you can understand the words at 800wpm...can you really comprehend what's being said? When I listen to youtube videos at 2x speed I can usually pick apart all the words just fine but I often have to slow it down to properly pro
108.
▲
by
markasoftware
1y ago
I'm writing an encrypted and padded IP tunnel to help people build their own multi-hop circuits to access the internet anonymously, without Tor, and with protection from end-to-end correlation attacks. https://github.com
109.
▲
by
markasoftware
1y ago
what if the boot image itself isn't corrupted but rather there's other persistent data which causes the firmware to get stuck / bootloop? This is more or less what happened to the Mazda head unit firmware in the link I posted
110.
▲
by
markasoftware
1y ago
Same things have been said of eg the massive Facebook years ago. It was DNS, which affected service discovery across the whole org. The massive Roblox outage was also caused by service discovery failure (Consul). If your machines don't
111.
▲
by
markasoftware
1y ago
if you could somehow put something into persistent storage on the satellites that causes it to crash every time it tries to start up before it gets to the point where it's able to update the software, then they'd be bricked. see a
112.
▲
by
markasoftware
1y ago
this sort of vulnerability (stealth audio and video capture) is surprisingly common, see https://googleprojectzero.blogspot.com/2021/01/the-state-of-...
113.
▲
by
markasoftware
1y ago
oh wow, I remember reading a blog post about how this effort wasn't going well a while ago. I guess it got through in the end!
114.
▲
by
markasoftware
1y ago
is this talk about apple? Regardless, lots of language runtimes still use utf16 (eg java, qt, haskell), and windows certainly still uses utf16.
115.
▲
by
markasoftware
1y ago
"former dropbox engineers" doesn't mean a whole lot -- it's a large company where tens of thousands of people have worked over the years. It's not like this is by the founders or anything.
116.
▲
by
markasoftware
1y ago
not an LLM, in case you're wondering. From the PyTheus paper: > Starting from a dense or fully connected graph, PyTheus uses gradient descent combined with topological optimization to find minimal graphs corresponding to some target
117.
▲
by
markasoftware
1y ago
the nixos package is unmaintained; BetterBird itself is fine.
118.
▲
by
markasoftware
1y ago
i see, this likely happened to me.
119.
▲
by
markasoftware
1y ago
just tried installing it in case last time I tried it >5 years ago was during the "rough". I was impressed that it correctly inferred the IMAP and SMTP settings for my custom domain name, but after using it for ~30 seconds rand
120.
▲
by
markasoftware
1y ago
As you point out, the most serious way to undermine the "safety" features in a "safe" language like Rust is to implement a VM, programming language, serdes framework, etc, because these operate outside of Rust's typ
More ›