Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
michwill
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
michwill
10y ago
Drone with a camera which flies and indexes physical world (like your house) automatically. So that you can find your stuff :-)
32.
▲
by
michwill
10y ago
* You can work on reducing cost of space access yourself! * There are some good things to do in space. Look for ZBLAN fibers, for example. It's actually interesting question, what price of space launch (per kg, when you have low or hig
33.
▲
by
michwill
10y ago
Same for me. Linux/Chromium or Linux/Firefox
34.
▲
by
michwill
10y ago
Since the exploit is known: I wonder, is it possible to hack all these devices and let them DDOS localhost?
35.
▲
by
michwill
10y ago
This stuff makes economic sense to retrieve at certain costs of space launch. As well as manufacturing some stuff (like optical fibers) in space, producing energy, sending nuclear waste there etc
36.
▲
by
michwill
10y ago
It means "Clinton"
37.
▲
by
michwill
10y ago
What do you think about: * As space access becomes cheaper, which economic opportunities will open, at which price point? * Mining asteroids and Moon * Space manufacturing. Any manufacturing more feasible in space than on Earth? * Space pow
38.
▲
by
michwill
10y ago
Very good. Basically, triggers similar intense "investor days" after the investor day :-D
39.
▲
by
michwill
10y ago
I think, you may have the application with a different cloud provider or even in a different geographic location, so that you can keep keys away from the data. In this case you sort of distribute trust.
40.
▲
by
michwill
10y ago
I wonder if uvloop will work with such pypy. The speed would be awesome!
41.
▲
by
michwill
10y ago
There are many proprietary methods which are based on deterministic encryption + obfuscating word distribution, that's what most companies do. We avoid doing that because of questionable security of such method. Also we tend to publish
42.
▲
by
michwill
10y ago
ZeroDB doesn't use deterministic encryption (neither Hadoop product, nor open source database)
43.
▲
by
michwill
10y ago
We have ideas how to make relational databases secure while running everything server-side, thanks to recent research publications [notably CipherBase from Microsoft Research http://www.cidrdb.org/cidr2013/Papers/C
44.
▲
by
michwill
10y ago
Malicious server, apart from possibility of removing data, would look pretty unusual for the client (like returning incorrect data etc). So it's a good idea to look for these patterns. An attack would probably look like trying to use t
45.
▲
by
michwill
10y ago
0db - that's I was thinking of. Way to fight 0days
46.
▲
by
michwill
10y ago
Yeah, I guess a little early to retire MySQL and Oracle :-) Thanks for pointing out, legacy is more about DB2
47.
▲
by
michwill
10y ago
The last is what's remembered best :-D. But yeah, good point
48.
▲
by
michwill
11y ago
Actually, I think it's not too hard to get a python library to iOS/Android (especially Android). But I see your point. Reference implementation without dependencies would be just a more cross-language rewrite of these dependencies
49.
▲
by
michwill
11y ago
Huh, interesting comparison. Thanks for pointing that out! We'll read more about Datomic: maybe we can learn something useful from them
50.
▲
by
michwill
11y ago
Deriving from passphrase is optional. Mainly, for development and testing, and also for users who are ok with passphrases. Having a passphrase + server-saved salt makes it better than a passphrase with no salt (for brute-force by dictionary
51.
▲
by
michwill
11y ago
No, we don't use any techniques from CryptDB at all. We thought about doing server-side set intersections using some ideas from CryptDB but we decided to not do that. In brief, we don't compute on encrypted data, we search for enc
52.
▲
by
michwill
11y ago
The thing is that anybody who is able to initiate queries has access to that data. No need to do inference attacks over there :-) So, an adversary cannot query data based on particular distribution b/c it cannot initiate meaningful que
53.
▲
by
michwill
11y ago
Yeah, that is actually deterministic encryption. Microsoft had a very interesting research paper called CipherBase (we cited it), but I think they didn't end up commercializing that research
54.
▲
by
michwill
11y ago
Yeah, right. I guess, as long as we don't redirect encrypted content of a database to a sound device, we should be all right :-)
55.
▲
by
michwill
11y ago
Yeah, actually that is true. Enigma worths mentioning as one of MPC references. Looks like Enigma would have challenges in many practical environments (mainly because it involves a lot of small interactions between nodes, so should be affec
56.
▲
by
michwill
11y ago
I don't think it's so much of a size issue. I'd use it for applications where you don't have too many simultaneous users of the same dataset (in future - that constraint would be only about simultaneous writing users). W
57.
▲
by
michwill
11y ago
In fact, the approach you used for actor (using GWT) is no less applicable to us (using pyjs or rapydscript - see https://medium.com/@ZeroDB_/zerodb-js-zerodb-in-the-browser-... )
58.
▲
by
michwill
11y ago
Yep, relevant pieces, thanks for bringing this! Our performance become a little better since then. And also we'll update our fulltext search algorithm using Lucene's practical scoring function: that makes it more scalable and will
59.
▲
by
michwill
11y ago
Also you cannot do queries on the encrypted db without being able to observe the results. E.g. if you are able to initiate a query on a fraction of the data, you already have access to that fraction of the data. And you cannot initiate a me
60.
▲
by
michwill
11y ago
You are right about the identifiers. And that is exactly what makes us concerned about access patterns attacks. They are not as dangerous when queries are rare. But we do explore possibilities to mitigate this attack vector completely using
More ›