Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mratsim
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
mratsim
3y ago
I am reading the replies. You don't understand the legal liabilities people open themselves to if they provide the software. Now they have to fully KYC customers to make sure they are from the US, with US only storage, and firewall so
32.
▲
by
mratsim
3y ago
How would US vendors prevent people from outside the US to acquire the software?
33.
▲
by
mratsim
3y ago
I understand where you're getting at, but lawyers would see "is it possible for people out of the US to download this? Yes? Well lawsuit incoming, by the government/military." This is way too much of an unknown. And we&#
34.
▲
by
mratsim
3y ago
How would you send encrypted email without an encryption library?
35.
▲
by
mratsim
3y ago
How would you send encrypted emails without an encryption library?
36.
▲
by
mratsim
3y ago
Cryptography was considered a war weapon and only allowed for military use. The United States had to be brought to court to finally allow cryptography: https://en.m.wikipedia.org/wiki/Bernstein_v._United_States > Ye
37.
▲
by
mratsim
3y ago
Premature slogans are the root of all evil.
38.
▲
by
mratsim
3y ago
The people who found the bug in glibc worked at an audit firm. Peers aren't enough. Finding vulnerabilities require training and an adversarial mindset that is rare. There is a reason why in cryptography people say "don't ro
39.
▲
by
mratsim
3y ago
Your argument is that asking for professional auditor is not necessary for open-source code. My argument is that open-source is not enough when high-assurance is needed and devs or end-user should still ask for a professional audits.
40.
▲
by
mratsim
3y ago
It's a project used by millions of people yet it took 2 years. What about projects used by 10~50 people?
41.
▲
by
mratsim
3y ago
And here 2 years to find a buffer overflow vulnerabity in glibc that was found via a fuzzer: https://news.ycombinator.com/item?id=39194093 In a library used on billions of devices.
42.
▲
by
mratsim
3y ago
There isn't
43.
▲
by
mratsim
3y ago
Do they have background in fuzzing or formal verification? That's what you need if you want to make high-assurance software.
44.
▲
by
mratsim
3y ago
What do you mean?
45.
▲
by
mratsim
3y ago
Auditing your own code doesn't help if you have a blindspot. You will miss it while developing and auditing. > Everyone who is able will want to take a look. This is not true. Auditing is very skill intensive and time intensive. The
46.
▲
by
mratsim
3y ago
It should be audited by professionals, but available for public reviews / additional audits. General folks and even most devs do not have the skills to audit code.
47.
▲
by
mratsim
3y ago
Not sure what's your use-case and threat model, but HKDF is likely what you want, the concatenation is done in a way to prevent attacks: https://www.rfc-editor.org/rfc/rfc5869
48.
▲
by
mratsim
3y ago
The compiler escape hatch is -ffast-math
49.
▲
by
mratsim
3y ago
The batch match-mul API would be very useful for convolutions. It's also used on Nvidia GPUs. Often you get tensors that are sliced views on one or more dimensions, with BLAS-api you need to allocate them in a contiguous buffer. BLIS d
50.
▲
by
mratsim
3y ago
MKL is very fast, on Intel. Due to how they do CPU detection. It is a specialized library and they JIT their kernel. Usually BLIS is slower.
51.
▲
by
mratsim
3y ago
MKL has a JIT similar to libxsmm for small sizes.
52.
▲
by
mratsim
3y ago
That's what I'm saying though. Either youbdo the accumulators yourself, or you need a compiler escape hatch.
53.
▲
by
mratsim
3y ago
They do reorder instructions. I think the SIMD part has more to do with loop analysis than ILP. It's quite telling that there is a #pragma omp simd to hint to a compiler to rewrite the loop. Now I wonder what's the state of polyhe
54.
▲
by
mratsim
3y ago
It depends. You need 2~3 accumulators to saturate instruction-level parallelism with a parallel sum reduction. But the compiler won't do it because it only creates those when the operation is associative, i.e. (a+b)+c = a+(b+c), which
55.
▲
by
mratsim
3y ago
Dow Jones Index?
56.
▲
by
mratsim
3y ago
A memory leak means it leaks, it's not anymore under control. Here the memory is under control, it can be reclaimed by the program.
57.
▲
by
mratsim
3y ago
GMP is not a cryptographic library and using it prevents you from being constant-time, you'll also be very slow. That's for the math. Then you'll have non-erased secrets in memory. Now for RSA specifically, you'll likely
58.
▲
by
mratsim
3y ago
Can you substantiate what makes this a cryptocurrency? Everytime you authenticate on your bank website you sign a payload, that doesn't make transactions there cryptocurrency.
59.
▲
by
mratsim
3y ago
The stuff on the PRO is a Xilinx FPGA, or they have both an ARM Processor and an FPGA?
60.
▲
by
mratsim
3y ago
Disagree, their reputation is tied to their audit quality. But I'm pretty sure in this case the scope was bad. Like they coukd have had audits on "Do I use OpenSSL well?" and then misrepresent that all their privacy claims we
More ›