Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
noident
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
noident
2y ago
I don't understand. Why aren't these devices using full disk encryption?
62.
▲
by
noident
2y ago
It looks like it will be some time before free-threading can be safely used in production. I don't want to have to worry about whether the underlying C code supports no-GIL mode, or trade off single-threaded performance. [0] Maybe some
63.
▲
by
noident
2y ago
>Every Python developer has heard about the GIL Sadly, that is not the world we live in. I've cleaned up dozens of applications written by people with flawed understandings of threads, multiprocessing, and asyncio. I don't even
64.
▲
United States International Cyberspace and Digital Policy Strategy
(state.gov)
2 points
by
noident
2y ago
|
0 comments
65.
▲
by
noident
3y ago
Why would Tony want to get into YC? He's already making enough money that he "hit the brakes" while answering to no one. Sounds like a better deal to me than being some tech gazillionaire's sharecropper.
66.
▲
by
noident
3y ago
"Grey hat" mass scraping is what allowed Google to exist in the first place. Now they want to pull the ladder up behind them.
67.
▲
by
noident
4y ago
Yes! Targeted DoS is one way to force traffic to your evil exit node, and also to attack onion service anonymity (by forcing the service to choose a new guard). The 10/90 attack you're describing is probably not feasible due to mo
68.
▲
by
noident
5y ago
> Both depict a way of living free from 20-year mortgages, nine-to-five jobs, conventional relationships, and family responsibilities Now it's a 30 year mortgage for a nine-to-six job, if you're lucky. Where's the new beat
69.
▲
by
noident
5y ago
A more correct way to describe obfs4 is "makes Tor traffic look like unidentifiable traffic", which is in itself potentially a suspicious marker for people who want to watch Tor users. If Tor makes up the bulk of identifiable traf
70.
▲
by
noident
5y ago
> But even in that case, it requires the collusion of both the exit node provider and Apple to unmask you. So it takes two national security letters to unmask you instead of one?
71.
▲
by
noident
5y ago
No, Tor and a VPN are not compareable services. The Apple VPN is a closed network run on servers run by Apple, so you have to put 100% of your trust in Apple, as opposed to the open network of Tor, where trust is (ideally) distributed among
72.
▲
by
noident
5y ago
A tool which end users are discouraged from using. Tor relay trust is an unsolved problem.
73.
▲
by
noident
5y ago
KAX17 also employed middle relays. It's not out of the question that they are attacking onion services in some way, like the 2014 "relay early" attack. For example, if you run a relay chosen as a guard for an onion service, t
74.
▲
by
noident
5y ago
That's a reasonable default for 99% of Tor users. For that last 1%, there is the safe/safer/safest slider bar that is a single click away. Javascript also has nothing to do with these attacks. Even if you turn off Javascript,
75.
▲
by
noident
5y ago
It's a false choice. If you say no, and the police really want it, they can subpoena Amazon and compel them to turn over "your" footage. You would never even learn that it happened. You shouldn't trust a 3rd party with y
76.
▲
by
noident
5y ago
Mastodon, Pleroma, and Misskey (via plugin) all support RSS feeds.
77.
▲
by
noident
5y ago
This is why I've completely ruled out buying another pair of Ray-Bans again, and I've owned several in the past.
78.
▲
by
noident
6y ago
I would say for the better - it's the only thing keeping RSS alive. Although I will also say that having to administer a database is overkill for most use cases.
79.
▲
by
noident
6y ago
I can't find a way to contact the author, so I'm just going to post this here: your RSS feed has broken links, it links to www.robertovitillo.com, but the www subdomain does not resolve to your site.
80.
▲
by
noident
6y ago
I’ve been searchin’ For the dolphins in the sea And sometimes I wonder Do you ever think of me https://www.youtube.com/watch?v=b8g_j5y2OK4
81.
▲
by
noident
6y ago
Can you be certain that nobody has retained a copy of this key?
82.
▲
by
noident
7y ago
That's not so great for a best case scenario, because destination IPs rarely change, and anyone can resolve any domain themselves, making it easy to associate a timestamped IP with a DNS record. I could walk the whole HSTS preload list
83.
▲
by
noident
7y ago
What difference does it make? Even if the DNS queries are completely encrypted, subsequent HTTPS requests made after domain resolution will contain the destination domain (but not the path or request body) in the clear. What makes you assum
84.
▲
by
noident
7y ago
I was relieved to see that only internal employee information was impacted. You don't even want to know how many banks, hospitals, and power plants rely on Citrix Receiver for remote desktop access.
85.
▲
by
noident
7y ago
This seems like the easiest way to do it, so I would speculate that this is how it was done. All you have to do is put a website up and make the server phone home, revealing the hidden IP address. Some more speculation: the government is hi
86.
▲
by
noident
7y ago
I have read the articles, but have not found an explanation or specific examples. It's not as if Tor doesn't care about onion services; they just spent 4 years designing and implementing the v3 onion service protocol.
87.
▲
by
noident
7y ago
Wouldn't your onion service uptime become correlated with the guard's uptime? DDoS probes as described in the OP plus some basic monitoring of known onion sites could discover onions paired with single guard nodes. And if I can be
88.
▲
by
noident
7y ago
First: it seems like the author has come up with a number of useful custom modifications to the Tor daemon to mitigate common attacks against onion operators. Why not work with the Tor Project to upstream some of the more useful ones, as we
89.
▲
by
noident
7y ago
Encrypted data is more like speech than a weapon. The analogy to guns just doesn't work.
90.
▲
by
noident
7y ago
>What are you tracking, how is it used, and how can I be confident it won't be abused? Because of the nature of computer security, you cannot be certain that any data that you give to a 3rd party will be secure. Once it leaves your
More ›