Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nwf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
nwf
2y ago
That's only mostly true; Big CHERI (that is, the 64-bit CHERI systems, not CHERIoT) specifically has support for running legacy binaries within capability confinement. It's true that we think recompiling is generally the better a
2.
▲
by
nwf
2y ago
FWIW... Morello boards are hard to come by, but there have been efforts to offer cloud-computing style use of them, especially now that bhyve support exists; if you're interested I can try to find out more (I'd offer you time on
3.
▲
by
nwf
2y ago
> it doesn't matter too much whether the emulator is CHERI or not since Rust itself lets me express memory safety in the type system You might be interested in a very timely blog post: https://cheriot.org/cheri
4.
▲
by
nwf
3y ago
> I wonder to what extent moving bounds checks into hardware provides the potential for efficient memory safety. It's great! The CHERI team at U. Cambridge has recently released their initial performance characterization of Morello
5.
▲
What’s the Smallest Variety of CHERI?
(msrc-blog.microsoft.com)
2 points
by
nwf
4y ago
|
0 comments
6.
▲
Confidence in Confinement: An Axiom-Free, Mechanized Verification [pdf]
(doerrie.us)
1 points
by
nwf
10y ago
|
0 comments
7.
▲
by
nwf
10y ago
You don't sign the whole image as a stream, and you don't sign every block. Recursion is your friend! You sign the Merkle tree root, check it once, and then check O(log n) hashes per block access. You can, of course, amortize t
8.
▲
by
nwf
11y ago
You may be interested in reading, if you haven't, our 2011 position paper on Dyna. (The 2012 paper on what I think you would call propagator networks was fun, but is nothing you don't know already, I'm sure.) http:/&#x
9.
▲
by
nwf
12y ago
Thanks for your response; it does clarify things. But, I don't think I understand your concern about abstract hashing and how it would need to be something fundamentally new. Both the order normalization and self-reference are simply
10.
▲
by
nwf
12y ago
Agitate browser implementers to add support for magnet: URIs and you can do exactly that without needing to add new attributes to HTML. :) There's a bug for firefox here: https://bugzilla.mozilla.org/show_bug.cgi?id=52
11.
▲
by
nwf
12y ago
First off, let me say that I'm always happy to see people thinking about the robustness of scientific data. It's a thing we do not do well at all, at present, and should be much more urgent, given its importance to the enterprise
12.
▲
by
nwf
12y ago
Unfortunately, the technology you need to do that is not yet finished: https://trac.torproject.org/projects/tor/ticket/9498 ETA: I should have said "one possible technology"; there may be others, bu
13.
▲
by
nwf
12y ago
As far as I can tell, openvpn with TLS authentication is vulnerable as it just uses the usual TLS suite. If you use PSKs or the (mis-named?) --tls-auth PSK additional MAC, then you are only owned if one of your own legitimate nodes reveale
14.
▲
by
nwf
13y ago
Any possibility of adding this kind of functionality to libotr?
15.
▲
by
nwf
13y ago
While on the topic of clever UDP-based NAT traversal techniques, I think my favorite to date is pwnat [ http://samy.pl/pwnat/ ]. Uses ICMP in a clever way, requires no 3rd party.
16.
▲
by
nwf
14y ago
A slight disagreement: the advantage of a ZFS online consistency checker would be to help ensure that there are no bugs in ZFS. It appears that ZFS lacks a full consistency checker -- scrub only walks the tree and computes checksums; notabl