Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
problems
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
751.
▲
by
problems
10y ago
> There is a world of difference between "come up with two things that hash to the same value" and "come up with something that hashes to a particular known value". Doesn't the PDF on their site pretty much prove
752.
▲
by
problems
10y ago
Would a TLS certificate not offer such a large similar prefix? Just change the domain to a wildcard or something like the RapidSSL MD5 attack from a few years back.
753.
▲
by
problems
10y ago
A few considerations though: - Google used GPUs, much of the Bitcoin network relies on fully custom ASICs now and mining without them isn't really profitable anymore - SHA1 hashes can also be computed over twice as fast as SHA256 even
754.
▲
by
problems
10y ago
Yeah, Elixir or Haskell is probably the way I'll wind up going if I want to pursue functional programming again. I can do the basics enough to handle LINQ well and stuff, so I'm getting away without a strong knowledge for now. One
755.
▲
by
problems
10y ago
There's also a lot of CC licensed stuff that might already be allowing use for such purposes with the authors not expecting any return from it.
756.
▲
by
problems
10y ago
I don't think we're likely to see it used for torrent poisoning if it takes 110 GPUs 1 year to compute a collision - the electricity costs for such a rig would be enormous. 110 GPUs * about 300 W each = about 290 thousand kilowatt
757.
▲
by
problems
10y ago
The problem I had going into this without a strong functional background is that often times to do practical things you're forced to work with .NET libraries - these .NET libraries are not nice functional libraries and don't encou
758.
▲
by
problems
10y ago
How bad are the rules for MSVC compared to the Itanium ones and would you consider adding support for it too? Not that I have a use case in mind or anything, just curious.
759.
▲
by
problems
10y ago
> enforcing it would be almost impossible It'd be about the same as GPL enforcement as is. I don't see any reason this would introduce a special circumstance.
760.
▲
by
problems
10y ago
You can make your own GPL fork if you'd like. That's the nice part about BSD, you can relicense it exactly as you please.
761.
▲
by
problems
10y ago
Curious, why do you favor GPL over BSD as a user? You have all the same abilities with it, and a few additional ones too. The closed source forks for the BSD licensed projects... sure, don't use those but the projects themselves are go
762.
▲
by
problems
10y ago
In the same place that you'd install it as a user? That'd be some very stupid malware - anyone who was actually rooted would notice immediately when their root tool told them their support binary needs to be updated.
763.
▲
by
problems
10y ago
It seems things have shifted again since I last checked and now magisk has its own builtin su, magiskhide is greatly improved and many people are using suhide instead altogether.
764.
▲
by
problems
10y ago
On Android, the standard root system most people apply to their device prompts you when you launch an application if you want to allow it root access. This makes it trivial to block malicious applications - that new game you downloaded prob
765.
▲
by
problems
10y ago
Sure, so detect that as the problem. That's not true of rooted Android devices though, most Android devices allow you to enable a developer mode which will allow you to replace the ROM entirely if you like with no need to exploit anyth
766.
▲
by
problems
10y ago
Yeah, so it depends on the way they detect it. You can bypass anything, even Google SafetyNet with stock ROM + magisk + systemless Xposed + phh su and using Magisk Hide if you're determined enough. CM ships pre-rooted - you just enable
767.
▲
by
problems
10y ago
Rooting a device doesn't immediately expose you to risk, you must manually allow that. There's very little malware around if you stick to the standard app stores like most users will too. Ads that push malware - a major problem on
768.
▲
by
problems
10y ago
The sandbox has been good in that it hasn't let the Windows model of apps running rampant with admin privileges do whatever they want with your data. It's mostly prevented cross-app data access. But that's not where it stops.
769.
▲
by
problems
10y ago
The bigger problem is that your browser let it without your permission.
770.
▲
by
problems
10y ago
> It's no secret that jailbroken phones are less secure There is no evidence that jailbroken or rooted users have resulted in any significant compromises. At least in the Android world, you must still approve any application which w
771.
▲
by
problems
10y ago
> If you are using the phone for work, you shouldn't be opening up access to a local admin account. Rooting/jailbreaking is a double edged sword. You get more control over the device but you also open up access to malicious app
772.
▲
by
problems
10y ago
You can try lots of things, detecting su binaries, UI applications, checksumming the entire filesystem, etc. But ultimately if the user doesn't want you to know, you won't know. Rooting or jail breaking your device is taking contr
773.
▲
by
problems
10y ago
> the kind of dangerous know-nothing who is bringing about the end of civilization as we know it I'm totally on board with you with regards to climate change, but do you really need to simplify and insult opponents like this?
774.
▲
by
problems
10y ago
> The comment I replied to originally included a question on whether Signals server is even open source. Sorry about that, I had looked it up just a second after I posted and then removed that line. > hate on Signal/OWS I don
775.
▲
by
problems
10y ago
I definitely wouldn't suggest it for video, but I've never had an interest in video conferencing in general. Extensions are pretty straight forward in my experience - either your server supports them or it doesn't, but most o
776.
▲
by
problems
10y ago
They're pretty critical of XMPP but aren't there direct counter examples to it, like Conversations https://conversations.im for one.
777.
▲
by
problems
10y ago
You might check out Conversations too ( https://conversations.im/ ), it's a federated XMPP (with some really clever extensions) based approach that uses the signal protocol.
778.
▲
by
problems
10y ago
That's sort of a weird scenario, but I'd say no - sending the bomb in the mail should have been illegal in the country they sent it from, whether it's illegal or not in the destination country shouldn't matter.
779.
▲
by
problems
10y ago
This was my immediate thinking on reading the title - is it incorrect?
780.
▲
by
problems
10y ago
Nice work. It's pretty incredible the kind of issues you see when you're running a service your customers depend on - especially if that's potentially latency sensitive. I've seen packets between Chicago and rural Ohio g
More ›