Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rainforest
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
151.
▲
by
rainforest
13y ago
The problem with Microsoft's approach the way I see it is that they're offering no value-add for the inconvenience. Gamers are used to discs being transferrable but MS is making a bold choice to devalue them and treat them as toke
152.
▲
by
rainforest
13y ago
The probability of a bit error on normal RAM is quite high [1]. The more RAM you add the more likely you are to see corruption. Not that ECC fixes everything - I still see uncorrected ECC errors on the older HPC nodes on our grid. [1] : ht
153.
▲
by
rainforest
13y ago
The burglary analogy rests on the assumption that we must leave the house unattended - it doesn't carry over to children surfing the net. No filter will work reliably enough to allow worry-free unsupervised access. Making porn harder to fin
154.
▲
by
rainforest
13y ago
For my own benefit, do you have more information about the circumstances of Tesla's loan? Did they get a special deal, or were they just successful applicants to an open-to-all opportunity?
155.
▲
The Cray Files
(modularcircuits.tantosonline.com)
3 points
by
rainforest
13y ago
|
0 comments
156.
▲
by
rainforest
13y ago
In a sense Windows (Vista) and 7 and 8 have encouraged targeting user-mode processes. The garden variety IRC bots that ship with the "hacking tools" available through various YouTube channels all run in user-mode. The most common (at least
157.
▲
by
rainforest
13y ago
That is a valid point, but I think some power is still retained by the consumer in the sense that they can reject individual DRM implementations and accept others, while with Flash they're forced to install it if one provider they wish to u
158.
▲
by
rainforest
13y ago
The same can be said of Flash, however. The other side of that coin is that content will never be available DRM free, so I'm not sure if it's an important point; mobile content delivery is normally achieved via apps, or in the BBC iPlayer's
159.
▲
by
rainforest
13y ago
Flash is a considerably larger undertaking than a plugin though; if the interface is standard shipping on different platforms should just involve setting up appropriate QA and another make target. At the very least, the decision of what p
160.
▲
by
rainforest
13y ago
Perhaps I could have been more clear; when I say "porting" I mean from the perspective of a vendor. The current status quo is that content is available only where Adobe can be bothered to provide Flash. Given that constructing a "secure" bl
161.
▲
by
rainforest
13y ago
None of the nightmare scenarios are enabled by this proposal that aren't already possible though. Flash is available and baked in, providers can already run to DRM-ed content since the ubiquitous platform enables it. It's currently used in
162.
▲
by
rainforest
13y ago
The former doesn't include redundant duplication of functionality and other bells and whistles. Since the only objective is decrypting content it'll presumably be more practical to port (and reverse engineer) and ship with fewer security vu
163.
▲
by
rainforest
13y ago
Isn't this already the case? Netflix forces users to use Silverlight; YouTube won't serve HTML5 videos if ads are enabled. The "Open Web" is already lacking their content because they rely on DRM already. Content industries won't give up on
164.
▲
by
rainforest
13y ago
A great academic who taught me once said of a PhD (paraphrasing); "It's not going to be your best work and it'll not be amazing. It's just your trade union card. Nobody gets really good at research until they're 10 years in." Pragmatic advi
165.
▲
by
rainforest
13y ago
This indictment [1] seems to suggest an Indian payment processor was compromised, whose name "is known". [1] : http://cbsnewyork.files.wordpress.com/2013/05/lajud-13-cr-02...
166.
▲
by
rainforest
13y ago
Is it? I was under the impression it just uses symbolic execution rather than invariant detection.
167.
▲
by
rainforest
13y ago
It's possible to debug targets running under the current user, so root privileges might not have been needed, if they had an agent running under the same UID as the application. > However, the private key can be then used to carry out c
168.
▲
by
rainforest
13y ago
Devils advocate: preparing a press release from a company after plugging holes and auditing that makes the appropriate admissions and apologies probably takes more time than writing up a successful hit after attacking a page.
169.
▲
by
rainforest
13y ago
It might have been encrypted, but surely it must be exposed to their system somewhere to enable them to make charges? Is it feasible, if that was the case, that the attackers could use that to exfiltrate decrypted CC info? I suppose this wi
170.
▲
by
rainforest
13y ago
Ah, my description wasn't the best, apologies. What I meant was the payment backend, a separate server, could only service write requests from the frontend. The backend itself would possess decryption keys to make charges, but the frontend
171.
▲
by
rainforest
13y ago
From their description it appears encrypted CC numbers were in the database amongst the other customer information. Sure, the data has to live somewhere, but the apparent situation of CC, customer, private key all accessible to the frontend
172.
▲
by
rainforest
13y ago
Should CC info even be stored in the customer database? I would have thought that information should be write only. Does PCI allow that to happen with only PKI in place?
173.
▲
by
rainforest
13y ago
They differ quite significantly. dtrace uses probes - points where instrumentation can be installed to inspect the process as it runs. Since it requires these probes to be defined, probes only come "for free" in kernel-space: e.g. tracing s