Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ramchip
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
ramchip
2y ago
In Quebec French "on" is often used instead of "nous"; a closer translation would be simply "we don't speak English".
92.
▲
by
ramchip
2y ago
No. EdDSA (with any curve) relies on the ECDLP for security, which is broken by Shor's algorithm on quantum computers.
93.
▲
by
ramchip
2y ago
"Seriously, stop using RSA" https://news.ycombinator.com/item?id=30879442
94.
▲
by
ramchip
2y ago
HPKE is only comparable to the one-way handshake variants of Noise. For a VPN you'd want an interactive handshake to get forward secrecy on both sides, like Wireguard.
95.
▲
by
ramchip
2y ago
https://mailarchive.ietf.org/arch/msg/cfrg/3SXM0I9jVs5i38Sya... The idea here is to write a clean, easy-to-use spec for hybrid public-key encryption. (We're using the name "ECIES", b
96.
▲
by
ramchip
2y ago
See "Hybrid encryption and the KEM/DEM paradigm": https://neilmadden.blog/2021/01/22/hybrid-encryption-and-the... tl;dr: resistance to padding attacks, better support for non-RSA cryptosystems
97.
▲
by
ramchip
2y ago
You can get them to meet a more sizeable chunk of the team which helps keep individual bias down and ensures people are fine with the new hire.
98.
▲
by
ramchip
2y ago
"Abundant" in the infographic is questionable... in the universe yes, but on Earth not really.
99.
▲
by
ramchip
2y ago
I worked in trading and we did the first one, in C++. We'd load all the instruments (stocks etc.) on startup to preallocate the "universe", and use ring buffers as queues. Instruments don't change during trading hours so
100.
▲
by
ramchip
2y ago
Have you tried it with CockroachDB?
101.
▲
by
ramchip
2y ago
Note that Dunbar's number (150) is quite controversial: https://www.nytimes.com/2021/05/11/science/dunbars-number-de...
102.
▲
by
ramchip
2y ago
Seems to be a weird mishmash of two Quora answers to this question: https://qr.ae/psQebz . One AI-generated and the other human.
103.
▲
by
ramchip
2y ago
Erlang / Elixir
104.
▲
by
ramchip
2y ago
I think you're just using "transaction" in a different sense than what the interviewer meant; "guarantee that an event happened in addition to a database update" sounds like at-least-once to me, and it's normal
105.
▲
by
ramchip
2y ago
The goal of the outbox pattern is at-least-once publishing though, not only-once. You either get P + (eventually) at least one copy of K, or you get no P and no K. Without the outbox you can get P without K or K without P, which lead to con
106.
▲
by
ramchip
2y ago
I'm a bit confused by the story. Why did you disagree?
107.
▲
by
ramchip
2y ago
> (or worse: using a shared-secret for signing tokens instead of asymmetric cryptography, ugh) What’s so terrible about that? Several security engineers I trust favor designs with symmetric crypto, e.g. Fly.io https://fly.io&#
108.
▲
by
ramchip
2y ago
That translation makes no sense. There's nothing in there that allows Google to deploy their own private keys and certificate on people's servers. > This [well protected] certificate must both be issued from a trust hierarchy [
109.
▲
Elixir v1.17.0-RC.0 Released
(github.com)
5 points
by
ramchip
2y ago
|
0 comments
110.
▲
by
ramchip
2y ago
There's an arbitration process for chargebacks.
111.
▲
by
ramchip
2y ago
Very tangential, but as a worker in Japan I find it depressing how Keyence's recruiting material proudly shows a software engineer's typical day that starts at 8:30AM and ends around 8:00PM. No wonder it's so hard to raise ki
112.
▲
by
ramchip
2y ago
The card may look like a credit card, but it doesn't have the fraud protection, chargeback, or cancellation features of a real card. Within a closed conference that's fine, but it sounds dangerous to distribute this to a wide audi
113.
▲
by
ramchip
2y ago
How does FHE lead to people getting access to more computation?
114.
▲
by
ramchip
2y ago
> https://github.com/f4b6a3 > f4b6a3: a meaningless random package name ...well, I guess that's one way to name your library!
115.
▲
by
ramchip
2y ago
> With the web you have to trust the app developer The linked comment goes into it, but you have to trust the web hosting platform, the CA ecosystem, etc. We're talking not just Apple/Google being able to attack you, but also C
116.
▲
by
ramchip
2y ago
I mean the data people send through the app. You say: > It is a p2p files and messages sharing platform without involvement of any server. It has end-to-end encryption, ensuring your messages and files remain confidential. However the cl
117.
▲
by
ramchip
2y ago
You have to trust the original developers either way, but the distribution mechanism is much weaker for a web app. The server / hosting platform can be compromised, the code can change at any time and even depend on the client that
118.
▲
by
ramchip
2y ago
> without involvement of any server > bypassing the need for centralized servers I don't follow this part... it's using a centralized server to serve the web app, which could easily serve JS code that steals confidential dat
119.
▲
by
ramchip
2y ago
I don't think it's that strange. People can queue early because they want to get overhead storage space (it often fills up), or just get the process done with and sit down and relax. Personally I can focus on my book better if I&#
120.
▲
by
ramchip
2y ago
Could it be that they protect more than just the value of the US dollar?
More ›