Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ramchip
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
ramchip
2y ago
There's also a legal risk for private entities, as the conviction of Avraham Eisenberg showed recently, and I think a strong possibility that a successful attack would crash the valuation of BTC and make it impossible to recoup costs.
122.
▲
Delinea has cloud security incident in Thycotic Secret Server gaffe
(doublepulsar.com)
1 points
by
ramchip
2y ago
|
0 comments
123.
▲
by
ramchip
2y ago
My local supermarket (in Japan) sells canned soup in a rack like this. It's a bit looser and the cans come out horizontally at the bottom and hit a stopper, so you grab one from the top rather than the sides. The one in the article is
124.
▲
by
ramchip
2y ago
There's a typo in the current title: Shiakaku -> Shikaku (Japanese for "square")
125.
▲
by
ramchip
3y ago
Great article. The `pg_sleep` is a nice trick to test for concurrency issues in postgres.
126.
▲
by
ramchip
3y ago
For others like me wondering what "the project" is, I think it's Ethereum. > Vitaly Dmitrievich Buterin, better known as Vitalik Buterin is a Canadian computer programmer and co-founder of Ethereum. > Gavin James Wood i
127.
▲
by
ramchip
3y ago
> digital signatures are implemented in terms of asymmetric encryption No, you're thinking of textbook RSA, which is a special case. Most signature algorithms don't work like that.
128.
▲
by
ramchip
3y ago
This is covered in the article. It even links to the exact same page.
129.
▲
by
ramchip
3y ago
Noise has one-way handshake patterns for things like file encryption, but the pattern implemented by Wireguard is an interactive one. Compare sections 7.4 and 7.5 in the spec.
130.
▲
by
ramchip
3y ago
From the article: > This is highly related to the "Null Object Pattern", but I thought I would explain it from the perspective of functions.
131.
▲
by
ramchip
3y ago
"I apologize for any confusion or misinformation my response may have caused. You're correct that improving the boot time is possible and will save considerable time for the customers. Subroutine X can be optimized by..."
132.
▲
by
ramchip
3y ago
Branch prediction and speculative execution can affect that. For instance failing on the first byte could cause more iterations to be thrown away and re-executed than failing on the last byte.
133.
▲
by
ramchip
3y ago
This article is rather terrible. Here's a better one with actual explanations: https://uk.sports.yahoo.com/news/unions-call-strikes-ubisoft...
134.
▲
by
ramchip
3y ago
The problem is that as an attacker sending requests to the server, what you control is the API key, not the hash of the API key. To test a specific hash like "c000...0000" you would need to find an input to the hash function that
135.
▲
by
ramchip
3y ago
H is a cryptographic hash. You observe via timing that H("123") starts with the same byte as H(key). How do you then guess the next byte? Consider what happens to the first byte of the hash if you add a new byte to the input, e.g.
136.
▲
by
ramchip
3y ago
I don't think hiring was the issue. See these Quora posts: https://qr.ae/ps8h6J
137.
▲
by
ramchip
3y ago
It's called rebinding, rather than mutation. Good background here: https://dashbit.co/blog/comparing-elixir-and-erlang-variable...
138.
▲
by
ramchip
3y ago
Makes sense. The Muppet was definitely needed. Thank you!
139.
▲
by
ramchip
3y ago
I'm curious why the connection from Rails is "mTLS-y" rather than actual mTLS. The macaroon repo mentions a Noise transport. Maybe to avoid dealing with X.509 certificates by distributing trusted public keys via LiteFS? >
140.
▲
by
ramchip
3y ago
The bug is triggered by the JIT - maybe you didn’t have it enabled?
141.
▲
by
ramchip
3y ago
The Erlang way doesn’t require exception handling code because processes are isolated, so when one dies the runtime can clean up after it (reclaiming memory, file handles, etc.) as it knows what process owns what resources. Links and monito
142.
▲
by
ramchip
3y ago
RabbitMQ is IMHO probably the best open source example tackling a large, complicated real world problem with graceful degradation (e.g. if a queue keeps crashing). Elixir has a lot of smaller but very high quality libraries to learn from. Y
143.
▲
by
ramchip
3y ago
Personally I've found Temporal very limited as a queue: no FIFO ordering (!), no priorities, no routing, etc. It's also very complex when you just want async jobs, and more specialized than a DB or message broker, which can be use
144.
▲
by
ramchip
3y ago
Eating out in Tokyo really is cheaper than the COL would imply. $8 will get you a nice set meal at a sit down restaurant, all included, and tip doesn't exist.
145.
▲
by
ramchip
3y ago
With FDB latency shoots up when a bunch of writers compete to update the same entry, because writers can have to retry many times before the write finally goes through, with a network round-trip each time. Personally I found this much harde
146.
▲
by
ramchip
3y ago
It's used for monitoring, not the actual trading. The Erlang scheduler is fantastic, but it targets a context switch roughly every 1ms, it's obviously not suitable for HFT where a process must respond to a network event within mic
147.
▲
by
ramchip
3y ago
I replied more in details elsewhere in the comments, but in a nutshell Erlang/Elixir processes are a tool to contain errors, and they make some opinionated design choices to achieve that. Goroutines are a pure concurrency primitive, th
148.
▲
by
ramchip
3y ago
Indeed, hence the "generally" :-)
149.
▲
by
ramchip
3y ago
The critical difference is that processes are isolated, they don't share resources like goroutines do. This makes it possible to separate the error handling from the business logic. When you open a file, a socket, allocate memory, borr
150.
▲
by
ramchip
3y ago
> Beam doesn't have anything to do with supervisors that's an OTP thing. The key VM feature you're missing is process isolation. Without it, supervisors are not really possible - you can implement something that vaguely lo
More ›