Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rphlx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
rphlx
8y ago
A decent fraction of the population views password restrictions as a challenge to come up with the shittiest, least secure password that they possibly can while still meeting all restrictions. You can blame users for that with some justice,
32.
▲
by
rphlx
8y ago
It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control th
33.
▲
by
rphlx
8y ago
> Bloomberg says it is in line with memory to CPUs to intercept some password validation code I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an exa
34.
▲
by
rphlx
8y ago
FWIW there's no conflict there in terms of the cryptography. A replay-protected, keyed authenticator of plaintext commands (HMAC, etc) is not encryption; it is authentication. In a similar sense you are allowed to put a rolling log-in
35.
▲
by
rphlx
8y ago
I completely agree. The rapid flux in these huge browser projects makes personal security audits impossible even if you are one of the top 10 super-rigorous C++ devs in the world. Would be nice if some project forked the browser of their ch
36.
▲
by
rphlx
8y ago
Google appears to have a long history of infantilizing its workforce, partly - one hopes - as a sort of group-bonding in-joke, and partly - one suspects - as a darker psychological management strategy with objectives that are not always una
37.
▲
by
rphlx
8y ago
At best a crackpot one with no serious support from contemporary leaders such as Churchill, or historians since then AFAIK. Putting the war in the Pacific aside, I think you can place much of the blame for WWII on the election of an extremi
38.
▲
by
rphlx
8y ago
The view that someone is automatically a monster or an "oppressor" because they voted Republican is wrong and offensive in the extreme. It is possible to vote Republican without wholly supporting - let alone personally imitating -
39.
▲
by
rphlx
8y ago
Be wary of the legal implications. At minimum GOOG can probably claim copyright and do a DMCA takedown.
40.
▲
by
rphlx
8y ago
If only it were so simple. What you are proposing seems to require universal acceptance of an authoritarian regime that sets the social rules which are, as you say, "not negotiable". Otherwise in a free society almost everything i
41.
▲
by
rphlx
8y ago
Intel's recovery a decade ago also came down to superior mfg, and that past strength is their main weakness this time around. I am very concerned about their ability to yield 24+ core monolithic server parts on 10nm at competitive cost
42.
▲
by
rphlx
8y ago
I like RISC-V more than is probably healthy, but it is not a player at all, let alone a compelling player, vs x86_64 or aarch64 in the server space and probably won't be for at least 2-3 years. One obvious missing feature is robust KVM
43.
▲
by
rphlx
8y ago
There's a cheap and timeless emotional thrill in supporting a rising underdog, but if Intel declines too far, that thrill will not be cheap, but very expensive for most of us here. AMD will gladly collect the same quasi-monopoly margin
44.
▲
by
rphlx
8y ago
If the government offers you a rebate of prior taxes paid, it's rational and in your self interest to accept it, even if you do not think the program providing it should exist.
45.
▲
by
rphlx
8y ago
I certainly agree with the top half of your post but I believe the bottom is mischaracterizing Rand. As far as I know she did not wish to form a violent authoritarian state a la Lenin to "plan" society into a certain pattern. She
46.
▲
by
rphlx
8y ago
> Who you are is almost entirely contained within your genes, with a minority contribution from enviroment and parents and schooling. Nature won the debate It would be more precise to say that maximum potential is largely genetic. Watson
47.
▲
by
rphlx
8y ago
According to Compiler Explorer, while 6.0.0 does it, llvm trunk is no longer doing the GVN load optimization. It reverted to using a double load: mov edx, dword ptr [rdi + 4*rcx] cmp edx, dword ptr [rdi + 4*rcx + 4
48.
▲
by
rphlx
8y ago
This is neat but I am still partial to slower but fully generic approaches for syscall filtering, such as BPF. Sooner or later you run out of clever English verbs for the plethora of fixed-function ones.
49.
▲
by
rphlx
8y ago
It is sadly necessary; 30%+ performance regressions from, say, gcc 4 to gcc 6 are not uncommon w/ vector intrinsics.
50.
▲
by
rphlx
8y ago
FWIW Haswell - on which this was benchmarked - does not downclock on AVX2; it just boosts vcore and thermal throttles if the cooling solution can't keep the die below ~100C (which of course, the crappy TIM plus bundled desktop heatsink
51.
▲
by
rphlx
8y ago
Transferring SIMD/FPU regs to/from memory is actually fast - a modest fraction of the typical context switch cost - on modern x86_64 thanks to XSAVE.
52.
▲
by
rphlx
8y ago
In general HN has a strong bias toward Apple over Android RE: security. Many of the points are entirely valid, but it's also true that some important advantages on the Android side (such as those listed above) as often understated or o
53.
▲
by
rphlx
8y ago
In most circumstances it's not clear to me that a >48 hour timeout is really a major impediment to law enforcement in a major metro. Of course, if they arrest like 10,000 people on the same day from a major protest or something it c
54.
▲
by
rphlx
8y ago
> Microsoft's only option is to completely drop the root cert, right? So there's no real non-nuclear option... In small-scale disputes MS (and other browser vendors) would not have to nuke an entire large CA to get their way.
55.
▲
by
rphlx
8y ago
Not to start another DNSSEC melee (as I start another DNSSEC melee..) but for it to be effective we really need browsers to a) be able to tell whether a DNS response was properly DNSSEC signed or not, b) produce some large, scary, red warni
56.
▲
by
rphlx
9y ago
> Avoid: the OpenSSL RNG Is that just historical - i.e. a tiny chance somebody is still using the broken Debian version from a decade ago - or is there actually something still insecure, or at least suspicious, even in 1.1.0+? I ask only
57.
▲
by
rphlx
9y ago
Indeed. If/When another major conflict comes to the developed world, you better believe major cloud DCs will be pretty high up on the cyber and (if it comes to it) kinetic target lists. Never have so few facilities been relied upon for
58.
▲
by
rphlx
9y ago
> Windows as a separate company probably cannot make it long term. That is surely overstating it, at least for definitions of "long" meaning <= 20 years. If you assume that Windows is more or less "done" their engi
59.
▲
by
rphlx
9y ago
> the only target audience for that consists of Radar techs walking around in front of hugeass antennas And perhaps US diplomats in Cuba.
60.
▲
by
rphlx
9y ago
Closed source disk encryption products: Not Even Once.
More ›