Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ryuuchin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
ryuuchin
9y ago
Multiple processes are used to implement sandboxing everywhere not just on Linux. Just be careful with using chrome://flags to enable/disable certain things. First not everything will have an appropriate flags option. Secon
32.
▲
by
ryuuchin
9y ago
Isn't the answer here to just run the latest stable version where the impact of field trials would be minimized? Even the stable version will probably have features/field trials in the command line if you start looking at it for
33.
▲
by
ryuuchin
9y ago
Auto brightness can help when it comes to avoiding burn-in. Using max brightness all the time with static things on the screen is a recipe for burn-in even on IPS displays.
34.
▲
by
ryuuchin
9y ago
Reminds me of the quote by George Steinbrenner[1]. "If you do something nice for somebody, and more than just the two of you know about it, maybe you're doing it for the wrong reason" [1] https://tree.mindbloom.com
35.
▲
by
ryuuchin
10y ago
Most of them are just built into Windows now and are accessible through both the registry[1] and at runtime[2][3]. The latter requires recompiling with source code changes but the former can be applied to any application. The EMET mitigati
36.
▲
by
ryuuchin
10y ago
I didn't see this mentioned in the blog posts but I believe Edge also has win32k filtering[1] to reduce the kernel attack surface as well (added in the AU). This is different from the win32k lockdown that Chrome uses which completely
37.
▲
by
ryuuchin
10y ago
One of my biggest gripes is not being able to use extensions in private/incognito mode.
38.
▲
by
ryuuchin
10y ago
The AppArmor profile provided by Ubuntu/Distro is likely not going to be very restrictive. Also modern versions of Office already run in a sandbox on Windows (AppContainer?) so how much are you really gaining?
39.
▲
by
ryuuchin
10y ago
The way to work around this is to either use a method which blocks until seeded (getrandom) or to simply seed it yourself before using it.
40.
▲
by
ryuuchin
10y ago
I believe the minimum considered secure for standard DHE is 2048 bits. Qualys will label 1024 bit DHE exchanges as WEAK. 256-bit+ ECDHE is also considered secure on the standard curves (x25519, secp256r1, secp384r1).
41.
▲
by
ryuuchin
10y ago
Now if only I could use extensions in private browsing mode...
42.
▲
by
ryuuchin
10y ago
> That's only if people agree with your ideology. You don't even have to do that. It behaves exactly the same as ABP if you use the same filter lists. It's just also happens to be more efficient than ABP.
43.
▲
by
ryuuchin
10y ago
The only reason for still using ABP is because you haven't heard of uBlock.
44.
▲
by
ryuuchin
10y ago
> When was the last time there was a reliable, public Chrome exploit with a sandbox escape? The only one I can think of was the Hacking Team exploit, which used a Windows kernel 0day to escape the sandbox. Don't forget that it'
45.
▲
by
ryuuchin
10y ago
> A 30 second glance at the source code makes it looks like this exploit pivots to attacker-controlled memory on the heap, and spawns a thread using kernel32.dll. As EMET has hardening against attacks like this, I am curious if this expl
46.
▲
by
ryuuchin
10y ago
This may be an unpopular opinion here but if the TorBrowser folks cared about security they should switch to a Chromium based browser. The sandbox provided by it would be robust and well tested as it's used in Chrome. I don't see
47.
▲
by
ryuuchin
10y ago
Well traditional news media is peer reviewed to a certain extent and will publish corrections.
48.
▲
by
ryuuchin
10y ago
Well you can at least argue that traditional news media does hold itself to certain journalistic standards (I'm talking news articles, not opinion pieces). I think an issue we have with getting news from places like FB is that (I think
49.
▲
by
ryuuchin
10y ago
> Actually it is extremely easy. It is easy to tell if an article has an angle or as not When I'm talking about bias it's something which would not be provable based on one article. I'm talking about something which would
50.
▲
by
ryuuchin
10y ago
Nate Silver made the point on twitter that when you control for race and education the effect that you see in the counties that used paper ballots completely disappears[1][2][3]. Clinton's lead continues to grow in the popular vote but
51.
▲
by
ryuuchin
10y ago
The GFW is apparently quite sophisticated[1] and likely uses machine learning among other things such as TLS side channel attacks. [1] http://blog.zorinaq.com/my-experience-with-the-great-firewal...
52.
▲
by
ryuuchin
10y ago
I'm not sure how relevant this is to this story but for news in general something which I found extremely helpful in my life has been actually learning how to digest the news (media) through a course that was taught at university (news
53.
▲
by
ryuuchin
10y ago
> poor subset of the EMET GUI over the IFEO parameters. Is it really though? I guess it depends how much value you place on the EAF and ROP protections. Personally I wouldn't place too much weight on them.
54.
▲
by
ryuuchin
10y ago
> basically, Windows 10 doesnt use EMET You can still use EMET on Windows 10 though. I believe the main takeaway from the article should be that they're discontinuing it. You can get almost all of the EMET provided mitigations exce
55.
▲
by
ryuuchin
10y ago
I think the featureset that Windows 10 provides is good enough as an alternative (see my top level comment[1]). EAF was never that useful because it uses debug registers and the ROP protections have been "replaced" by CFG (contro
56.
▲
by
ryuuchin
10y ago
You can control almost all EMET mitigations except for the ROP and EAF protections through IFEO (Image File Executable Options). There's also the cert pinning but I believe that was only useful for IE. There are also other Windows 10
57.
▲
by
ryuuchin
10y ago
I believe CABAC in h265/HEVC should be faster than CABAC in h264/AVC. If you produced CABAC for h264 and h265 with all things being equal you should actually gain in decoding speed moving to h265.
58.
▲
by
ryuuchin
10y ago
It'll be interesting to see the adoption rate of h265/HEVC and whether it will actually take off since the licensing costs seem to be prohibitively expensive[1]. AV1 may wind up being the defacto winner because of this even if it
59.
▲
by
ryuuchin
10y ago
The workarounds are reliant on filter lists to remain up to date. You can also just block websocket completely by adding the following to your filters (provided you're not using websockets for anything else): ||*$websocket,importa
60.
▲
by
ryuuchin
10y ago
uBlock Origin provides a websocket companion[1][2] plugin for blocking websocket requests in Chrome. [1] https://github.com/gorhill/uBO-WebSocket [2] https://chrome.google.com/webstore/detail/
More ›