Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
some_furry
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
some_furry
12d ago
I mean this with absolutely no shade but: That was objectively good advice. (Not to detract from anyone's cleverness or hard work.)
2.
▲
by
some_furry
12d ago
Ah, right. That was clearly tongue-in-cheek and easily forgettable, not an actual accusation on either party. I've added an important clarification in case anyone else missed the rest of the prose that discussed how this was entirely
3.
▲
by
some_furry
12d ago
You walked back putting an accusation of evil in my mouth while following up with warning me not to make an accusation I would not make to begin with. Incredible.
4.
▲
by
some_furry
12d ago
You can write algorithms that leak every bit of your secrets, trivially. The npm "elliptic" package does this. Daniel Bleichenbacher has tested several packages' timing leakage in Rooterberg that are easily exploited: https:
5.
▲
by
some_furry
12d ago
> Nobody was evil you just tried to rely on a property that V8 never promised. Tell me you didn't read past the headline without telling me you didn't read past the headline.
6.
▲
by
some_furry
13d ago
Requiring manual key verification is a bad design that doesn't scale or benefit most people.
7.
▲
by
some_furry
14d ago
If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up. It's already the case today (and has been for years) that you don't need to give strangers your phone number to ch
8.
▲
by
some_furry
14d ago
> Together with how low a profile they keep, I'm not convinced they aren't a honeypot. You don't need to be convinced of such things. In fact, it's better if technical people remain skeptical and check . I did in 202
9.
▲
The V8 JavaScript Runtime Undermined My Constant-Time JavaScript Library
(soatok.blog)
20 points
by
some_furry
14d ago
|
11 comments
10.
▲
Megolm Key Confusion Vulnerability
(lotte.chir.rs)
3 points
by
some_furry
15d ago
|
0 comments
11.
▲
by
some_furry
16d ago
Trying to position the conversation as "we're on the same team, trying to figure the problem out together" also helps a lot of the intensity of these conversations melt away.
12.
▲
by
some_furry
1mo ago
> Citizens United is a very sound ruling. Corporations only have the powers granted to them by the state. Contributing to politics need not be one of them.
13.
▲
by
some_furry
1mo ago
> About the post you linked, see [1] and [2], which makes me question both whether that is an actual vulnerability (Signal, the messenger recommended by the author, also didn't have that check, and it's addition is absent from
14.
▲
by
some_furry
1mo ago
Every time Meta does something, it makes me yearn for the day they lose that $1.4 Trillion lawsuit and declare bankruptcy.
15.
▲
by
some_furry
2mo ago
I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.
16.
▲
by
some_furry
2mo ago
I wouldn't worry about too many mathematicians adopting the "even AI couldn't solve it" attitude. Business folks riding the hype train? Maybe.
17.
▲
by
some_furry
2mo ago
> One attack weakens HAWK, a post-quantum cryptography cipher candidate. I don't trust these PQC things one bit. I'll use them in combination with a strong clasically-resistant cipher (in so-called hybrid encryption modes), but
18.
▲
by
some_furry
2mo ago
https://codeberg.org/awebo-chat/awebo
19.
▲
by
some_furry
2mo ago
To be clear: This isn't a technical discussion, it's a political one. While your point is valid on its own merits, it isn't relevant here.
20.
▲
by
some_furry
2mo ago
It's a mix of grifts, gaffes, and Project 2025 .
21.
▲
by
some_furry
2mo ago
I don't personally have a horse in this race, but if you want to accurately predict the next step: Start with the outcome you believe will be the most in line with the spirit and traditions of the open source community. This is precise
22.
▲
by
some_furry
2mo ago
It's not that silly of a blogpost. See: "permanent underclass", a term popular among people that believe that an Artificial General Intelligence (AGI) is imminent and desirable .
23.
▲
We cannot wait for better post-quantum signature algorithms
(blog.cloudflare.com)
9 points
by
some_furry
3mo ago
|
0 comments
24.
▲
by
some_furry
3mo ago
You're all over the place except where the discussion was actually taking place.
25.
▲
by
some_furry
3mo ago
What does a work of fiction have to do with whether two distinct government entities are the same thing or not? That's beyond moving goalposts. Just take the L, dude.
26.
▲
by
some_furry
3mo ago
NIST does a lot of things that have nothing to do with computer security! Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?
27.
▲
by
some_furry
3mo ago
Didn't the FDA used to recommend pasteurizing milk?
28.
▲
by
some_furry
3mo ago
> You're argument is that I shouldn't think of NIST as a patsy for the NSA, Incorrect. My argument is that they aren't the same entity. The thing you said is a whole different argument. "I like waffles" "So
29.
▲
by
some_furry
3mo ago
> In the past NSA has weakened encryption standards, for example NSA madified DES standard. They made DES more secure against differential cryptanalysis (a method that was classified at the time DES was being designed). Sure, the whole &
30.
▲
by
some_furry
3mo ago
> But if I am honest, NIST recommending it at all is enough to suspect it of being compromised. NIST isn't the NSA and doesn't have the NSA's goals in mind. They are briefed by NSA on some matters, sure, but they're n
More ›