Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
some_furry
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
some_furry
6mo ago
No, but they decide the moderation policy that incentivizes the content produced (by nature of selecting which users feel comfortable using their product and which do not). For example, I do not feel comfortable using the same platform as p
92.
▲
by
some_furry
6mo ago
> How can you falsely revoke a certificate? If you don't have the private key on hand to issue a revocation, your next best bet is to find a parser bug that convinces some subset of user agents that the valid certificate you don&#x
93.
▲
by
some_furry
6mo ago
Can you explain a bit more what you mean by "secure" in the context of "actual revocations"? The oxymoronic nature isn't self-evident enough for me to catch your intended meaning before my first cup of coffee.
94.
▲
by
some_furry
6mo ago
Which governments are you thinking of?
95.
▲
by
some_furry
6mo ago
Another thing that I think Europeans often fail to take into consideration is scale. USA: 9,147,590 km^2 Switzerland: 41,295 km^2 That's a factor of 221.5 to 1.
96.
▲
by
some_furry
6mo ago
What? Quantum computers don't break SHA256, nor would this attack be "reasonably attributable" to a SHA256 break. In fact, if you have funds in a wallet that has never spent a transaction before (only received), it's s
97.
▲
by
some_furry
7mo ago
The Other Side = the "afterlife" apparently
98.
▲
by
some_furry
7mo ago
No. Getting a crypto module validated by FIPS 140-3 simply lets you sell to the US Government (something something FedRAMP). It doesn't give you better assurance in the actual security of your designs or implementations, just verifies
99.
▲
by
some_furry
7mo ago
And the people who repeat such statements uncritically to their reports will also get mildly annoyed when they have no Earthly clue what that actually means.
100.
▲
by
some_furry
7mo ago
> "Bloats record sizes" > - ECC sigs can be sent in a single packet. It's 2026. If you're deploying a cryptosystem and not considering post-quantum in your analysis, you'd best have a damn good reason. ECC sig
101.
▲
by
some_furry
7mo ago
I wonder if this is the start of a trend or just a one-off?
102.
▲
by
some_furry
7mo ago
It starts with you. Doesn't matter if others won't. You can't expect anything to chamge if you, yourself, are not willing to change.
103.
▲
by
some_furry
7mo ago
There are dozens of us! But, yeah, anti-fingerprinting is still a useful signal if less people do it. So more people should do it; especially if they're less likely to be targeted. "More haystack" makes their job harder.
104.
▲
by
some_furry
7mo ago
Good reporting, but this has always been Meta's M.O. so I'm really not surprised. The sooner we collectively stop trusting them (and maybe even actively campaign to have the U.S. government meaningfully regulate them), the better.
105.
▲
by
some_furry
7mo ago
I guess I'll have to go out of my way to refer to their shitty product as "Microslop Copilot" then. What are they going to do? Ban me from using their operating system?
106.
▲
by
some_furry
8mo ago
Usually HN only auto-edits on first submission. If you go in and undo it manually as the submitter, you can force it to read how you intend.
107.
▲
Cryptography Engineering Has an Intrinsic Duty of Care
(soatok.blog)
8 points
by
some_furry
8mo ago
|
0 comments
108.
▲
by
some_furry
8mo ago
Daria was ahead of its time.
109.
▲
by
some_furry
8mo ago
I still dislike almost everything on that list (GitHub is still the least bad offender so far ).
110.
▲
by
some_furry
8mo ago
A disappointing response. Like, yeah, it checks all the PR speak boxes, but the substance is disappointing. See https://soatok.blog/2026/02/17/cryptographic-issues-in-matri...
111.
▲
by
some_furry
8mo ago
https://soatok.blog/2026/02/17/cryptographic-issues-in-matri...
112.
▲
by
some_furry
8mo ago
https://soatok.blog/2026/02/17/cryptographic-issues-in-matri...
113.
▲
by
some_furry
8mo ago
> It explains why the implementation can produce a fixed secret under malicious input, and that there’s an RFC saying “don’t implement it like this” but not what effect it has on the security of the system. https://soatok.blog
114.
▲
by
some_furry
8mo ago
I'm not worried about "losing" in a merge transaction. I'm worried about causing confusion like https://news.ycombinator.com/item?id=46990110 :)
115.
▲
by
some_furry
8mo ago
No, it isn't. Dang moved all the comments from https://news.ycombinator.com/item?id=46979742 to this thread so now it's confusing.
116.
▲
by
some_furry
8mo ago
Dang, I think this might've been a mistake. Taggart's blog post was their opinion on Discord alternatives with an arbitrary ranking. Mine was about the whole notion of asking for alternatives to Discord being a bad question to ask
117.
▲
by
some_furry
8mo ago
The part that was "alarmingly cavalier" was when you admitted to knowing about these problems for years and not fixing them or telling the ecosystem of competing clients about them so they could mitigate their risk. https:/
118.
▲
by
some_furry
8mo ago
https://github.com/zulip/zulip/issues/6096 Still not implemented.
119.
▲
by
some_furry
8mo ago
I dunno, how does it fare with graph databases?
120.
▲
by
some_furry
8mo ago
> For me the point is that if you feel uncomfortable over something that is widespread and considered normal social etiquette, it's on you to deal with feeling uncomfortable, and you can't really expect everyone else to change
More ›