Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sporksmith
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
1.
▲
by
sporksmith
7mo ago
I thought this must be a joke at first. "Glaze" is in pretty heavy use as recent slang for "when someone excessively praises another person in a way that feels over-the-top." https://creativesimiles.com/
2.
▲
by
sporksmith
3y ago
After the "trust nothing" security model in the rest of the article I found it funny to complain that a hardware kill switch is useless when you can just trust the software to do it for you > The switch is useless in either of
3.
▲
by
sporksmith
3y ago
Cool, will be interested to see how this develops! tokio's loom framework has been a big help in testing some tricky concurrency code I've worked on. Folks interested in this space might also be interested in the system I spend mo
4.
▲
by
sporksmith
4y ago
> if you're allowed to look inside the process, which would be for similar reasons to why you're allowed to look inside a configuration file belonging to the user On recent Linux distros, by default you can't ptrace (or re
5.
▲
by
sporksmith
4y ago
Folks are saying to practice your fall-possibility-sport where a fall won't hurt as much. I say take it a step further and do focused practice of falling and rolling intentionally. There are a lot of videos on YouTube about how to do s
6.
▲
by
sporksmith
4y ago
Yes. Though I'm not sure I see the connection to the OP...? The example I'm most familiar with, because I work on it, is Shadow. We used ptrace for a bit but now use seccomp. https://github.com/shadow/shadow&#
7.
▲
by
sporksmith
4y ago
In my journaling I realized the process of writing was valuable, but I rarely referred back to anything. So for personal / stream of consciousness things I either write on paper and put it in the shred pile, or to something like an eph
8.
▲
by
sporksmith
4y ago
True, but it'd be difficult to both make arrests based on info learned from having broken Tor, and keep it secret that they'd broken Tor. It's possible by obscuring how they got information (e.g. via parallel construction),
9.
▲
by
sporksmith
4y ago
There is a bit of a heuristics-based arms race here for sure. https://blog.torproject.org/malicious-relays-health-tor-netw... talks about this
10.
▲
by
sporksmith
4y ago
This article is from 2013, and notes a huge increase in tor clients . While the article notes we weren't able to determine the cause of the sudden increase, the primary hypothesis put forward was that it was a true growth in usage due
11.
▲
by
sporksmith
4y ago
UDP is currently not supported, but we're working on a design for it now https://gitlab.torproject.org/tpo/core/torspec/-/blob/main/p...
12.
▲
by
sporksmith
4y ago
The spec documents linked from there are the most canonical documentation, though the gitweb link will probably be deprecated soon in favor of gitlab. https://gitlab.torproject.org/tpo/core/torspec As always it&#x
13.
▲
by
sporksmith
4y ago
Probably some, but the Tor network is designed to be robust to that. The community does a lot of active monitoring to kick out misbehaving relays. "Misbehaving" includes running multiple relays without correctly setting the family
14.
▲
by
sporksmith
4y ago
Tor dev here! We're super excited about this launch! The lead dev on this feature, who also wrote the blog post, is taking some well deserved r&r after getting this feature out the door. I was somewhat tangentially involved (I work
15.
▲
by
sporksmith
4y ago
... No? Could you be more specific? Disclaimer: am a Tor developer and employee.
16.
▲
by
sporksmith
5y ago
Folks interested in the state of the art of this kind of DPI evasion might want to check out obs4, which is a "look-like nothing obfuscation protocol", and the default pluggable transport for connecting to tor bridges from places
17.
▲
by
sporksmith
5y ago
The original Mario Bros arcade game had crab enemies: https://www.youtube.com/watch?v=FgOAW6lv1qg
18.
▲
by
sporksmith
5y ago
We've started looking into eBPF a bit - IIUC eBPF by itself doesn't give us the ability to service or arbitrarily manipulate the traced process's syscalls. We have recently learned of an interesting technique that dettrace
19.
▲
by
sporksmith
5y ago
For anyone interested in following current development on Shadow, we've been publishing a series of updates. Most recent: https://github.com/shadow/shadow/discussions/1274 The previous update has links b
20.
▲
by
sporksmith
5y ago
Sorry, I'm not well versed in the network model; most of my work has been on the new ptrace-based syscall interposition. That sure sounds like a bug, though. We recently added a discussion section to Shadow's GH repo: https:/
21.
▲
by
sporksmith
5y ago
Shadow developer here! Disclaimer - I joined the project a little over a year ago. I'm not as well versed in some of the related work as my colleagues, but I can take a shot - Mininet looks cool! It looks like Mininet lets programs run
22.
▲
by
sporksmith
5y ago
The in-repo docs have a general walk-through for getting started: https://github.com/shadow/shadow/tree/main/docs . Shadow's primary use-case is simulating the Tor network. Shadow's tor plugin h
23.
▲
by
sporksmith
6y ago
Yup. I just tested ~~the fdroid~~ signal (the non-google-play apk from signal's web site) with orbot (a tor VPN for android) and verified it works correctly for text messaging. As you say, using a bridge should make it difficult for
24.
▲
by
sporksmith
6y ago
(Relatively new) Tor developer here. Yes, unfortunately some sites and such "protection" services block Tor IP addresses to mitigate abuse. While just blocking exit nodes would be sufficient (though still an overly blunt instrumen
25.
▲
by
sporksmith
7y ago
I wonder if OSM has clean extension points for adding this sort of specialized metadata. Might be a nice way to create these kind of specialized geo-databases without having to do as much of your own implementation and hosting.
26.
▲
by
sporksmith
7y ago
Seems like the main flaw in the ones the author labeled "awful" was a geofence policy that limited the top speed on a "bike path", or locked them out of it altogether. Makes it a bit difficult to generalize their conclus
27.
▲
by
sporksmith
14y ago
Makes sense. Thanks!
28.
▲
by
sporksmith
14y ago
> I don't 100% get the band limited signal bit. How does band limiting imply that there's only a single possible reconstruction of the digital signal? I agree that was a little unclear. I think what he's saying is that since humans can'
29.
▲
by
sporksmith
14y ago
Ha! Clever idea, but I hope you're not serious :). The most likely result would be infuriated users, and quite possibly lawsuits.
30.
▲
by
sporksmith
14y ago
That's exactly what Clipperz does :). The main weak point is there's no way for the user to know if the javascript they're downloading is the correct Clipperz javascript, or a trojan'd version that will send my master password and decrypted
More ›