Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
spr-alex
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
spr-alex
2mo ago
The last 3-4 years have had tax obstacles that have motivated funded models over bootstrapped businesses: 1) the jobs act introduced a toxic R&D code from 2022-2025 2) tariffs with no reasonable means of manufacturing domestically and i
2.
▲
Hacker Fantastic and team report a pre-auth remote root exploit against openwrt
(twitter.com)
3 points
by
spr-alex
3mo ago
|
1 comments
3.
▲
by
spr-alex
3mo ago
These are serious security researchers and this is almost certainly a widespread vulnerability affecting mainline openwrt.
4.
▲
by
spr-alex
5mo ago
how can i upvote this twice?
5.
▲
by
spr-alex
5mo ago
this is not an ocassional bug this is still the system design today. privacy gateways upstream of big tech are the way to go on this because privacy isn't their profit center
6.
▲
by
spr-alex
6mo ago
Adding to your comment a similar letter was published as recently as September 2025 https://support.apple.com/en-us/122234 "we have never built a backdoor or master key to any of our products or services and we ne
7.
▲
by
spr-alex
6mo ago
So once again since I think I am not explaining it well, it might take a long time to go from factoring 21 to 35, and a long time from 35 to anything bigger, but from that point on the engineering has scaled up to the point that progress is
8.
▲
by
spr-alex
6mo ago
We are talking to different things. There is linear engineering progress for getting from 32 bits to 256 bits being factored is my claim. If we want to talk RSA the engineering journey from factoring 21 to 35 is big, because it requires cre
9.
▲
by
spr-alex
6mo ago
My read of this post is that there's nuance here and that by the time we see 32-bit integers being factored then the roadmap to 256 bit integers can be counted in months on ten fingers rather than being a decade out. The underlying sca
10.
▲
by
spr-alex
6mo ago
Beware the Ides of march: this is 1 of 2 cryptographic doom papers that was released this week. This google paper with Babbush, Gidney, Boneh is authoritative. And we also have another with Preskill and Hsin-Yuan Huang (widely cited for cla
11.
▲
by
spr-alex
6mo ago
I was just very naive at 18 about program analysis. I haven't lost my imagination though. I was a self-taught IOI gold division competitor. I thought every problem had an algorithm. It doesn't work like that. Program analysis is c
12.
▲
by
spr-alex
6mo ago
I interned for the author at 18. I assumed security testing worked like this: 1. Static analysis catches nearly all bugs with near-total code coverage 2. Private tooling extends that coverage further with better static analysis and dynamic
13.
▲
Show HN: Vibed Linux Rust BitChat Client Using Bluez
(github.com)
1 points
by
spr-alex
1y ago
|
0 comments
14.
▲
by
spr-alex
1y ago
Thanks for the post!
15.
▲
by
spr-alex
1y ago
we've happily running on routers on the pi5/cm5 since last year ( https://www.supernetworks.org ) and openwrt support is there as well.
16.
▲
by
spr-alex
1y ago
We're adding support to gvisor for container plugins, it's a reasonable approach for limiting the rich attack surface on linux
17.
▲
by
spr-alex
1y ago
on a related note the search space for https://www.qdayprize.org/curves seems far too small to be a meaningful contest and the rules dont seem to address how they judge the validity of the "quantumness" when sifti
18.
▲
by
spr-alex
1y ago
there's been advances, at least for RSA work from håstad, ekerå, gidney has brought this to O(N) qubits, on the runtime the papers are a little bit harder to read as they differ in notation but O(log(N)^3) runtime is what i recall. its
19.
▲
by
spr-alex
1y ago
blog author mentioned in the article here, previously submitted to hn at https://news.ycombinator.com/item?id=44497622 blog post here, https://www.supernetworks.org/pages/blog/agentic-insecurity-..
20.
▲
by
spr-alex
1y ago
i am not using it as a pejorative here, I am pretty sure that is the case for this code base, as every block has a comment describing the code that immediately follows also i do not doubt jack's cryptography and encryption understandin
21.
▲
by
spr-alex
1y ago
bitchat has a trivial MITM flaw with the favorite's identity system. i wrote up my thoughts around vibe coding cryptographic security and rolling a new protocol
22.
▲
MitM Flaw in Bitchat: Identity Is a Bitchat Challenge
(supernetworks.org)
7 points
by
spr-alex
1y ago
|
6 comments
23.
▲
by
spr-alex
1y ago
Very good
24.
▲
by
spr-alex
1y ago
I made a CTF challenge 3 years ago that proves why local devices are not so protected. exploitv99 bypasses PNA with timing as the other commentor points out. https://github.com/adc/ctf-midnightsun2022quals-writeups
25.
▲
by
spr-alex
1y ago
The existing PNA is easily defeated for bugs that can be triggered with standard cross origin requests. For example PNA does nothing to stop a website from exploiting some EOL devices I have with POST requests and img tags. This is a much b
26.
▲
by
spr-alex
2y ago
i think the opposite, the error accumulation thing is basically the daily experience of using LLMs. As for the premise that models cant self correct that's not the argument i've ever seen, transformers have global attention across
27.
▲
by
spr-alex
2y ago
maybe i understand this a little differently, the argument i am most familiar with is this one from lecun, where the error accumulation in the prediction is the concern with autoregression https://drive.google.com/file/
28.
▲
by
spr-alex
2y ago
we've got a tailscale integration that takes care of the security concerns. set policy to decide what can talk out to the tailscale node and what the tailscale gateway is granted access to. this is especially important when you can&#x
29.
▲
by
spr-alex
2y ago
yeah, nobody can claim scaling without having the error to prove it. SPAM + coherence time + gate fidelity are the limiting factors to scaling, not the concept of an idea of how to build it at scale :-)
30.
▲
by
spr-alex
2y ago
Given that Microsoft has been a heavy research collaborator ( Atom and Quantinuum), is there a possibility that the cross pollination would make it harder to deliver a farcical majorana chip since microsoft isn't all in on their home r
More ›