Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
strstr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
26 ms
·
241.
▲
by
strstr
8y ago
Z-list probably isn't illegal (despite it being pretty disheartening).
242.
▲
by
strstr
8y ago
Problem is that it’s easy to correlate dna data against each other and infer who you are (assuming some small number of relatives have also used the service). In fact, a find your relatives service is built in.
243.
▲
by
strstr
8y ago
Enclaves (e.g. SGX) get you there without the need for fancy math. And you get to maintain normal computation (i.e. x86). Enclaves have the downside of being a bit of a pain to use. But hell, FHE isn’t any easier.
244.
▲
by
strstr
8y ago
At first I gave these houses the benefit of the doubt. Maybe they look tacky so the interior could be logical. Then I cracked up looking at the turret in [0]. [0] http://mcmansionhell.com/post/149472892236/houston-
245.
▲
by
strstr
8y ago
Cool idea, seems like a mess for side channels.
246.
▲
by
strstr
8y ago
Only sort of fringe, a few comments link to Derek Lowe's blog post which posits an infectious cause (a different strain of herpes iirc): https://news.ycombinator.com/item?id=17444515
247.
▲
by
strstr
8y ago
I'm not really familiar with people referring to Washington State University as Washignton State. WSU is common. Wazzu is common. Washington State not so much.
248.
▲
by
strstr
8y ago
Feral cats aren't people?
249.
▲
by
strstr
8y ago
Relatedly: Anna's Hummingbirds' winter range has changed (likely) because of home feeders and urbanization. [1] http://rspb.royalsocietypublishing.org/content/royprsb/284/1...
250.
▲
by
strstr
8y ago
What’s the right way to flag as spam?
251.
▲
by
strstr
8y ago
Isn't this why MOVSS interrupt shadowing exists?
252.
▲
by
strstr
8y ago
This is reminiscent of the #TF CVE from last year: https://bugzilla.redhat.com/show_bug.cgi?id=1464473 ... Except not requiring a buggy instruction emulator. Traps and MOVSS shadowing (and any other temporary state after a
253.
▲
by
strstr
8y ago
Sounds like the university doesn’t want the liability. Students can just do things anyway, so long as it’s not under the university’s purview. Annoying, but not that bad.
254.
▲
by
strstr
9y ago
Wait, what? You only have to press up and down on that Sonic 3 level? That’s BS. Someone call seven year old me and tell them that Sonic 3 is possible!
255.
▲
by
strstr
9y ago
Just going to give a shout out to the openness of the Supreme Court oral arguments. You can find them directly from the Supreme Court ( https://www.supremecourt.gov/oral_arguments/argument_audio/2... ) or in Podcast
256.
▲
by
strstr
9y ago
I recommend checking out the snowy plover before they disappear from the west coast! https://en.m.wikipedia.org/wiki/Snowy_plover
257.
▲
by
strstr
9y ago
1) Modern LBR might solve this. LWN has a summary (though I've only skimmed this): https://lwn.net/Articles/680996/ 2) Not sure for this, though I can think of some crappy hacks: --A) Timed LBR mentioned in t
258.
▲
by
strstr
9y ago
Perf counters are super useful. On linux the perf tool (and perf event api) make these usable: https://perf.wiki.kernel.org/index.php/Main_Page The counters vary per Intel CPU, though the most useful ones are universal
259.
▲
by
strstr
9y ago
Cloud providers should already be concerned about rowhammer related DoS anyway, and be mitigating/preventing rowhammer through other means (e.g. buying ram that doesnt suck).
260.
▲
by
strstr
9y ago
There’s a pretty straightforward mitigation to this: only allow enclaves from software authors you trust. The kernel does not have to allow usermode to run enclaves, which is very much by design.
261.
▲
by
strstr
9y ago
This could also be used to estimate how many people (with one of those devices) are actually watching your ad.
262.
▲
by
strstr
10y ago
(Echoing Bonzini) You don't need it to be in the kernel for modern guests (performance wise), but you still need it.
263.
▲
by
strstr
10y ago
Current implementation has everything in userspace. The perf hit hasn't been compelling enough to make even minor perf improvements. (Yet-another-Googler: I worked on this and spoke about it at KVM Forum)
264.
▲
by
strstr
10y ago
Some of the tools have been: https://github.com/google/syzkaller
265.
▲
by
strstr
10y ago
ECC is one of the mitigations, as well as increased refresh rate. The 'best' solution is better ram: some vendors are more vulnerable than others.
266.
▲
by
strstr
11y ago
TXT's interactions with SMM are pretty broken [1]. For example, TXT doesn't (can't) validate SMRAM. This exploit still requires ring 0, which, hopefully, the code running in TXT doesn't give access too willy nilly. [1]
267.
▲
by
strstr
11y ago
The whole "ring-2" thing is misleading. Root to SMM doesn't imply a VM escape. Most hypervisors don't even implement APIC relocation properly (I believe KVM fixes it to 0xfee00000). Even if APIC were relocatable in a gue
268.
▲
by
strstr
11y ago
The APIC's registers are an unusual form of per core black magic. As far as I know, no other memory addresses behave in the same way -- visible and reacting only to that specific core. It's unsurprising that Intel initially didn&#
269.
▲
by
strstr
12y ago
I'm guessing the study from 2007 is a bit stale now. Intel/AMD/... have almost certainly been trying to decrease the penalty for context switches. I'm curious how much they've changed over time.
270.
▲
by
strstr
14y ago
This could be intentional, as it may increase his peripheral vision through the Eye Glass.
More ›