Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
taway2012
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
taway2012
13y ago
Pretty cool. Related: anybody has ideas to achieve the following? display the stdout of a program on the console and also write a gzipped version of stdout to a file. I currently jump through some hoops (involving two term windows) to achie
32.
▲
by
taway2012
13y ago
The XKCD panel included below point 4 seems misguided to me. Asking for the admin password prevents AUTOMATED, DRIVE-BY installs of device drivers etc. Only responding since people seem to take XKCD's opinions on tech seriously.
33.
▲
by
taway2012
13y ago
Yeah, I looked into that. There doesn't seem to be a way to have a "hidden" extension whose URL isn't public, but which can be downloaded without signing into a Google account. That sucks for people in my network who are
34.
▲
by
taway2012
13y ago
I am displeased by this change. Although the Firefox version of my extension is more work to develop, I will be pouring most of my resources into that in the future. I currently have a product that uses a Chrome extension to work. I am priv
35.
▲
by
taway2012
13y ago
I'm uncomfortable about the opacity of BTsync's privacy architecture. AFAIK even the protocol isn't documented. The code obviously isn't open source. I wouldn't use it sync anything except Truecrypt volumes. :)
36.
▲
by
taway2012
13y ago
I think you've probably misunderstood. The mere loading of the widget sends a signal to Facebook that you visited the shoes page. You don't have to interact with the widget for the info to be sent. Ghostery blocks the widget fro
37.
▲
by
taway2012
13y ago
Hi moxie! First off, I agree with what you said. But I had a question about your observation. Don't the same problems apply to any autoupdating system (including smartphones, tablets and computers)? I've posted once before asking
38.
▲
by
taway2012
13y ago
I read the book a while back. This is very good review of the book. Read the book if you can. If not, read this review at least. I'm planning to re-reading it to see if I agree more or less with the book now. I also found "Moral M
39.
▲
by
taway2012
13y ago
Will blocking third party cookies prevent this? Or is this a server-to-server transfer of regular (second-party?) cookies?
40.
▲
by
taway2012
13y ago
There is such a thing as a B-corporation. https://en.wikipedia.org/wiki/Benefit_corporation "A benefit corporation or B corporation is a corporate form in the United States designed for for-profit entities that wa
41.
▲
by
taway2012
13y ago
Remember the huge controversy that erupted when Intel wanted to put a program-readable unique serial number into its CPUs (in 1999)? https://www.schneier.com/essay-187.html http://slashdot.org/story/00&
42.
▲
by
taway2012
13y ago
They can split the program into two parts. The "UI" part and the "transport" part. The UI part will be in charge of converting plaintext into ciphertext and vice versa. ciphertext will be handed off to the transport modu
43.
▲
by
taway2012
13y ago
Replying to myself since I can't edit my reply now. This is the link to the TaoBao Tengine doc describing the feature: http://tengine.taobao.org/document/http_ssl.html My memory was faulty: they have a way to get
44.
▲
by
taway2012
13y ago
My two cents is that requiring the ability to snoop on a running process is a significant extra hurdle compared to simply reading the filesystem. Especially for virtual machines which almost everybody is running on these days. An attacker c
45.
▲
by
taway2012
13y ago
The TaoBao version of nginx has a patch to send the private key through the network to the server. IIRC. In that case, it won't be lying around in plaintext on your server's disk. I will edit this post with a link if I can find it
46.
▲
by
taway2012
13y ago
OK. FWIW, I do not consider credit card number theft to be a big deal (I just lost my wallet a couple of weeks ago). I know I am probably in the minority on this. That said, they should have an option to pay by paypal to outsource this risk
47.
▲
by
taway2012
13y ago
You've written the same thing twice in this thread, without giving specifics. Which Linode specific security policies caused you what specific "grief"? And what provider do you use now? I know (1) they were late to the two-fa
48.
▲
by
taway2012
13y ago
They handle 3072-bit keys now. http://shop.kernelconcepts.de/product_info.php?cPath=1_26&pr...
49.
▲
by
taway2012
13y ago
You should compared it to cold-brewed coffee and report back. :)
50.
▲
by
taway2012
13y ago
AFAIK, Chrome "certificate pinning" may not exactly be what you think "certificate pinning" means. It should be more precisely called "certificate authority pinning". What it means is that Chrome will not trust
51.
▲
by
taway2012
13y ago
Thanks, I think I understand now. The chip verifies the update using the public key present in the blob. But before doing so, it checks the public key against some whitelist of valid public keys. The private key used to sign the blob is nev
52.
▲
by
taway2012
13y ago
Maybe I'm missing something: the public key is present in the microcode update blob (according to the article), and CPU itself must have corresponding private key within it. The sender uses the public key to sign, the receiver uses the
53.
▲
by
taway2012
13y ago
Can somebody explain what extra security they gained by using an RSA-based signature as opposed to a straight-up HMAC (with the secret key burned into the CPU)?
54.
▲
by
taway2012
13y ago
I don't think this is a big problem. Just wanted to chime in with the opposing view. We already have legal structures to account for people who are unable to provide informed consent (e.g., unconscious person, dementia sufferer etc):
55.
▲
by
taway2012
13y ago
Short answer: No. Longer answer: see below. http://www.thehindubusinessline.com/opinion/are-high-vegetab... "According to Government data, India’s onion output in 2012-13 at 16.65 million tonnes, wasn’t much below
56.
▲
by
taway2012
13y ago
Hmm, check out 'Autopilot' by Andrew Smart. It has some sections about equilibrium etc. And 'On Intelligence' by Jeff Hawkins (very under-rated book imho). Good luck!
57.
▲
by
taway2012
13y ago
This site uses the 'Globalsign Organization Validation CA - G2' certificate, which I've removed from my trust list. It's is a certificate that can be theoretically used to sign any domain (i.e., it's MITM-capable).
58.
▲
by
taway2012
13y ago
As other said, Keepass2 works under Mono. Even better, Keepass2 is included in the Ubuntu official repos. And it runs pretty well. Autotyping your password into other programs also works. I really like Keepass2. sudo apt-get install kee
59.
▲
by
taway2012
13y ago
OK, that's a good point, but IMHO the question still stands. If Cantonese is as different from Mandarin as French is from Italian (though, IIRC, both are Latin languages), then why are they still called dialects? I see from the rest of
60.
▲
by
taway2012
13y ago
Hmm, if Cantonese is as different from Mandarin as Spanish is from English, why do you still call it a "dialect" of Mandarin?
More ›