Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
timmclean
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
timmclean
12y ago
oh god, hopefully not
32.
▲
by
timmclean
12y ago
It shouldn't affect end-to-end encryption, because those keys should only be generated at the endpoints (i.e. the users' devices, probably not running FreeBSD). It could affect TLS, etc, however.
33.
▲
by
timmclean
12y ago
Do you have HTTPS Everywhere installed? Their JavaScript is hosted on HTTP, so it gets blocked with a mixed content warning on Firefox (probably on Chrome too).
34.
▲
by
timmclean
12y ago
KDFs are definitely suitable for password storage, so I'm pretty confused at how the author arrived at their conclusion. They mention that scrypt with low security params is less secure than bcrypt at an adequate security setting. Th
35.
▲
by
timmclean
12y ago
If you XOR'd this RNG's output with, say, /dev/urandom, you could mitigate that risk significantly (you would be no worse off than before).
36.
▲
by
timmclean
12y ago
"reliable rides" fits with their stance on surge pricing -- they want to be a service that can always get you a ride, as long as you're willing to pay the price (not saying this is good or bad).
37.
▲
by
timmclean
12y ago
Real-time updates to queries looks awesome. Way simpler than doing pushing updates through pubsub. Great work, guys!
38.
▲
by
timmclean
12y ago
In case this is helpful: I interned at a company, Polychart, where we built a product similar to chart.io that is now open source and can be self-hosted: https://www.polychart.com/
39.
▲
by
timmclean
12y ago
I think the interesting stuff starts on page 2: With the help of Mathematica, one of us found some counterexamples to our conjectures. Fortunately, another one of us was using Maple and, when checking those supposed counterexamples, found
40.
▲
by
timmclean
12y ago
The implication that psychological damage is not "real" damage is false.
41.
▲
by
timmclean
12y ago
The psychological impact of "I'll drink your blood out of your c--- after I rip it open" [1] is very different from that of recruiter spam. [1] https://twitter.com/femfreq/status/504718160902492160
42.
▲
by
timmclean
12y ago
Source?
43.
▲
Why Qubes OS is more than just a random collection of VMs [pdf]
(invisiblethingslab.com)
4 points
by
timmclean
12y ago
|
0 comments
44.
▲
by
timmclean
12y ago
This document[1] talks about that risk and what they've done to mitigate it at the bottom of page 10. [1] http://www.invisiblethingslab.com/resources/2014/Software_co...
45.
▲
by
timmclean
12y ago
Time to prove him wrong! :)
46.
▲
by
timmclean
12y ago
Maybe, but it doesn't belong on HN either way.
47.
▲
by
timmclean
12y ago
That's great! Thanks for open sourcing it. I really don't think there's much value though if it's not self-hosted -- it just adds another point of failure to the CA system. Edit: what if this were built into Firefox?
48.
▲
by
timmclean
12y ago
Trust exactly who you want to trust... as you download certificates from a random person's server. But seriously, great idea, but wouldn't this be better as a command-line tool installable via a package manager? At least then it
49.
▲
Modern anti-spam and E2E crypto
(moderncrypto.org)
398 points
by
timmclean
12y ago
|
137 comments
50.
▲
by
timmclean
12y ago
It's not safe to use this for anything serious, of course, since it uses crypto in a web page. Were there any real intended uses for this, or was it just a fun side project?
51.
▲
by
timmclean
12y ago
Couldn't you say that about any company selling services?
52.
▲
by
timmclean
12y ago
Gson worked perfectly for me a few years ago. Why did you end up implementing your own?
53.
▲
by
timmclean
12y ago
And then, of course, we'll effectively be back to leaking hostnames, since there will be a 1:1 mapping between IPs and hostnames...
54.
▲
by
timmclean
12y ago
Sort of like what IE used to do the first time you submitted a form? http://bmlinks-committee.jbmia.or.jp/eng/image/EnDlg03.gif
55.
▲
by
timmclean
12y ago
In Canada, at least, background checks can reveal attempted suicides and dropped charges, unfortunately: http://www.therecord.com/news-story/4538747-names-of-420-000...
56.
▲
by
timmclean
12y ago
>> most servers don't make a new process for every request anymore That's correct. Most designs use either a prefork model (e.g. Apache) or an asynchronous event-driven model (e.g. Nginx). With prefork, a number of worker
57.
▲
by
timmclean
12y ago
It sounds like EventSource would be a good solution in that case: low overhead, and you'd get auto reconnect for free.
58.
▲
by
timmclean
12y ago
Google has plenty of experience in that department.
59.
▲
by
timmclean
12y ago
Tools like http://raphaeljs.com/ allow you to support older versions of IE.
60.
▲
by
timmclean
12y ago
As a bonus, the website accepting pre-orders (everbuying.com) emails you your password in cleartext after registering!
More ›