Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tytso
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
121.
▲
by
tytso
7y ago
You still need some way to securely seed a CSRNG. That's what we use the entropy pool for in Linux. The idea is that we mix multiple sources, and hopefully at least one can't be guessed by a particular attacker. For example, yo
122.
▲
by
tytso
7y ago
To be completely correct: On modern kernels, /dev/urandom is not an interface to the kernel entropy pool. It is rather a ChaCha20 Cryptographic Random Number Generator which is periodically seeded from the kernel entropy pool.
123.
▲
by
tytso
7y ago
Part of the problem is that Linux supports a much larger set of architectures and boot loader than OpenBSD. So trying to use a seed file which is read by the bootloader at boot time is hard. Could systemd choose to read a seed file after
124.
▲
by
tytso
7y ago
The problem is "trusted" is as much a social construct as it is a technical one. For example, if you are an NSA employee, you might be utterly confident that the NSA didn't twist Intel's arms to put in a backdoor into RD
125.
▲
by
tytso
7y ago
I wasn't a real fan of the 5.3 change, but it was better than some of the alternatives that people were proposing. At the end of the day, the problem is that userspace just shouldn't be trying to get randomness during early boot.
126.
▲
by
tytso
7y ago
There are a number of things that the blog post gets wrong. First of all, it was not Jason A. Donenfeld, the author of Wiregard, which added the ChaCha20-based cryptographic random number to Linux. It was me, as the maintainer of Linux&#x
127.
▲
by
tytso
7y ago
My argument is that employees are responsible for reading the contract, and if the contract have terms that might be problematic for open source contribution, the employee is responsible for finding out ahead of time what the policy is. (F
128.
▲
by
tytso
7y ago
> "Giving up" is an ambiguous term here and I should have tried to be more specific. But I wasn't just referring to ownership. If I'm working on a project, and joining Google means I need to stop working on it for 3-4
129.
▲
by
tytso
7y ago
> It's absurd for any company to say they're going to attract passionate programmers, and then expect them to just roll over and give up projects that were started before they even joined at the company. This is not necessarily
130.
▲
by
tytso
7y ago
marcan_42, I will have been at Google for 10 years in January, and even back then the Open Source policies were part of the Noogler training, and the fact that Google would own everything you did, even on your own time, was clearly in the s
131.
▲
by
tytso
7y ago
Oh, please. It's standard industry practice for companies to claim ownership of everything a software engineer comes up with, even "on their own time". The problem is it's extremely difficult to say, figure out when
132.
▲
by
tytso
7y ago
The PIA clients are closed source, and can't be verified. (They also run as root....)
133.
▲
by
tytso
7y ago
The primary disconnect on this larger thread is a disagreement about terms. Does an "IC" mean someone who doesn't have any direct reports? What does it mean to be an "engineering manager"? Are staff, senior st
134.
▲
by
tytso
7y ago
Yes, I'm the /dev/random guy as well as the ext4 guy. I've also been the serial driver guy, and the tty guy (Posix job control was my first large contribution to Linux). I also was on the board of the FSG when we hired
135.
▲
by
tytso
7y ago
The biggest projects span such a wide number of teams and/or departments and/or product areas (product areas at Google are headed by Senior VP's) that you're never going to have someone with the formal authority having e
136.
▲
by
tytso
7y ago
You can find ways of being a technical leader without having a formal role. You can mentor more junior engineers; you can try to establish better coding and test/QA standards at your company. You can find some open source project t
137.
▲
by
tytso
7y ago
This is definitely not true. There are IC tracks at many companies. I'm over 50, still doing technical work, and I'm having a lot of fun. I was a STSM (Senior Technical Staff Member) at IBM and I'm now a Senior Staff Eng
138.
▲
by
tytso
7y ago
> My understanding is that the trouble only comes if the company has actually done something illegal. As you said earlier, "[pricing] is a constantly debated line". Suppose a search engine displays the lyrics on the results p
139.
▲
by
tytso
7y ago
Many startups lose money when they are first started; and a new product may very well be losing money until it reaches a certain scale. That's not the problem. The question is what's the motivation. If the motivation is to p
140.
▲
by
tytso
7y ago
It was an extended metaphor categorizing an ISP's (or a cloud provider) customers into multiple buckets: Kobolds, Lizardmen, Hobbits, and Princesses. Princeses were the customres which sometimes required a lot of customer support, but
141.
▲
by
tytso
7y ago
> "I want every other free email provider out of business right asap. Lose money on it, I don't care, just make us the best!" Every single large company I've worked at has had mandatory training classes where lawyers
142.
▲
by
tytso
7y ago
It depends on the customer. If you're an Office 365 customer who is a major enterprise with huge numbers of paid users, and your CIO goes golfing with Microsoft board members, you have a huge amount of power. Similarly, if you are a
143.
▲
by
tytso
7y ago
You can amp up a team by challenging them to give the very best possible user experience, so that your customers loves your product. Exhorting the team to "crush the competition" or "dominate the market" is not necessari
144.
▲
by
tytso
7y ago
Filtering SPAM mail with an acceptable false positive and false negative rate is part of the service. Unfortunately for you, the e-mail providers' customers (the users receiving the mail) get to decide what is an unacceptably high fals
145.
▲
by
tytso
7y ago
It's not like fingerprint sensors are all that secure. From Mythbusters: https://www.youtube.com/watch?v=MAfAVGES-Yc "Remember, according to the manufacturer says this lock has never been broken...." Watch
146.
▲
by
tytso
7y ago
I proposed a solution where you could specify this via a boot-command line option, and/or a default specified why a compile-time kernel config option. That got rejected because most users wouldn't be able to find the tuning knob
147.
▲
by
tytso
7y ago
My response to Linus: I'm OK with this as a starting point. If a jitter entropy system allow us to get pass this logjam, let's do it. At least for the x86 architecture, it will be security through obscurity. And if the alternat
148.
▲
by
tytso
7y ago
My theory about what is going on, and why it's not totally insane that Softbank is throwing bad money after bad: By throwing in $3 billion more (after already having throwing $11 Billion into WeWork) this gives Masayoshi Son the fo
149.
▲
by
tytso
7y ago
The tool doesn't understand all lockless techniques, so there will be some false positives. For example, there are some cases where people have used the low-level primitives barrier() and cmpxchg(), which this tool (not possessing h
150.
▲
by
tytso
7y ago
If you don't trust Intel, then don't use Intel CPU's at all. Using Intel CPU's and simultaneously saying, "but we can't trust RDRAND because could be backdoored" is completely insane. Intel hid an entire
More ›