Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wiktor-k
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
wiktor-k
2y ago
The SSH agent shipped with OpenSSH already includes PKCS#11 support (check out the `-s` flag). I'm using that daily to work with TPM-backed keys.
32.
▲
by
wiktor-k
2y ago
The server can get the calling process info [0], which may be useful for local access control. TCP sockets cannot distinguish clients like that. [0]: https://docs.rs/tokio/latest/tokio/net/struct.UnixStre
33.
▲
by
wiktor-k
2y ago
AFAIR you can choose to use Windows OpenSSH or the other one during Git for Windows installation. [0] [0]: https://duckduckgo.com/?q=git+for+Windows+openssh&t=fpas&iax...
34.
▲
by
wiktor-k
2y ago
SSH agent extensions are really powerful. I'm maintaining a crate for writing own agents (and clients) and just recently added an example of providing decryption over extensions [0] which, coupled with the other examples, allows using
35.
▲
Calling Time on DNSSEC?
(blog.apnic.net)
1 points
by
wiktor-k
2y ago
|
0 comments
36.
▲
by
wiktor-k
2y ago
Hmm... this is about PQ cryptography while I was expecting a status update of Ed25519 in WebCrypto which, sadly, is still available only via experimental platform flag: https://caniuse.com/mdn-api_subtlecrypto_verify_ed25519
37.
▲
by
wiktor-k
2y ago
Is it just me or should the following fragment use EnforcedAlignment in main? #[derive(TypeLayout, Copy, Clone)] #[repr(C)] struct EnforcedAlignment { _offset: [u8; GAP - 8], data: AlignedU128, } pub f
38.
▲
by
wiktor-k
2y ago
It gives me strong Amiga-vibes and it seems it's open-source now... I like it and will definitely try it out!
39.
▲
by
wiktor-k
2y ago
> Windows checks the code signing certificate of the exe, and if it isn't present and the binary not widely used shows you a big scary warning to discourage you from running it. Actually even if the file is correctly signed but is n
40.
▲
by
wiktor-k
2y ago
Streaming is not a problem (it's just a simple flag: https://github.com/wiktor-k/llama-chat/blob/main/index.ts#L2... ) but I've never used voice input. The examples show image input though: htt
41.
▲
by
wiktor-k
2y ago
Ollama is simply great! I was quite surprised how easy it is to integrate through their API. A simple chat using Ollama + llama3 is less than 40 lines of TypeScript: https://github.com/wiktor-k/llama-chat
42.
▲
by
wiktor-k
2y ago
> I'm curious, what do you like about the Emacs key bindings? Is it the GNU system integration, like with Bash? Nah, I actually don't use them I'm Bash that frequently. It may be just due to the non-modal way of the hot ke
43.
▲
by
wiktor-k
2y ago
> The thing about Emacs isn't it's key bindings. It's the extensibility and integration of the overall system. Well, I guess Emacs is many things to different people. After using Helix for quite some time the single thing
44.
▲
by
wiktor-k
2y ago
> I wonder if it means that the author will stop working on the library after their next release, Just FYI it seems the library will still be maintained: https://infosec.exchange/@firstyear/112337225055591544
45.
▲
by
wiktor-k
2y ago
Just to clarify Estonian Id-Card most certainly implements the PIV applet while Yubikeys implement both PIV and the OpenPGP Card (the latter has a benefit of natively supporting ed25519: https://github.com/wiktor-k/age-
46.
▲
by
wiktor-k
2y ago
Linux most definitely has a TPM interface, it's called /dev/tpmrm0 and plenty of libraries for accessing it (eg. https://github.com/parallaxsecond/rust-tss-esapi/ full disclosure: I'm co-mainta
47.
▲
by
wiktor-k
2y ago
I had to use Windows machine to test an app recently and the amount of ads and other annoyances there is just mindblowing. I wanted to show Solitaire to my kids but it's so ad-ridden it's painful to play. I'm strongly conside
48.
▲
by
wiktor-k
3y ago
Sequoia aims to be a "complete gnupg replacement" but in many ways it's still the same mindset as gnupg (core devs are former developers of gnupg). Sequoia also got support from VCs and just recently received significant fund
49.
▲
by
wiktor-k
3y ago
Yep, the schism is really bad for the end users and based on my "insider" knowledge it doesn't seem like the resolution is near. The tl;dr is that GnuPG basically forked OpenPGP into https://librepgp.org/
50.
▲
by
wiktor-k
3y ago
It uses this crate: https://crates.io/crates/pcsc On Windows and Mac it binds to system libraries. On Linux it works with pcsclite. Btw I'm not aware of any tooling that's used by Sequoia, rather wrappers t
51.
▲
by
wiktor-k
3y ago
Indeed. There were some discussions over choosing MPL but the parent foundation was more aligned with GPL and after it collapsed it seemed th3 idea of relicensing to MPL was dropped. Do note that sequoia and rpgp are different in many aspec
52.
▲
by
wiktor-k
3y ago
I agree that gpg did not age well. If we compare it to a different project with similar history: curl, it's apparent that gpg chose wrong on several fronts. It should be a library first instead of a cli tool. Funny part is that even th
53.
▲
by
wiktor-k
3y ago
Yep. We've got it working with OpenPGP Card devices (Yubikeys, Nitorkeys, etc.). The signing part was actually pretty easy and the decryption required a bit more work but the maintainer was super responsive ( https://github
54.
▲
by
wiktor-k
3y ago
Rpgp is great (we're currently using it for a better git signer with smartcards) but I wonder why is it trending right now at HN? Maybe because it's currently #1 in the test suite? https://tests.sequoia-pgp.org/
55.
▲
by
wiktor-k
3y ago
SEEKING WORK Location: Poland Remote: Yes Technologies: Rust, cryptography, HSMs, TypeScript, Docker recently but I have professional experience in all sorts of technologies Résumé/CV: available on request, but see https://g
56.
▲
by
wiktor-k
3y ago
Location: Poland Remote: Yes Willing to relocate: No Technologies: Rust, cryptography, HSMs, TypeScript, Docker recently but I have professional experience in all sorts of technologies Résumé/CV: available on request, but see https:&#
57.
▲
by
wiktor-k
3y ago
> OpenSSH certs are weird in that they include the signer's public key. OpenSSH signatures in general contain signer's public key, which I personally think it's not weird but rather cool since it allows verifying the signa
58.
▲
by
wiktor-k
3y ago
Could you share what's the property name for the update url?
59.
▲
by
wiktor-k
3y ago
I've just tried a sample vcf and on my Samsung phone and it shows the URL field ( https://codeberg.org/nfraprado/vcf-test/src/branch/pages/vca... ) in the contact page. But not the other links. I
60.
▲
by
wiktor-k
3y ago
Just for the record I've seen other providers giving routers with GPON SFP/XGS-PON SFP+ modules, which act as an ONT (see eg. https://www.play.pl/pomoc/naprawa-i-konfiguracja/telewizja-i... ). I'm no
More ›