Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ylk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
31.
▲
by
ylk
2y ago
In what way are [1] not “full OSes”? They’re minimal templates, but afaik they still run systemd, the kernel, etc. needed to boot the standard Linux systems they are. When I clicked the link I was expecting something like a unikernel, eg h
32.
▲
by
ylk
2y ago
Original title: Cloudflare helps verify the security of end-to-end encrypted messages by auditing key transparency for WhatsApp
33.
▲
Cloudflare audits key transparency for WhatsApp
(blog.cloudflare.com)
2 points
by
ylk
2y ago
|
1 comments
34.
▲
by
ylk
2y ago
The topic has been e2ee, which is first and foremost about security. You can have e2ee without privacy, as is likely the case with WhatsApp. You certainly can “prove” and “disprove” “security” by reverse engineering, to the same extent a so
35.
▲
by
ylk
2y ago
The app uses the (i)phone OS’s cloud storage APIs to write to the backup folder, meta’s servers don’t have access to any credentials. For Android I currently can’t check, but it’s obvious from their FAQs that they have the app upload to Goo
36.
▲
by
ylk
2y ago
It’s certainly not outrageous. It’s how people regularly find vulnerabilities in all kinds of closed-source software.
37.
▲
by
ylk
2y ago
Meta has access to the backups that are stored on each individual’s Google Drive/iCloud? How does that work exactly? Please elaborate.
38.
▲
by
ylk
2y ago
You can always go ahead and decompile the apps and then show everyone that they’re in fact lying, that story would be huge. That alone doesn’t make it true, but there have so far not been hints of them pulling weird stuff with their e2ee, u
39.
▲
by
ylk
2y ago
> whatsapp E2EE is a joke Could you please elaborate why (in detail)?
40.
▲
by
ylk
2y ago
Are you intentionally ignoring the part where I provided reasons for why alternatives to the use of password managers by vendors that (supposedly) cause lock-in won’t go away? It turns your fear into a hypothetical that you’re more than wel
41.
▲
by
ylk
2y ago
> What if I don't want to pay for Bitwarden, or buy a smartphone, or tie my log-ins to my computer? Then you and the people you influence can continue to enjoy getting phished. > What happens when the WebAuthn standard evolves an
42.
▲
by
ylk
2y ago
Let me preface with: I’m neither a web dev nor experienced with accessibility. Which tools did you use? I’d argue a human probably also won’t review all your alt tags manually or you could just do it yourself, too. If you have lots of them
43.
▲
by
ylk
2y ago
You are confused because you interpret the meticulous and time-intensive nature of the research as potentially conflicting with the claims of affordability and ease of application. To clear up this confusion, let's break down the key p
44.
▲
by
ylk
2y ago
Tip: It only „seems“ and „sounds“ that way. Your conclusion is quite obviously based on incomplete information.
45.
▲
by
ylk
2y ago
Yes it’s standard for interval arithmetic. Have a look at the interval operations section: https://en.m.wikipedia.org/wiki/Interval_arithmetic
46.
▲
by
ylk
3y ago
Okay, I’ll give you one more thing: I love using rust. I also use zoxide, ripgrep, dua, etc. I don’t hate the language. Quite the opposite. I hope you can now go back and just see the argument for what it is and not for what you thought I w
47.
▲
by
ylk
3y ago
I’m not mocking it. I’m just applying the argument I see many people on HN make in discussions about rust to this case, where I suspect many will lean much more on the side of using regexes to reimplement parsers. Don’t know if that’ll be t
48.
▲
by
ylk
3y ago
I think re-implementing the functionality is the mistake here. A big counter-argument to “rewrite in rust” is usually that by rewriting you introduce new bugs. Especially for security critical things one should re-use the implementation to
49.
▲
by
ylk
3y ago
Possibly stupid question: why can’t the metadata be exported and imported? Is there other metadata aside from the exif data? Or does Apple not export all of it? And in case you’re talking about additional features like face recognition, do
50.
▲
by
ylk
3y ago
One of the inputs for MD5 is the length of the message, so I'm at least wrong in the case of MD5. Don't know about the general case and although I'm interested in the answer I can't spend time on it right now. But if any
51.
▲
by
ylk
3y ago
Didn’t think about it much, but file size should be a good indicator if the hash isn’t horrible. md5 + file size comparison could work for your use-case.
52.
▲
by
ylk
3y ago
Your phone manufacturer gave you a box with syncthing + storage for free with purchase of your device? Nextcloud also works on iOS, integrates with the Files app and was always able to sync photos right after I took them.
53.
▲
by
ylk
3y ago
This could be a paid option for parsing forms (not sure about ocr): https://demos.textcontrol.com/chapter/topic/PDF/PDFFormData https://www.textcontrol.com/technologies/pdf/
54.
▲
by
ylk
3y ago
WhatsApp is working on improving this situation: https://engineering.fb.com/2023/04/13/security/whatsapp-key-... Note: not trying to start a discussion on how much one can trust facebook
55.
▲
by
ylk
3y ago
Signal also created an easier to understand blog post in case you haven’t seen it, yet: https://signal.org/blog/pqxdh/
56.
▲
by
ylk
3y ago
CVSS is not a measure for risk. I feel like it’s pretty hard to define an objective measure for “how much should you care about this” that applies to everyone, since you’d need to know how common the affected software is among all computers
57.
▲
by
ylk
3y ago
Could you not achieve the same by shipping the required tools with Excel and running them inside a Windows Sandbox? Isolation isn't as good, but it probably protects users against the threats you/they care about?
58.
▲
by
ylk
3y ago
Does lockdown mode not help here because abusers know the device passcode?
59.
▲
by
ylk
3y ago
I thought emergency reset is supposed to protect you from abusive people but I skimmed the support article and it seems like emergency reset does not remove management profiles: https://support.apple.com/en-asia/guide&#
60.
▲
by
ylk
4y ago
Since jb1991 is being downvoted I want to clarify that this doesn’t somehow support the grandparent. Using your opponents strength as weapon means deflecting their attack and using the force to throw them on the ground/defeat them. Hav
More ›