Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zrm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
27 ms
·
271.
▲
by
zrm
6y ago
Or to say it a different way, protons without electrons. Though I don't think protons get transferred over a wire.
272.
▲
by
zrm
6y ago
> While version 3 of the dependency is innocent, commit 5678 is not. Something went wrong in the interaction between the code and its dependencies in that change and discovering that change quickly is valuable. The trouble is that this w
273.
▲
by
zrm
6y ago
https://wiki.openssl.org/index.php/Versioning https://developer.gnome.org/gtk3/stable/gtk3-Feature-Test-Ma... https://everything.curl.dev/libcurl/api
274.
▲
by
zrm
6y ago
That's a name, not an IP address. And what you would expect to find at that name is not an A record for that IP address (which would be redundant) but a PTR record providing its canonical name.
275.
▲
by
zrm
6y ago
> you're able to find the first commit that introduced the issue in O(log(commits)) time, rather than needing O(commits * (num dependencies * dependency versions)) time. Try the oldest and newest compatible version of your code and
276.
▲
by
zrm
6y ago
> This worked in a world when there wasn't much software, when releases were rare and when most programs only had one or two dependencies. None of these properties are true any more. I don't think this is even the problem. It&#
277.
▲
by
zrm
6y ago
> A vanity address is only human-meaningful up to a certain point in the string. Not really memorizable. This is also the reason why they're discouraged from a security perspective. You burn a given amount of CPU time to get Cyberdy
278.
▲
by
zrm
6y ago
> Then we’ll end up with a csprng getting used in a tight loop iterating over every pixel in a raytracer... Which will then be conspicuous enough for the developer to notice and fix it. > “Lazy people who don’t want to type” are not t
279.
▲
by
zrm
6y ago
It's also a good idea to give safer things shorter names. So make random() a CSPRNG (and an alias for SecureRandom() for people who want to be explicit) while InsecureFastRandom() is just what it says and has no other name. Then if you
280.
▲
by
zrm
6y ago
See also: https://en.wikipedia.org/wiki/If-by-whiskey
281.
▲
by
zrm
6y ago
I think I get it. The idea is that you assign capabilities based on whatever authentication mechanism. Access to read email sent to this email address, access to withdraw money from this bank account, etc. The way a lot of people think abou
282.
▲
by
zrm
6y ago
> The article never claimed they are impossible to solve. If they aren't impossible to solve then why should we not just solve them instead of abandoning decentralization?
283.
▲
by
zrm
6y ago
Running a Matrix server is complex because the software could be better, not from some inherent user-facing complexity. Encouraging users to use a VPN can be as simple as bundling the WireGuard installer with your software and providing a l
284.
▲
by
zrm
6y ago
> to have compatible servers that could communicate across different protocols, which is a run to the bottom just as in e-mail where adding new security and removing legacy is near impossible. TLS was not in the original email RFC. Such
285.
▲
by
zrm
6y ago
Most of these criticisms are solvable problems. If you make a direct connection to other users, they see your IP address. So use Tor or a VPN. Many P2P lookup systems assign identifiers for routing etc. So assign ephemeral ones for anything
286.
▲
by
zrm
6y ago
Forcing your way into the capitol and taking over a police station are both illegal and should not be done. They both meet the formal definition of "violent insurrection" and they both happened over the last year. The media respon
287.
▲
by
zrm
6y ago
> If HN is overrepresented by vanguards of decentralization and free speech, why are a lot of us here on HN instead of running USENET nodes and posting to a newsgroup such as "comp.programming.hackernews" to avoid being moderat
288.
▲
by
zrm
6y ago
> At the very minimum you would need a centralized discovery server. That's not necessarily true. You could use a DHT. Or have decentralized discovery servers, i.e. your username is user@example.com and then example.com is contacted
289.
▲
by
zrm
6y ago
> They can always fuel a generator But then so can you and charge your EV with it.
290.
▲
by
zrm
6y ago
The effect of not including non-free firmware is that the user is inconvenienced when using that hardware, but not hardware with free firmware. It also causes the user to be aware of whether the hardware they bought has non-free firmware. O
291.
▲
by
zrm
6y ago
https://en.wikipedia.org/wiki/Brendan_Eich
292.
▲
by
zrm
6y ago
I've seen it regularly happen where a user's company account is used for email that whenever the user changes their password, the email app on their phone causes their account to get locked out by doing repeated retries with the o
293.
▲
by
zrm
6y ago
I wonder if Signal would be open to doing that. I know they don't like third party implementations because then if you need to make a protocol change you'd have to wait 30 years for everyone else to update their clients. But if yo
294.
▲
by
zrm
6y ago
> Somehow people started associating UFOs with flying saucers and aliens. I saw a video (that I can't currently find) of Feynman explaining this once. The US government had a classified program that suspended 1940s saucer microphone
295.
▲
by
zrm
6y ago
Notably that the perpetrators are currently in prison for related crimes.
296.
▲
by
zrm
6y ago
No it isn't.
297.
▲
by
zrm
6y ago
> Increasing price with number of domains held. If I hold myname.com, it's $1. If I hold a thousand domain, the last 500 are at $1000/year. People will just form a thousand LLCs or use straw men. > Managed by a government in
298.
▲
by
zrm
6y ago
It's a license to print a specific amount of money every year. So the party who would want to sell it is the party who wants an enormous pile of money right away instead of a large amount every year indefinitely. It's inherently s
299.
▲
by
zrm
6y ago
> These are all very difficult attacks that require the attacker to have recorded your traffic off the network. The entire premise of encrypting the traffic passing over the network is that an attacker may have access to your traffic off
300.
▲
by
zrm
6y ago
> Timing side-channels are extremely hard to perform, especially if it is over the internet. Not all attackers are over the internet. Especially the ones who have had the opportunity to capture your past traffic, e.g. because they compro
More ›