Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DanielDent
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
DanielDent
5y ago
Here's a very quick summary of what I linked above: In Israel it would be easy to look at the data and conclude that vaccines are providing ~67% efficacy against severe disease/death. But, once the data is broken down into buckets
2.
▲
by
DanielDent
5y ago
Things that matter a lot these days: https://en.wikipedia.org/wiki/Base_rate_fallacy https://en.wikipedia.org/wiki/Simpson%27s_paradox Someone that's done some analysis using the above mental
3.
▲
by
DanielDent
5y ago
For a little bit of ancient history: I was one of the admins who worked to create OFTC. We all knew each other from Open Projects Network (which rebranded as Freenode). I was barely in high school when I came up with the name OFTC and I reg
4.
▲
by
DanielDent
6y ago
This paper references https://www.ndss-symposium.org/wp-content/uploads/2019/02/nd... They in turn reference my 2015 take on this: http://dnscookie.com/ With homage Moxie's Cryptogr
5.
▲
Prepare Android Apps for ISRG Let’s Encrypt Expiry of IdenTrust Cross-Signature
(danieldent.com)
2 points
by
DanielDent
6y ago
|
0 comments
6.
▲
by
DanielDent
6y ago
I think a fairly manageable path forward is underway which makes this a smaller issue than it first seems: (1) Firefox already uses its own root store (2) App developers can include additional roots in addition to the system root store: ht
7.
▲
by
DanielDent
6y ago
There's a really big gap between the $0.01/gb you are talking about being charged on droplets and the $0.10/gb that DigitalOcean is using on newer offerings like this and "App Platform". https://www.digit
8.
▲
by
DanielDent
6y ago
There are many CDNs that make money charging < $0.01/gb. Indeed DigitalOcean themselves built their place in the market by charging $0.01/gb for bandwidth. How do we reasonably get to $0.10 as is the case here? If it were reall
9.
▲
by
DanielDent
6y ago
sigh . DigitalOcean continues their march towards irrelevance. First it was the app platform and now this. Gouging us at $0.10/gigabyte bandwidth charges makes us: (1) think less of you, and (2) adds a bunch of cognitive complexity &a
10.
▲
Amazon S3 Path Deprecation Plan (Sept 30, 2020 bucket creation deadline) (2019)
(aws.amazon.com)
5 points
by
DanielDent
6y ago
|
0 comments
11.
▲
by
DanielDent
6y ago
What this describes is a mechanism for k8s to delete underlying resources prior to removing them from k8s. E.g. before completely removing the CRD representing an S3 bucket, this provides a mechanism for that S3 bucket to be deleted from AW
12.
▲
by
DanielDent
6y ago
The .com zone file is updated every few minutes. Caching behaviours will vary significantly. Frequently a significant fraction of traffic can be using new nameservers within minutes, with a long tail of traffic with older information. Each
13.
▲
by
DanielDent
6y ago
It used to be that nameserver changes with TLDs were measured in days, not minutes. Even today some TLDs continue to operate this way.
14.
▲
by
DanielDent
7y ago
I appreciate the compliment, but sadly I haven't yet made the time to write much on the subject. There's a lot I'd like to see implemented.
15.
▲
by
DanielDent
7y ago
It would be difficult to differentiate between responses that vary due to load balancing and responses that vary due to active fingerprinting. Even when a site only has a single physical location, load balancing might be done in part by hav
16.
▲
by
DanielDent
7y ago
This would make it harder to build a fingerprint, especially if responses were sampled from a number of independent sources. The next logical step in the arms race would likely involve fingerprinting systems using more bits than strictly ne
17.
▲
by
DanielDent
7y ago
Third party DNS servers are helpful in one sense - you can share your state with other users. Turning off EDNS with your own recursor won't really make much difference. Limiting the maximum cache length will help, but will also elimina
18.
▲
by
DanielDent
7y ago
I doubt this is quite what you are looking for, but https://github.com/fazibear/export provides simple Elixir/Python interop.
19.
▲
by
DanielDent
7y ago
- Never allow any part of the computing systems you use to cache anything. - Insist that everything in your life exist in a state of being functionally pure & stateless. - Eliminate access to all sources of timing data. - Make sure that
20.
▲
by
DanielDent
7y ago
It's fun when you check the front page of HN and see your work :).
21.
▲
by
DanielDent
7y ago
I published dnscookie.com in late 2015. I google "dns cookies" and a few other things terms, was surprised that the terminology appeared unused, and it seemed suitable for the concept I was describing. In May 2016, RFC 7873 was pu
22.
▲
by
DanielDent
7y ago
An example of something that Cloudflare's approach provides some protection from: http://dnscookie.com/
23.
▲
by
DanielDent
8y ago
I have been eagerly waiting for this ever since I saw Chris McCord's demo. Having this become tightly integrated into the Phoenix framework will be game changing. I think there are a large number of use cases for which this completely
24.
▲
by
DanielDent
8y ago
PDFs that work in Chrome's PDF renderer: A calculator: https://pspdfkit.com/images/blog/2018/how-to-program-a-calcu... A game of breakout: https://github.com/osnr/horrifying-pdf-expe
25.
▲
by
DanielDent
8y ago
GSMA standards have always included purposeful insecurity, e.g. look at the history of A5/1 & A5/2. It's a group that buys into the idea of secure backdoors, I'm not sure it's possible for them to build a secure
26.
▲
by
DanielDent
8y ago
At one point, one of the attack vectors was said to be by spoofing or otherwise manipulating traffic to/from a wireless femtocell. The same wireless femtocells that many operators will gladly sell or give to you for free or very little
27.
▲
by
DanielDent
8y ago
"Friendly fraud" is not a Facebook-invented term. It's a term used and understood by card issuers, acquirers, and merchants. Friendly fraud encompasses: - Dissatisfied customers who don't find refuge in a refund policy&#
28.
▲
by
DanielDent
8y ago
Nonsense. The AGPL is a pretty nasty license to begin with, but this new license makes your software nearly useless. For example: prior to this change, people could develop an extension to MongoDB which combined MongoDB with some GPLv3 soft
29.
▲
by
DanielDent
8y ago
My understanding is that SLC is seen as safer, and lower densities are also seen as safer. Beyond that I don't know for sure. I imagine that even an "industrial" grade flash card is still engineered with the assumption that i
30.
▲
by
DanielDent
8y ago
As I understand, SSD would be an especially poor choice for this - an SSD left unpowered for an extended period will begin to experience data durability issues. The firmware of a powered SSD will mitigate this issue by engaging in periodic
More ›