Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Natanael_L
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Natanael_L
9mo ago
What's your usecase here? Internal or external messaging?
2.
▲
by
Natanael_L
9mo ago
There's no clear segmentation. There's symmetric and asymmetric primitives (and stuff that doesn't fit into these like ZKP), algorithms, protocols, research in many different types of attacks against each of these, research i
3.
▲
by
Natanael_L
9mo ago
The fact that every email encryption integration exports secure context messages into insecure contexts when decrypting (which is how encrypted messages end up cited in plaintext) means email can't be secured. This is true both for GPG
4.
▲
by
Natanael_L
9mo ago
You need a private PKI, not keyring. They're subtly different - a PKI can handle key rotation, etc. Yes there aren't a lot of good options for that. If you're using something like a Microsoft software stack with active direct
5.
▲
by
Natanael_L
9mo ago
What you described IS WHY age is the better option. GPG's keyring handling has also been a source of exploits. It's much safer to directly specify recipient rather than rely on things like short key IDs which can be bruteforced. A
6.
▲
by
Natanael_L
9mo ago
Then your next best bet is Matrix.org. Not to the same security standard as Signal, but if you don't have a specific threat against you then it's fine.
7.
▲
by
Natanael_L
9mo ago
Asking for an equivalent to GPG is like asking for an equivalent of a Swiss knife with unshielded chainsaws and laser cutters. Stop asking for it, for your own good, please. If you don't understand the entire spec you can't use it
8.
▲
by
Natanael_L
11mo ago
C2PA has the problem that it has a ton of optional metadata support and no well-defined strict validation procedure, so it's trivial to make fake photos appear valid using currently available C2PA enabled software. They absolutely must
9.
▲
by
Natanael_L
11mo ago
Also, the RPi is the wrong kind of hardware for attestation, at least use something like USB Armory which provides a user programmable ARM TrustZone environment. Since USB Armory supports pinning multiple keys for secure boot (and IIRC prot
10.
▲
by
Natanael_L
2y ago
... At which point the only new data that chatgpt can reliably scrape is its own answers...
11.
▲
by
Natanael_L
2y ago
Everything is open source so yes you can, it's mostly a question of practicality. There's already third party clients, account hosting servers, etc, as well as different apps building on the same system (and which can use the same
12.
▲
by
Natanael_L
2y ago
Before Musk, Twitter used to fight those requests. The platform can not be called better, with more bugs and errors than ever. Why don't they apply those rules to Republicans? Why can they specifically post stuff like private info abou
13.
▲
by
Natanael_L
2y ago
Musk is reposting actual neonazi accounts
14.
▲
by
Natanael_L
2y ago
Most of that doesn't deserve to be called an improvement. That message encryption is one of the worst designs I've ever seen. The algorithm isn't open enough that anybody can see if what it's doing matches the code. And
15.
▲
by
Natanael_L
2y ago
It's used in a not particularly advanced way - bluesky uses repositories per each user for all their public social activity (posts, likes, etc) and it creates a Merkle tree as an index for them and signs that index (this enables stuff
16.
▲
by
Natanael_L
2y ago
It's currently built into the applications, not configurable by default. It's preferable if everybody in a thread / space / community uses the same one because otherwise differences can cause validation failures and conf
17.
▲
by
Natanael_L
3y ago
Signal relies on the client program to not be compromised to keep conversations secret
18.
▲
by
Natanael_L
3y ago
There's a few self hosting forums, and there's Lemmy / Kbin for federated ones
19.
▲
by
Natanael_L
3y ago
Since you own the console you dump the keys from, nope
20.
▲
by
Natanael_L
5y ago
Re forms: I did primarily mean rather simple ones (like say attendance forms), but there's a bigger argument here; This type of API copyright would post likely not just mean the paper form is under copyright protection, but that the so
21.
▲
by
Natanael_L
5y ago
The irony is that what they claim happened is instead what would have happened only if the case was resolved in the opposite direction. Everybody having to pay for API licenses for absolutely everything would be disastrous. The gridlock wou
22.
▲
by
Natanael_L
5y ago
As others has said elsewhere, the jury rules on facts and judges rules on law. SCOTUS are judges. Under one interpretation of law, the most recent jury findings of fact held that Google infringed. SCOTUS altered the interpretation of the la
23.
▲
by
Natanael_L
5y ago
How often does the API itself exceed the level of creativity of uncopyrightable plain lists of facts? It's not clear to me that it should be considered copyrightable on its own, especially with the fact that copyright explicitly do not
24.
▲
by
Natanael_L
5y ago
One of the issues here is that it's not even clear under which license the API should be covered. Does the existing software license also cover the API, or must it be explicitly defined? What happens when an API is co-created by differ
25.
▲
by
Natanael_L
5y ago
Their failure to take control over those markets is not the same as a failure to cause damage. They slowed down development of web standards by many many years, as one example.
26.
▲
by
Natanael_L
5y ago
It also saved open source software which reimplements proprietary API:s
27.
▲
by
Natanael_L
5y ago
Independent copyright when a work was independently created is a thing in most jurisdictions, as copyright covers copying and is not like patents in that regard. However, that would indeed require a ton more work to prove that you did not
28.
▲
by
Natanael_L
5y ago
Something I've said before: believing that you are a good person is dangerous, because it makes you likely to assume that what you're doing is also good just because you have good intent. It's better to focus on trying to d
29.
▲
by
Natanael_L
5y ago
I also think trust is the single biggest issue here. The more you trust somebody the more leeway you will give them in how they can express themselves to you, because you expect them to be honest and you assume that they mean well. You are
30.
▲
by
Natanael_L
6y ago
Most jurisdictions' copyright law covers translations as derivative work which is still protected.
More ›