Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
brl
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
brl
9y ago
Why would anybody censor the viewpoint of a woman scientist in this particular debate? How much cognitive dissonance is too much?
2.
▲
by
brl
10y ago
> I would love to hear his side of the story. Some of his side of the story has been told in the leaked emails: https://www.hdevalence.ca/etc/34de2f3c2a48f7da/EmAiLs.txt
3.
▲
by
brl
10y ago
I'm answering a comment chain about how Subgraph OS does not 'isolate' the network or USB stacks which is frequently brought up as an important deficiency in comparison to Qubes OS. My point is that this isn't a signifi
4.
▲
by
brl
10y ago
> I don't think there are any amnesic features like in Tails nor strong isolation between gateway and workstation to prevent IP leaks like in Whonix. Subgraph sandboxes run in a network namespace with no direct access to the network
5.
▲
by
brl
10y ago
I'm from Subgraph and I disagree. On Qubes OS the networking VM runs a standard Linux kernel with no special security hardening at all apart from the simple fact that it runs in a separate Xen VM. If an attacker is able to compromise N
6.
▲
by
brl
10y ago
> imho the qubes approach is more viable and exposes far less attack surface. I don't know what you base that opinion on since it's not an easy comparison to reason about. One metric you could use would be actual vulnerabilitie
7.
▲
by
brl
10y ago
Two people published open letters resigning from their involvement in Tor yesterday: https://www.oneeyedman.net/?p=2581 https://shiromarieke.github.io/tor
8.
▲
Jacob Appelbaum: What Has This Man Done?
(zeit.de)
6 points
by
brl
10y ago
|
1 comments
9.
▲
by
brl
10y ago
Sandbox implementation is described here: https://github.com/subgraph/oz/wiki/Oz-Technical-Details
10.
▲
by
brl
11y ago
Well there was this survey: https://en.wikipedia.org/wiki/Syrian_presidential_election,_... Also surveyed at that time were the million Syrian refugees living in Lebanon: https://www.washingtonpost.com/
11.
▲
by
brl
11y ago
http://www.voltairenet.org/en is a good site with many essays on these themes.
12.
▲
by
brl
12y ago
Check out the 'more details on Convertible Notes' link for the answer to your question.
13.
▲
by
brl
12y ago
Escalation to root from an active admin user account is trivial. Use your imagination.
14.
▲
by
brl
12y ago
Even if you validate certificates an active attacker can return false MX records and direct the sending MTA to connect to an attacker-controlled server which presents a perfectly valid certificate.
15.
▲
by
brl
12y ago
I would love for this to exist. I've thought about streaming on twitch before but it is apparently against their ToS to stream anything which isn't video games.
16.
▲
by
brl
12y ago
You can copy your private keys to another device obviously, and eventually Nyms can help you do this by brokering an end-to-end encrypted tunnel between devices to transfer keys securely.
17.
▲
by
brl
12y ago
Maintenance of public keys is automated, by which I mean the user does not need to do anything manually for them to be published and recertified before they expire. Private keys don't need maintenance after generation since they are si
18.
▲
by
brl
12y ago
The user only needs to install a Nyms supporting email client or webmail browser extension and they're good to go for transparent communication with any other Nyms user. Registration and maintenance of keys is entirely automated. Maki
19.
▲
by
brl
12y ago
I'll be pushing some initial code to github soon for the first stage of the project which is a locally running agent that provides encryption service to email clients over a json-rpc interface. We're also building our own email c
20.
▲
by
brl
12y ago
Hi, I'm the author of this document and principal developer of the project. This is a somewhat detailed design overview for a proposed alternative to the PGP keyserver system that I'm building and I didn't really write it fo
21.
▲
by
brl
12y ago
Yawn. Let me know when you're ready to announce a project to competently sign and verify artifacts.
22.
▲
by
brl
12y ago
Even if you have carefully installed the correct key from the author, if your download is intercepted and an attacker sends you a bogus artifact and signature it looks like Lein will just retrieve the attackers key from the keyserver and va
23.
▲
by
brl
12y ago
How does it know what the correct signing key is? edit: Looked up answer myself. Lein downloads whatever key the signature claims to be made with from public keyservers. How does this provide any additional security over not bothering to
24.
▲
by
brl
12y ago
RSA has this property, but the public and private keys are not chosen arbitrarily. The public key can easily be derived from the private key, but there is no obvious way to determine the private key from the public key.
25.
▲
by
brl
12y ago
I'll admit that it's the most exceptional trademark violation that I've seen today: http://www.dsource.org/projects/dwt/wiki/Logo
26.
▲
by
brl
12y ago
I use SWT quite a lot and while it's not perfect I find that it works brilliantly in most cases. I encourage the authors of this Go UI library to study SWT and crib heavily from the library internals. Otherwise they'll be sorting
27.
▲
by
brl
12y ago
Yes, Subgraph OS is meant to be used as a general purpose desktop operating system. There is pressure on TAILS to evolve in this direction by people who like TAILS and want to use it as their main everyday OS, but this conflicts with the &
28.
▲
by
brl
12y ago
Hi Bruce from Subgraph here. Yesterday we updated our website with information about a new project that we've been working on since December and made a very small announcement on Twitter about the website change and this generated more
29.
▲
by
brl
12y ago
> Some developers have noted Go’s lack of features or a few other things: no exceptions, nils instead of options, inability to specify dependency versions, mark and sweep GC, no macros, no generics. Not having exceptions is one thing and
30.
▲
by
brl
12y ago
> The only other option is that it wasn't random, but some event led to both discoveries. Perhaps a hint was around, a new method of > finding vulnerabilities, or anything at all that could nudge people's minds in that dire
More ›