Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
conformal
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
conformal
12y ago
i assume you've read the recent article by nafeez ahmed from vice, etc, about how google's search algorithms were funded via the NSF/CIA/NSA for 2 years before google ever existed and that sergey reported to someone work
2.
▲
by
conformal
12y ago
predictably well put from mr chomsky. to effect a classic double flashback, fight club style, here's a dose of bread and circus from juvenal from CE 100: "'It is scarcely possible that the eyes of contemporaries should discov
3.
▲
by
conformal
12y ago
they live is one of the best john carpenter films, and that includes the epic 10-minute on-concrete wrestling match before keith david will don the glasses. being extremely entertained to see a blog entry about they live aside, making priva
4.
▲
by
conformal
12y ago
space-alien technology speculation aside, i've been aware of openssh's less-than-reassuring default selection order for Ciphers, HostKeyAlgorithms, KexAlgorithms and MACs for a few years. for most modern computers and cpus, using
5.
▲
by
conformal
12y ago
this work from 2011 by IVT doesn't exactly inspire confidence. http://theinvisiblethings.blogspot.com/2011/05/following-whi...
6.
▲
by
conformal
12y ago
oh, you mean like VT-d etc on intel cpus. what reason could you possibly have to suspect that the IOMMUs from a company named "intel" are backdoored? :)
7.
▲
by
conformal
12y ago
good luck detecting baseband attacks in the wild. i hope you've got a transceiver with you and a rainbow table for cracking the A5/1 etc on your cell link.
8.
▲
by
conformal
12y ago
i really am a fan of what moxie et al are doing with textsecure. i am less of a fan of redphone, but that's another matter (zrtp, woof). while i trust textsecure, it is hard to trust any mobile OS and mobile hardware.
9.
▲
by
conformal
12y ago
while i am generally loathe to comment on HN, i consider it truly sad to see the passing of grothendieck. he was a truly revolutionary mathematician and his contribution to the (hard) science of mathematics cannot be overstated. people who
10.
▲
by
conformal
12y ago
i hear they are going to ban air soon because pedophiles can use it prey on children.
11.
▲
by
conformal
12y ago
i think it's great to see ppl being skeptical of security claims from phone manufacturers. trying to secure a normal cellphone is pretty much impossible and if you're storing sensitive information on one, you are just waiting to g
12.
▲
by
conformal
12y ago
your characterization of visits to the doctor is spot on: they are gatekeepers to medication and treatment and they have a warped incentive structure that biases them to under-treat anyone they don't "believe". on top of what
13.
▲
by
conformal
12y ago
even better, how about you name the compounds he "discovered" and demonstrate that they were not the subject of prior work. maybe i should write a book about a whole bunch of stuff other ppl did, not give proper attribution, then
14.
▲
by
conformal
12y ago
it's not slander, it's the truth. someone else discovered and tested MDMA many decades before sasha, but he is credited with "discovering" the compound.
15.
▲
by
conformal
12y ago
just like most people who are sasha fanboys, you obviously have zero domain knowledge on this subject. try them out yourself, see what happens.
16.
▲
by
conformal
12y ago
i know i'm going to get downvoted, but illumen is completely correct. there is nothing so american as downvoting the truth.
17.
▲
by
conformal
12y ago
entirely untrue. do your homework. sasha almost exclusively synthesized compounds that were already in the academic literature. he reproduced others' work and gave minimal attribution.
18.
▲
by
conformal
12y ago
it is sad to hear that sasha passed, he was a great man. he did a lot of really positive work for expanding the public's knowledge of hallucinogenic compounds, mainly 5HT-2A agonists of various varieties. that said, he is typically ov
19.
▲
by
conformal
12y ago
if anyone thinks that a few semesters of introductory mathematics or science courses is "not relevant" for a CS program, they have completely missed the point. this is a fool's complaint, like saying that "because i'
20.
▲
by
conformal
12y ago
nice to see btcd getting more usage, goldmar :) for the related blog entry with some more details, check out http://markgoldenstein.com/building-websocket-client-btcwall... we just recently released a small library that mak
21.
▲
by
conformal
12y ago
i always advocate for FDE, but that often has issues with remote serial console. the threat model of running without disk encryption is far worse for most bitcoin-related sites than the complexity associated with redundancy. if they get hac
22.
▲
by
conformal
12y ago
i strongly suggest that sites concerned with their security use (1) full-on colocation services and (2) encrypt the partition they store user data on or encrypt the entire disk. if you have proper disk encryption, it is non-trivial to game
23.
▲
by
conformal
12y ago
DISCLAIMER: i know and have worked with kyle (the author). while the factual content of tptacek's review may be spot on, his overall tone is very negative and smacks of "only experts allowed" logic. while he could have easily
24.
▲
by
conformal
12y ago
i'm in my 30s and i am in total agreement with you: the modern helicopter parents are so preoccupied with "bullying" that the next generation of kids are going to be soft-minded nitwits on the average. catching a beatdown on
25.
▲
by
conformal
12y ago
i suspect the memory accessible by this bug depends a lot on the software, OS and possibly hardware, e.g. on openbsd and bitrig amd64, the amount of memory leaked per exploit is less than 64 KB, closer to 32 KB. if you go much past the 32 K
26.
▲
by
conformal
12y ago
we appreciate your supportive comments :) there are about 10 of us at conformal.
27.
▲
by
conformal
12y ago
nice write up. we saw similar results in that the keying material never made it into the memory leaked. i've never felt so thankful for a memory allocation pattern.
28.
▲
by
conformal
12y ago
what i am expecting ppl to see is that you can't actually get to the tls private key itself. we have done some testing with our backup service, cyphertite, and have yet to attack and actually compromise any keying material. EDIT: forgo
29.
▲
FreeBSD OpenSSH Hole?
(article.gmane.org)
50 points
by
conformal
12y ago
|
12 comments
30.
▲
by
conformal
12y ago
^ this! back in 2010, my business partner, marco peereboom, submitted a patch to openssl to add support for aes-xts. it was coded by joel sing, now a google employee and golang dev. they _didn't even respond to the mailing list email_
More ›