Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dadrian
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
dadrian
3d ago
I was actually referencing repeated exploitation by leaking TheHole, which actually has no particular reason it needs to be sensitive.
2.
▲
by
dadrian
1mo ago
Have you attempted to kidnap the DA during a prisoner transfer on Lower Wacker, only to be thwarted by a vigilante? If not, I question your Chicago bona fides.
3.
▲
by
dadrian
1mo ago
In fact, the default behavior in every web browser right now is to use a hybrid.
4.
▲
by
dadrian
1mo ago
The cryptographers in charge of major web browsers, TLS libraries, and programming language standard libraries do not stand by DJB’s points.
5.
▲
by
dadrian
1mo ago
RSA is asymmetric crypto. This article is about symmetric cryptography. I expect LLMs will advance state of the art in factoring algorithms, considerably.
6.
▲
by
dadrian
2mo ago
There are only three programs where memory safety matters: HTTP server, browsers, and operating systems. In practice, really just browsers and operating systems. Memory safety schemes that don't work for those systems are primarily cos
7.
▲
by
dadrian
2mo ago
The pricelist was a marketing stunt.
8.
▲
by
dadrian
4mo ago
While the result is impressive, this blog post is extremely disappointing. - It does not show an example of the new best solution, nor explain why they couldn't show an example (e.g. if the proof was not constructive) - It does not eve
9.
▲
by
dadrian
4mo ago
There's something ironic about vibe-coding an anti-YC site. They're why OpenAI exists!
10.
▲
by
dadrian
5mo ago
The Internet in 1999 was not good at all. Browsers barely worked, computers crashed constantly, the ability to actually search for useful things was limited, and many things we take for granted as being online (news, people, documentation)
11.
▲
by
dadrian
5mo ago
I dunno, they'll let anybody get on the Internet and start a podcast.
12.
▲
by
dadrian
5mo ago
I will bring this up at the next meeting of the secret cryptographer cabal where we decide what information to reveal to non-cryptographers.
13.
▲
by
dadrian
5mo ago
Except for the part where it's constantly having quality and reliability issues, even independent of the server-side infrastructure (OOMs on long running tasks, etc).
14.
▲
by
dadrian
6mo ago
As opposed to Pip, which is obviously free and sustainable forever.
15.
▲
by
dadrian
7mo ago
The person with the most HN karma of anyone on this site, currently thinks djb's actions are wrong.
16.
▲
by
dadrian
7mo ago
For someone to come in and buy Bluesky and then hold everyone’s data hostage, then Bluesky would actually have to have enough value that someone would want to buy it.
17.
▲
by
dadrian
7mo ago
RMS has, at minimum, showed that he swayed by parrots, spider plants, and free plane tickets and guest lodgings.
18.
▲
by
dadrian
7mo ago
> SAML is arguably the worst cryptographic standard ever created The PGP packet has entered the chat.
19.
▲
by
dadrian
7mo ago
GOT ‘EM
20.
▲
by
dadrian
8mo ago
Some of them also aren't really dead.
21.
▲
by
dadrian
8mo ago
The 90-day disclosure window is an arbitrary courtesy, not a binding contract about the behavior of either party. They probably had other things to do.
22.
▲
by
dadrian
8mo ago
Taken both in name and role, more or less.
23.
▲
by
dadrian
9mo ago
PE didn’t kill housing. Private equity owns 2-3% of homes.
24.
▲
by
dadrian
9mo ago
It's not red! You're just colorblind.
25.
▲
by
dadrian
9mo ago
Network DLP is also not bulletproof so I'm not sure what the argument is there. These things are all best effort. > if you have DLP at work, open the integrated browser in VS Code and notice how you can send protected test strings w
26.
▲
by
dadrian
9mo ago
That is not true, you can run DLP on an endpoint directly and inside a browser directly (e.g. via an extension or direct integration hooks). You can also try to stop the situation where the CC numbers are in the clear anywhere in the first
27.
▲
by
dadrian
10mo ago
This is good advice, and there's good people on the signature list, but why is this is an open letter? This feels navel-gazey and straight out of 2017.
28.
▲
by
dadrian
11mo ago
A MITM could replace the redirect with malicious content, as described in the blog.
29.
▲
by
dadrian
11mo ago
Yes, it started that way, but complaining about the current auto-update behavior of the software (not the ACME protocol), is completely unrelated to Let's Encrypt and is instead an arbitrary design decision by someone at EFF.
30.
▲
by
dadrian
11mo ago
Add a /, e.g. `shortname/`
More ›