Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dgrove
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
1.
▲
by
dgrove
8mo ago
I'm not sure what problem this is solving. This seems like chainguard but being built in "your ci" (github) vs "their ci". Images may be a bit smaller, but this is already a feature set that wolfi already allows for
2.
▲
by
dgrove
2y ago
Also login over a VPN unless you want your IP leaked to everyone else
3.
▲
by
dgrove
2y ago
Just because you make exceptions doesn't mean everyone else does
4.
▲
by
dgrove
2y ago
This feels like MilkSad.info and the 2020/2021 Cake Wallet flaws all over again https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3991... https://milksad.info/posts/research-update-10&#x
5.
▲
by
dgrove
2y ago
Looks like the XMPP adapter hasn't been open sourced so it can't be built https://github.com/SAMA-Communications/sama-server/tree/main... https://github.com/SAMA-Communications/
6.
▲
by
dgrove
2y ago
scp has the assumption that you have a login on the computers you're trying to share data from. wormhole allows for sharing with others without providing login access to the computer
7.
▲
Milk Sad Disclosure
(milksad.info)
136 points
by
dgrove
3y ago
|
125 comments
8.
▲
by
dgrove
3y ago
Because a single hot key for signing on a random build server has never fucked anyone before? https://www.techtarget.com/whatis/feature/SolarWinds-hack-ex...
9.
▲
by
dgrove
3y ago
The lack of package signing and reproducible builds leaves a lot to be desired
10.
▲
by
dgrove
3y ago
HKPK doesn't have a ton of adoption and only works in browsers. So this does nothing for curl, wget, pip
11.
▲
Waymo unveils design for new autonomous fleet
(twitter.com)
7 points
by
dgrove
4y ago
|
0 comments
12.
▲
by
dgrove
4y ago
Sure, so you add it as part of the P2MS script but that doesn't solve the issue of every re-key costing money
13.
▲
by
dgrove
4y ago
Is this because you have a time-locked transaction to move the funds from the P2MS to a P2PKH? How does that work when it's "re-keyed"? Wouldn't each re-key move to a new P2MS and have a transaction fee associated with i
14.
▲
by
dgrove
4y ago
The only problem with LN is that is actively requires an internet connection. Wherein Bitcoin could be done offline similarly to a Card Imprinter
15.
▲
by
dgrove
4y ago
Bitcoins entire premise is around the movement of unspents. If you always use the same wallet for every transaction it is pretty easy to track who sent the money. If you instead are always sending your money to a newly derived wallet from y
16.
▲
What's New in Spot (May 2022)
(youtube.com)
1 points
by
dgrove
4y ago
|
0 comments
17.
▲
Disclosing Shamir’s Secret Sharing Vulnerabilities and Announcing ZKDocs
(blog.trailofbits.com)
1 points
by
dgrove
5y ago
|
0 comments
18.
▲
by
dgrove
6y ago
3rd Party browsers are not, they have their own sync infrastructure. This is mostly affecting builds of Chromium that are not directly built by Google https://groups.google.com/a/chromium.org/g/embedder-dev&#x
19.
▲
Security fail by Apple allowed total remote control of iPhones via WiFi
(9to5mac.com)
2 points
by
dgrove
6y ago
|
0 comments
20.
▲
by
dgrove
7y ago
"Stocks only go up"
21.
▲
CVE-2019-19604: Git Submodule Arbitrary Command Execution
(gitlab.com)
5 points
by
dgrove
7y ago
|
0 comments
22.
▲
A federated package registry for anything, but mostly JavaScript
(github.com)
1 points
by
dgrove
7y ago
|
0 comments
23.
▲
by
dgrove
7y ago
iCloud security code can come over SMS if your account is configured as such, therefore the above example of a SIM port applies
24.
▲
by
dgrove
7y ago
Lots of talk about passwords, but fewer about password managers. The password managers listed in this do not protect against backdoors. Lastpass, for example keeps all your passwords in plain text once you've unlocked it. Passwords sto
25.
▲
by
dgrove
7y ago
Multiple teams I've been on at multiple companies have done this process, but with donuts and other foods. A little bit of public shame goes a long way.
26.
▲
by
dgrove
7y ago
I use pass for my password manager which links to my yubikey that has my gpg key on it. My yubikey has touch enabled which means that even if someone got access to my machine with my yubikey on it and asked me to tap they would only get tha
27.
▲
by
dgrove
7y ago
Google Authenticator does not help prevent against a compromised device (as all TOTP secrets and seeds are on device) and is truly a pain when working with multiple phones. Personally I use Yubico Authenticator as all the TOTPs live on my Y
28.
▲
by
dgrove
8y ago
> perhaps something that can be automated This is solved using WKD. Thunderbird already supports this with enigmail enabled
29.
▲
I/O Transmission
(events.google.com)
3 points
by
dgrove
8y ago
|
0 comments
30.
▲
by
dgrove
8y ago
Use the elliptic curve version instead https://security.stackexchange.com/questions/46802/what-is-t... This is built into modern browsers so you can use that as the basis for HMAC if you can't trust TLS or ha
More ›