Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
goldsteinq
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
goldsteinq
4mo ago
I think at least some skepticism about independency is warranted when the board of directors is 3/4 Anthropic employees. Zulip is an awesome tool, and I want to assume good faith here, but it’s really hard to interpret this as anything
2.
▲
by
goldsteinq
4mo ago
I think this misses the point of LISP macros. LISP macros are just functions written in LISP , so here macros need to be functions written in Rust-but-LISP, but it is not so. In fact, I think this macro language lacks conditionals, so it’s
3.
▲
by
goldsteinq
6mo ago
> Folks who manually enable our "Resist Fingerprinting" preference (which we don't officially support, and I don't generally recommend - but hey, you do you) are very loud on Bugzilla. VERY loud. To the point where I&
4.
▲
by
goldsteinq
7mo ago
It keeps missing the fact that BlueSky, as of today, is not decentralized in any meaningful way. If tomorrow bsky.app (and/or PLC registry) goes dark, the network is dead. There’re no public alternative AppViews. Most users use central
5.
▲
by
goldsteinq
9mo ago
No “Submit Debug Logs” there, as far as I can see. Do I need to be on matrix.org homeserver for this to work or something? https://photos.goldstein.lol/share/OIgowBN4Wmi4zlm8DmDP0s8jH...
6.
▲
by
goldsteinq
9mo ago
I’m facing it on Element Desktop, but I’ll try to reproduce it on Element Web. I’ve tried to submit logs from Element Desktop, but it says that `/rageshake` (which I was told to do) is not a command. I’m happy to help with debugging th
7.
▲
by
goldsteinq
9mo ago
Okay, sorry, not oss-security mailing list, oss-security _distros_ mailing list. https://oss-security.openwall.org/wiki/mailing-lists/distros > Only use these lists to report security issues that are not yet pu
8.
▲
by
goldsteinq
9mo ago
> Say more. Plenty of people use Signal as a serious communication tool. I did say more already. Maybe you believe in serious communication tools that can’t synchronize searchable history between devices, but I don’t. > They, and othe
9.
▲
by
goldsteinq
9mo ago
I’m definitely not “commiting malpractice” on account of not being a security practicioner. I’m talking from a perspective of a user. It’s important to me — as a user — that a communication tool doesn’t lose my data, and Signal already did.
10.
▲
by
goldsteinq
9mo ago
Pros of Matrix: it actually has a consistent history (in theory); no vendor lock-in. Cons of Matrix: encryption breaks constantly. Right now I’m stuck in a fun loop of endlessly changing recovery keys: https://github.com/ele
11.
▲
by
goldsteinq
9mo ago
Yes, if your only device is a single Android phone you can do that. You can’t, however, use that backup to populate your message history on other platforms. I’ve already lost message history consistency because one of my devices was offline
12.
▲
by
goldsteinq
9mo ago
> You don't have to use it like "encrypted SMS"! You're free. Using it as something more than encrypted SMS requires persistent message history between devices. > metric fuckton of messages “More than 45 days” is a
13.
▲
by
goldsteinq
9mo ago
> If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that. I want secure messaging, not encrypted SMS. I want my messages
14.
▲
by
goldsteinq
9mo ago
According to the official Matrix website ( https://matrix.org/ecosystem/clients/element-x/ , https://matrix.org/ecosystem/clients/element/ ): threads, voice calls, spaces, SSO.
15.
▲
by
goldsteinq
9mo ago
> some Element users are still stuck on the Classic app, unaware that Element X exists This sounds really arrogant. Element X _still_ lacks a lot of features, saying that the only reason to use classic Element is that you must be unaware
16.
▲
by
goldsteinq
9mo ago
I wanted to make a more descriptive title, mentioning that Microsoft uses its own program for `curl` command, but ran out of characters.
17.
▲
by
goldsteinq
9mo ago
> Also, for OP: Do you mean "access to the system it runs on"? Because I'm pretty sure it doesn't run with "SYSTEM" access (as in privileged user). Yeah, I mean “access to the system”. It’s not the same as u
18.
▲
PowerShell's curl runs JavaScript code with system access
(support.microsoft.com)
13 points
by
goldsteinq
9mo ago
|
8 comments
19.
▲
by
goldsteinq
9mo ago
Equivalent of $5-6 monthly
20.
▲
Maintaining an open source software during Hacktoberfest
(crocidb.com)
3 points
by
goldsteinq
9mo ago
|
0 comments
21.
▲
by
goldsteinq
9mo ago
I am subscribed to recurrent donations to Thunderbird. I would pay for Firefox if it was focused on privacy and customizabilty, not telemetry and LLMs.
22.
▲
by
goldsteinq
11mo ago
So the first scenario is also basically “automatic scanner bypass”? That answers my question, yes. > making a tar file that when inspected looks fine Am I correct in understanding that manual inspection would reveal a nested .tar archive
23.
▲
by
goldsteinq
11mo ago
Is this LLM-generated? The style is somewhat off (long lists repeating the same thing over and over, calling random meta statements “theorems”), and the link to the repo is completely broken.
24.
▲
by
goldsteinq
11mo ago
Hi! Could you elaborate on the first attack scenario? > Target: Python package managers using tokio-tar (e.g., uv). An attacker uploads a malicious package to PyPI. The package's outer TAR contains a legitimate pyproject.toml, but t
25.
▲
by
goldsteinq
1y ago
I’m still not sure how do you even compromise a key without also compromising message history. The keys are stored on-device, along with associated history. If attacker has access to the keys, they also have access to all the previous messa
26.
▲
by
goldsteinq
1y ago
So non-browser clients have no feasible way of checking certificate revocation anymore.
27.
▲
by
goldsteinq
1y ago
In Firefox, I get a new permissions request every time I join a Jitsi call.
28.
▲
by
goldsteinq
1y ago
I’m not surprised that the number is that high, but I’m surprised they write it outright instead of hiding it in the “salaries” section.
29.
▲
Premium accounts to fund the matrix.org homeserver
(matrix.org)
13 points
by
goldsteinq
1y ago
|
2 comments
30.
▲
by
goldsteinq
1y ago
It’s kinda hard to find out from this website who do you trust in this model. I think the answer is that you trust the hardware manufacturer: the initial attestation uses private key built into the hardware, and NVIDIA could, in principle,
More ›