Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hyper_reality
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
hyper_reality
5y ago
Reminds me of this from last week: https://catinthehatattack.com/
32.
▲
by
hyper_reality
5y ago
True, but less than half of world countries are covered by street view and it's possible for a human to learn the distinctive metadata features of every single one, together with all the common roadside features like poles, road markin
33.
▲
by
hyper_reality
5y ago
Interesting post, but I disagree with the conclusion that with a bit of work AI could take down the best Geoguessrs. The best players already take into account all the metadata like camera quality and distinctive features of the Google car.
34.
▲
by
hyper_reality
6y ago
This is being discussed in CryptoHack Discord. We are struggling to understand the paper, it is written in a very dense style and the difficulty is compounded by the fact that lattice problems can be a challenging topic even for cryptograph
35.
▲
Debian Discusses Vendoring–Again
(lwn.net)
3 points
by
hyper_reality
6y ago
|
0 comments
36.
▲
by
hyper_reality
6y ago
https://projectbullrun.org/dual-ec/ext-rand.html contains more information about the TLS Extended Random proposal and how it relates to the backdoored Dual EC DRBG. Also Eric Rescorla, the other author of the Extended
37.
▲
by
hyper_reality
6y ago
The best I could find is the "false-signaling theory of hypocrisy": social psychology research which demonstrates that "people judge hypocrites negatively-even more negatively than people who directly make false statements ab
38.
▲
by
hyper_reality
6y ago
"Just fork" underestimates the huge amount of effort it requires to develop a modern browser that stays up to date with the latest web standards. There's a reason why even Microsoft's browser now is based on Chromium.
39.
▲
by
hyper_reality
6y ago
I think the article somewhat misconstrues the reasons why maintainers are thinking of dropping support for packaging Chromium. Maintaining the Chromium package is an unusually laborious task, with a lot of releases, and huge compile times.
40.
▲
by
hyper_reality
6y ago
Great writeup on how to do a black box "cold-boot stepping attack" ( https://www.usenix.org/system/files/conference/woot17/woot17... ) on an encrypted HDD. This is why the recommendation is to us
41.
▲
by
hyper_reality
6y ago
Return Oriented Programming (ROP) can bypass the non-executable stack protection, since existing "gadgets" from program memory are executed rather than attacker-provided shellcode. However the stack protection will probably requir
42.
▲
by
hyper_reality
6y ago
Paged Out is great, Rafale appears to be offline though (and French only).
43.
▲
by
hyper_reality
6y ago
What a classic! Phrack stopped publishing some time ago but the world of security ploughs on, who can recommend similar modern resources to Phrack? Here's a few I'm aware of: https://www.alchemistowl.org/pocorgtfo&
44.
▲
by
hyper_reality
6y ago
That was a typo, I fixed it, thank you.
45.
▲
by
hyper_reality
6y ago
The article notes that in South Korea, "from next year, cash bonuses of 2m won (£1,320) will be paid to every couple expecting a child, on top of existing child benefit payments". These cash awards for having children being paid b
46.
▲
by
hyper_reality
6y ago
This was very nicely expressed, I would read a book in this style! By the way, I'm not sure the hnchat.com service linked in your profile works any more?
47.
▲
Ask HN: What are the fundamental “must read” papers on software security
6 points
by
hyper_reality
6y ago
|
3 comments
48.
▲
by
hyper_reality
6y ago
How do you know these aren't honeypots?
49.
▲
by
hyper_reality
6y ago
This is impressive work. First it shows how the top CTFs can showcase the state of the art in terms of exploitation. It's hard for anyone to argue that the CTF scene does not reflect the "real world" when it is producing soli
50.
▲
A Swiss parliamentary investigation into the Crypto AG case
(electrospaces.net)
3 points
by
hyper_reality
6y ago
|
0 comments
51.
▲
by
hyper_reality
6y ago
I've seen the opposite. Many of the very best security researchers are also top performers in CTFs (to give one example, Orange Tsai). It's hard for me to see how your correlation works unless "cybersecurity industry" is
52.
▲
by
hyper_reality
6y ago
I'm fed up of people repeating this over-simplified putdown of WHO on HN. The advice about masks was on their website on March 2020 largely because they were worried about mass public buying of masks, leaving a shortage for frontline m
53.
▲
by
hyper_reality
6y ago
This is in response to the issue last week where slowness of Apple's OCSP responders caused hangs in apps launching. It was a bad look for privacy-conscious Apple especially considering that basic OCSP queries are unencrypted HTTP requ
54.
▲
by
hyper_reality
6y ago
Agreed, and furthermore the article calls the privacy arguments "far-fetched" and "dogwhistles", while only tackling a strawman version of the other side's view. The article doesn't for instance investigate the
55.
▲
by
hyper_reality
6y ago
Nice list, here are suggestions for improving a few of the commands: Generate Random Passwords >_ < /dev/urandom tr -dc _A-Z-a-z-0-9 | head -c6 This produces a 6-character password which only has 35 bits of entropy
56.
▲
by
hyper_reality
6y ago
I don't think you can dismiss the beef/submarine by-products argument without further analysis. If the beef by-products are being sold by cow farmers for a profit, that makes slaughtering a cow more profitable for farmers. It coul
57.
▲
by
hyper_reality
6y ago
Similar opinions are expressed by a number of Green political groups around the world, and I've also struggled to reconcile their commitment to slowing global climate change with their rejection of nuclear power. Ignoring the typical a
58.
▲
by
hyper_reality
6y ago
The extent of Stasi surveillance and repression was profound and explains why Germans take privacy more seriously than other Western democracies. It's scary to imagine what the Stasi would have been able to accomplish with today's
59.
▲
Postcards from the post-XSS world (2011)
(lcamtuf.coredump.cx)
1 points
by
hyper_reality
6y ago
|
0 comments
60.
▲
by
hyper_reality
6y ago
Yes, to take predictions seriously, we should ask the visionary for a rough timescale. And we should also ask not just them but their peers on how likely they think the prediction is to come true. It's not impressive to identify an exi
More ›