Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
iscoelho
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
iscoelho
13d ago
Power usage is also very reasonable! 400GE switches and routers pull a ridiculous amount of power.
2.
▲
by
iscoelho
1mo ago
"there was a correction issue" is downplaying it. Etcd is truly the worst example of Raft. Etcd corruption and loss of quorum is extremely common in practice and the GitHub issues sit for years. The design is simple, the performan
3.
▲
by
iscoelho
1mo ago
Not speaking to their code, but to start GoBGP has the worst performance of any BGP daemon by a large margin [1]. [1] https://elegantnetwork.github.io/posts/comparing-open-source...
4.
▲
by
iscoelho
2mo ago
I don't think iPhone Upgrade Program was ever the best deal to be honest. It's just convenient.
5.
▲
by
iscoelho
2mo ago
I stand corrected! This doesn't look too bad then.
6.
▲
by
iscoelho
2mo ago
The Apple Upgrade lease model isn't even a replacement as you have to wait 24 months before upgrading. The entire point of the iPhone Upgrade Program was to make it painless to swap to the newest iPhone every year. Without that, there&
7.
▲
by
iscoelho
2mo ago
You'd be surprised to know that this strategy works quite well! Pixel bots require a hardware fake display when faced with kernel anti-cheat. They also depend on color/pattern recognition, as AI is not yet capable of operating at
8.
▲
by
iscoelho
2mo ago
Aimbot is actually very solvable! 1) When DMA is fully blocked, Aimbot resorts to being a pixel bot. 2) Once you're relying on a pixel bot, all the anti-cheat has to do is "bait" the bot. After you click the bait a few times,
9.
▲
by
iscoelho
2mo ago
> "How come replay analysis doesn’t catch more cheaters?" 1) There's too many players. 2) Closet cheaters are extremely subjective: automated & manual moderation would be full of false positives. In these cases, functi
10.
▲
by
iscoelho
2mo ago
I feel someone doesn't need to play competitive games to be able to give an honest assessment of the privacy & security risks. I'm sad I'm not seeing that honesty elsewhere in this thread.
11.
▲
by
iscoelho
2mo ago
At least in Valorant, DMA is becoming impossible due to IOMMU / Memory Integrity enforcement. The only option is becoming pixel bots. As for faking the input device: I'm sure it's possible, but I'm also sure that perfect
12.
▲
by
iscoelho
2mo ago
In my opinion, the debate about kernel anti-cheat on Windows is disingenuous fear-mongering. I'm confused why Hacker News of all places misrepresents the technical details. You can already completely compromise the average user's
13.
▲
by
iscoelho
2mo ago
That's a different type of game entirely. Private/community servers cannot be competitive at the scale of modern competitive games.
14.
▲
by
iscoelho
2mo ago
This isn't possible in Valorant. Their kernel module is extremely particular about input devices: 1) only allows a single mouse input device at a time 2) completely ignores virtual mouse input 3) flags "special"/"un
15.
▲
by
iscoelho
4mo ago
I don't disagree. Clarifying, I personally don't think this exploit is a backdoor, but rather that the negligence is enough to appear malicious. Just for fun (not saying I believe this!): Did you ever consider that a malicious Mic
16.
▲
by
iscoelho
4mo ago
If the device does not have BitLocker, WinRE already by default provides full Administrator access to the unencrypted disk via Command Prompt. > I think that level of pushback against the claims is a valid (and small) amount of "dow
17.
▲
by
iscoelho
4mo ago
If the device doesn't have BitLocker, this exploit is pointless because you can already boot any OS USB and immediately have full access to the unencrypted disk. This exploit is only ever relevant with BitLocker enabled (as a method to
18.
▲
by
iscoelho
4mo ago
1) Except that the entire premise behind BitLocker TPM's security relies on the login screen as a hard security boundary, and thus any attack on the login screen is an attack on BitLocker. It is semantics to dispute this and certainly
19.
▲
by
iscoelho
4mo ago
Considering the researcher had already reported these to Microsoft, and delayed releasing them publicly until Microsoft "pulled every childish game possible" (quote) instead of patching them, it's not unreasonable for the res
20.
▲
by
iscoelho
4mo ago
What's with all the replies on these threads downplaying this? Why is it mainly brand new accounts? What's going on here? I've seen every variant of: 1) "this is an authentication/privilege escalation bug, not a bit
21.
▲
by
iscoelho
4mo ago
That’s quite a stretch, to say the least.
22.
▲
by
iscoelho
6mo ago
But it doesn't. Full authentication bypass exploits are extremely rare and unheard of among tech giants. Maybe account takeover/recovery, sure, but full bypass? It just never happens. Microsoft goes beyond that: they've manag
23.
▲
by
iscoelho
6mo ago
I knew there was another incident that I was forgetting, insanity... I don't understand how Microsoft keeps getting away with this and everyone just forgets.
24.
▲
by
iscoelho
6mo ago
Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / A
25.
▲
by
iscoelho
8mo ago
I'd use WireGuard in that case. The main reason WireGuard is popular at all is because it is approachable. IPsec is much more complicated and is designed for network engineers, not users.
26.
▲
by
iscoelho
8mo ago
That's a large packet benchmark, not mixed packet size, and it just barely hits it. If you need consistent 10Gbps for a business use case, I would not consider that sufficient. > "To me, the bulk of Tailscale's overhead
27.
▲
by
iscoelho
8mo ago
Mikrotik can be popular for CE (Customer Edge) devices, that is correct. Those are not ISPs however, those are customers.
28.
▲
by
iscoelho
8mo ago
CE (Customer Edge) is what you are referring to. ISPs would be the PE (Provider Edge). I am aware it can be popular for SMB CE devices, however that is simply not the case for PE devices. Service Provider ISPs cannot use Mikrotik - It is im
29.
▲
by
iscoelho
8mo ago
AWS/GCE/Azure's network implementations pre-date EVPN and are proprietary to their cloud. EVPN is for on-premise. You don't exactly have the opportunity to use their implementation unless you are on their cloud, so I am
30.
▲
by
iscoelho
8mo ago
I'm curious what you classify as a business ISP? Take a look at AMS-IX, one of the largest internet exchanges: https://bgp.tools/ixp/AMS-IX 21/1020 (2%) of all peers are Mikrotik. 15 (1.4%) of those are >=
More ›