Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jeffmcjunkin
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
jeffmcjunkin
1mo ago
Often people are counting all tokens, including cached input tokens, for those more impressive "billions of tokens" quotes.
2.
▲
by
jeffmcjunkin
1mo ago
Artificial Analysis page is up: https://artificialanalysis.ai/models/deepseek-v4-pro
3.
▲
by
jeffmcjunkin
3mo ago
Confirmed: https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-wor...
4.
▲
by
jeffmcjunkin
5mo ago
Can confirm. Matching decompilation in particular (where you match the compiler along with your guess at source, compile, then compare assembly, repeating if it doesn't match) is very token-intensive, but it's now very viable: ht
5.
▲
by
jeffmcjunkin
5mo ago
Can confirm.
6.
▲
Google releases Gemma 4 open models
(deepmind.google)
1812 points
by
jeffmcjunkin
6mo ago
|
474 comments
7.
▲
by
jeffmcjunkin
1y ago
I absolutely agree that Microsoft could do better, but they are making progress in removing support entirely for broken (from a security perspective) older protocols such as NTLMv1 (which uses DES as well: more here -- https://bi
8.
▲
by
jeffmcjunkin
1y ago
The RC4 encryption type correlates to the DES hash (more commonly the "NT" hash), so PingCastle has the right warning.
9.
▲
by
jeffmcjunkin
1y ago
KeySavvy is the normal workaround for this. $99 extra cost to both sides for them to handle the title verification and shipping, and to act as the dealer to make it qualify for EV credits.
10.
▲
by
jeffmcjunkin
1y ago
Thank you, this was affecting me too.
11.
▲
by
jeffmcjunkin
1y ago
From https://personal.math.ubc.ca/~CLP/about/ : > For various reasons we have christened these notes “CLP” - none of those reasons can be found [here]( https://en.m.wikipedia.org/wiki/CLP )
12.
▲
by
jeffmcjunkin
2y ago
Recently, yes :) https://www.cnn.com/2023/08/06/us/oregon-drivers-pump-own-fu...
13.
▲
by
jeffmcjunkin
2y ago
We don't advance as a society unless people ask new questions. Having folk willing to spend some time answering those questions (in public, no less!) helps others. It's really, really damn hard to predict how advancements in one a
14.
▲
by
jeffmcjunkin
2y ago
Title needs a small fix, it should be `ping ff02::1` (with two colons) to be a valid IPv6 address, match the actual command, and match the original title.
15.
▲
by
jeffmcjunkin
2y ago
FWIW I've heard the term "dark fiber" used in both ways as well. Whenever there's ambiguity in jargon, I just avoid that jargon and use more words to describe the actual concept.
16.
▲
by
jeffmcjunkin
3y ago
That helps with "we've encrypted your data; pay us for the key" but doesn't help you with "we've made copies of your patient records, leadership's emails; pay us or we publish it all". The phrase to d
17.
▲
by
jeffmcjunkin
3y ago
Sorry, it was alluded to elsewhere: https://infosec.exchange/@iagox86/112045097519922098 There's more to the story that Rapid7 didn't want to air publicly, and none of it is good for JetBrains.
18.
▲
by
jeffmcjunkin
3y ago
Yup, silently patching (like JetBrains did) has a lot of downsides. Let alone the deception from JetBrains to the Rapid7 team. (Disclosure: I know some of the folk on the Rapid7 side, so I'm perhaps biased towards their interpretation
19.
▲
by
jeffmcjunkin
3y ago
For whatever reason, Domain Fronting is considered more of an attack behavior, used by red teamers and penetration testers. Doubling down on that behavior likely didn't seem as appealing from a PR perspective.
20.
▲
by
jeffmcjunkin
3y ago
Ahem, that's _9000_.
21.
▲
by
jeffmcjunkin
4y ago
Nearly 100% have on-prem AD (full name: "Active Directory: Domain Services"). Azure AD is a separate identity provider -- to a first approximation it's HTTPS and cookies, not Kerberos, LDAP, and Ticket-Granting Tickets that w
22.
▲
by
jeffmcjunkin
4y ago
In contrast, the vast majority of companies with Azure AD also have on-prem AD (full name: "Active Directory: Domain Services") with some type of synchronization between them. Usually this amounts to having an on-prem service that
23.
▲
by
jeffmcjunkin
5y ago
Smart cards are essentially a big Secure Enclave themselves. The whole point of a smart card (same as a military CAC, and almost the same as a TPM chip on computers) is to sign operations using the private key, without allowing export of th
24.
▲
by
jeffmcjunkin
5y ago
Title doesn't quite fit, how about this instead? "Privilege escalation with polkit: Rooting Linux with a 7-year-old bug"
25.
▲
by
jeffmcjunkin
6y ago
Bugs get patched. Features are protected, and sometimes simultaneously abused. Thank you!
26.
▲
by
jeffmcjunkin
6y ago
It strongly implies that the vendor was thoroughly compromised, in order to insert backdoors into their software (possibly amongst other attacker actions).
27.
▲
by
jeffmcjunkin
6y ago
Oregonian here. I joke that we're the Canadians of the United States. "Sorry" in regular conversation is a social nicety, very different from a sincere apology, even though the sincere apology may incorporate that same word.
28.
▲
by
jeffmcjunkin
6y ago
Despite that list, it actually works against much older devices. I've ran it with a T2i, for example, which is like three generations older than they officially support.
29.
▲
by
jeffmcjunkin
6y ago
Exactly this. Much like the Volatility Framework's psscan[1] module. [1] https://github.com/volatilityfoundation/volatility/wiki/Comm...
30.
▲
by
jeffmcjunkin
7y ago
Releasing in September: https://www.amd.com/en/products/cpu/amd-ryzen-9-3950x :)
More ›