Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jmsgwd
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
jmsgwd
2mo ago
If the database is not local, and there’s no authentication, what stops someone else from accessing it inappropriately?
2.
▲
by
jmsgwd
4mo ago
> The idea that AWS's services are fully regionalized or isolated has always been a myth. This is highly misleading. It's true that there's a handful of global AWS services - but only their control planes operate from a si
3.
▲
by
jmsgwd
5mo ago
But the fact that it's so boring is interesting.
4.
▲
by
jmsgwd
5mo ago
> In the beginning there was a cron I thought you were paraphrasing John 1:1 for a moment! [1] [1] https://en.wikipedia.org/wiki/John_1:1
5.
▲
by
jmsgwd
8mo ago
How else could you represent piano roll data than as a stream of events? I thought that was ubiquitous since the invention of MIDI. Are you saying other sequencers are unable to render the same data as piano roll and score?
6.
▲
by
jmsgwd
9mo ago
Are you referring to Windows Kerberos here or NTLM?
7.
▲
by
jmsgwd
9mo ago
That came across more snarky than I intended! Let me rephrase: for the majority of users, the usability and resilience benefits of synced credentials are enormous, and the security costs are marginal at best. But this rests on a number of a
8.
▲
by
jmsgwd
9mo ago
>Huh interesting, how does that work? I thought the way yubikeys operate the keys are generated on-device and are impossible to remove, and also come in limited number. I wasn't referring to hardware keys (like YubiKeys), but rather
9.
▲
by
jmsgwd
9mo ago
Just to point out, protecting a key using the secure enclave and syncing it using end-to-end encryption aren’t necessarily mutually exclusive. The security property you care about is that the plaintext key is only ever processed in use with
10.
▲
by
jmsgwd
9mo ago
There are many cross-platform password managers that sync very nicely, which would solve for the machines you control - the Windows gaming machine and Android phone. For machines you don't control, such as your employer Mac, well that&
11.
▲
by
jmsgwd
9mo ago
> I dont want an online backup. I want my credentials to only be on my computers. So now I gotta learn about which apps are ok, don't have cloud synching If an "online" password manager uses end-to-end encryption, then the
12.
▲
by
jmsgwd
9mo ago
OK but you'd still be able to use the open source "password manager" to export the keys - which solves the issue lapcat raised in this thread - even if relying parties blocked it for authentication, which would be a separate
13.
▲
by
jmsgwd
9mo ago
Once "secure credential exchange" becomes supported by commercial credential managers, what's to stop someone implementing an open source password manager that implements the standard and allows local export in plaintext?
14.
▲
by
jmsgwd
9mo ago
OK I see what you mean. Having the ability to switch between vendors but not the ability to export your data locally (e.g. as plaintext keys) is a new meaning of "vendor lock-in" I hadn't considered before.
15.
▲
by
jmsgwd
9mo ago
> Because by default, they do, and you have to explicitly install software to let it be moved Apple's native passkey implementation doesn't require doesn't require you to install extra software, and the passkeys sync by de
16.
▲
by
jmsgwd
9mo ago
> passkeys in Safari requires iCloud Keychain This is not true - browsers including Safari support passkeys managed by third-party password managers. I'm using 1Password with browser extensions for Safari and Chrome on macOS and iOS
17.
▲
by
jmsgwd
9mo ago
Some password managers provide an offline root of trust which family members can use in this scenario. For example, 1Password tells users to print off an "Emergency Kit" which is a physical piece of paper with secret recovery code
18.
▲
by
jmsgwd
9mo ago
I keep hearing it repeated, but where does this "tied to a single device" idea come from? The default, built-for-the-masses implementation of passkeys is called "synced passkeys". They are designed to sync between all yo
19.
▲
by
jmsgwd
10mo ago
> it might take only one intelligent life form for the space to (eventually) get filled with it It wouldn't need to be intelligent to do this; it could be a self-replicating machine with no intelligence at all - which is orders of m
20.
▲
by
jmsgwd
10mo ago
Your first question is discussed in the book The Recursive Universe by William Poundstone (1984). One of the chapters asks "what is life?". It considers (and rejects) various options, and finally settles upon a definition based on
21.
▲
by
jmsgwd
1y ago
How did they do damage to the hoods of a few cars?
22.
▲
Why MCP's Disregard for 40 Years of RPC Best Practices Will Burn Enterprises
(julsimon.medium.com)
6 points
by
jmsgwd
1y ago
|
0 comments
23.
▲
by
jmsgwd
2y ago
Presumably endpoint detection & response (EDR) agents need to do things like dynamically fetch new malware signatures at runtime, which is understandable. But you'd think that would be treated as new "content", something
24.
▲
by
jmsgwd
2y ago
As an example, look at how NIST define "permission" in one of the early RBAC papers: https://nvlpubs.nist.gov/nistpubs/Legacy/IR/nistir6192.pdf Here "permission" is defined as an "
25.
▲
by
jmsgwd
2y ago
This sucks... authorization and permissions are not the same thing. Permissions are rights or privileges, which exist independently of their assignment to particular users. Authorization, on the other hand, can have two meanings - both of
26.
▲
by
jmsgwd
3y ago
I think you're mixing up the effects of _sample rate_ and _bit depth_ here! Everything you said about sample rate applies more to bit depth. Higher bit depth (bits per sample) results in a lower noise floor. When audio is digitally pro