Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
matthew9219
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
matthew9219
3y ago
Do you think these statues are hate speech or obscenity?
2.
▲
by
matthew9219
3y ago
Not sure this is the technology at play here, but ATL Server, a C++ based Microsoft web technology discontinued in 2008 basically supported two files extensions - .srf and .dll. See e.g. https://github.com/redpower1998/
3.
▲
by
matthew9219
3y ago
How would it hurt you? The American Heritage Dictionary gives three definitions of hurt: > 1. To cause physical damage or pain to (an individual or a body part); injure. > 2. To experience injury or pain to or in (an individual or a b
4.
▲
by
matthew9219
3y ago
They do. The problem is drug addiction. If you give drug addicts free houses, eventually the word gets out, and then even more drug addicts move to your state. Eventually you find yourself like California - spending an immense amount of mon
5.
▲
by
matthew9219
3y ago
People addicted to heroin don't achieve their potential or their aspirations. The compassionate thing to do for drug addicts is to help them stop being addicted to drugs, not give them an apartment where they can do drugs without bothe
6.
▲
by
matthew9219
3y ago
It's a bit more complex than that. At the surface, it's true - only 15% of homeless people in Seattle lived out of county before becoming homeless. But a deeper look shows as many as 30% more never really could afford housing - th
7.
▲
by
matthew9219
3y ago
I didn't quite speak clearly and so let me try to clarify. It's the opinion presented as opinion containing opinion presented as fact :). In examples: - "summer is the best season" is an opinion - "summer has the hi
8.
▲
by
matthew9219
3y ago
Seems specious. Democratically elected representatives said it was to encourage the investment of capital as they wrote the laws, and then got reelected by the voters. You can say the representatives were lying and the voters didn't ca
9.
▲
by
matthew9219
3y ago
The discussion is about the quote in the article, not about what the previous commentator said.
10.
▲
by
matthew9219
3y ago
It's an understandable position yes. It's not quite so understandable to me that somebody would believe that position to be an inherent truth ("truly owe") rather than just a position. Capital gains taxes have historical
11.
▲
by
matthew9219
3y ago
Fwiw (tangent), I don't necessarily believe either of those instances were cosmic-ray induced bit-flips. I'd have to dig up the study, but I read a study once that more or less concluded "cosmic-rays are more common in memory
12.
▲
by
matthew9219
3y ago
You are looking for a debate, I think. It's the whole thread. You're nerd sniping. It's classic. You're not a fan of DNSSEC and prefer CT. When faced with examples where CT doesn't cut it, you refuse to discuss the
13.
▲
by
matthew9219
3y ago
Of course it does. CT trust relies on root programs removing bad CAs and root programs and security researchers sharing information about bad CAs with root programs. The root programs, CA, and security researchers are colloquially "the
14.
▲
by
matthew9219
3y ago
Do you believe CT protects set-top boxes against surveillance from nation state actors who compromise your router? Yes or no, if you don't answer, you're not engaging in good faith.
15.
▲
by
matthew9219
3y ago
> Meanwhile if DNSSEC's vision is ever fully realized, you will lose that control entirely. There is no CT there, and even if it was build somehow it will be useless as it has no "teeth" This is a false dichotomy. DNSSEC s
16.
▲
by
matthew9219
3y ago
Web PKI so strong that we recommend not using it for critical scenarios.. /s It's late and I maybe haven't been super constructive here, but I think when you try to write out the actual assumptions behind CT as the whole solu
17.
▲
by
matthew9219
3y ago
The example I gave was a router or gaming system updating itself (e.g. using CUrl) not a full browser. Don't strawman please - if my argument is as weak as you say, you shouldn't need to. I want a version of Web PKI strong enough
18.
▲
by
matthew9219
3y ago
It's the argument I made at the top: > The fundamental difference is that with TLS you have to trust ALL certificate issuers, but with DNSSec you only have to trust your TLD and your certificate issuer. It's probably fair to sa
19.
▲
by
matthew9219
3y ago
That's just not what's happening. Reread the conversation. I started from here: > Certificate transparency is cool, but it's not clear it really works for many classes of devices Smart TVs aren't some gotcha I'm
20.
▲
by
matthew9219
3y ago
The crucial difference is who decides which cryptographic entities to trust. With TLS and CT, the browser defines the list of entities and if 3 or more of those entities live in a hostile country, you can be compromised. With DNSSec and CAA
21.
▲
by
matthew9219
3y ago
Admittedly, the US is a bit of a special case because of ICANN. Better examples are probably Saudi Arabia, Israel, Australia, Russia, etc.
22.
▲
by
matthew9219
3y ago
That page explains that Chrome (which is best in class here - most IOT devices don't do any of this stuff) fails open: > If the installed version of Chrome has not applied security updates and has been unable to obtain an updated CT
23.
▲
by
matthew9219
3y ago
> you can't fake the SCT entries without having access to the CT private keys. So... Governments like the US and China can fake the entries by using their police forces to seize the private keys? SCT has the same set of problems as
24.
▲
by
matthew9219
3y ago
> Forging a ‘fake CT log’ isn’t possible, either Why do you think this isn't possible?
25.
▲
by
matthew9219
3y ago
If you wanted to use your words to explain why you think that, that might be more constructive. I could well respond "yes, it does work" but that wouldn't be useful. I know you're an expert in the space and might appreci
26.
▲
by
matthew9219
3y ago
Clients get pre certificates (which are portions of the log) as claims in certificates. It's correct that they never download the whole log - I'm simplifying for clarity, not out of lack of understanding. The fact remains - an adv
27.
▲
by
matthew9219
3y ago
The client has to get the CT log from somewhere, like an update channel (typically TLS). An attacker would compromise both the target and the process by which the client gets CT log updates. Such an attack would be detected if some clients
28.
▲
by
matthew9219
3y ago
Everybody has to do business somewhere. Nobody can prevent the government in whose territory they do business from compromising them. The question is whether you can be compromised by all governments (TLS) or just your government (TLS+DNSSe
29.
▲
by
matthew9219
3y ago
In the attack DNSSec prevents, a client is compromised by a cert that doesn't appear in the CT logs, so infrastructure monitoring is irrelevant.
30.
▲
by
matthew9219
3y ago
Somebody has got to check the logs and report violations. Chrome does, so CT works mostly for the world wide web, because all websites want to work in Chrome. For a device like a router, if the router doesn't check the logs itself, and
More ›