Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mjg59
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
mjg59
9d ago
In the given case - you want to bind communication to a given confidential compute instance, which means you want to be able to ensure that the communication is coming from within the confidential compute instance, which means you want to b
2.
▲
by
mjg59
10d ago
This feels like a somewhat odd design choice - you have a TEE, most TEEs (outside TPMs) are fast so there's little overhead in pushing your signing through there, why bother with short-lived credentials instead of just attesting to pri
3.
▲
by
mjg59
10d ago
I helped design the attestation framework for https://docs.cloud.google.com/transfer-appliance/docs/4.0/re... - the goal was to ensure that the device you're about to copy a bunch of sensitive informatio
4.
▲
by
mjg59
10d ago
A dedicated HSM will give you stronger trust that the private key material can't be extracted, but there's no real way to bind an HSM to a specific client and that's a very easy thing to do in the vTPM case.
5.
▲
by
mjg59
10d ago
You didn't really go into actually verifying the machine identity - obviously if you have a trusted mechanism to do that in advance then that's easy enough, but otherwise you'd want something like https://github.co
6.
▲
by
mjg59
10d ago
The benchmarks are from GCP, where the vTPM is implemented in the hypervisor rather than on something that's plausibly an 8051[1]. Doing this on actual client hardware is going to be a bunch slower. [1] Typically ARM these days, but mo
7.
▲
by
mjg59
24d ago
I teach OS security for a masters course. I don't know where my students are for any given semester - it's a mixture between experts who need a certification (I have taught someone who literally wrote the book on a major OS's
8.
▲
by
mjg59
28d ago
I wholeheartedly agree. Making it more difficult to obtain GPLed source code than it was before is fundamentally a dick move.
9.
▲
by
mjg59
28d ago
Oh, I agree there.
10.
▲
by
mjg59
28d ago
They are, which is how they know how long it's taking.
11.
▲
by
mjg59
28d ago
My personal website isn't customarily used for software interchange, but http is. I think getting into discussions about which websites are acceptable and which aren't feels like a bad place.
12.
▲
by
mjg59
28d ago
But nobody has done this, which is why it's a problem for Graphene
13.
▲
by
mjg59
28d ago
1) floppy disks are not customarily used for software interchange - where they are still used (aircraft software updates, bits of San Francisco's streetcar infrastructure) it's weird enough to be remarked upon. 2) the cost to Goo
14.
▲
by
mjg59
28d ago
If distributing under 3(b) then it's legitimate to only supply source on request. Historically source has been distributed without revision control history or metadata and been considered acceptable (the source tarballs on gnu.org are
15.
▲
by
mjg59
28d ago
The license requires that it be distributed on a medium customarily used for software interchange, and I don't think you'd stand a good chance of arguing that paper satisfies that.
16.
▲
by
mjg59
28d ago
Yes, but that person still needs to file a request and wait several days
17.
▲
by
mjg59
29d ago
My experience is that they're better than me at a lot of the process, so probably worse than someone who's a full time reverse engineer but as good as or better than most. They'll definitely get some small details wrong that
18.
▲
by
mjg59
1mo ago
Originally added to the upstream compose map in https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/f052... , and replaced in https://gitlab.freedesktop.org/xorg/lib/lib
19.
▲
by
mjg59
1mo ago
Dialup systems typically spent most of their time offline. If you wanted to connect to one over IP you'd need some way to get it to dial back up to the ISP, and then some way to get the new address it'd ended up on.
20.
▲
by
mjg59
1mo ago
https://lock.cmpxchg8b.com/wordperfect.html describes getting the UNIX release of Word Perfect running on modern Linux. There was a SCO release of Word in 1990, so plausibly that could be fudged into a similar setup?
21.
▲
by
mjg59
2mo ago
The refresh token is often going to be good for a week, even if the access token isn't.
22.
▲
by
mjg59
2mo ago
> at some point credentials will pass to your llm of the week. How?
23.
▲
by
mjg59
2mo ago
No they don't - you're still giving the agent a static token that can be exfiltrated and used elsewhere.
24.
▲
by
mjg59
2mo ago
17-bit distributed a lot of redistributable stuff - in this case it's listed as disk 1423 in their collection
25.
▲
by
mjg59
2mo ago
Nor was it in the final versions of Maemo, if you want to be pedantic.
26.
▲
by
mjg59
2mo ago
"The way Apple destroyed the competition was by creating so much hype around their product that they could demand concessions from carriers" is very easy to read as people buying iPhones because of hype and not because they were m
27.
▲
by
mjg59
2mo ago
The Maps experience on the iPhone was sufficiently better than on any other platform that it was justification in itself for many people to buy one. But you're also massively underselling the media aspect - iTunes integration was compe
28.
▲
by
mjg59
2mo ago
Oh, come on. Yes, compared to any modern device the iPhone was a piece of shit (no cut and paste when shipped? No 3G?), but as someone who owned a high end S60 device at the time, the iPhone was a breath of fresh air - the Maps experience o
29.
▲
by
mjg59
2mo ago
The N900 was never really intended to be a mass market device, more something to attract enthusiast excitement and serve as a reasonable developer platform - so in that respect it being kind of half assed isn't too much of a surprise.
30.
▲
by
mjg59
2mo ago
And no multitouch.
More ›