Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmc
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
151.
▲
The Dark Web’s Top Drug Market, Evolution, Just Vanished
(wired.com)
134 points
by
nmc
12y ago
|
108 comments
152.
▲
by
nmc
12y ago
I kind of agree on the overall tone... feels like the guy is afraid of coming out Western-sided. However I would need more fact-checking to conclude.
153.
▲
by
nmc
12y ago
The Wikipedia article about Russian space dogs [0] mentioned in this post would almost deserve a HN submission by itself. [0] http://en.wikipedia.org/wiki/Russian_space_dogs
154.
▲
by
nmc
12y ago
Why the downvote? I was just checking.
155.
▲
by
nmc
12y ago
On Mac?
156.
▲
by
nmc
12y ago
Already posted yesterday: https://news.ycombinator.com/item?id=9165725
157.
▲
Java 8 Update 40 Installer App Fun
(brunerd.com)
1 points
by
nmc
12y ago
|
0 comments
158.
▲
by
nmc
12y ago
As some commenters pointed out, the installer is now an APP instead of a PKG. The original PKG is inside the APP at Contents/Resources/JavaAppletPlugin.pkg (right click on APP -> Show package contents).
159.
▲
by
nmc
12y ago
I feel puzzled. How can a WP journalist link to three blog posts about the attack, while not linking to the actual researchers' website? Here it is: https://www.smacktls.com
160.
▲
by
nmc
12y ago
The signatures should be checked client-side. As I pointed out in another comment on this page ( https://news.ycombinator.com/item?id=8896318 ), recent studies find that more and more resolvers send the RRSIGs to the client
161.
▲
by
nmc
12y ago
> It's worth keeping in mind that the Turkish government hi-jacked DNS resolvers; as-deployed DNSSEC would in no way have helped. Entirely false! ! ! Please get your facts right. [Not talking about the 2nd part of your comment] Ye
162.
▲
by
nmc
12y ago
I am distinguishing on the attacker, not the means. Sorry if that was not clear. Of course DNSSEC is vulnerable to NSLs, but that is not relevant. What is relevant is: - DNSSEC is vulnerable to nation-state attacks. - The CA system is vulne
163.
▲
by
nmc
12y ago
You are right, so let me sum up: Centralized architecture leaves DNSSEC vulnerable to nation-state attacks. This is by design. Decentralized architecture leaves the CA system vulnerable to attacks coming from any trusted CA. This is by desi
164.
▲
by
nmc
12y ago
Perseids made his counter-arguments clear in many places on this page, but your comment allows me to summarize. > If the CA signature means anything, you don't need DNSSEC. If DNSSEC is fully deployed and supported, you don'
165.
▲
by
nmc
12y ago
"signed with DNSSEC" is an ambiguous statement. You need to take into account that, while nameservers may enable DNSSEC, resolvers may: (a) validate (include the AD bit) but strip the RRSIGs (i.e. regular DNSSEC resolver) (b) om
166.
▲
by
nmc
12y ago
This "Facebook approach" almost certainly requires you to have, at least once, access to your users' non-hashed passwords. Which is widely regarded as bad security practice because your users' passwords can be compromise
167.
▲
by
nmc
12y ago
Link for the lazy: https://petitions.whitehouse.gov/response/isnt-petition-resp...
168.
▲
by
nmc
12y ago
As the article points out, this translates to: "Listen to this message, brother"
169.
▲
by
nmc
12y ago
Thank you knieveltech and chrismcb for enlightening me. You made me feel very stupid though.
170.
▲
by
nmc
12y ago
Hum, downvoted again... Not only am I bad at joking, it seems I am also bad at apologizing for it. Sorry HN.
171.
▲
by
nmc
12y ago
I was going for a joke. And, technically, I live under a roof made of tiles. However, I have never owned a TV — though, yes Jules, I am aware that there is an invention called television, and that , on that invention, they show shows. Also,
172.
▲
by
nmc
12y ago
"That's absurd!" You misspelled "American".
173.
▲
by
nmc
12y ago
> "the stethoscope is being misused, all the time" If I understand correctly, which is not likely at all, this is about the stethoscope being misused in scientific research, not in the practice of medicine, right? Then the
174.
▲
by
nmc
12y ago
Take a look at Mozilla's Shumway [0], an engine to convert Flash to HTML5, so that you need not use Flash Player anymore. This should mitigate most (if not all) of Flash's vulnerabilities. Be aware it is undergoing active developm
175.
▲
by
nmc
12y ago
Nice! This strongly reminds me of: http://pcottle.github.io/learnGitBranching
176.
▲
by
nmc
12y ago
Are you sure about that? [1] [1] http://en.wikipedia.org/wiki/Beaufortia_(plant)
177.
▲
by
nmc
12y ago
> "If the system knows [...] " He was outlining that the difference is: humans do not need the context. I do not know who Curly is, and I still got what car he drives just by reading the three-line dialog.
178.
▲
by
nmc
12y ago
I entirely agree, and I am glad you got my point. Not sure about the beauty of 'zzzz', but it certainly is a good thing to learn by doing. Nice job. You did not answer my question about spam. Are you taking measures to prevent you
179.
▲
by
nmc
12y ago
> DynDNS replacement I would disagree. This may look like a replacement from the end-user's point of view, but it does not address the real issues of DNS management: space to store all zone data, bandwidth to support requests flow
180.
▲
by
nmc
12y ago
> any captcha worth breaking is already "broken", given the existence of captcha farms Yes, but there remains a cost . The goal of a security measure is to make it so difficult/expensive that it becomes worthless doing.
More ›