Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zahllos
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
zahllos
13d ago
In the UK Nominet (the UK domain namr registrar - nic.uk) only permitted 3rd domains - co.uk. org.uk, me.uk. then there were "prove your status" ones such as ltd.uk, plc.uk and ac.uk plus ones like gov.uk, mod.uk, sch.uk, nhs.uk e
2.
▲
by
zahllos
2mo ago
I implemented something similar for my bot defences. If headless chrome is detected you still get the same anubis-style PoW but even if you submit the right answer you get rejected.
3.
▲
by
zahllos
2mo ago
I've never done anything "serious" with haskell, just small personal projects. Mostly this is because I've found the ecosystem to be a pain - when I was trying stack stack was the thing to use but from what I can tell gh
4.
▲
by
zahllos
4mo ago
Also true. The BOMs though are annoying.
5.
▲
by
zahllos
4mo ago
Additional Detail: it is specifically utf-16 little endian when a byte order mark is not used, which is the opposite of the recommended choice of big endian in the RFC. Worse are the byte order marks required to support both endians that en
6.
▲
by
zahllos
4mo ago
There is ARM SystemReady in a couple of flavours, one of which is UEFI: https://documentation-service.arm.com/static/68512137d12d1a1... While I'm not exactly enthused about UEFI I prefer this to android's for
7.
▲
by
zahllos
5mo ago
Not the OP, but: -march says the compiler can assume that the features of that particular CPU architecture family, which is broken out by generation, can be relied upon. In the worst case the compiler could in theory generate code that does
8.
▲
by
zahllos
6mo ago
No unfortunately it is not correct. You can supply a different CA to verify client certs against to what is given in server hello. There's no need for them to be related at all. Critically you probably want to use a custom CA for clien
9.
▲
by
zahllos
6mo ago
I agree. I wanted a particular tool to support my development. The libraries are well known and understood by people who work in text editors, but this is not my area and I have a busy life. Simply working out what I needed to know produced
10.
▲
by
zahllos
8mo ago
The windows assessment and deployment kit is what you need, with the windows pe add-on: https://learn.microsoft.com/en-us/windows-hardware/manufactu... You should be aware there's a 3 day limit to uptime, the
11.
▲
by
zahllos
10mo ago
I understand his concern perfectly. What I am saying is that his concern is not mitigated at all by the presence or absence of an IETF standard. This is going to happen anyway (non hybrid) at least inside USG because that's what NSA wa
12.
▲
by
zahllos
10mo ago
I guess that would have been Silverman etc? That's true there was NTRU before reductions were shown. Good call.
13.
▲
by
zahllos
10mo ago
Source for this loss of security? I'm aware of the MATZOV work but you make it sound like there's a continuous and steady improvement in attacks and that is not my impression. Lots of algorithms were broken, but so what? Things li
14.
▲
by
zahllos
10mo ago
Sure. I'm not American either. I agree, maximum scrutiny is warranted. The thing is these algorithms have been under discussion for quite some time. If you're not deeply into cryptography it might not appear this way, but these ar
15.
▲
by
zahllos
10mo ago
Indeed. Dual_EC was a NOBUS backdoor relying on the ECDLP. That's fair. My point was more that it looked suspicious at the time (why use a trapdoor in a CSPRNG) and at least the possibility of "escrow" was known, as evidenced
16.
▲
by
zahllos
10mo ago
SHA-2 was designed by the NSA. Nobody is saying there is a backdoor.
17.
▲
by
zahllos
10mo ago
I will reply directly r.e. the analogy itself here. It is a poor one at best, because it assumes ML-KEM is akin to "internetting without cryptography". It isn't. If you want a better analogy, we have a seatbelt for cars right
18.
▲
by
zahllos
10mo ago
The commentor means Dual_EC, a random number generator. The backdoor was patented under the form of "escrow" here: https://patents.google.com/patent/US8396213B2/en?oq=USOO83.9... - replace "escrow&q
19.
▲
by
zahllos
10mo ago
ML-KEM and ML-DSA are not "known weak". The justification for hybrid crypto is that they might have classical cryptanalytical results we aren't aware of, although there's a hardness reduction for lattice problems showing
20.
▲
by
zahllos
10mo ago
"The government" already have. That's what CNSA 2.0 means - this is the commercial crypto NSA recommend for the US Government and what will be in FIPS/CAVP/CMVP. ML-KEM-only for most key exchange. In this context, i
21.
▲
by
zahllos
10mo ago
In context, this particular issue is that DJB disagrees with the IETF publishing an ML-KEM only standard for key exchange. Here's the thing. The existence of a standard does not mean we need to use it for most of the internet. There wi
22.
▲
by
zahllos
10mo ago
Ah no I was just being snarky and not at you. We're all missing (hyper)text markup language as the UI markup layer, plus js. We previously had some kind of alternative "load app from internet" but the runtimes were external (
23.
▲
by
zahllos
10mo ago
We could call it Flash. Or Java Applets.
24.
▲
by
zahllos
10mo ago
Yeah. No revenue. Nobody wants to hear about revenue! It's not about how much you make, it is about how much you're worth and who is worth the most? Companies that lose money.
25.
▲
by
zahllos
11mo ago
End to end could still be default for 1-1 chats. Multi device support turns this into a small group chat but it is doable (Wire did it this way afaik; I think Signal does too). Small groups could likewise be supported. I take the point that
26.
▲
by
zahllos
1y ago
You can sort of look up a birth certificate but the service isn't designed for that. It is here: https://www.gro.gov.uk/gro/content/ This is where you get certified copies should you ever need that for inte
27.
▲
by
zahllos
1y ago
I guess we'll have to wait for specifics. Unfortunately "it will have inclusion at its core" doesn't really say much. They are considering enabling its use for more than just work, so what happens when my grandma forgets
28.
▲
by
zahllos
1y ago
Please don't give them ideas!
29.
▲
by
zahllos
1y ago
One of my concerns with this is the assumption that every adult has a suitable smartphone. Do the government plan to hand them out?
30.
▲
by
zahllos
1y ago
Crucial point on this though: it isn't going to be mandatory. Swiss ID cards are not mandatory either although in practice not having one can be inconvenient. Next year Swiss ID cards will come in two variants: biometric if you want to
More ›