Viewing profile — Natanael_L
Natanael_L
HN member- Joined
- Tue, Jun 17, 2014, 6:38 PM UTC
- HN karma
- 1,262
- Public activity
- 1,089 items
- HN profile
- View on Hacker News ↗
About Natanael_L
@natanael.bsky.social
Recent public activity
-
comment
Comment #46414597
What's your usecase here? Internal or external messaging?
-
comment
Comment #46414500
There's no clear segmentation. There's symmetric and asymmetric primitives (and stuff that doesn't fit into these like ZKP), algorithms, protocols, research in many different types…
-
comment
Comment #46414374
The fact that every email encryption integration exports secure context messages into insecure contexts when decrypting (which is how encrypted messages end up cited in plaintext) …
-
comment
Comment #46414321
You need a private PKI, not keyring. They're subtly different - a PKI can handle key rotation, etc. Yes there aren't a lot of good options for that. If you're using something like …
-
comment
Comment #46414207
What you described IS WHY age is the better option. GPG's keyring handling has also been a source of exploits. It's much safer to directly specify recipient rather than rely on thi…
-
comment
Comment #46414141
Then your next best bet is Matrix.org. Not to the same security standard as Signal, but if you don't have a specific threat against you then it's fine.
-
comment
Comment #46414000
Asking for an equivalent to GPG is like asking for an equivalent of a Swiss knife with unshielded chainsaws and laser cutters. Stop asking for it, for your own good, please. If you…
-
comment
Comment #45790421
C2PA has the problem that it has a ton of optional metadata support and no well-defined strict validation procedure, so it's trivial to make fake photos appear valid using currentl…
-
comment
Comment #45790358
Also, the RPi is the wrong kind of hardware for attestation, at least use something like USB Armory which provides a user programmable ARM TrustZone environment. Since USB Armory s…
-
comment
Comment #42637692
... At which point the only new data that chatgpt can reliably scrape is its own answers...
-
comment
Comment #41972242
Everything is open source so yes you can, it's mostly a question of practicality. There's already third party clients, account hosting servers, etc, as well as different apps build…
-
comment
Comment #41972177
Before Musk, Twitter used to fight those requests. The platform can not be called better, with more bugs and errors than ever. Why don't they apply those rules to Republicans? Why …
-
comment
Comment #41958829
Musk is reposting actual neonazi accounts
-
comment
Comment #41958823
Most of that doesn't deserve to be called an improvement. That message encryption is one of the worst designs I've ever seen. The algorithm isn't open enough that anybody can see i…
-
comment
Comment #41958798
It's used in a not particularly advanced way - bluesky uses repositories per each user for all their public social activity (posts, likes, etc) and it creates a Merkle tree as an i…
-
comment
Comment #41958496
It's currently built into the applications, not configurable by default. It's preferable if everybody in a thread / space / community uses the same one because otherwise difference…
-
comment
Comment #37574409
Signal relies on the client program to not be compromised to keep conversations secret
-
comment
Comment #36352918
There's a few self hosting forums, and there's Lemmy / Kbin for federated ones
-
comment
Comment #36100798
Since you own the console you dump the keys from, nope
-
comment
Comment #26721164
Re forms: I did primarily mean rather simple ones (like say attendance forms), but there's a bigger argument here; This type of API copyright would post likely not just mean the pa…
-
comment
Comment #26706647
The irony is that what they claim happened is instead what would have happened only if the case was resolved in the opposite direction. Everybody having to pay for API licenses for…
-
comment
Comment #26706539
As others has said elsewhere, the jury rules on facts and judges rules on law. SCOTUS are judges. Under one interpretation of law, the most recent jury findings of fact held that G…
-
comment
Comment #26706050
How often does the API itself exceed the level of creativity of uncopyrightable plain lists of facts? It's not clear to me that it should be considered copyrightable on its own, es…
-
comment
Comment #26705511
One of the issues here is that it's not even clear under which license the API should be covered. Does the existing software license also cover the API, or must it be explicitly de…
-
comment
Comment #26700450
Their failure to take control over those markets is not the same as a failure to cause damage. They slowed down development of web standards by many many years, as one example.