Live data from Hacker News

Viewing profile — Veserv

Veserv

HN member
Joined
Sat, May 04, 2019, 7:02 PM UTC
HN karma
5,022
Public activity
1,525 items

About Veserv

No profile information was provided.

Recent public activity

  1. comment
    Comment #49202894

    Shadow memory mappings are only needed when you do not have hardware virtualization or when doing nested virtualization. From the page: "it can threaten the guest-host isolation of…

  2. comment
    Comment #49076130

    You can prove a program is correct and terminates for all inputs and, absent a hardware or other assumption vulnerability that breaks the abstract machine assumptions, there would …

  3. comment
    Comment #49075926

    > You claimed without evidence, or more accurately, bad evidence, confusing RTOS with "reliability and security." That sentence is grammatical nonsense. Try again to articulate you…

  4. comment
    Comment #49074692

    You have a serious misunderstanding of the consequences of the undecidability of the Halting Problem. The Halting Problem says you can not prove the precise halting behavior in eve…

  5. comment
    Comment #49073593

    You did not claim that microkernels were less commercially successful. You claimed that microkernels suffer from the same security problems that plague commercial monolithic kernel…

  6. comment
    Comment #49061279

    > history has proven What history? What proof? What evidence? What commercial microkernel systems are you referencing that suffer from trivial LPEs? Or whole system DoS from unpriv…

  7. comment
    Comment #48925432

    Have they figured out how to implement free() yet? Last I looked you need a garbage collector to deallocate at which point you might as well use Java which is actually designed for…

  8. comment
    Comment #48886591

    Sure, this is why virtualization is a valuable feature, it is just not the basis of security/isolation. One of the points I am making is that when deploying on a modern multi-tenan…

  9. comment
    Comment #48886187

    Yes, you do enjoy evading the argument. You continuously point at implementation and operational model differences as proof that virtualization is the key factor. Theo's argument i…

  10. comment
    Comment #48885819

    Cool, show me a LPE in a seL4 deployment. Do you believe that is easier or harder than finding a KVM escape? Since you are varying the security basis, implementation, and operation…

  11. comment
    Comment #48885740

    Great, then falsify it. Point at a system with the same operational model as KVM-based multi-tenant systems with large numbers of platform vulnerabilitys. Let us review a standard …

  12. comment
    Comment #48885162

    Virtualization is responsible for effectively none of those security benefits. It is the reduction to a smaller “kernel” that is responsible. If you applied the same design and ope…

  13. comment
    Comment #48864556

    Claims do not support themselves. The claim is unsupported by evidence and thus the burden of proof is on them or you to produce that evidence. As the author and implementer of the…

  14. comment
    Comment #48798498

    Writers make conscious trade offs between time, cost, feasibility. Are writers language engineers? Literally everybody makes trade offs, that is not a distinguishing aspect. I am c…

  15. comment
    Comment #48797585

    To add on, engineering is about objective guarantees to meet objective responsibility. This bridge is rated for 10 tons. This chemical process produces 1 mg 99% purity crystals. Th…

  16. comment
    Comment #48782717

    Why do we judge an organization by their leader and head executive who has complete control over direction and operations? Who individually has a controlling interest which can and…

  17. comment
    Comment #48778085

    To add on, that is just ~40 million m^3 of water. Desalination, turning unlimited sea water into fresh water which is one of the most expensive sources of fresh water, is ~0.50 $/m…

  18. comment
    Comment #48738259

    Capability passing and dependency injection are just convoluted ways to describe passing parameters instead of using globals. Capability passing is just extending that to the level…

  19. comment
    Comment #48649824

    No tzdata. When a time becomes the past you canonicalize it to the UTC, or better yet TAI, second it occurred at. As in, this occurred N cesium atom vibrations after the zero times…

  20. comment
    Comment #48564897

    Just to clarify are you saying a 1 gigabyte/s link or a 1 gigabit/s link? And you are seeking to saturate a 10 gigabyte/s link or a 10 gigabit/s link?

  21. comment
    Comment #48559723

    Obviously. The cubicle was invented as a more humane and private alternative to the standard open plan office of the 1960s, let alone hotdesking which is somehow even more of a fun…

  22. comment
    Comment #48529638

    > One can make the argument that the requirements is a much smaller surface to verify than that of the entire program. This argument is unfortunately empirically false for any prog…

  23. comment
    Comment #48529496

    Not at all. WASM is a repudiation of the thesis, not a confirmation. The thesis is that javascript-compatible source will be the substrate of the future. A javascript engine, thoug…

  24. comment
    Comment #48521993

    Huh? It is a argument against government backdoor access to messages. The government demonstrated that they are unqualified to keep data securely under their control. As such, any …

  25. comment
    Comment #48510705

    Nope. Those accusations were proven false and the people who made them have lost all their credibility. It was just a smear campaign by Tesla promoters so effective that here you a…