Viewing profile — bracewel
bracewel
HN member- Joined
- Fri, Dec 05, 2014, 12:32 AM UTC
- HN karma
- 464
- Public activity
- 66 items
- HN profile
- View on Hacker News ↗
About bracewel
No profile information was provided.
Recent public activity
-
comment
Comment #45348555
This is mainly actually for testing constant-time code, rather than doing proper memory tracking (see https://www.imperialviolet.org/2010/04/01/ctgrind.html for a slightly out-of-d…
-
comment
Comment #45348445
Author of the linked CL here: we added this mostly so that we could abuse the memory initialization tracking to test the constant-time-ness of crypto code (similar to what BoringSS…
- story
-
comment
Comment #33230094
There is a fifth, incredibly common, (arguably) non-malicious possibility. You don't control the entirety of your web stack, and your hosting provider, or DNS provider, or someone …
-
comment
Comment #21206859
ah yes, I remember personally lying to congress and pushing false narratives in the media. oh wait, no, that wasn't me was it...
- story
-
comment
Comment #17710896
Note that CABF bylaws require a simple majority of browsers to vote positively for a ballot for it to pass, regardless of how CAs vote.
- story
- story
- story
- story
- story
- story
- story
-
comment
Comment #12543529
> CA/SSL specification does not change weekly... The draft ACME specification does though.
- story
-
comment
Comment #12168282
DNSSEC is enforced at the resolvers.
-
comment
Comment #12167784
Yup.
- story
-
comment
Comment #11673106
Google did not write the HTTP/2 spec. While Roberto Peon is one of the authors (and a core developer of the preceding SPDY protocol) saying that HTTP/2 is some Google invention is …
- story
-
comment
Comment #11363163
It allowed users to bypass Twitter blocks by tweeting at the bot while tagging users that block them, which seems pretty bad and was abused very quickly. Also it's a violation of t…
-
comment
Comment #11339529
> paltry $15k The tech/security community is crazy.
- story
-
comment
Comment #11214833
> The two CVEs against Varnish were both utterly bogus "trophy-hunter" CVEs in my opinion. (But don't take my word for it, judge for yourself.) ok > CVE-2013-4484: Varnish before 3…