Live data from Hacker News

Viewing profile — bracewel

bracewel

HN member
Joined
Fri, Dec 05, 2014, 12:32 AM UTC
HN karma
464
Public activity
66 items

About bracewel

No profile information was provided.

Recent public activity

  1. comment
    Comment #45348555

    This is mainly actually for testing constant-time code, rather than doing proper memory tracking (see https://www.imperialviolet.org/2010/04/01/ctgrind.html for a slightly out-of-d…

  2. comment
    Comment #45348445

    Author of the linked CL here: we added this mostly so that we could abuse the memory initialization tracking to test the constant-time-ness of crypto code (similar to what BoringSS…

  3. story
  4. comment
    Comment #33230094

    There is a fifth, incredibly common, (arguably) non-malicious possibility. You don't control the entirety of your web stack, and your hosting provider, or DNS provider, or someone …

  5. comment
    Comment #21206859

    ah yes, I remember personally lying to congress and pushing false narratives in the media. oh wait, no, that wasn't me was it...

  6. story
  7. comment
    Comment #17710896

    Note that CABF bylaws require a simple majority of browsers to vote positively for a ballot for it to pass, regardless of how CAs vote.

  8. story
  9. story
  10. story
  11. story
  12. story
  13. story
  14. story
  15. comment
    Comment #12543529

    > CA/SSL specification does not change weekly... The draft ACME specification does though.

  16. story
  17. comment
    Comment #12168282

    DNSSEC is enforced at the resolvers.

  18. comment
  19. story
  20. comment
    Comment #11673106

    Google did not write the HTTP/2 spec. While Roberto Peon is one of the authors (and a core developer of the preceding SPDY protocol) saying that HTTP/2 is some Google invention is …

  21. story
  22. comment
    Comment #11363163

    It allowed users to bypass Twitter blocks by tweeting at the bot while tagging users that block them, which seems pretty bad and was abused very quickly. Also it's a violation of t…

  23. comment
    Comment #11339529

    > paltry $15k The tech/security community is crazy.

  24. story
  25. comment
    Comment #11214833

    > The two CVEs against Varnish were both utterly bogus "trophy-hunter" CVEs in my opinion. (But don't take my word for it, judge for yourself.) ok > CVE-2013-4484: Varnish before 3…