Live data from Hacker News

Viewing profile — brl

brl

HN member
Joined
Wed, Sep 19, 2007, 3:15 PM UTC
HN karma
1,178
Public activity
395 items

About brl

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #14971660

    Why would anybody censor the viewpoint of a woman scientist in this particular debate? How much cognitive dissonance is too much?

  3. comment
    Comment #13891758

    > I would love to hear his side of the story. Some of his side of the story has been told in the leaked emails: https://www.hdevalence.ca/etc/34de2f3c2a48f7da/EmAiLs.txt

  4. comment
    Comment #13027729

    I'm answering a comment chain about how Subgraph OS does not 'isolate' the network or USB stacks which is frequently brought up as an important deficiency in comparison to Qubes OS…

  5. comment
    Comment #13026947

    > I don't think there are any amnesic features like in Tails nor strong isolation between gateway and workstation to prevent IP leaks like in Whonix. Subgraph sandboxes run in a ne…

  6. comment
    Comment #13026933

    I'm from Subgraph and I disagree. On Qubes OS the networking VM runs a standard Linux kernel with no special security hardening at all apart from the simple fact that it runs in a …

  7. comment
    Comment #13026004

    > imho the qubes approach is more viable and exposes far less attack surface. I don't know what you base that opinion on since it's not an easy comparison to reason about. One metr…

  8. comment
    Comment #12305075

    Two people published open letters resigning from their involvement in Tor yesterday: https://www.oneeyedman.net/?p=2581 https://shiromarieke.github.io/tor

  9. story
  10. comment
    Comment #11438300

    Sandbox implementation is described here: https://github.com/subgraph/oz/wiki/Oz-Technical-Details

  11. comment
    Comment #10159921

    Well there was this survey: https://en.wikipedia.org/wiki/Syrian_presidential_election,_... Also surveyed at that time were the million Syrian refugees living in Lebanon: https://w…

  12. comment
    Comment #9658759

    http://www.voltairenet.org/en is a good site with many essays on these themes.

  13. comment
    Comment #8336320

    Check out the 'more details on Convertible Notes' link for the answer to your question.

  14. comment
    Comment #8331881

    Escalation to root from an active admin user account is trivial. Use your imagination.

  15. comment
    Comment #8229110

    Even if you validate certificates an active attacker can return false MX records and direct the sending MTA to connect to an attacker-controlled server which presents a perfectly v…

  16. comment
    Comment #8224585

    I would love for this to exist. I've thought about streaming on twitch before but it is apparently against their ToS to stream anything which isn't video games.

  17. comment
    Comment #8198884

    You can copy your private keys to another device obviously, and eventually Nyms can help you do this by brokering an end-to-end encrypted tunnel between devices to transfer keys se…

  18. comment
    Comment #8198187

    Maintenance of public keys is automated, by which I mean the user does not need to do anything manually for them to be published and recertified before they expire. Private keys do…

  19. comment
    Comment #8198093

    The user only needs to install a Nyms supporting email client or webmail browser extension and they're good to go for transparent communication with any other Nyms user. Registrati…

  20. comment
    Comment #8197439

    I'll be pushing some initial code to github soon for the first stage of the project which is a locally running agent that provides encryption service to email clients over a json-r…

  21. comment
    Comment #8197392

    Hi, I'm the author of this document and principal developer of the project. This is a somewhat detailed design overview for a proposed alternative to the PGP keyserver system that …

  22. comment
    Comment #8100582

    Yawn. Let me know when you're ready to announce a project to competently sign and verify artifacts.

  23. comment
    Comment #8100529

    Even if you have carefully installed the correct key from the author, if your download is intercepted and an attacker sends you a bogus artifact and signature it looks like Lein wi…

  24. comment
    Comment #8100176

    How does it know what the correct signing key is? edit: Looked up answer myself. Lein downloads whatever key the signature claims to be made with from public keyservers. How does t…

  25. comment
    Comment #8090342

    RSA has this property, but the public and private keys are not chosen arbitrarily. The public key can easily be derived from the private key, but there is no obvious way to determi…