Live data from Hacker News

Viewing profile — d2mw

d2mw

HN member
Joined
Fri, Jul 19, 2019, 1:45 AM UTC
HN karma
129
Public activity
34 items

About d2mw

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #20669887

    Society is only one Android release away from most consumer traffic metadata being tunnelled by default through a new instrument of political policy, thanks to a company who not so…

  3. comment
    Comment #20669419

    I can't see into the future, unfortunately, but you're welcome to bookmark the parent comment and set a calendar entry to compare it with reality about once every 6 months. It's po…

  4. comment
    Comment #20669393

    you appear to have jumped to step 2 in the masterplan, and completely skipped step 1. It's not even mandatory yet, but when it is, the choice will be between N<10 providers, most o…

  5. comment
    Comment #20669264

    They can fight it on the basis of censorship, and I'll support them on the basis of a decentralized Internet that does not rely on some folk who leaked private data all over the In…

  6. comment
    Comment #20661076

    What I mean is https://i.ibb.co/P6N35qv/Screenshot-from-2019-08-10-10-27-25... does not make it clear whatsoever that 'public' really means public. Before we get into blaming the c…

  7. comment
  8. comment
  9. comment
    Comment #20657712

    For EBS, step 1 is reading the docs, step 2 is cutpasting a documentation example. For S3 I'm not sure how people are building their lists. AFAIK the API provides no enumeration. S…

  10. comment
    Comment #20657707

    > Who on Earth is thinking that it is a good idea to take an EBS snapshot and make it public? Non-marketplace AMIs are built on public EBS snapshots, but that's something they shou…

  11. comment
    Comment #20657534

    Public EBS snapshots are great, and thankfully a design other clouds didn't copy. I've found all kinds of stuff in there, including a 900GB Oracle backup of a publicly traded manuf…

  12. comment
    Comment #20649523

    I didn't recognize the story until you corrected the path. https://news.ycombinator.com/item?id=1242831

  13. comment
  14. comment
    Comment #20639545

    Google can claim many firsts, but hopping from a baseband to an application processor most certainly isn't one of them. I'm sure you can find presentations from e.g. CCC much older…

  15. comment
    Comment #20639521

    It's unusual but certainly not novel. There have been similar attacks against e.g. server network cards >10 years ago, where (IIRC) a magic pattern used for factory testing could p…

  16. comment
    Comment #20637245

    > It makes cross-platform desktop development much easier. That is literally how Adobe Air was billed

  17. comment
    Comment #20633826

    Pwn2Own fell out of the spotlight over time because they managed to piss off sponsors and teams alike, not because any material improvement occurred in software security, involving…

  18. comment
    Comment #20631002

    > we all know that it's basically impossible to attack a modern well configured system Where in the world did this fantastic idea come from? https://events.linuxfoundation.org/wp-c…

  19. comment
    Comment #20628434

    I'm curious about how these things are expected to scale.. 1000 subscribers, dedicated support person 5000, ??? 10000, ??? At some point these community efforts must grow back into…

  20. comment
  21. comment
    Comment #20607315

    Tears of joy.

  22. comment
  23. comment
    Comment #20604224

    If SCM_CRED passing were a real problem in _any_ scenario, SELinux should target that instead, not an entire subsystem on which half the system is built

  24. comment
    Comment #20602600

    One reason to dislike SELinux is the arbitrary assumptions baked in by default that barely anyone knows how to or cares to change, which makes carefully designed software look brok…

  25. comment