Viewing profile — d2mw
d2mw
HN member- Joined
- Fri, Jul 19, 2019, 1:45 AM UTC
- HN karma
- 129
- Public activity
- 34 items
- HN profile
- View on Hacker News ↗
About d2mw
No profile information was provided.
Recent public activity
- comment
-
comment
Comment #20669887
Society is only one Android release away from most consumer traffic metadata being tunnelled by default through a new instrument of political policy, thanks to a company who not so…
-
comment
Comment #20669419
I can't see into the future, unfortunately, but you're welcome to bookmark the parent comment and set a calendar entry to compare it with reality about once every 6 months. It's po…
-
comment
Comment #20669393
you appear to have jumped to step 2 in the masterplan, and completely skipped step 1. It's not even mandatory yet, but when it is, the choice will be between N<10 providers, most o…
-
comment
Comment #20669264
They can fight it on the basis of censorship, and I'll support them on the basis of a decentralized Internet that does not rely on some folk who leaked private data all over the In…
-
comment
Comment #20661076
What I mean is https://i.ibb.co/P6N35qv/Screenshot-from-2019-08-10-10-27-25... does not make it clear whatsoever that 'public' really means public. Before we get into blaming the c…
- comment
- comment
-
comment
Comment #20657712
For EBS, step 1 is reading the docs, step 2 is cutpasting a documentation example. For S3 I'm not sure how people are building their lists. AFAIK the API provides no enumeration. S…
-
comment
Comment #20657707
> Who on Earth is thinking that it is a good idea to take an EBS snapshot and make it public? Non-marketplace AMIs are built on public EBS snapshots, but that's something they shou…
-
comment
Comment #20657534
Public EBS snapshots are great, and thankfully a design other clouds didn't copy. I've found all kinds of stuff in there, including a 900GB Oracle backup of a publicly traded manuf…
-
comment
Comment #20649523
I didn't recognize the story until you corrected the path. https://news.ycombinator.com/item?id=1242831
- comment
-
comment
Comment #20639545
Google can claim many firsts, but hopping from a baseband to an application processor most certainly isn't one of them. I'm sure you can find presentations from e.g. CCC much older…
-
comment
Comment #20639521
It's unusual but certainly not novel. There have been similar attacks against e.g. server network cards >10 years ago, where (IIRC) a magic pattern used for factory testing could p…
-
comment
Comment #20637245
> It makes cross-platform desktop development much easier. That is literally how Adobe Air was billed
-
comment
Comment #20633826
Pwn2Own fell out of the spotlight over time because they managed to piss off sponsors and teams alike, not because any material improvement occurred in software security, involving…
-
comment
Comment #20631002
> we all know that it's basically impossible to attack a modern well configured system Where in the world did this fantastic idea come from? https://events.linuxfoundation.org/wp-c…
-
comment
Comment #20628434
I'm curious about how these things are expected to scale.. 1000 subscribers, dedicated support person 5000, ??? 10000, ??? At some point these community efforts must grow back into…
- comment
-
comment
Comment #20607315
Tears of joy.
- comment
-
comment
Comment #20604224
If SCM_CRED passing were a real problem in _any_ scenario, SELinux should target that instead, not an entire subsystem on which half the system is built
-
comment
Comment #20602600
One reason to dislike SELinux is the arbitrary assumptions baked in by default that barely anyone knows how to or cares to change, which makes carefully designed software look brok…
- comment