Viewing profile — dhx
dhx
HN member- Joined
- Wed, Oct 19, 2011, 11:35 AM UTC
- HN karma
- 2,781
- Public activity
- 536 items
- HN profile
- View on Hacker News ↗
About dhx
David Hicks (dhx)
Web (IPv6 and IPv4): https://david.hicks.id.au
E-mail (IPv6 and IPv4): david@hicks.id.au
PGP: Public Key: https://david.hicks.id.au/pgp/728F3435.asc Key ID: 728F3435 Fingerprint: 2442 14B5 2E51 CB0F CA3B 9DB8 59E0 E7B7 728F 3435
Hacker News: https://news.ycombinator.com/user?id=dhx
Last updated: 2012-03-05
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEJEIUtS5Ryw/KO524WeDnt3KPNDUFAlqcjdcACgkQWeDnt3KP NDUoJQ//TTN8pul74acpaVWImkdxEzqU1xOtAn/JyrZtYLjO2XnMDJSF9fTYKD7o AT19lV6kZnMo0p0lsNg5tnk5QMJ96rqPhpelAiXBYkdfz3VfVVj3X3AOdkg5XRbm 6Uy1sa8Omp6Jo21wtUOE+jtSYWwEiUFn9NPl3B1aNZSUo/LuMTJve1IidJuW705m OCenqn/Ro8eZ6kUOUByWoDBbGlobAkZpBZEyzHCpczZ1nGj50mn4cssXxDG4St62 S+o9009ZMgjFtfIDTwI7gwaNCgn6ldBbwYwfMaPL2cs2Kxl05iqbM/KcsU/CLZE5 Dmh/0aPaYNJdg8PDjpItupxryNwwROB/lCigGsp+msiXtOJTENdCfojFF6ffiFTl Lxqfmbe+bn3JcqTOXzExPD0NXstx7sdetQZSwVnuCQGH4JjcUpyzKmrEw4ATvpXb VXWf00jXAMWhGHSQJLzecTXw8/iWWh0swIpLrokq3ISrMBwK2oAavZzPh4TpH5ao Y+VL0LkqAaiEpLyBAJDUFFdrJbDv9P82fZ8NFEiK3plgm5xfv62UOzFVIG+ezdDY PvfodliBtu/mLMc9YIjo5H59NtnmT4fXb8/LW5rNP7xSxWjMbCGiG3/pVSUx+FBN v74Ykn2ioBPNM3ApFC3kBrlS1K8jIcNgCfMQcH0oc7y6+e84NwY= =sBF3 -----END PGP SIGNATURE-----
Recent public activity
-
comment
Comment #49241353
They're going to rely on a fuel source which only has 9-17 years of domestic supply at current production rates and proven reserves?[1] And a fuel source with largest proven reserv…
-
comment
Comment #49197950
For lumber, data at [1] indicates much volatility in North American lumber prices from January 2023 to February 2026. Trough-to-peak prices for 2023, 2024 and 2025 have been over 3…
-
comment
Comment #49140971
There can be surprisingly few critical components and processes in a water and sewerage network due to gravity-fed designs (far more cost efficient), large buffers (water reservoir…
-
comment
Comment #49056890
OSM probably has the best data on golf courses because for many courses, people have mapped each 'golf=hole' as a way, and mapped other golf course features such as 'golf=bunker', …
-
comment
Comment #49047028
Update 2: Upon checking Sentinel-2 imagery for BAH55 from 2026-03-29 to 2026-04-13 (and all later imagery) there is also visible blast damage to the roof of BAH55, which would corr…
-
comment
Comment #49046618
Update: IRGC published satellite imagery a few hours ago showing an impact to BAH54, apparently impacted on 2026-07-24, alongside another undated image before the impact. From a qu…
-
comment
Comment #49037145
To add: The request has not yet been published by GitHub to https://github.com/github/gov-takedowns/tree/master/India/20... Also not mentioned in the project's GitHub repository ye…
-
comment
Comment #49036640
AWS's 3 data centres in me-south-1 are: BAH53 (Manama): https://www.openstreetmap.org/way/1492345589 An adjoining substation to BAH53 had one of it's two main buildings damaged/des…
-
comment
Comment #48967579
See [1] for April 2024 Clickhouse Github activity analysis of the xz backdoor. I haven't seen anyone write up a proper analysis that includes consideration of: - GitHub activity (e…
-
comment
Comment #48916625
Title is not correct. Microsoft didn't patch a lot of this, they're reporting patches for dependencies that other people patched and Microsoft are inheriting. For example, Mariner …
-
comment
Comment #48833102
If demographics are a problem for chipmaking in China, then it's good to compare against key chipmaking countries. To compare, 2024 (UN) fertility rates (highest-lowest):[1] US: 1.…
-
comment
Comment #48832696
For some recent data, see the diagram "Semiconductor foundry capacity 8" & 12" - by foundry location (in %)" at [1] for a rough idea of kWpm (thousand 300mm equivalent wafer starts…
-
comment
Comment #48828385
My key point you are avoiding with personal attacks is: If I see another computer offer TLS named group 0x0200 (MLKEM512) as introduced by draft-ietf-tls-mlkem, do I have any assur…
-
comment
Comment #48827670
It looks like recent Tenda hardware/firmware is encrypted per below examples, making it harder to audit. binwalk US_AC10V6.0si_V16.03.62.09_multi_TDE01.bin DECIMAL HEXADECIMAL DESC…
-
comment
Comment #48826736
From RFC8446 (TLSv1.3) sE.4: "In general, TLS does not have specific defenses against side-channel attacks (i.e., those which attack the communications via secondary channels such …
-
comment
Comment #48816002
The draft considers FIPS 203 to be normative. Therefore FIPS 203 forms part of this draft. You can't implement this draft without first implementing FIPS 203. FIPS 203 doesn't care…
-
comment
Comment #48815950
To point out some positive examples of what RFCs should include: RFC 5288 s3 (AES-GCM): "Each value of the nonce_explicit MUST be distinct for each distinct invocation of the GCM e…
-
comment
Comment #48815012
This reads to me as an argument of "If you thought ECDSA was bad, wait until you see MLKEM?" ECDSA history is repeating itself again when you consider how poorly the proposed MLKEM…
-
comment
Comment #48814213
Not all cryptographers (and cryptography standards) care about real world implementation, or have the same use cases in mind for their cryptography algorithms and protocols. Almost…
-
comment
Comment #48813122
To extend on this good point-- DJB is not just a mathematician looking over theoretical equations. He's also an expert in the real world _implementation_ of cryptography where most…
-
comment
Comment #48798730
At least in my experience for large retail chains or restaurant chains, hours on their websites are very accurate. I think where Google might benefit from calling to verify hours i…
-
comment
Comment #48795614
See alltheplaces.xyz for continuously updated straight-from-the-primary-source opening hours of chains of shops and restaurants, public facilities such as libraries, etc. This is p…
-
comment
Comment #48795500
1. This is largely country-dependent with some governments being quite adamant that address data should be in the public domain, and some governments doing the opposite and selling…
-
comment
Comment #48781986
I change that slightly to "Good luck getting an explosive payload." The difficulty for an attacker is the explosive payload, not the delivery mechanism. If it were easy for an atta…
-
comment
Comment #48554633
"Fix this code" should ideally solve entire vulnerability classes, not just spot fix buffer overflows one by one. Thus it may be possible to design an LLM which can solve entire vu…