Live data from Hacker News

Viewing profile — dhx

dhx

HN member
Joined
Wed, Oct 19, 2011, 11:35 AM UTC
HN karma
2,781
Public activity
536 items

About dhx

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512

David Hicks (dhx)

Web (IPv6 and IPv4): https://david.hicks.id.au

E-mail (IPv6 and IPv4): david@hicks.id.au

PGP: Public Key: https://david.hicks.id.au/pgp/728F3435.asc Key ID: 728F3435 Fingerprint: 2442 14B5 2E51 CB0F CA3B 9DB8 59E0 E7B7 728F 3435

Hacker News: https://news.ycombinator.com/user?id=dhx

Last updated: 2012-03-05

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEJEIUtS5Ryw/KO524WeDnt3KPNDUFAlqcjdcACgkQWeDnt3KP NDUoJQ//TTN8pul74acpaVWImkdxEzqU1xOtAn/JyrZtYLjO2XnMDJSF9fTYKD7o AT19lV6kZnMo0p0lsNg5tnk5QMJ96rqPhpelAiXBYkdfz3VfVVj3X3AOdkg5XRbm 6Uy1sa8Omp6Jo21wtUOE+jtSYWwEiUFn9NPl3B1aNZSUo/LuMTJve1IidJuW705m OCenqn/Ro8eZ6kUOUByWoDBbGlobAkZpBZEyzHCpczZ1nGj50mn4cssXxDG4St62 S+o9009ZMgjFtfIDTwI7gwaNCgn6ldBbwYwfMaPL2cs2Kxl05iqbM/KcsU/CLZE5 Dmh/0aPaYNJdg8PDjpItupxryNwwROB/lCigGsp+msiXtOJTENdCfojFF6ffiFTl Lxqfmbe+bn3JcqTOXzExPD0NXstx7sdetQZSwVnuCQGH4JjcUpyzKmrEw4ATvpXb VXWf00jXAMWhGHSQJLzecTXw8/iWWh0swIpLrokq3ISrMBwK2oAavZzPh4TpH5ao Y+VL0LkqAaiEpLyBAJDUFFdrJbDv9P82fZ8NFEiK3plgm5xfv62UOzFVIG+ezdDY PvfodliBtu/mLMc9YIjo5H59NtnmT4fXb8/LW5rNP7xSxWjMbCGiG3/pVSUx+FBN v74Ykn2ioBPNM3ApFC3kBrlS1K8jIcNgCfMQcH0oc7y6+e84NwY= =sBF3 -----END PGP SIGNATURE-----

Recent public activity

  1. comment
    Comment #49241353

    They're going to rely on a fuel source which only has 9-17 years of domestic supply at current production rates and proven reserves?[1] And a fuel source with largest proven reserv…

  2. comment
    Comment #49197950

    For lumber, data at [1] indicates much volatility in North American lumber prices from January 2023 to February 2026. Trough-to-peak prices for 2023, 2024 and 2025 have been over 3…

  3. comment
    Comment #49140971

    There can be surprisingly few critical components and processes in a water and sewerage network due to gravity-fed designs (far more cost efficient), large buffers (water reservoir…

  4. comment
    Comment #49056890

    OSM probably has the best data on golf courses because for many courses, people have mapped each 'golf=hole' as a way, and mapped other golf course features such as 'golf=bunker', …

  5. comment
    Comment #49047028

    Update 2: Upon checking Sentinel-2 imagery for BAH55 from 2026-03-29 to 2026-04-13 (and all later imagery) there is also visible blast damage to the roof of BAH55, which would corr…

  6. comment
    Comment #49046618

    Update: IRGC published satellite imagery a few hours ago showing an impact to BAH54, apparently impacted on 2026-07-24, alongside another undated image before the impact. From a qu…

  7. comment
    Comment #49037145

    To add: The request has not yet been published by GitHub to https://github.com/github/gov-takedowns/tree/master/India/20... Also not mentioned in the project's GitHub repository ye…

  8. comment
    Comment #49036640

    AWS's 3 data centres in me-south-1 are: BAH53 (Manama): https://www.openstreetmap.org/way/1492345589 An adjoining substation to BAH53 had one of it's two main buildings damaged/des…

  9. comment
    Comment #48967579

    See [1] for April 2024 Clickhouse Github activity analysis of the xz backdoor. I haven't seen anyone write up a proper analysis that includes consideration of: - GitHub activity (e…

  10. comment
    Comment #48916625

    Title is not correct. Microsoft didn't patch a lot of this, they're reporting patches for dependencies that other people patched and Microsoft are inheriting. For example, Mariner …

  11. comment
    Comment #48833102

    If demographics are a problem for chipmaking in China, then it's good to compare against key chipmaking countries. To compare, 2024 (UN) fertility rates (highest-lowest):[1] US: 1.…

  12. comment
    Comment #48832696

    For some recent data, see the diagram "Semiconductor foundry capacity 8" & 12" - by foundry location (in %)" at [1] for a rough idea of kWpm (thousand 300mm equivalent wafer starts…

  13. comment
    Comment #48828385

    My key point you are avoiding with personal attacks is: If I see another computer offer TLS named group 0x0200 (MLKEM512) as introduced by draft-ietf-tls-mlkem, do I have any assur…

  14. comment
    Comment #48827670

    It looks like recent Tenda hardware/firmware is encrypted per below examples, making it harder to audit. binwalk US_AC10V6.0si_V16.03.62.09_multi_TDE01.bin DECIMAL HEXADECIMAL DESC…

  15. comment
    Comment #48826736

    From RFC8446 (TLSv1.3) sE.4: "In general, TLS does not have specific defenses against side-channel attacks (i.e., those which attack the communications via secondary channels such …

  16. comment
    Comment #48816002

    The draft considers FIPS 203 to be normative. Therefore FIPS 203 forms part of this draft. You can't implement this draft without first implementing FIPS 203. FIPS 203 doesn't care…

  17. comment
    Comment #48815950

    To point out some positive examples of what RFCs should include: RFC 5288 s3 (AES-GCM): "Each value of the nonce_explicit MUST be distinct for each distinct invocation of the GCM e…

  18. comment
    Comment #48815012

    This reads to me as an argument of "If you thought ECDSA was bad, wait until you see MLKEM?" ECDSA history is repeating itself again when you consider how poorly the proposed MLKEM…

  19. comment
    Comment #48814213

    Not all cryptographers (and cryptography standards) care about real world implementation, or have the same use cases in mind for their cryptography algorithms and protocols. Almost…

  20. comment
    Comment #48813122

    To extend on this good point-- DJB is not just a mathematician looking over theoretical equations. He's also an expert in the real world _implementation_ of cryptography where most…

  21. comment
    Comment #48798730

    At least in my experience for large retail chains or restaurant chains, hours on their websites are very accurate. I think where Google might benefit from calling to verify hours i…

  22. comment
    Comment #48795614

    See alltheplaces.xyz for continuously updated straight-from-the-primary-source opening hours of chains of shops and restaurants, public facilities such as libraries, etc. This is p…

  23. comment
    Comment #48795500

    1. This is largely country-dependent with some governments being quite adamant that address data should be in the public domain, and some governments doing the opposite and selling…

  24. comment
    Comment #48781986

    I change that slightly to "Good luck getting an explosive payload." The difficulty for an attacker is the explosive payload, not the delivery mechanism. If it were easy for an atta…

  25. comment
    Comment #48554633

    "Fix this code" should ideally solve entire vulnerability classes, not just spot fix buffer overflows one by one. Thus it may be possible to design an LLM which can solve entire vu…