Live data from Hacker News

Viewing profile — goldsteinq

goldsteinq

HN member
Joined
Thu, Oct 01, 2020, 9:01 AM UTC
HN karma
188
Public activity
118 items

About goldsteinq

No profile information was provided.

Recent public activity

  1. comment
    Comment #48158586

    I think at least some skepticism about independency is warranted when the board of directors is 3/4 Anthropic employees. Zulip is an awesome tool, and I want to assume good faith h…

  2. comment
    Comment #48133866

    I think this misses the point of LISP macros. LISP macros are just functions written in LISP , so here macros need to be functions written in Rust-but-LISP, but it is not so. In fa…

  3. comment
    Comment #47273168

    > Folks who manually enable our "Resist Fingerprinting" preference (which we don't officially support, and I don't generally recommend - but hey, you do you) are very loud on Bugzi…

  4. comment
    Comment #47170390

    It keeps missing the fact that BlueSky, as of today, is not decentralized in any meaningful way. If tomorrow bsky.app (and/or PLC registry) goes dark, the network is dead. There’re…

  5. comment
    Comment #46419081

    No “Submit Debug Logs” there, as far as I can see. Do I need to be on matrix.org homeserver for this to work or something? https://photos.goldstein.lol/share/OIgowBN4Wmi4zlm8DmDP0s…

  6. comment
    Comment #46415939

    I’m facing it on Element Desktop, but I’ll try to reproduce it on Element Web. I’ve tried to submit logs from Element Desktop, but it says that `/rageshake` (which I was told to do…

  7. comment
    Comment #46414823

    Okay, sorry, not oss-security mailing list, oss-security _distros_ mailing list. https://oss-security.openwall.org/wiki/mailing-lists/distros > Only use these lists to report secur…

  8. comment
    Comment #46414655

    > Say more. Plenty of people use Signal as a serious communication tool. I did say more already. Maybe you believe in serious communication tools that can’t synchronize searchable …

  9. comment
    Comment #46414417

    I’m definitely not “commiting malpractice” on account of not being a security practicioner. I’m talking from a perspective of a user. It’s important to me — as a user — that a comm…

  10. comment
    Comment #46414233

    Pros of Matrix: it actually has a consistent history (in theory); no vendor lock-in. Cons of Matrix: encryption breaks constantly. Right now I’m stuck in a fun loop of endlessly ch…

  11. comment
    Comment #46414182

    Yes, if your only device is a single Android phone you can do that. You can’t, however, use that backup to populate your message history on other platforms. I’ve already lost messa…

  12. comment
    Comment #46413880

    > You don't have to use it like "encrypted SMS"! You're free. Using it as something more than encrypted SMS requires persistent message history between devices. > metric fuckton of…

  13. comment
    Comment #46412463

    > If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that. I want secure me…

  14. comment
    Comment #46384032

    According to the official Matrix website ( https://matrix.org/ecosystem/clients/element-x/ , https://matrix.org/ecosystem/clients/element/ ): threads, voice calls, spaces, SSO.

  15. comment
    Comment #46383529

    > some Element users are still stuck on the Classic app, unaware that Element X exists This sounds really arrogant. Element X _still_ lacks a lot of features, saying that the only …

  16. comment
    Comment #46340715

    I wanted to make a more descriptive title, mentioning that Microsoft uses its own program for `curl` command, but ran out of characters.

  17. comment
    Comment #46340708

    > Also, for OP: Do you mean "access to the system it runs on"? Because I'm pretty sure it doesn't run with "SYSTEM" access (as in privileged user). Yeah, I mean “access to the syst…

  18. story
  19. comment
    Comment #46337751

    Equivalent of $5-6 monthly

  20. story
  21. comment
    Comment #46301943

    I am subscribed to recurrent donations to Thunderbird. I would pay for Firefox if it was focused on privacy and customizabilty, not telemetry and LLMs.

  22. comment
    Comment #45679769

    So the first scenario is also basically “automatic scanner bypass”? That answers my question, yes. > making a tar file that when inspected looks fine Am I correct in understanding …

  23. comment
    Comment #45679757

    Is this LLM-generated? The style is somewhat off (long lists repeating the same thing over and over, calling random meta statements “theorems”), and the link to the repo is complet…

  24. comment
    Comment #45667032

    Hi! Could you elaborate on the first attack scenario? > Target: Python package managers using tokio-tar (e.g., uv). An attacker uploads a malicious package to PyPI. The package's o…

  25. comment
    Comment #45460689

    I’m still not sure how do you even compromise a key without also compromising message history. The keys are stored on-device, along with associated history. If attacker has access …