Viewing profile — goldsteinq
goldsteinq
HN member- Joined
- Thu, Oct 01, 2020, 9:01 AM UTC
- HN karma
- 188
- Public activity
- 118 items
- HN profile
- View on Hacker News ↗
About goldsteinq
No profile information was provided.
Recent public activity
-
comment
Comment #48158586
I think at least some skepticism about independency is warranted when the board of directors is 3/4 Anthropic employees. Zulip is an awesome tool, and I want to assume good faith h…
-
comment
Comment #48133866
I think this misses the point of LISP macros. LISP macros are just functions written in LISP , so here macros need to be functions written in Rust-but-LISP, but it is not so. In fa…
-
comment
Comment #47273168
> Folks who manually enable our "Resist Fingerprinting" preference (which we don't officially support, and I don't generally recommend - but hey, you do you) are very loud on Bugzi…
-
comment
Comment #47170390
It keeps missing the fact that BlueSky, as of today, is not decentralized in any meaningful way. If tomorrow bsky.app (and/or PLC registry) goes dark, the network is dead. There’re…
-
comment
Comment #46419081
No “Submit Debug Logs” there, as far as I can see. Do I need to be on matrix.org homeserver for this to work or something? https://photos.goldstein.lol/share/OIgowBN4Wmi4zlm8DmDP0s…
-
comment
Comment #46415939
I’m facing it on Element Desktop, but I’ll try to reproduce it on Element Web. I’ve tried to submit logs from Element Desktop, but it says that `/rageshake` (which I was told to do…
-
comment
Comment #46414823
Okay, sorry, not oss-security mailing list, oss-security _distros_ mailing list. https://oss-security.openwall.org/wiki/mailing-lists/distros > Only use these lists to report secur…
-
comment
Comment #46414655
> Say more. Plenty of people use Signal as a serious communication tool. I did say more already. Maybe you believe in serious communication tools that can’t synchronize searchable …
-
comment
Comment #46414417
I’m definitely not “commiting malpractice” on account of not being a security practicioner. I’m talking from a perspective of a user. It’s important to me — as a user — that a comm…
-
comment
Comment #46414233
Pros of Matrix: it actually has a consistent history (in theory); no vendor lock-in. Cons of Matrix: encryption breaks constantly. Right now I’m stuck in a fun loop of endlessly ch…
-
comment
Comment #46414182
Yes, if your only device is a single Android phone you can do that. You can’t, however, use that backup to populate your message history on other platforms. I’ve already lost messa…
-
comment
Comment #46413880
> You don't have to use it like "encrypted SMS"! You're free. Using it as something more than encrypted SMS requires persistent message history between devices. > metric fuckton of…
-
comment
Comment #46412463
> If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that. I want secure me…
-
comment
Comment #46384032
According to the official Matrix website ( https://matrix.org/ecosystem/clients/element-x/ , https://matrix.org/ecosystem/clients/element/ ): threads, voice calls, spaces, SSO.
-
comment
Comment #46383529
> some Element users are still stuck on the Classic app, unaware that Element X exists This sounds really arrogant. Element X _still_ lacks a lot of features, saying that the only …
-
comment
Comment #46340715
I wanted to make a more descriptive title, mentioning that Microsoft uses its own program for `curl` command, but ran out of characters.
-
comment
Comment #46340708
> Also, for OP: Do you mean "access to the system it runs on"? Because I'm pretty sure it doesn't run with "SYSTEM" access (as in privileged user). Yeah, I mean “access to the syst…
- story
-
comment
Comment #46337751
Equivalent of $5-6 monthly
- story
-
comment
Comment #46301943
I am subscribed to recurrent donations to Thunderbird. I would pay for Firefox if it was focused on privacy and customizabilty, not telemetry and LLMs.
-
comment
Comment #45679769
So the first scenario is also basically “automatic scanner bypass”? That answers my question, yes. > making a tar file that when inspected looks fine Am I correct in understanding …
-
comment
Comment #45679757
Is this LLM-generated? The style is somewhat off (long lists repeating the same thing over and over, calling random meta statements “theorems”), and the link to the repo is complet…
-
comment
Comment #45667032
Hi! Could you elaborate on the first attack scenario? > Target: Python package managers using tokio-tar (e.g., uv). An attacker uploads a malicious package to PyPI. The package's o…
-
comment
Comment #45460689
I’m still not sure how do you even compromise a key without also compromising message history. The keys are stored on-device, along with associated history. If attacker has access …