Viewing profile — janosd
janosd
HN member- Joined
- Wed, Apr 20, 2022, 5:21 AM UTC
- HN karma
- 1,557
- Public activity
- 631 items
- HN profile
- View on Hacker News ↗
About janosd
No profile information was provided.
Recent public activity
-
comment
Comment #41047712
Yeah, like the shares being transfered under duress. It's not like that can't be undone. The only thing this would achieve is a bunch of prison time and possibly destruction if dat…
-
comment
Comment #40940633
This seems awfully complicated. A lot of applications will happily respect system proxy settings and connect to mitmproxy directly.
-
comment
Comment #40940603
Content gating behind login screens. Scraping content behind a login screen could constitute a contract violation and would give rise to a lawsuit independent of copyright.
-
comment
Comment #40924176
AFAIK it's not enough to write it in your privacy policy. Art 21 of the GDPR makes this explicit: > (4) At the latest at the time of the first communication with the data subject, …
-
comment
Comment #40924115
After reading the specs, this sounds like an awful lot of complexity for something that should be simple and low cost. The spec also seems to be very loosely defined, more like a r…
-
comment
Comment #40914898
Legitimate interest still requires the data subject to be informed under Art 13. Not sure how that would be accomplished without at least an info banner. (This goes for server logs…
- comment
-
comment
Comment #40756857
I'd say unlikely, games do a lot of work within graphics cards that are not as easily dumpable/restorable as memory.
-
comment
Comment #40734816
Unreal Engine and Steam Audio may be worth looking into before you invest significant amounts of time into this.
-
comment
Comment #40656766
Name recognition? You know exactly what you get, which isn't necessarily true for the bajilion clones out there. You know that if you buy an rPi, you can buy a replacement tomorrow…
-
comment
Comment #40616065
There are very legit reasons to use passwords, for example in conjunction with a second factor. Authentication methods can also be chained.
-
comment
Comment #40616035
As far as OpenSSH is concerned, I believe the main problem is that there is no centralized revocation functionality. You have to distribute your revocation lists via an external me…
-
comment
Comment #40615485
Not necessarily. There is a fork of OpenSSH that supports x509, but I remember reading somewhere that it's too complex and that's why it doesn't make it into mainline.
-
comment
Comment #40612750
As I said, "should". In some places there will be enough people in the chain that won't be bothered to go to the LIR directly. Think small rural ISPs in small countries.
-
comment
Comment #40612559
The provider doesn't care, the owner of the server who needs to log in from their home internet at 2AM in an emergency cares. Bad actors have access to botnets, the server admin do…
-
comment
Comment #40612489
Use TOTP (keyboard-interactive) and password away!
-
comment
Comment #40612463
I saw a Postgres story like this one. Badly managed AWS org with way too wide permissions, a data scientist sort of person set it up and promptly reconfigured the security group to…
-
comment
Comment #40612425
That may be true mathematically, but there are no guarantees that a small provider won't end up having only a single /64, which would likely be the default unit of range-based bloc…
-
comment
Comment #40612396
The hard part is making sure every one of your servers got the CRL update. Since last I checked OpenSSH doesn't have a mechanism to remotely check CRLs (like OCSP), nor does SSH ha…
-
comment
Comment #40612293
There is nothing wrong with this approach if enabled as an informed decision. It's the part where they want to enable this by default I have a problem with. Things that could be do…
-
comment
Comment #40612234
IPv6 has the potential to be even worse. You could be knocking an entire provider offline. At any rate, this behavior should not become default.
-
comment
Comment #40611599
You can use SSH certificate authorities (not x509) with OpenSSH to authorize a new key without needing to deploy a new key on the server. Also, Yubikeys are useful for this.
-
comment
Comment #40611450
Having written an SSH server that is used in a few larger places, I find the perspective of enabling these features on a per-address basis by default in the future troubling. First…
-
comment
Comment #40609252
It's for making game sounds. Fairlight looks like it could work though, thanks!
-
comment
Comment #40608292
The deal fell through: https://www.theverge.com/2023/12/18/24005996/adobe-figma-acq...