Live data from Hacker News

Viewing profile — janosdebugs

janosdebugs

HN member
Joined
Wed, Apr 20, 2022, 5:21 AM UTC
HN karma
1,557
Public activity
631 items

About janosdebugs

No profile information was provided.

Recent public activity

  1. comment
    Comment #41047712

    Yeah, like the shares being transfered under duress. It's not like that can't be undone. The only thing this would achieve is a bunch of prison time and possibly destruction if dat…

  2. comment
    Comment #40940633

    This seems awfully complicated. A lot of applications will happily respect system proxy settings and connect to mitmproxy directly.

  3. comment
    Comment #40940603

    Content gating behind login screens. Scraping content behind a login screen could constitute a contract violation and would give rise to a lawsuit independent of copyright.

  4. comment
    Comment #40924176

    AFAIK it's not enough to write it in your privacy policy. Art 21 of the GDPR makes this explicit: > (4) At the latest at the time of the first communication with the data subject, …

  5. comment
    Comment #40924115

    After reading the specs, this sounds like an awful lot of complexity for something that should be simple and low cost. The spec also seems to be very loosely defined, more like a r…

  6. comment
    Comment #40914898

    Legitimate interest still requires the data subject to be informed under Art 13. Not sure how that would be accomplished without at least an info banner. (This goes for server logs…

  7. comment
  8. comment
    Comment #40756857

    I'd say unlikely, games do a lot of work within graphics cards that are not as easily dumpable/restorable as memory.

  9. comment
    Comment #40734816

    Unreal Engine and Steam Audio may be worth looking into before you invest significant amounts of time into this.

  10. comment
    Comment #40656766

    Name recognition? You know exactly what you get, which isn't necessarily true for the bajilion clones out there. You know that if you buy an rPi, you can buy a replacement tomorrow…

  11. comment
    Comment #40616065

    There are very legit reasons to use passwords, for example in conjunction with a second factor. Authentication methods can also be chained.

  12. comment
    Comment #40616035

    As far as OpenSSH is concerned, I believe the main problem is that there is no centralized revocation functionality. You have to distribute your revocation lists via an external me…

  13. comment
    Comment #40615485

    Not necessarily. There is a fork of OpenSSH that supports x509, but I remember reading somewhere that it's too complex and that's why it doesn't make it into mainline.

  14. comment
    Comment #40612750

    As I said, "should". In some places there will be enough people in the chain that won't be bothered to go to the LIR directly. Think small rural ISPs in small countries.

  15. comment
    Comment #40612559

    The provider doesn't care, the owner of the server who needs to log in from their home internet at 2AM in an emergency cares. Bad actors have access to botnets, the server admin do…

  16. comment
    Comment #40612489

    Use TOTP (keyboard-interactive) and password away!

  17. comment
    Comment #40612463

    I saw a Postgres story like this one. Badly managed AWS org with way too wide permissions, a data scientist sort of person set it up and promptly reconfigured the security group to…

  18. comment
    Comment #40612425

    That may be true mathematically, but there are no guarantees that a small provider won't end up having only a single /64, which would likely be the default unit of range-based bloc…

  19. comment
    Comment #40612396

    The hard part is making sure every one of your servers got the CRL update. Since last I checked OpenSSH doesn't have a mechanism to remotely check CRLs (like OCSP), nor does SSH ha…

  20. comment
    Comment #40612293

    There is nothing wrong with this approach if enabled as an informed decision. It's the part where they want to enable this by default I have a problem with. Things that could be do…

  21. comment
    Comment #40612234

    IPv6 has the potential to be even worse. You could be knocking an entire provider offline. At any rate, this behavior should not become default.

  22. comment
    Comment #40611599

    You can use SSH certificate authorities (not x509) with OpenSSH to authorize a new key without needing to deploy a new key on the server. Also, Yubikeys are useful for this.

  23. comment
    Comment #40611450

    Having written an SSH server that is used in a few larger places, I find the perspective of enabling these features on a per-address basis by default in the future troubling. First…

  24. comment
    Comment #40609252

    It's for making game sounds. Fairlight looks like it could work though, thanks!

  25. comment
    Comment #40608292

    The deal fell through: https://www.theverge.com/2023/12/18/24005996/adobe-figma-acq...