Viewing profile — matthew9219
matthew9219
HN member- Joined
- Thu, Mar 30, 2023, 2:08 AM UTC
- HN karma
- 101
- Public activity
- 61 items
- HN profile
- View on Hacker News ↗
About matthew9219
No profile information was provided.
Recent public activity
-
comment
Comment #36211924
[dead]
-
comment
Comment #36189310
Do you think these statues are hate speech or obscenity?
-
comment
Comment #36189243
Not sure this is the technology at play here, but ATL Server, a C++ based Microsoft web technology discontinued in 2008 basically supported two files extensions - .srf and .dll. Se…
-
comment
Comment #36180546
How would it hurt you? The American Heritage Dictionary gives three definitions of hurt: > 1. To cause physical damage or pain to (an individual or a body part); injure. > 2. To ex…
-
comment
Comment #36171535
They do. The problem is drug addiction. If you give drug addicts free houses, eventually the word gets out, and then even more drug addicts move to your state. Eventually you find …
-
comment
Comment #36171295
People addicted to heroin don't achieve their potential or their aspirations. The compassionate thing to do for drug addicts is to help them stop being addicted to drugs, not give …
-
comment
Comment #36171227
It's a bit more complex than that. At the surface, it's true - only 15% of homeless people in Seattle lived out of county before becoming homeless. But a deeper look shows as many …
-
comment
Comment #36170864
I didn't quite speak clearly and so let me try to clarify. It's the opinion presented as opinion containing opinion presented as fact :). In examples: - "summer is the best season"…
-
comment
Comment #36170587
Seems specious. Democratically elected representatives said it was to encourage the investment of capital as they wrote the laws, and then got reelected by the voters. You can say …
-
comment
Comment #36169682
The discussion is about the quote in the article, not about what the previous commentator said.
-
comment
Comment #36169492
It's an understandable position yes. It's not quite so understandable to me that somebody would believe that position to be an inherent truth ("truly owe") rather than just a posit…
-
comment
Comment #36144378
Fwiw (tangent), I don't necessarily believe either of those instances were cosmic-ray induced bit-flips. I'd have to dig up the study, but I read a study once that more or less con…
-
comment
Comment #36133303
You are looking for a debate, I think. It's the whole thread. You're nerd sniping. It's classic. You're not a fan of DNSSEC and prefer CT. When faced with examples where CT doesn't…
-
comment
Comment #36130103
Of course it does. CT trust relies on root programs removing bad CAs and root programs and security researchers sharing information about bad CAs with root programs. The root progr…
-
comment
Comment #36130011
Do you believe CT protects set-top boxes against surveillance from nation state actors who compromise your router? Yes or no, if you don't answer, you're not engaging in good faith…
-
comment
Comment #36122422
> Meanwhile if DNSSEC's vision is ever fully realized, you will lose that control entirely. There is no CT there, and even if it was build somehow it will be useless as it has no "…
-
comment
Comment #36122310
Web PKI so strong that we recommend not using it for critical scenarios.. /s It's late and I maybe haven't been super constructive here, but I think when you try to write out the a…
-
comment
Comment #36122183
The example I gave was a router or gaming system updating itself (e.g. using CUrl) not a full browser. Don't strawman please - if my argument is as weak as you say, you shouldn't n…
-
comment
Comment #36122088
It's the argument I made at the top: > The fundamental difference is that with TLS you have to trust ALL certificate issuers, but with DNSSec you only have to trust your TLD and yo…
-
comment
Comment #36122008
That's just not what's happening. Reread the conversation. I started from here: > Certificate transparency is cool, but it's not clear it really works for many classes of devices S…
-
comment
Comment #36121872
The crucial difference is who decides which cryptographic entities to trust. With TLS and CT, the browser defines the list of entities and if 3 or more of those entities live in a …
-
comment
Comment #36121829
Admittedly, the US is a bit of a special case because of ICANN. Better examples are probably Saudi Arabia, Israel, Australia, Russia, etc.
-
comment
Comment #36121820
That page explains that Chrome (which is best in class here - most IOT devices don't do any of this stuff) fails open: > If the installed version of Chrome has not applied security…
-
comment
Comment #36121759
> you can't fake the SCT entries without having access to the CT private keys. So... Governments like the US and China can fake the entries by using their police forces to seize th…
-
comment
Comment #36121750
> Forging a ‘fake CT log’ isn’t possible, either Why do you think this isn't possible?