Live data from Hacker News

Viewing profile — matthew9219

matthew9219

HN member
Joined
Thu, Mar 30, 2023, 2:08 AM UTC
HN karma
101
Public activity
61 items

About matthew9219

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #36189310

    Do you think these statues are hate speech or obscenity?

  3. comment
    Comment #36189243

    Not sure this is the technology at play here, but ATL Server, a C++ based Microsoft web technology discontinued in 2008 basically supported two files extensions - .srf and .dll. Se…

  4. comment
    Comment #36180546

    How would it hurt you? The American Heritage Dictionary gives three definitions of hurt: > 1. To cause physical damage or pain to (an individual or a body part); injure. > 2. To ex…

  5. comment
    Comment #36171535

    They do. The problem is drug addiction. If you give drug addicts free houses, eventually the word gets out, and then even more drug addicts move to your state. Eventually you find …

  6. comment
    Comment #36171295

    People addicted to heroin don't achieve their potential or their aspirations. The compassionate thing to do for drug addicts is to help them stop being addicted to drugs, not give …

  7. comment
    Comment #36171227

    It's a bit more complex than that. At the surface, it's true - only 15% of homeless people in Seattle lived out of county before becoming homeless. But a deeper look shows as many …

  8. comment
    Comment #36170864

    I didn't quite speak clearly and so let me try to clarify. It's the opinion presented as opinion containing opinion presented as fact :). In examples: - "summer is the best season"…

  9. comment
    Comment #36170587

    Seems specious. Democratically elected representatives said it was to encourage the investment of capital as they wrote the laws, and then got reelected by the voters. You can say …

  10. comment
    Comment #36169682

    The discussion is about the quote in the article, not about what the previous commentator said.

  11. comment
    Comment #36169492

    It's an understandable position yes. It's not quite so understandable to me that somebody would believe that position to be an inherent truth ("truly owe") rather than just a posit…

  12. comment
    Comment #36144378

    Fwiw (tangent), I don't necessarily believe either of those instances were cosmic-ray induced bit-flips. I'd have to dig up the study, but I read a study once that more or less con…

  13. comment
    Comment #36133303

    You are looking for a debate, I think. It's the whole thread. You're nerd sniping. It's classic. You're not a fan of DNSSEC and prefer CT. When faced with examples where CT doesn't…

  14. comment
    Comment #36130103

    Of course it does. CT trust relies on root programs removing bad CAs and root programs and security researchers sharing information about bad CAs with root programs. The root progr…

  15. comment
    Comment #36130011

    Do you believe CT protects set-top boxes against surveillance from nation state actors who compromise your router? Yes or no, if you don't answer, you're not engaging in good faith…

  16. comment
    Comment #36122422

    > Meanwhile if DNSSEC's vision is ever fully realized, you will lose that control entirely. There is no CT there, and even if it was build somehow it will be useless as it has no "…

  17. comment
    Comment #36122310

    Web PKI so strong that we recommend not using it for critical scenarios.. /s It's late and I maybe haven't been super constructive here, but I think when you try to write out the a…

  18. comment
    Comment #36122183

    The example I gave was a router or gaming system updating itself (e.g. using CUrl) not a full browser. Don't strawman please - if my argument is as weak as you say, you shouldn't n…

  19. comment
    Comment #36122088

    It's the argument I made at the top: > The fundamental difference is that with TLS you have to trust ALL certificate issuers, but with DNSSec you only have to trust your TLD and yo…

  20. comment
    Comment #36122008

    That's just not what's happening. Reread the conversation. I started from here: > Certificate transparency is cool, but it's not clear it really works for many classes of devices S…

  21. comment
    Comment #36121872

    The crucial difference is who decides which cryptographic entities to trust. With TLS and CT, the browser defines the list of entities and if 3 or more of those entities live in a …

  22. comment
    Comment #36121829

    Admittedly, the US is a bit of a special case because of ICANN. Better examples are probably Saudi Arabia, Israel, Australia, Russia, etc.

  23. comment
    Comment #36121820

    That page explains that Chrome (which is best in class here - most IOT devices don't do any of this stuff) fails open: > If the installed version of Chrome has not applied security…

  24. comment
    Comment #36121759

    > you can't fake the SCT entries without having access to the CT private keys. So... Governments like the US and China can fake the entries by using their police forces to seize th…

  25. comment
    Comment #36121750

    > Forging a ‘fake CT log’ isn’t possible, either Why do you think this isn't possible?