Live data from Hacker News

Viewing profile — tryauuum

tryauuum

HN member
Joined
Wed, Oct 03, 2018, 6:00 PM UTC
HN karma
969
Public activity
659 items

About tryauuum

No profile information was provided.

Recent public activity

  1. comment
    Comment #49201390

    Doesn't this one need it as well? I see the shadow mmu

  2. comment
    Comment #49093907

    ah, to live in a country where the government doesn't block wireguard packets

  3. comment
    Comment #49090240

    no, I mean the attacker boots his own copy of Windows or Ubuntu, which is supposedly trusted by the UEFI keys. Will tpm somehow detect that it shouldn't unlock secrets for this boo…

  4. comment
    Comment #49089967

    It all weird still Suppose the physical attacker doesn't reset the bios. He boots Ubuntu or any other os which is signed. Will the tpm unlock and give out the key? I guess it depen…

  5. comment
    Comment #49087701

    holy hell! snap-based kernel can someone explain like I'm 5, what's the point of during storing disk encryption keys in TPM? What kind of attack or attacker do we protect from? my …

  6. comment
    Comment #48967119

    So Microsoft did something good? I thought they are too busy keeping my personal data in a prison and writing tight bash loops wasting 100 percent of a core

  7. comment
    Comment #48938914

    I've never had a twitter account so all these people hating durov for his exile marketing look weird to me. I'm not disagreeing with what you say but it's like a whole another subs…

  8. comment
    Comment #48926035

    > You people are just racist towards Russians and need help. >> That doesn’t exclude the statements about Telegram to be correct though. just attack the telegram from the technical…

  9. comment
    Comment #48919045

    that's stupid. getent passwd will fetch the user list from the network depending on setup. Have fun fetching 40000 records from the network every call

  10. comment
    Comment #48859475

    come on guys, stop upvoting me and answer the question please

  11. comment
    Comment #48853315

    whoa, didn't expect a wall of text When I said about "no mitigations except for the kernel updates" I meant exactly that. Some sysctl config to flip, some kernel module to unload. …

  12. comment
    Comment #48852226

    Today they already analyze the SSL handshake and traffic patterns in Russia. And if your valid https traffic crosses the border but doesn't behave like https (I don't know how they…

  13. comment
    Comment #48850365

    > new technology that is designed to balance interests on all sides and actually enforce the guarantees IN CODE AND PROTOCOLS. They will just call your code illegal in law. And if …

  14. comment
    Comment #48850317

    That's cool and all but looks like we are running out of good countries And if they all have censorship, they are not failing (when comparing them to each other)

  15. comment
    Comment #48850246

    It's hard to compare US and EU internet freedom because a person usually spends most of their life in one place and is clueless about the life in other. I've never lived in US, wer…

  16. comment
    Comment #48830908

    it's all so tiresome so no mitigation except for kernel updates?

  17. comment
    Comment #48817136

    how dangerous is the vulnerability in practice? How hard is to actually achieve the KVM escape?

  18. comment
    Comment #48810590

    Not all device files, only /dev/kvm. I assume the logic was "with /dev/kvm access the user can ...allocate memory and execute code, which they already can, so why not allow it?". C…

  19. comment
    Comment #48763585

    "lock-in factor"?

  20. comment
    Comment #48737621

    > don't, like, invade their country I did not invade any country At least this app just displays the flags and not prints such accusations

  21. comment
    Comment #48732295

    this touches two pieces of my knowledge: - microsoft is evil, I cannot delete my github account, will never use anything by this company - if the attacker knows your *public* key t…

  22. comment
    Comment #48732223

    wonder if anyone tried X over infiniband, latency would be so great

  23. comment
    Comment #48715455

    The ad companies I think would want the opposite If they cannot distinguish real people from bots they can just charge more for more ads shown !

  24. comment
    Comment #48715431

    I would tell them to not give their children internet access at all until they think they are ready. Does it sound realistic? I don't know. From technical point of view certainly r…

  25. comment
    Comment #48685834

    I don't fully get you. Do you mean untrusted regex or untrusted data it operates on? And to be honest, even if the regex is trusted (came from a developer) and the data as well (so…