Viewing profile — twitchyliquid64
twitchyliquid64
HN member- Joined
- Wed, Mar 22, 2017, 12:36 AM UTC
- HN karma
- 110
- Public activity
- 18 items
- HN profile
- View on Hacker News ↗
About twitchyliquid64
No profile information was provided.
Recent public activity
-
comment
Comment #39297995
I've been fairly impressed at Waymo's defensive driving skills, down to it being able to tell when someone turns around towards the road with an eye to cross, & the car slowing-dow…
-
comment
Comment #37353911
A simple fix might be to bind the encrypted value to a PCR (hopefully one that isnt too fragile, but prefs one that measures the initrd) and then to invalidate that PCR when you dr…
-
comment
Comment #35348981
Can anyone that knows a thing or two about law comment on section 12 & 13? Seems like there's... a LOT of calve-outs for due process / checks-and-balances? or is that fairly normal…
-
comment
Comment #15487545
I stand corrected. Rogue AP / MiTM only needs a AP with the ability to send raw packets, gotcha.
-
comment
Comment #15486674
> Many, many websites and APIs don't have HSTS enabled to force all connections to use TLS. True. Yet another reason for us to push for it. I have a chrome extension that sets the …
-
comment
Comment #15486645
On second read, timing requirements arent a thing if you are spoofing the network (obviously) so for that attack vector you don't need specialized hardware. (wont let me edit :( )
-
comment
Comment #15482764
You can't preload the whole internet, but by getting the top xx thousand you get 99% of all Chrome users traffic. Its not perfect, but it is very, very effective.
-
comment
Comment #15482726
This is not an end-of-the-world type vulnerability. 1. Does not affect long-term credentials - certs, wifi passwords are still safe. Rather, confidentiality (secrecy) from client -…
-
comment
Comment #15413497
Guess you could say noise is pretty quiet xD +1 for trying to eliminate complexity from developer error. This was one of the worst cows in the herd for OpenSSL. That said, I think …
-
comment
Comment #15413474
> What a bunch of senseless FUD. inb4 strawman arguments and other funzies. Perhaps you should argue with me on my actual assertion, which is that 'we should use crypto that has st…
-
comment
Comment #15409468
Throughput: It depends on the link, but I'm getting 16mbps peak where my connection to my ISP gets me 20mbps peak. Mobile: You have to use the APIs that are available on the platfo…
-
comment
Comment #15409453
Thanks! This is definitely something I need to get around to once I read up a bit more on vendoring.
-
comment
Comment #15409381
I'm glad you're asking these kinds of questions, they need to come up more often especially in a software-supply-chain context. I am a strong advocate of the saying 'trust but veri…
-
comment
Comment #15409341
Correct. While simple, this does have the performance impact you're alluding to. On my 20mbps (down) connection, I peak out at 16mbps on subnet. The 'double congestion-control' eff…
-
comment
Comment #15409318
My concern is that 'built on modern crypto' and 'reviewed by cryptographers' amounts to 'rolled our own crypto'. IMHO history has shown us time and time again that this is a bad id…
-
comment
Comment #15409288
I'm afraid not :/ Windows is a whole new kettle of fish to get working - you need a device driver to emulate TUN/TAP. That said, I'm using a library called Water for the low-level …
- story
- story