Live data from Hacker News

Viewing profile — twitchyliquid64

twitchyliquid64

HN member
Joined
Wed, Mar 22, 2017, 12:36 AM UTC
HN karma
110
Public activity
18 items

About twitchyliquid64

No profile information was provided.

Recent public activity

  1. comment
    Comment #39297995

    I've been fairly impressed at Waymo's defensive driving skills, down to it being able to tell when someone turns around towards the road with an eye to cross, & the car slowing-dow…

  2. comment
    Comment #37353911

    A simple fix might be to bind the encrypted value to a PCR (hopefully one that isnt too fragile, but prefs one that measures the initrd) and then to invalidate that PCR when you dr…

  3. comment
    Comment #35348981

    Can anyone that knows a thing or two about law comment on section 12 & 13? Seems like there's... a LOT of calve-outs for due process / checks-and-balances? or is that fairly normal…

  4. comment
    Comment #15487545

    I stand corrected. Rogue AP / MiTM only needs a AP with the ability to send raw packets, gotcha.

  5. comment
    Comment #15486674

    > Many, many websites and APIs don't have HSTS enabled to force all connections to use TLS. True. Yet another reason for us to push for it. I have a chrome extension that sets the …

  6. comment
    Comment #15486645

    On second read, timing requirements arent a thing if you are spoofing the network (obviously) so for that attack vector you don't need specialized hardware. (wont let me edit :( )

  7. comment
    Comment #15482764

    You can't preload the whole internet, but by getting the top xx thousand you get 99% of all Chrome users traffic. Its not perfect, but it is very, very effective.

  8. comment
    Comment #15482726

    This is not an end-of-the-world type vulnerability. 1. Does not affect long-term credentials - certs, wifi passwords are still safe. Rather, confidentiality (secrecy) from client -…

  9. comment
    Comment #15413497

    Guess you could say noise is pretty quiet xD +1 for trying to eliminate complexity from developer error. This was one of the worst cows in the herd for OpenSSL. That said, I think …

  10. comment
    Comment #15413474

    > What a bunch of senseless FUD. inb4 strawman arguments and other funzies. Perhaps you should argue with me on my actual assertion, which is that 'we should use crypto that has st…

  11. comment
    Comment #15409468

    Throughput: It depends on the link, but I'm getting 16mbps peak where my connection to my ISP gets me 20mbps peak. Mobile: You have to use the APIs that are available on the platfo…

  12. comment
    Comment #15409453

    Thanks! This is definitely something I need to get around to once I read up a bit more on vendoring.

  13. comment
    Comment #15409381

    I'm glad you're asking these kinds of questions, they need to come up more often especially in a software-supply-chain context. I am a strong advocate of the saying 'trust but veri…

  14. comment
    Comment #15409341

    Correct. While simple, this does have the performance impact you're alluding to. On my 20mbps (down) connection, I peak out at 16mbps on subnet. The 'double congestion-control' eff…

  15. comment
    Comment #15409318

    My concern is that 'built on modern crypto' and 'reviewed by cryptographers' amounts to 'rolled our own crypto'. IMHO history has shown us time and time again that this is a bad id…

  16. comment
    Comment #15409288

    I'm afraid not :/ Windows is a whole new kettle of fish to get working - you need a device driver to emulate TUN/TAP. That said, I'm using a library called Water for the low-level …

  17. story
  18. story