Live data from Hacker News

Viewing profile — xori

xori

HN member
Joined
Fri, Oct 02, 2015, 2:46 PM UTC
HN karma
505
Public activity
170 items

About xori

[ my public key: https://keybase.io/xori; my proof: https://keybase.io/xori/sigs/W_1XH7IBMBMoEdDty0B7InSWogVa5ERYBSjb745Xylk ] xUjKBzgdeC

Recent public activity

  1. comment
    Comment #47104740

    ~~Written by the same people?~~ EDIT: ha, confused with https://wiki.xxiivv.com/site/uxn.html

  2. comment
    Comment #46099749

    The real question is can Windows defender scan these drives?

  3. comment
    Comment #44663303

    I've been wanting to do this for ages. Originally I wanted to do this at the home router level, but that quickly got shut down when I got a test net up and running and my friends c…

  4. comment
    Comment #43922249

    "How do you get corporate secrets out of a software engineer? Sit them next to another engineer on a plane."

  5. comment
    Comment #43399841

    Well they aren't in Canada for me yet, but that's probably because we aren't the public that needs to know.

  6. comment
    Comment #42308228

    "Show me what you got"

  7. comment
    Comment #40922582

    I understand, but things like https://github.com/GoogleChromeLabs/comlink enable it. Similar to how iFrames don't have access to their parent page you need a facilitator. My questi…

  8. comment
    Comment #40922571

    I see it now, I don't know how I missed it.

  9. comment
    Comment #40920945

    Why reach for iFrames over other technology like WebWorkers?

  10. comment
    Comment #40147051

    I'm confident then that you can skip the base64 encoded header and just have the server use the jwt passed in the bearer token and the new signature you propose. (As the base64 enc…

  11. comment
    Comment #40146967

    When you `.get` a credential you can provide a challenge that it signs which you can make the JWT. With an added bonus that this passkey can exist on your phone or password manager…

  12. comment
    Comment #40146934

    Yeah that does it for new keys generated, any old keys in IDB obviously still are exposed.

  13. comment
    Comment #40145082

    Rather than generating key data on the client in the open, and storing it in IDB, I would recommend the Credential Management API[0]. Hand off the responsibility to proper generati…

  14. comment
    Comment #40144994

    so I don't fully understand what you're preventing const db = await openDatabase(); const keyPair = await getKeyPair(db); await crypto.subtle.exportKey("jwk", keyPair.privateKey) e…

  15. comment
    Comment #40136092

    Not much here explicitly in the source code dump. A little insight into their worker node infra but no "secret sauce" imo.

  16. comment
    Comment #39867100

    Hyperswarm has been my go-to for stuff like this, but you bring up a good point that I don't think it's encrypted. https://github.com/holepunchto/hyperswarm

  17. comment
    Comment #34265018

    I don't know if 5 miles is long enough for the people who actually need it, but if I was a postal worker, these would be pretty sweet. And 1400 USD is cheaper than some car insuran…

  18. comment
  19. comment
    Comment #30000732

    JPGs are not security, and moving JPGs can be fabricated very easily. Some v-tuber software with a deepfake GAN strapped to it I feel like would fool 1-on-1 meetings too. I got my …

  20. comment
    Comment #29594501

    > we can't decrypt your data. But I thought the point of the cages, is that _do_ decrypt the data. And any government mandated backdoors would then go into that process. You're not…

  21. comment
    Comment #29233689

    It's actually built into vanilla android https://support.google.com/googleplay/answer/9283534?hl=en

  22. comment
    Comment #27841051

    They've updated their list with a few new ones. https://www.sjc.edu/academic-programs/undergraduate/great-bo...

  23. comment
    Comment #25183226

    I agree, I thought the same thing when I hit that section. "What's wrong with that?"

  24. comment
    Comment #25156475

    Well that was the most compelling trailer I've ever experienced for a SQL reference book. Well done.

  25. comment
    Comment #24470800

    I think they're still working on that https://hyax.com/pricing