Viewing profile — xori
xori
HN member- Joined
- Fri, Oct 02, 2015, 2:46 PM UTC
- HN karma
- 505
- Public activity
- 170 items
- HN profile
- View on Hacker News ↗
About xori
Recent public activity
-
comment
Comment #47104740
~~Written by the same people?~~ EDIT: ha, confused with https://wiki.xxiivv.com/site/uxn.html
-
comment
Comment #46099749
The real question is can Windows defender scan these drives?
-
comment
Comment #44663303
I've been wanting to do this for ages. Originally I wanted to do this at the home router level, but that quickly got shut down when I got a test net up and running and my friends c…
-
comment
Comment #43922249
"How do you get corporate secrets out of a software engineer? Sit them next to another engineer on a plane."
-
comment
Comment #43399841
Well they aren't in Canada for me yet, but that's probably because we aren't the public that needs to know.
-
comment
Comment #42308228
"Show me what you got"
-
comment
Comment #40922582
I understand, but things like https://github.com/GoogleChromeLabs/comlink enable it. Similar to how iFrames don't have access to their parent page you need a facilitator. My questi…
-
comment
Comment #40922571
I see it now, I don't know how I missed it.
-
comment
Comment #40920945
Why reach for iFrames over other technology like WebWorkers?
-
comment
Comment #40147051
I'm confident then that you can skip the base64 encoded header and just have the server use the jwt passed in the bearer token and the new signature you propose. (As the base64 enc…
-
comment
Comment #40146967
When you `.get` a credential you can provide a challenge that it signs which you can make the JWT. With an added bonus that this passkey can exist on your phone or password manager…
-
comment
Comment #40146934
Yeah that does it for new keys generated, any old keys in IDB obviously still are exposed.
-
comment
Comment #40145082
Rather than generating key data on the client in the open, and storing it in IDB, I would recommend the Credential Management API[0]. Hand off the responsibility to proper generati…
-
comment
Comment #40144994
so I don't fully understand what you're preventing const db = await openDatabase(); const keyPair = await getKeyPair(db); await crypto.subtle.exportKey("jwk", keyPair.privateKey) e…
-
comment
Comment #40136092
Not much here explicitly in the source code dump. A little insight into their worker node infra but no "secret sauce" imo.
-
comment
Comment #39867100
Hyperswarm has been my go-to for stuff like this, but you bring up a good point that I don't think it's encrypted. https://github.com/holepunchto/hyperswarm
-
comment
Comment #34265018
I don't know if 5 miles is long enough for the people who actually need it, but if I was a postal worker, these would be pretty sweet. And 1400 USD is cheaper than some car insuran…
- comment
-
comment
Comment #30000732
JPGs are not security, and moving JPGs can be fabricated very easily. Some v-tuber software with a deepfake GAN strapped to it I feel like would fool 1-on-1 meetings too. I got my …
-
comment
Comment #29594501
> we can't decrypt your data. But I thought the point of the cages, is that _do_ decrypt the data. And any government mandated backdoors would then go into that process. You're not…
-
comment
Comment #29233689
It's actually built into vanilla android https://support.google.com/googleplay/answer/9283534?hl=en
-
comment
Comment #27841051
They've updated their list with a few new ones. https://www.sjc.edu/academic-programs/undergraduate/great-bo...
-
comment
Comment #25183226
I agree, I thought the same thing when I hit that section. "What's wrong with that?"
-
comment
Comment #25156475
Well that was the most compelling trailer I've ever experienced for a SQL reference book. Well done.
-
comment
Comment #24470800
I think they're still working on that https://hyax.com/pricing