Hacker Newsnew | past | comments | ask | show | jobs | submit | gatestone's commentslogin


Reminds me when Russ Cox (Go, Google, Bell Labs) used Rob Pike's APL like Ivy to solve 2021 Advent of code puzzles:

https://www.reddit.com/r/apljk/comments/uccbd6/russ_cox_solv...


I am especially fond of this article inventing LLMs as Markov chains.

https://archive.org/details/byte-magazine-1984-11/page/n129/...


Who ever invented the idea that you can embed Javasript to picture files?


Someone else can explain, how me pressing "a" gets to light some LEDs on my screen, and what happens in the output part of the data flow.


No one mentioned Upspin? A global file namespace (URL, but better...) and protocol to isolate public data users from private governance and storage, by gurus like Rob Pike. https://github.com/upspin/upspin


At least in Finland the jail sentences have been related to extreme widely published antisemitism. Fines have been given for other sorts of hate speech.

If the U.S. wants this to be allowed, it is your business. But it is ours to decide, if we want to allow nazis synmpathy newspapers advocating killing of the jew. Generally, the americans are lost in their arrogance here, as always.


Who decide what is hate speech?


The same people who decide what's defamation, slander, fraud, criminal intent, deceptive practices, etc. etc. etc.


I don't think there has been a rock album ever since, that would have been so big, popular, revolutionary and generation defining. I guess some genius must have been there.


Can you explain me, why do you need to be online to extract the private key? Can't you just steal the token, input the nonces offline, and meter timing? Then, crunch out the private key, and only then, if needed, phish the password?


Yubikeys and similar FIDO hardware authenticators roughly speaking have two modes of operation:

Resident/discoverable credentials are stored on the hardware itself. You can attack these completely offline.

Non-discoverable credentials are not stored on the hardware. To get the authenticator to perform a private key operation (which is a prerequisite for being able to exfiltrate the private key using this attack), you need to supply the credential ID to it, which contains the data required for the authenticator to re-derive the private key.

Usually (i.e. in the WebAuthN-as-a-second-factor use case), a website will only reveal candidate client IDs upon successfully entering your password.


If this is inefficient, what are you comparing to? What is the best way to purify water or produce hydrogen with solar energy? Is there a good way? Certainly producing electricity first can't be the most affordable way?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: