HNHacker News
TopNewBestAskShowJobs

HurrdurrHodor

153 karma · joined August 26, 2016

submissionscomments
HurrdurrHodor··on Zarf’s Interactive Fiction (2017)
<3 Emily Short <3 I should replay Savoir Faire.
HurrdurrHodor··on A Child’s Garden of Inter-Service Authentication Schemes
I am somewhat surprised by the statements about asymmetric crypto algorithms. Given a good library they don't seem more error prone and given many common use-cases they are not significantly slower.
HurrdurrHodor··on Inside Firefox’s DNS-over-HTTPS engine
Just a guess but maybe they wanted to build this in a way that it would actually get used.
HurrdurrHodor··on The Engineer vs. the Border Patrol
1. Click on link. 2. Get huge GDPR banner. 3. Close tab.

GDPR, the new productivity booster.

HurrdurrHodor··on Please Stop Using Adblock (But Not Why You Think)
Seriously? You want people to switch from software A to software B and you write an article that for the first half of the page sounds like you want them to stop using either of those softwares?
HurrdurrHodor··on Please Stop Using Adblock (But Not Why You Think)
Whatever the reasoning:

HAHAHAHAHA! No.

HurrdurrHodor··on Cryptographic filesystem for the cloud
Actually I think, the misunderstanding is on your side. Unauthenticated DOES mean that the attacker can modify anything without you noticing. You might only notice because you are getting a file that looks like random junk but you wanted it to be a picture. But that is not something you should rely on for security.
HurrdurrHodor··on Obscurity Is a Valid Security Layer
But here's the point: Do you want people to spend their 10 minutes picking good passwords or setting up public key auth or should the spend them switching their server to port 24? Security BY obscurity is bad as the article states and unless you have infinite resources everything is a trade-off.
HurrdurrHodor··on Obscurity Is a Valid Security Layer
But obscuring may take away time from securing and it adds complexity to the system but systems with less complexity are easier to secure. So you at least have to be careful.
HurrdurrHodor··on FZF and RipGrep – Navigate with bash faster than ever before
I've just tried this and in my case it leads to "cd \~[...]" which obviously does not work.
HurrdurrHodor··on The “Happy Path” to HTTPS
The appropriate way for users to defend themselves is to simply install https-everywhere and check "Block all unencrypted requests". This avoids sslstrip, requires no redirect magic and no HSTS.

Although somebody should really patch it to just display big fat warnings because it is somewhat annoying to turn it on and off all the time.

HurrdurrHodor··on Show HN: Crackle – keyboard layout for programmers
I have been using http://neo-layout.org/ for years now and it works very well comes out of the box with Linux and does pretty much the same. If you type only in english you will be wasting a few keys because it has german umlauts but it is imho still nicer than qwerty.
HurrdurrHodor··on How to Determine If Candidates Will Thrive in a Remote Work Environment
My high-school math teacher used to say that we have our best ideas for solving problems in the shower and on the toilet. :)
HurrdurrHodor··on How I implemented my own crypto
Write a crypto library and blog about how great it is.

Apply the tools that other people used to find bugs in it and repeat blogging about how great it is.

...

In the end you get a library that is slower and smaller (because you left out the optimized code, duh). It's still not as small as the smallest.

Is this easier to audit? Dubious but it doesn't matter because if people hadn't wanted the extra speed they wouldn't have added the optimized code anyway.

Plus, that code is already audited and rolled out and works! Who cares about auditing another library that provides nothing new?

The only non obviously-garbage argument here is usability which I am too lazy to look at because it is too fuzzy to refute anyway.

By all means, write your own crypto but DON'T USE IT! And of course don't tell other people to use it either.

HurrdurrHodor··on How I implemented my own crypto
TLDR: Crypto library with two claimed advantages: Better usability and smaller code than libsodium. However, it is also slower.
HurrdurrHodor··on The language of choice
I think this needs a bit more motivation (why do I want to know about BDDs) and more pictures. The code is great for playing with things and remembering better but the fundamental concepts would be clearer with more pictures.
HurrdurrHodor··on Package Management: The problem with using version ranges
Well, if you already know which updates are non-breaking, of course you have solved this problem.
HurrdurrHodor··on Show HN: Seashells – Pipe output from CLI apps to the web in real time
For sharing code snippets you can just do something like this:

alias paste='curl -s -F '\''sprunge=<-'\'' http://sprunge.us | tee >(xclip -selection clipboard)'

Which on my system will create a paste of whatever you pipe to it and put the link to it in your clipboard.

HurrdurrHodor··on Privileged Ports Are Expensive (2016)
"Trace the flow of data from client to network to app to disk to app to network to client etc."

How would one go about doing that?

HurrdurrHodor··on Magma – An encrypted email server daemon
I know of lavabit but I want to know what this software does.
HurrdurrHodor··on Magma – An encrypted email server daemon
Can somebody tell me what this actually does? All I see is an MTA and some hand waving.
HurrdurrHodor··on Why is the Quintic Unsolvable?
It doesn't work with Firefox, right?
HurrdurrHodor··on Switching to the Mutt Email Client
"fiddling feels a lot more productive than it actually is"

Best thing about this article. Unfortunately he didn't derive anything from this wise statement.

HurrdurrHodor··on SQRL – Secure Quick Reliable Login
A more viable competitor: https://www.n-auth.com/
HurrdurrHodor··on SQRL – Secure Quick Reliable Login
2FA requires 2 authentication factors like a password & a token i.e. your PIN and banking card. It doesn't really have anything to do with where you enter those. https://en.wikipedia.org/wiki/Multi-factor_authentication
HurrdurrHodor··on A Case of Stolen Source Code
"There’s no indication any customer information was obtained by the attacker. Furthermore, there’s no indication Panic Sync data was accessed."

Read: The attacker could have accessed all that data but didn't send me an e-mail telling me that he did.

HurrdurrHodor··on Git-crypt – Transparent file encryption in git
Maybe it's not a great idea for software projects but for keeping personal data in git (the author wrote it for dotfiles) it seems brilliant.
HurrdurrHodor··on Mine3D: A Web 3D Minesweeper Game
This would probably be better if each cube had only 6 neighbors because the way it is the areas are pretty large and it gets quite difficult.
HurrdurrHodor··on iPhone App will not stay open - just flashes when trying to launch
I'm kind of happy that this is happening. Whatever the legal situation may be this is just wrong and it needs to be fixed.

On steam you don't buy games anymore you only buy the right to play them so you cannot resell them. You are effectively buying a service.

Now in this case you are buying a device that does not work without the service and you don't have a right to the service?

No, this does not make sense.

HurrdurrHodor··on Why F.E.A.R.’s AI is still the best in first-person shooters
I think it is important to keep in mind that AI in games often not only needs to do the smartest thing but actually the smartest thing a human would do.

So in the case of F.E.A.R. the AI is simulating humans so they shouldn't seem smarter than that.

This starts at not microing to well in strategy games and not aiming to well in shooters but is almost limitless in how complicated one can make it.

Page 1 of 2Next →