62 karma · joined October 24, 2010
1: https://developer.apple.com/videos/play/wwdc2013/712/ (I think the relatively short graphics section mentions this. Can't seem to find the talk that goes into it in more detail...)
reallocarray() has some difficulties as an interface, mostly inherited from realloc(). I'm a bigger fan of reallocarr(), but that's NetBSD only. We (the operating systems community) need to find a consensus here, but I'm not convinced that reallocarray() is that consensus yet.
If my passphrase gets compromised, I have to retire the keypair.
That's true of a key file with current asymmetric systems; but, presently if the passphrase of my GPG private key is compromised (e.g. by a hardware key logger), I only have to change the passphrase and ensure the old keyfiles are destroyed.
With MiniLock, if my passphrase is compromised the entire key material is compromised and I need to revoke the public key. But how do I revoke it? Do I tweet a message with the private key saying the public key is revoked? Will there be a centralized place to publish revocation messages? Efficient key revocation will be absolutely critical to this system and that's hard if the key distribution mechanism is tweets or some other ad hoc mechanism. This is one thing that PGP key servers really help with.
My two cents: While I would have hated such a thing in an engineering class, I really appreciated public discussion and criticism of my work in the arts. I found that such transparency, even when painful, was hugely valuable to me as I grew as an artist.
That's all you need to know as a lay-rescuer. And if you forget, the 911 operator will walk you through it.
( Or, if you'd rather: http://supersexycpr.com )
It is possible that there are people who work at Apple that read HN and if you post a bug number one of those people might then be able to open the bug.
I think the many people who work in "no cameras" facilities might love the option of a camera phone with an employer's profile that makes the phone safe to bring into the facility. This isn't much different from how my employer enforces the use of a passcode when connecting an iPhone to VPN.
When you make strong statements, other people often have a tendency to react strongly and defensively. I assume that the person at the other end is both competent and concerned - give them all benefits of the doubt.
If you find that isn't the case, then, and only then, you can email them and use the word "security" and talk about going public after n weeks, etc.
(I am not a lawyer.)