HNHacker News
TopNewBestAskShowJobs

aisio

37 karma · joined November 21, 2017

submissionscomments
aisio··on Trump says Venezuela’s Maduro captured after strikes
America has plenty of the wrong type of oil. They need heavy oil as that's what the usa oil refinery are made to handle, but they have a shortage of heavy oil, and a oversupply of light oil. Venezuela has the heavy oil they need
aisio··on DeepSeek could represent Nvidia CEO Jensen Huang's worst nightmare
2048 GPUs cost $400m? pretty sure the GPUs don't cost 200k each?
aisio··on Sonos CEO steps down after app update debacle
Not a sonos engineer, but its a good external analysis https://www.linkedin.com/pulse/what-happened-sonos-app-techn...
aisio··on What is the minimal possible UK address?
True, heres a larger collection of North and South Postage

https://www.irishmirror.ie/sport/rugby-union/times-bizarre-i...

aisio··on What is the minimal possible UK address?
In Ireland you can just describe the person instead of the actual address and it'll get delivered

https://twitter.com/weefeargal/status/1479069076144234497?s=...

aisio··on UK Network Operators Target iCloud Private Relay in Complaint to Regulator
MITM for TLSv1.3 is possible. Plenty of solutions available for enterprises to do this. The MITM occurs still happens for TLSv1.3 on key exchange, allowing for the subsequent certificate to also be MITM and be replaced and encrypted. The only real affect TLSv1.3 has for MITM is that company policies for decryption can't match on the cert to determine if decrypt should occur, but they can still use the SNI which is plaintext
aisio··on Let’s Encrypt DST Root CA X3 Expiration – September 2021
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications
aisio··on Let’s Encrypt DST Root CA X3 Expiration – September 2021
"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail"

All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems

aisio··on “They introduce kernel bugs on purpose”
One reviewers comments to a patch of theirs from 2 weeks ago

"Plainly put, the patch demonstrates either complete lack of understanding or somebody not acting in good faith. If it's the latter[1], may I suggest the esteemed sociologists to fuck off and stop testing the reviewers with deliberately spewed excrements?"

https://lore.kernel.org/lkml/YH4Aa1zFAWkITsNK@zeniv-ca.linux...

aisio··on OpenSSL 3.0
Yes it supports Kernel TLS offload support. Both in SW mode (where the kernel does the TLS operations) and HW mode https://www.kernel.org/doc/html/latest/networking/tls-offloa...
aisio··on GCC eBPF for Linux port has landed
For loops are now allowed with eBPF in the latest kernels
aisio··on BPF comes to firewalls
Some interesting metrics on bpfilter, especially when combined with smart network card offloading

https://www.netronome.com/blog/bpf-ebpf-xdp-and-bpfilter-wha...