HNHacker News
TopNewBestAskShowJobs

amckinlay

383 karma · joined September 5, 2012

submissionscomments
amckinlay··on A new look for rust-lang.org
The new design looks like it was made in Microsoft Word.
amckinlay··on We are Google employees – Google must drop Dragonfly
They do deserve it, just not a censored one.
amckinlay··on Why Aren't There C Conferences?
Why doesn't C have an actual, formal semantic model?

"Furthermore, we argue that the C standard does not allow Turing complete implementations, and that its evaluation semantics does not preserve typing. Finally, we claim that no strictly conforming programs exist. That is, there is no C program for which the standard can guarantee that it will not crash." [1]

Maybe someone should file a defect report.

[1] https://pdfs.semanticscholar.org/6237/6bcf5e1b55abcaa301b9c8...

amckinlay··on HTTP-over-QUIC will officially become HTTP/3
What's wrong with SCTP?
amckinlay··on Blizzard Says It Wasn't Expecting Fans to Be This Angry About Diablo Immortal
The mobile game is just a reskin of an existing Netease (Chinese) game. Mobile games are also full of microtransactions which players already protestested in Diablo 3 with the real money auction house. Players actually are angry about a Diablo mobile game.
amckinlay··on Messenger systems compared by security, privacy, compatibility, and features
Is there any messenger that does end-to-end encryption with reliable, in-order delivery with decentralized group chat and conversation history syncing? Been looking for years but so far the double-ratchet is inadequate.
amckinlay··on Postbox email client
What is with all these email clients supporting folders but not labels for Gmail. I get that labels are not a supported abstraction in IMAP, but they are supported through the Gmail API.
amckinlay··on Found hooked up to my router
I still don't understand how this device could steal login details. Everything should be encrypted and authenticated through PKI when using any website that accepts login details. Whenever I visit a website with an expired certificate, for example, Chrome gives me a big red warning banner before allowing me to continue to the site.
amckinlay··on Google Suppresses Memo Revealing Plans to Closely Track Search Users in China
And this time we actually have legitimate, real, censorship to fight.
amckinlay··on Google Suppresses Memo Revealing Plans to Closely Track Search Users in China
That sounds like a suspiciously confident prediction given the nature of the internet.
amckinlay··on David Patterson Says It’s Time for New Computer Architectures and Languages
I want a language where you can express time and constraints on time within the language and the type system. I want to be able to guarantee program correctness, pre-calculate fine-grained energy usage, optimize for energy/power-saving mode usage, interface with asynchronous signals, and whatnot -- all with respect to program execution at the ISA-level within some hard real-time constraints.

Compilers make optimizations using detailed instruction timing information, but as far as I know, these details do not bubble up to the surface in any programming language.

It may be wise to keep these details under the surface at the compiler level, but for 8-bit architectures, it would be awesome to have a language where you have explicit control of time.

amckinlay··on Krypton: phone-based U2F Authenticator
Should not be too hard to develop a free version of this. Do not look at their source code on GitHub, though.
amckinlay··on Australia’s Proposed Surveillance Laws Will Break the Trust Tech Depends On
Migration policy really has nothing to do with this surveillance law.
amckinlay··on WireGuard VPN review: A new type of VPN offers serious advantages
Why can't we have IPSec + IKEv2 everywhere as originally intended as part of IPv6. No "VPN" necessary.
amckinlay··on Commons Clause
I think that licensing restriction only applies if you provide the source to the client.
amckinlay··on Researcher at center of epic fraud remains an enigma to those who exposed him
How is it responsible, medically, to sit on a report of scientific fraud without action for two years, selling and profiting off bad data.
amckinlay··on PipesFS: Fast Linux I/O in the Unix Tradition (2008)
Still wish the Linux kernel had zero-copy IPC with pipes. vmsplice(1) can zero-copy data into the pipe, but the destination process cannot vmsplice(1) the data out of the pipe without incurring a copy.
amckinlay··on White House earmarks over $1B for quantum technology research
It was kind of funny, though.
amckinlay··on The Egison Programming Language
This looks like an intruiging alternative to Julia. Last time I tried Julia, effecient multidimensional code generation was incomplete due to required work in the type system. I wonder how Egison's performance matches it's expressiveness.
amckinlay··on Wi-Fi Alliance Introduces Wi-Fi Certified WPA3 Security
And if the IoT device is using Wi-Fi anyway there is no need for low power demand of Bluetooth.
amckinlay··on Special-Use Domain 'home.arpa.'
.localhost is the loopback IP on most resolvers, though.
amckinlay··on Special-Use Domain 'home.arpa.'
.local is used ad-hoc by mDNS (Apple). Last time the issue of naming local-area devices came up on ##networking, the consensus was to purchase a domain name in order to name local network devices without interfering with global name resolution standards, which seems ridiculous.
amckinlay··on Towards Scala 3
Last time I tried Scala I had to give up because I couldn't understand what a "trampoline" was, or how to use it to get multi-function tail recursion to work. Probably not Scala's fault.
amckinlay··on Thousands of Turks accused of using Bylock app despite never having used it
And this is a government we're going to rescue if they're ever under attack.
amckinlay··on Alert About Missile Bound for Hawaii Was Sent in Error, Officials Say
This kind of accident has happened many times in the history of the Emergency Alert System (EAS)[1] and the earlier Emergency Broadcast System (EBS). The false alarm of 1971[2] actually revealed a major flaw in the EBS. During the incident, a legitimate national alert initiation message was erroneously broadcast instead of the scheduled test message. Many stations did not propagate the message as required because of confusion caused by receiving it within the time window of a scheduled test. Interestingly, this revealed a major flaw in the system in the event of a real emergency: that an adversary could time its attack with a test broadcast of the EBS, rendering the system generally ineffective.

[1] https://en.wikipedia.org/wiki/Emergency_Alert_System#Inciden...

[2] https://en.wikipedia.org/wiki/Emergency_Broadcast_System#Fal...

amckinlay··on iOS 11 Security [pdf]
Apple security is confusing. For example, Find My Mac does not require 2FA even when 2FA is enabled. An attacker can remotely wipe your MacBook with just your iCloud password.

Another example: apparently there is a distinction between "two-factor authentication" and "two-step authentication", the later being a deprecated, but active system. Reading the docs for the older system, you'll soon discover differences in things such as account access and recovery that lead to an entirely different set of consequences and caveats for security. You'll find out that in certain scenarios you could permanently lose access to your iCloud account and iTunes purchases under "two-step authentication*, but not the newer "two-factor authentication". If a user confused the two while reading the Apple online support pages, it could have grave consequences.

Security is something that needs to be documented and marketed in clear terms. Why Apple would adopt names so similar for two distinct implementations of a security mechanism that they could arbitrarily describe either is incoherent with Apple's supposed model of user friendliness. It's what Microsoft does with its products, not Apple. Additionally, all facets of a security feature should be documented, and documented well. It is unacceptable that Apple does not warn users that 2FA can be bypassed in certain scenarios. I hope Apple does further focus on security, and documenting it well.

amckinlay··on iMac Pro's T2 chip
I'm glad they allow you to completely disable the "secure boot" functionality so that other OSes like Linux can be installed. Glad Apple didn't pull a Microsoft here. I would be delighted, however, if the secure boot functionality was programmable with custom certificates!
amckinlay··on Linux page table isolation is not needed on AMD processors
Pretty extraordinary that a user's most important files (their documents and whatever else is in their home folder) are accessible to any app at any time. Why are we still using this outdated security model? On Windows, I could download an .exe and it could upload the entire contents of my Dropbox without even prompting for elevation or anything. Kinda scary when you think about it.
amckinlay··on Linux page table isolation is not needed on AMD processors
AMD is doing a lot of things right recently and they have a bright future. And after seeing this, apparently they have been doing things right longer than I thought.
amckinlay··on An introduction to reverse-engineering x86 microcode and writing it
Providing "support" probably means "fix defects that are otherwise unnoticed in a closed/secret system."
Page 1 of 3Next →