641 karma · joined August 22, 2011
> a Library that contains 251,312,000 volumes of random sequences of letters (1,312,000 being the number of characters in any given book, each of which admits of twenty-five variations)
This seems to be a typo of sorts. I believe the correct number is 25^1312000 (sequence length m, n possible values for each, n^m distinct possible sequences).
Having hit this in the past, my guess is it was originally written with a superscript, then the text lost the formatting (leaving 251312000), and an editor left it as 251,312,000. Always worth checking final rendering for any text you expect to include superscripts.
Both parties should want a place that's enjoyable to work over the long term, yet sometimes the company will have to make hard decisions. Priorities slip or people are straight-up unable to avoid, say, laying off half the staff. Framing and context matter, as always. "Your employer is not on your side" is hopefully not a statement about the day-to-day interactions with your boss, or even a statement about company values, but it can serve as a reminder that there's always a line somewhere, and, intent aside, your best interests may simply fall on the wrong side.
> There exist several closed-form solutions to Fibonacci sequence which gives us the
> false hope that there might be an O(1) solution. Unfortunately they all turn out to
> be non-optimal if you want an exact solution for a large n.
One thing I hope they make a little clearer is how to delegate cipher suite selection to certbot. I saw some discussion about making options-ssl-nginx.conf use, say, one of Mozilla's server-side configurations (whichever one you've configured). That way you could include options-ssl-nginx.conf and it'd auto-update over time.
Don't human professional players do exactly this? They care about playing the best move and winning. The difference is that AlphaGo is likely much more accurate at determining what "95% probability of winning" means in terms of gameplay. A human has a harder time judging the eventual outcome of a game, and so plays more "aggressively" (favouring point margins to account for variance in the estimate, etc.) than AlphaGo might.
I think the issue here is that 301 and 302 were originally intended to preserve the HTTP method but they became permanent and temporary versions of "issue a new request with a GET". So to try and fix that they provided 307 (and now 308) as temporary and permanent versions of "this resource changed location, so reissue this request at the new URL".
I actually wrote a post about this a couple of days before RFC 2616 got marked for official deprecation: https://aprescott.com/posts/http-redirects
I plan on updating that with more information once a proper RFC deprecates 2616 and 308 makes its way into something other than a referenced alternative, as it is in the current draft last time I checked.
Also, for fun, try pointing curl at a server returning various response codes and see what it does with `-X [method]` and compare it with the latest Chrome and Firefox.
In fact, I usually just copy the password with Ctrl-C and the username with Ctrl-B. You can configure a secure clipboard erase after n seconds.
One thing I really wish had better support is ssh-based entry-level sync of databases[1]. Keepass has a plugin for it but I don't know the status for KeepassX 2 (currently in a non-stable release state). If I could point KeepassX at an SSH remote path and have it transparently sync at the entry level it'd be almost perfect.
It does appear, however, that price manipulation by a single trader who accumulated a large directional position on Romney may have been a factor. This trader accounted for one-third of all bets placed on Romney during our observational window, and lost almost four million dollars in the process. This position was accumulated by placing large bids for Romney and large offers for Obama that effectively created a firewall, preventing prices from moving in response to incoming information. This resulted in remarkable stability in Intrade prices for several hours on Election Day, and at other critical moments of the campaign, even as prices on Betfair were moving sharply. On Election Day, these orders were removed just as voting ended in Colorado, the last swing state to close its polls. The eect was a sharp price movement and immediate convergence to the Betfair odds. Financial gain though correlated changes in stock prices seems an unlikely motivation for this activity, since these correlations appear to have broken down in 2012. More plausibly, this trader could have been attempting to manipulate beliefs about the odds of victory in an attempt to boost fundraising, campaign morale, and turnout.
And the biased vs unbiased numbers:
Manipulation aside, one of our most striking findings is that 86% of traders, accounting for 52% of volume, never change the direction of their exposure even once. A further 25% of volume comes from 8% of traders who are strongly biased in one direction or the other. A handful of arbitrageurs account for another 14% of volume, leaving just 6% of accounts and 8% of volume associated with individuals who are unbiased in the sense that they are willing to take directional positions on either side of the market. This suggests that information finds its way into prices largely through the activities of traders who are biased in one direction or another, and differ not only with respect to their private information but also with respect to their interpretations of public information.
The real thing you shouldn't need to put on a door, though, is how to use it: "Use as an entrance."
Since BEAST was fixed in TLS 1.1, I think you can require 1.1+ and get an A, but the test suggests you might break things for a significant chunk of users.
Even if you get a B because you're vulnerable to BEAST, if you prioritise 1.1+ ciphers, you'll still fail to get an A but you'll mitigate against it. It looks like Qualys themselves have a post on this, actually: https://community.qualys.com/blogs/securitylabs/2011/10/17/m...
I contacted the author about this, but I don't think this is correct.
The OpenSSL ciphers documentation[1] says "DH" is simply all suites using Diffie–Hellman, not necessarily authenticated DH, which is "aDH". I actually couldn't check if it does include aDH since `openssl ciphers -v 'aDH'` tells me I don't have any aDH ciphers!
Unfortunately there's no documentation to explain the difference between EDH (ephemeral DH?) and DHE. Are they synonyms? I'm assuming DHE is ephemeral since using a string with DHE Will get you Perfect Forward Secrecy "points" on an SSL Labs test[2]. (Run the test! Secure your web servers! You can get at least a B rating easily enough.)