HNHacker News
TopNewBestAskShowJobs

botto

198 karma · joined October 24, 2016

github.com/botto
submissionscomments
botto··on SQRL: Secure Quick Reliable Login
Thank you :)

I just reread it, I should do a bit of grammar linting in the future.

botto··on SQRL: Secure Quick Reliable Login
Just as a preamble, I listen to his podcast and have for years, so I'm probably biased to some degree.

I agree with your first points around SQRL, it's an interesting concept but in the long run the industry has solved the problem eventually and possibly better. Also keeping one sqrl identity is a slog to say the least.

On the latter point, I feel like it's a mixed bag, SpinRite honestly works (and yes I've tried other tools), if you haven't been in the unlucky spot of a dead drive then I understand how SpinRite can seem a little snake oil like.

Having said that there is a big "not invented here/me syndrome" and I do wish he would participate in the open source community as a whole more, it might make him more aware of what is happening within the software community more.

botto··on SQRL: Secure Quick Reliable Login
Nice quote out of context there.

If you read on further it does explain how SQRL can mitigate this:

- Because the request from the SQRL client will not match the request from the phishing site the original website will be able to see that and reject the login. Keep in mind the SQRL login request is signed by the original site so can't spoof the payload/qr code the user clicks/scans

botto··on SQRL: Secure Quick Reliable Login
It is complicated for sure and I think one of the problems is currently the clients for SQRL are pretty bad (I've tried them all, maybe I'm just picky)

However it's very questionable regarding the per device security.

Keep in mind a lot of people manage more and more of their life through their devices so more security is being pushed on to individual devices, however 3rd party websites and services have little to no oversight that they are actually doing the correct job and keeping peoples data secure.

Just look at https://haveibeenpwned.com/ for a vague idea of how bad security is still handled by service providers.

botto··on SQRL: Secure Quick Reliable Login
Please do explain how it's phishable?

I've found this doc on the subject https://www.grc.com/sqrl/phishing.htm

botto··on Samsung committing to three generations of Android OS upgrades
So they are supporting three generations of android version, so if a phone comes out on 8, that means it will receive major upgrades to 10, so that's 3 years there and then Google seem to support 3 more years of security of 10 after it comes out.

I'm aware android 8 is old now, just using it as an example.

botto··on Samsung committing to three generations of Android OS upgrades
Depends on which upgrades you are concerned about. I agree that having new os versions supported for longer than 3-4 years would be good, but at least it looks like they will be supporting security updates for longer now, 6 years of security upgrades if I'm not mistaken.
botto··on Chat server on a WiFi-enabled SD card
It's goodish, the firmware is hard to get right and the chip itself gets waaaarm
botto··on Google speakers are listening to more than just voice commands
I've unplugged mine too but saying it's spying is mincing words a bit.

I highly doubt they care what individuals say in their home but probably care a lot more about what your demographic talks about, watches on TV, listens to on the radio and any other data they can glean from sound.

Think about it, distinct actions make certain sounds, (i.e. from washing dishes to sleeping)

They probably have a lot more of a complete picture of your home than you realise.

botto··on The Rise of Platform Engineering
I'm sorry to hear that as someone who has done this role in the past I can tell you that it's the opposite of what a platform team should be doing.

When done right a platform team should basically not be noticed except that the tooling, developer experience and overall reliability of a system goes up.

botto··on Zoom to bring end-to-end encryption to all users, including non-paying
You can audit the client either through source code or through very painful binary analysis.
botto··on Zoom to bring end-to-end encryption to all users, including non-paying
The whitepaper is fine, it's the comments from Alex Stemos that make me think they are abusing the term.

https://twitter.com/alexstamos/status/1268061792527241216

He did not say they can't monitor calls.

https://twitter.com/alexstamos/status/1268061795572314113

If they can enter the meeting, either they have to get confirmation from the host who would send the keys to the person entering the meeting or they already have the keys and can enter the meeting and decrypt the stream.

botto··on Zoom to bring end-to-end encryption to all users, including non-paying
You should copyright and license it to Zoom
botto··on Zoom to bring end-to-end encryption to all users, including non-paying
This is true, but they are going to help law enforcement with calls that have bad content in them, the only way this can happen is if they have the ability to decrypt the streams or enter calls silently and get the keys.

Edit: Sorry for coming across a little brash, I'm quite a strong advocate of real encryption and this kind dilution of terms makes my blood boil because terms are being diluted and people have trust in something that betrays them.

botto··on Zoom to bring end-to-end encryption to all users, including non-paying
Yes, if the keys are held in servers that they have access to then they would be able to decrypt the traffic and see what is happening. The whole point of e2e encryption is that only the 2 parties have the keys, Zoom are abusing this term and making people believe they are doing e2e
botto··on Zoom to bring end-to-end encryption to all users, including non-paying
I'm quite frustrated they are calling this end to end. I can't find it now but a tweet earlier indicated that they have the keys and can help law enforcement with investigations which means it's can't be end to end.
botto··on Is Cloudflare Safe Yet
I guess no one read all the way to the copyright

> While this site is a parody, it may contain factual information. :) The author has no affiliation with Cloudflare, Inc.

botto··on AWS Ground Station
I don't think AWS are involved in the satellites themselves, they are simply making access to ground station equipment available over the net.
botto··on Earth-sized exoplanet ‘habitable zone’
Any way we can capture one of these beings and study them, I'd love to understand how the brain works
botto··on Zorin OS Is the Alternative to Windows and macOS
FreeBSD is also an alternative to Windows and macOS
botto··on Tesla Cybertruck
This is dystopian future car, how many sci fi movies have we seen with cars looking like this? I.e. Ghost in the Shell
botto··on Show HN: USB PD Stand-Alone Sink Controller
So you say you set the voltage and current requirements once in the software, but looking at the data sheet it can be reprogrammed?

Do you mean you set it and it works between power cycles?

Otherwise you have to be careful and set the values you need first time I guess.

botto··on Show HN: USB PD Stand-Alone Sink Controller
you could hang one off the output, not the most elegant but at least modular then
botto··on Serverless: slower and more expensive
This feels very "Serverless is cool, everyone is saving money on it, lets do the same"

> I only had to add a simple config file, add one dependency and one small startup class to my existing API project.

This is not the way to do it, you have to spend some time on lambda approach.

Usually splitting up your code in to smaller chuncks so you don't end up with long spool up times and you can do things like keeping your lambda warm and caching high impact parts of the code. (sometimes of course you can't cache, I know)

Having gone through this process myself with a very very large code base, it would have not worked to just slap it into serverless.

Going server less can save you money, but not by just taking your existing app and throwing it on Lambda.

botto··on Almost one-fifth of Britons 'do not use internet'
So probably the privacy concerns come from over blown news articles and reporting about latest passwords leak, information leak, hacking, exploit and any other word that remotely sounds like it's related to the internet.

You should watch Sky News sometimes talk about the latest security problem, they do not take a balanced approach to the reporting.

botto··on Almost one-fifth of Britons 'do not use internet'
I would suggest reading the original report. https://oxis.oii.ox.ac.uk/wp-content/uploads/sites/43/2019/0...

Quite interesting to see that the majority of people who don't want to join the internet is because of choice and worry that they will lose their privacy.

Anyone done a study of how people who don't use the internet usually vote in elections and generally feel socially about the rest of the world?

botto··on 25 Years of PHP [video]
True, they use hacklang but it's no longer folowing the php spec https://hhvm.com/blog/2019/02/11/hhvm-4.0.0.html
botto··on Tesla Model 3 accounted for over 12% of Norwegian auto market in Jan-July
I do wonder how the electrical grid in Norway is going to hold up to the massive increase in demand that EV charging will cause.
botto··on Not a full timer
True, when I was contracting I did attend less meetings although it always felt like too many and the pay was good (not so much now).

But I always found it a little bit of a lie when the idea of a contractor coming in and working on a problem from day 2 or 3.

Granted this usually was because the problem was poorly defined and/or limited but even when I joined teams that had really good project managers it still was not as simple as "work on this in isolation".

I have since ditched contracting in UK, too much of a mess with the taxman.

botto··on Not a full timer
It never feels like the contractor is an "expert" in a field, is any more efficient than another employee and is nothing more than another person that has been hired to do programming with less HR/employment overhead.

So not sure which audience this article is aimed at.

Maybe my experience in London doesn't reflect other places but as a contract and as someone who has looked for contractors it never felt like we got anyone special. They were another person and they took just as long to on board and become efficient.

← PreviousPage 2 of 3Next →