HNHacker News
TopNewBestAskShowJobs

dadrian

676 karma · joined June 3, 2013

https://dadrian.io

@davidcadrian

@dadrian@a2mi.social

@dadrian.io

Must read: 'tptacek, 'jblow, 'JumpCrisscross, 'idlewords, 'hwayne, 'luu, 'gdb, 'antics

submissionscomments
dadrian··on HTTPS by default
Yes, it started that way, but complaining about the current auto-update behavior of the software (not the ACME protocol), is completely unrelated to Let's Encrypt and is instead an arbitrary design decision by someone at EFF.
dadrian··on HTTPS by default
Add a /, e.g. `shortname/`
dadrian··on HTTPS by default
Let's Encrypt does not write or maintain certbot
dadrian··on HTTPS by default
Non-unique hostnames, which are RFC 1918 space, single-label hostnames, and addresses assigned to mDNS (.local).
dadrian··on HTTPS by default
Chrome has shown the HTTP warning in Incognito mode for about a year, and has shown the warning if you're in Advanced Protection mode for about 2-3 years.
dadrian··on Zig feels more practical than Rust for real-world CLI tools
Web browsers and operating systems are full of memory safety bugs, and are not written by engineers in crunch these days.
dadrian··on Zig feels more practical than Rust for real-world CLI tools
Not clear to me there's a correlation between hours worked and number of memory safety vulnerabilities
dadrian··on Zig feels more practical than Rust for real-world CLI tools
I like Zig, although the Bun Github tracker is full of segfaults in Zig that are presumably quite exploitable. Unclear what to draw from this, though.

[1]: https://github.com/oven-sh/bun/issues?q=is%3Aissue%20state%3...

dadrian··on Not all browsers perform revocation checking
Yes, because this is not a security-relevant revocation.
dadrian··on Not all browsers perform revocation checking
https://dadrian.io/blog/posts/revocation-aint-no-thang/
dadrian··on OCSP Service Has Reached End of Life
OCSP stapling, when done correctly with fallback issuance, is just a worse solution than short-lived certificates. OCSP lifetimes are 10 days. I wrote about this some here [1].

[1]: https://dadrian.io/blog/posts/revocation-aint-no-thang/

dadrian··on Japan sets record of nearly 100k people aged over 100
Yeah, I assume this means there’s a lot of fraud
dadrian··on The US is now the largest investor in commercial spyware
This is an unserious article.

1) If you're counting investment, you should count it in dollars, not number of investors or corporate entity locations.

2) This is missing at least two extremely well-known CNE vendors, which makes me doubt its accuracy.

3) The takeaway from the graph on Mythical Beasts [1] should be that the industry is _very small_, not that it's very big.

4) Americans should be happy that the US government is the biggest player. Would you prefer to have China or Russia or the Middle East be the biggest player? Get a warrant -> own a phone is a very straightforward process that fits into existing models of civil liberties in the US.

[1]: https://mythicalbeasts.atlanticcouncil.org/

dadrian··on The US is now the largest investor in commercial spyware
No, that is also illegal.
dadrian··on The US is now the largest investor in commercial spyware
It is illegal for an employer to hack your phone.
dadrian··on Mistral raises 1.7B€, partners with ASML
I saw someone joke that "once Mistral gets back from their European summer, they'll really be in it", and damn, it does feel like that happened.
dadrian··on Charting Form Ds to roughly see the state of venture capital “fund” raising
Oh nice! That's probably reasonable, although I am pro keeping the accredited investor requirement.
dadrian··on Charting Form Ds to roughly see the state of venture capital “fund” raising
The most basic SaaS companies are not raising $10MM at pre-seed, they’re raising $1-3MM at $10-30MM post.
dadrian··on Charting Form Ds to roughly see the state of venture capital “fund” raising
Most Fund I’s are going to be smaller funds, often $9.99MM to allow for a larger number of smaller LPs due to the $10MM threshold from the SEC. Whereas Fund II-IV are going to be considerably bigger, often hundreds of millions of dollars. So a large number of smaller funds falling off won’t make that big of a dent in the total dollars available, but may make it harder to get the smaller initial checks.
dadrian··on Obsidian Bases
Are there any good LLM plugins for Obsidian, beyond just throwing Claude Code / Codex at your markdown folder?
dadrian··on U.S. alcohol consumption drops to a 90-year low, new poll finds
It's because GenZ is addicted to nicotine and millennials are all using legal weed. We've just replaced one substance with some others, rather than started abstaining.
dadrian··on The Chrome VRP Panel has decided to award $250k for this report
You still have to pay taxes on income from non-bug bounty vulnerability markets, be it to law enforcement, brokers, or criminals.
dadrian··on OpenSSH Post-Quantum Cryptography
I don't take Gutmann seriously.
dadrian··on PanamaPlaylists – Leaked Tech CEOs Spotify Profiles
hey now
dadrian··on The FIPS 140-3 Go Cryptographic Module
There's a difference between FIPS validation and FIPS-approved algorithms. We can say "you have to use the FIPS-approved algorithms", but skip the useless validation step.
dadrian··on The FIPS 140-3 Go Cryptographic Module
If DOGE had done nothing other than get rid of FIPS validation, the GDP unlock alone would have solved the debt problem.
dadrian··on A proposal to restrict sites from accessing a users’ local network
That is literally what this proposal is suggesting.
dadrian··on The Shape of the Essay Field
You should absolutely buy a Miata. I have a 2021 Miata and it's one of the best decisions I ever made.
dadrian··on RIP Usenix ATC
I think people are glossing over the fact that Usenix ATC wasn’t even a good academic conference. If you’re submitting high-quality academic work to Usenix, you’re sending it to one of the higher prestige Usenix conferences in a specific subfield, such as Usenix Security or NSDI.
dadrian··on Nevermind, an album on major chords
Dave’s riffs are also stolen from disco. Which again, is fine! I love them!

Source: https://youtu.be/dZCrdSC2-1I

← PreviousPage 2 of 8Next →