HNHacker News
TopNewBestAskShowJobs

dadrian

653 karma · joined June 3, 2013

https://dadrian.io

@davidcadrian

@dadrian@a2mi.social

@dadrian.io

Must read: 'tptacek, 'jblow, 'JumpCrisscross, 'idlewords, 'hwayne, 'luu, 'gdb, 'antics

submissionscomments
dadrian··on Bill to Ban Private Equity from Owning Medical Practices
That’s absolutely not true. Private equity regularly buys small businesses, D2C businesses, retail businesses, failing businesses, software businesses…
dadrian··on Playing whack-a-mole is losing
I was actually referencing repeated exploitation by leaking TheHole, which actually has no particular reason it needs to be sensitive.
dadrian··on GPS and the Lost Art of Getting Lost
Have you attempted to kidnap the DA during a prisoner transfer on Lower Wacker, only to be thwarted by a vigilante? If not, I question your Chicago bona fides.
dadrian··on NSA and IETF, Part 9
In fact, the default behavior in every web browser right now is to use a hybrid.
dadrian··on NSA and IETF, Part 9
The cryptographers in charge of major web browsers, TLS libraries, and programming language standard libraries do not stand by DJB’s points.
dadrian··on LLMs won't break symmetric crypto
RSA is asymmetric crypto. This article is about symmetric cryptography. I expect LLMs will advance state of the art in factoring algorithms, considerably.
dadrian··on Memory safety absolutists
There are only three programs where memory safety matters: HTTP server, browsers, and operating systems. In practice, really just browsers and operating systems. Memory safety schemes that don't work for those systems are primarily cosplaying if their goal is safety.
dadrian··on Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
The pricelist was a marketing stunt.
dadrian··on An OpenAI model has disproved a central conjecture in discrete geometry
While the result is impressive, this blog post is extremely disappointing.

- It does not show an example of the new best solution, nor explain why they couldn't show an example (e.g. if the proof was not constructive)

- It does not even explain the previous best solution. The diagram of the rescaled unit grid doesn't indicate what the "points" are beyond the normal non-scaled unit grid. I have no idea what to take away from it.

- It's description of the new proof just cites some terms of art with no effort made to actually explain the result.

If this post were not on the OpenAI blog, I would assume it was slop. I understand advanced pure mathematics is complicated, but it is entirely possible to explain complicated topics to non-experts.

dadrian··on YC's Biggest Scandals
There's something ironic about vibe-coding an anti-YC site. They're why OpenAI exists!
dadrian··on Using the internet like it's 1999
The Internet in 1999 was not good at all. Browsers barely worked, computers crashed constantly, the ability to actually search for useful things was limited, and many things we take for granted as being online (news, people, documentation) were not.

The mid-to-late 2000s are perhaps closer to what the author is looking for.

dadrian··on OpenSSL 4.0.0
I dunno, they'll let anybody get on the Internet and start a podcast.
dadrian··on Cloudflare targets 2029 for full post-quantum security
I will bring this up at the next meeting of the secret cryptographer cabal where we decide what information to reveal to non-cryptographers.
dadrian··on The cult of vibe coding is insane
Except for the part where it's constantly having quality and reliability issues, even independent of the server-side infrastructure (OOMs on long running tasks, etc).
dadrian··on Astral to Join OpenAI
As opposed to Pip, which is obviously free and sustainable forever.
dadrian··on DJB's Cryptographic Odyssey: From Code Hero to Standards Gadfly
The person with the most HN karma of anyone on this site, currently thinks djb's actions are wrong.
dadrian··on Be wary of Bluesky
For someone to come in and buy Bluesky and then hold everyone’s data hostage, then Bluesky would actually have to have enough value that someone would want to buy it.
dadrian··on DJB's Cryptographic Odyssey: From Code Hero to Standards Gadfly
RMS has, at minimum, showed that he swayed by parrots, spider plants, and free plane tickets and guest lodgings.
dadrian··on What Is OAuth?
> SAML is arguably the worst cryptographic standard ever created

The PGP packet has entered the chat.

dadrian··on I want to wash my car. The car wash is 50 meters away. Should I walk or drive?
GOT ‘EM
dadrian··on The Startup Graveyard
Some of them also aren't really dead.
dadrian··on We found cryptography bugs in the elliptic library using Wycheproof
The 90-day disclosure window is an arbitrary courtesy, not a binding contract about the behavior of either party. They probably had other things to do.
dadrian··on Comparing AI agents to cybersecurity professionals in real-world pen testing
Taken both in name and role, more or less.
dadrian··on Private equity is killing private ownership: first it was housing, now it's PCs
PE didn’t kill housing. Private equity owns 2-3% of homes.
dadrian··on Ask HN: Why is Hacker News red? Christmas?
It's not red! You're just colorblind.
dadrian··on Stop Breaking TLS
Network DLP is also not bulletproof so I'm not sure what the argument is there. These things are all best effort.

> if you have DLP at work, open the integrated browser in VS Code and notice how you can send protected test strings without anything chirping you.

I recognize it's not instrumented, but how are protected strings getting there in the first place?

dadrian··on Stop Breaking TLS
That is not true, you can run DLP on an endpoint directly and inside a browser directly (e.g. via an extension or direct integration hooks).

You can also try to stop the situation where the CC numbers are in the clear anywhere in the first place, so that you can't copy/paste them around. What happens if someone writes the CC number down on a piece of paper?

dadrian··on Stop Hacklore – An Open Letter
This is good advice, and there's good people on the signature list, but why is this is an open letter? This feels navel-gazey and straight out of 2017.
dadrian··on HTTPS by default
A MITM could replace the redirect with malicious content, as described in the blog.
dadrian··on HTTPS by default
Yes, it started that way, but complaining about the current auto-update behavior of the software (not the ACME protocol), is completely unrelated to Let's Encrypt and is instead an arbitrary design decision by someone at EFF.
Page 1 of 8Next →