HNHacker News
TopNewBestAskShowJobs

kohtatsu

1,024 karma · joined March 26, 2019

submissionscomments
kohtatsu··on Google knows where we are, and so do advertisers
Explore the Privacy section of the Settingd app to find out.
kohtatsu··on EU Draft Council Declaration Against Encryption [pdf]
If you're looking for a domain I recommend https://domainr.com for search (they get affiliate revenue but I don't) and https://namecheap.com for registration. Namecheap has done a great job of defending privacy and offering a solid product. Also no affiliation, but the CEO did respond to me on twitter!
kohtatsu··on EU Draft Council Declaration Against Encryption [pdf]
We can do small tributes on a subdomain. I'll do two small ones;

- dang.matcha.life

- dang.moka.moe

One tea related and one coffee related, of course.

I'll aim to have them live by December 1st.

kohtatsu··on Be skeptical of Ring's indoor security drone
Settings > Accessibility > Sound Recognition

https://www.theverge.com/21300261/ios-14-update-smoke-alarm-...

kohtatsu··on MacOS-like Fonts on Manjaro/Arch Linux
Command+, to bring up preferences is surefire, does linux/windows have the same yet? I remember Command+W not working as consistently as well.

Word and like jumps in Windows also felt backwards to me, doing the equivalent of w instead of e in vim, and couldn't be consistently combined with shift.

Support for Alt+Dpad(+Shift) and Command+Dpad(+Shift) is important IMO. As well as Double/Triple-click+Drag: it should select additional units not letters.

These last paragraphs are OS-level but the features were missing or inconsistent.

kohtatsu··on Death decreed over Zoom
Dystopia isn't guaranteed; don't go gentle into that good night.

Highly recommend reading "On Tyranny", it's a great small, pertinent book for $10 at most book stores.

Edit: to be clear China's social credit system is extremely dystopian to me and is already taking shape, but I trust most/all democratic societies (including US) to fend it off.

kohtatsu··on Firefox 81.0
Browser fingerprinting is a problem, but the solution isn't to throw your hands up and spoonfeed them identifiers.

Blocking tracking scripts does thwart fingerprinting. I really hope we can figure out a decent access model for JavaScript someday.

kohtatsu··on AWS IAM is having issues again
https://hckrnews.com is an alt-reader that sorts the front page chronologically which helps.
kohtatsu··on Uber backup driver indicted in 2018 self-driving crash that killed woman
It's okay self-driving cars aren't yet single seater.
kohtatsu··on Oracle Wins Bid for TikTok in U.S.
My favourite humans see money as a means to an end.
kohtatsu··on Oracle Wins Bid for TikTok in U.S.
You can favourite comments for people to see them in your profile. Click on the time of the comment for the link to appear.
kohtatsu··on Super Mario Bros. 3 in 3 Minutes – World Record Speedrun Explained [video]
This comment is indistinguishable from sarcasm.
kohtatsu··on A Secret Recording Reveals Oil Executives’ Private Views on Climate Change
I'm not convinced this poll is much indication of anything; it's just asking about a weird carbon tax scheme.

> Suppose a proposal was on the ballot next year to add a monthly fee to consumers' monthly electricity bill to combat climate change. If this proposal passes, it would cost your household $____ every month. Would you vote in favor of this monthly fee to combat climate change, or would you vote against this monthly fee?

  $1/month:    57% favor
  $10/month:   28% favor
  $20/month:   30% favor
  $40/month:   23% favor
  $75/month:   15% favor
  $100/month:  16% favor
A more useful question would be: "Would you oppose climate change regulations that had the effect of increasing your energy bills $10/month?"
kohtatsu··on Implement BeamAsm – A JIT for Erlang/OTP
Introducing C++ doesn't mean they have to allow every pull request to use whichever C++ features it wants to.
kohtatsu··on List of All Current TLDs
There were plans on potentially allowing https://netflix/

I can't recall the technical term for it though, and my search engine couldn't help me find it within a few minutes.

kohtatsu··on Huawei’s HarmonyOS is now open source
Growth hacking, if you can consider that logic.
kohtatsu··on Huawei’s HarmonyOS is now open source
This is parody, tho I had to double check.
kohtatsu··on Everything you ever wanted to know about terminals (2018)
I was just reading up an ANSI escape sequences a few days ago, this is gold.

I adore the format and writing style too.

kohtatsu··on Apple accuses Epic of “Willful, brazen, and unlawful” conduct
Darn, I was hoping the weekly review of high profile legal cases was real.

I'd pay $5/month.

kohtatsu··on Western Digital is trying to redefine the word “RPM”
You fell directly in line with what they wanted.

It's reasonable to expect companies to honour their spec sheets, and to not lie in their firmware.

Once they're caught doing otherwise it's important to hold them accountable, not throw our hands up and pay up anyway.

kohtatsu··on Ubuntu 20.04 LTS’ snap obsession has snapped me off of it
Snap is a distribution format, akin to .msi or .pkg.
kohtatsu··on We didn't encrypt your password, we hashed it
It's possible to change the pepper during login (same as adjusting parameters).

The downside for the scheme is complexity and limited upside; complexity gets a lot more attention when it comes to security considerations.

Best practice especially needs to be simple; it's easy to mess this stuff up and hard to understand. A lot of the comments on this post betray a very poor understanding of password storage; they simply haven't come across the correct information.

Overall pepper is good as long as you include salt. There are times when the db gets leaked and the env variables don't.

There's nothing wrong with your scheme if it's implemented properly, but being able to change the site-wide key is a limited upside compared to using a pepper. There is an upside though.

And all of this doesn't matter much as long as you do the bare minimum of using a tuned pbkdf+salt and keep your stuff patched.

kohtatsu··on We didn't encrypt your password, we hashed it
SHA256 is also no good for storing passwords, you need to use a PBKDF like scrypt, bcrypt, or pbkdf2.

The SHA-family cryptographic hash functions are purposefully designed for throughput, if you combine them thousands of times like in PBKDF2 they can be fine. One round of SHA256 is trivial to brute-force especially with the plethora of ASICs available.

HMAC is also completely unnecessary here, and see the article title for your variable naming: it's not encrypted_pw it's hashed_pw.

kohtatsu··on We didn't encrypt your password, we hashed it
8 characters is short, especially when all the characters are directly derived from a word.
kohtatsu··on We didn't encrypt your password, we hashed it
You add a salt, which is stored plaintext alongside the password.
kohtatsu··on We didn't encrypt your password, we hashed it
It's up to the site operator to tune the cost; it's generally recommended 100-250ms depending on how much you're willing to make your users wait.

FWIW there are ASICs now that will get orders of magnitude faster hash throughput than your servers.

kohtatsu··on The Hash Monster: ESP-32 Tamagotchi for WiFi Cracking
https://en.m.wikipedia.org/wiki/Joffe_v._Google,_Inc%2E

HN eats the last period; you can use %2E to avoid that.

kohtatsu··on Most-favorited Hacker News posts
I'd actually assume one favourite to be a misclick.
kohtatsu··on Most-favorited Hacker News posts
I use it as a super-upvote.

I try to only favourite the cream of the crop, in the hopes someone will stumble into my favourites list and enjoy them.

I mostly favourite comments not submissions though.

kohtatsu··on Applebot
It's a courtesy, afaict.
Page 1 of 15Next →