6,734 karma · joined September 4, 2013
https://brooker.co.za/blog/2025/04/17/decomposing.html (includes talk)
https://brooker.co.za/blog/2024/12/03/aurora-dsql.html
https://brooker.co.za/blog/2024/12/04/inside-dsql.html
https://brooker.co.za/blog/2024/12/05/inside-dsql-writes.htm...
https://brooker.co.za/blog/2024/12/06/inside-dsql-cap.html
https://brooker.co.za/blog/2024/12/17/occ-and-isolation.html
This doesn’t look possible on the iOS/iPadOS Calendar apps.
A good incremental improvement in service level indicator measurements for large-scale cloud services.
Obligatory The Morning Paper post: https://blog.acolyer.org/2020/02/26/meaningful-availability/
In contrast, iCloud Backup is pretty much an open door: https://www.apple.com/legal/transparency/account.html
The ambiguous position on true end-to-end encryption shows once again that Apple is in for the marketing (both to consumers—predatory and dangerous, and to engineering talent—dishonest). Same hypocrisy as on the China issue. Not that there is an easy solution when you are one of the biggest companies on the planet and that shareholders essentially expect you to grow forever while playing nice with everyone.
Special mention for the Kauaʻi ʻōʻō: https://www.wnycstudios.org/podcasts/anthropocene-reviewed/e...
> Free customer base—Free customers are an important part of our business. These customers sign up for our service through our self-serve portal and are typically individual developers, early stage startups, hobbyists, and other users. Our free customers create scale, serve as efficient brand marketing, and help us attract developers, customers, and potential employees. These free customers expose us to diverse traffic, threats, and problems, often allowing us to see potential security, performance, and reliability issues at the earliest stage. This knowledge allows us to improve our products and deliver more effective solutions to our paid customers. In addition, the added scale and diversity of this traffic makes us valuable to a diverse set of global ISPs, improving the breadth and economic terms of our interconnections, bandwidth costs, and co-location expenses. Finally, the enthusiastic engagement of our free customer base represents a “virtual quality assurance” function that allows us to maintain a high rate of product innovation, while ensuring products are extensively tested in real world environments before they are deployed to enterprise customers.
(page 80)
The underlying cryptography is NaCl, which is referenced in the original post.
Thoughts?
On the flip side the software a bit slow to start and uses a lot of resources—it’s based on Electron, but I encourage everyone to try it (the demo on their website is cool!).
This is as close to “painting the back of the fence” as it gets.
To go further, always use a standard formatting tool (gofmt, clang-format...) before committing code.
I was only voicing my personal experience, which has been very poor (maybe the team, or the seriousness of the bugs), but in general I have heard some good things, especially for truly critical issues.
However, the iPhone of the attacker is an iPhone 5C, which does not have Touch ID or a Secure Enclave. This means that the time between passcode unlock attempts is not enforced by the cryptographic coprocessor. More generally, there's no software integrity protection, and the encryption key is relatively weak (since it is only based on the user's passcode).
The amount of work needed to turn security into good user experience is phenomenal: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
Of course, "Amazon releases the Kindle Paperwhite" or "New Kindle Paperwhite preorders" would be a lot clearer.