HNHacker News
TopNewBestAskShowJobs

rasengan

4,974 karma · joined December 27, 2010

My comments are my own and do not reflect any of the organizations, or nations, I belong to unless I specifically clarify as such in a comment.
submissionscomments
rasengan··on Rich Dad Poor Dad author shocks fans with $1.2B debt
Depends what interest, contingencies and on other information to understand if 1.2B debt is a problem or not. Otherwise, for most UHNW people, debt is just a number on a balance sheet.
rasengan··on Civic Hygiene – avoid building technologies that could be used by a police state (2013)
I feel really bad for you.

It might actually be wise [1] to create a new, slightly less permissioned license for open source wherein the open is defined as anything that isn’t in a kill or surveillance chain or, more broadly, for military use…

[1] for the community

rasengan··on NSA and IETF, Part 9
> Orr Dunkelman

The great Dr. Orr Dunkelman was admirably vocal in his opposition to the publishing of this draft.

rasengan··on NSA and IETF, Part 9
RFCs are used by developers as strict guidelines for implementation.

The mere publishing of an RFC has customarily been treated by developers as a stamp of approval from the IETF.

The NSA, contractors and their fans argue that simply adding a "RECOMMENDED=N" in an obscure section of this draft will somehow prevent said implementations in deployments.

However, as an example, Canada's NSA equivalent specifically requested the draft to be published so that they can use it to support their poor choice in deployment of solo ML-KEM nation-wide.

While ML-KEM may be sound, significant bugs in implementations in the wild continue to be published.

To be clear, CRQCs do not exist today.

ECC is battle tested, proven, and is used today.

It makes no sense to delete working cryptography and replace it with potentially buggy, non-battle tested implementations of new cryptography for a threat that does not yet exist today.

Instead, you fight HNDL [1] with hybrid which preserves the safety of today, and hopefully also, tomorrow.

No serious security person should be recommending otherwise which is, perhaps, why some may question the motives of those that are pushing for solo ML-KEM.

[1] Harvest now decrypt later

rasengan··on NSA and IETF, Part 9
> A majority (but not a large majority) of cryptography engineers would use hybrids at this point

Actually, based on the WGLC, or the three of them rather, it's pretty clear that Ph.D cryptographers significantly prefer hybrid over pure ML-KEM.

> he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

The brigade by the NSA (6+ votes or more if you include NSA contractors), the AD being former NSA and the moderation of Dr. Bernstein for a footnote seems pretty fair and balanced </sic>.

Meanwhile, the lead of the EU PQC program, professors from several universities, Ph.Ds and, additionally, legendary cryptographers all expressed significant concern and even stronger opposition to the publishing of the draft.

Finally, the chairs refused to share their methodology in determining consensus when asked by several Professors and Ph.Ds.

rasengan··on NSA and IETF: Fairness
> In the NSA's defense, combining cryptosystems also creates attack surfaces, timing problems, additional complexity, etc

Actually, Dr. Nadim Kobeissi formally proved that hybrid is secure, even if ML-KEM fails. [1]

[1] https://eprint.iacr.org/2026/1147

rasengan··on NSA and IETF: Fairness
I certainly find it fascinating that the majority of those in favor come from signal intelligence agencies, while the majority of those against are PhD cryptographers.

I was happy to see the lead of Europe’s PQC team also voted with the cryptographers.

rasengan··on The US Used to Demand the Best Tech. Now We Ban It
It’s been like this for a while. Take a technology, call it a weapon and control it. Same playbook.
rasengan··on Previewing GPT‑5.6 Sol: a next-generation model
To be fair, whenever I join a pre-existing code-base [1], it's the same. I have no idea and have to map it out ;)

[1] Not AI codebases (and of course, AI code bases I guess)

rasengan··on VPN ban update for UK households as government looks at 'age-gate'
The UK can’t block Dissent [1] since it looks like normal HTTPS traffic.

[1] https://godissent.com

rasengan··on Hardware Attestation as Monopoly Enabler
I agree hw attestation is net negative when forced upon end users. OTOH, when service providers use it, it results in transparency to end users [1] so it's really about how it is used.

[1] https://bmail.ag/verify

rasengan··on Ubuntu 26.04
> TPM-backed full-disk encryption

This is going to be very useful for servers hosted in third party DCs.

rasengan··on Show HN: Clone, a small Rust VMM, forks VMs in under 20ms via CoW
Great question! We rebuild if there's a security update or otherwise every few weeks. We're working on a better method, but right now a few templates can be kept warm so users aren't forced to reboot.
rasengan··on Do you even need a database?
Sounds like a good way to waste the only scarce resource: time.
rasengan··on Launch HN: Freestyle – Sandboxes for Coding Agents
Interesting!

We're working on a similar solution at UnixShells.com [1]. We built a VMM that forks, and boots, in < 20ms and is live, serving customers! We have a lot of great tools available, via MIT, on our github repo [2] as well!

[1] https://unixshells.com

[2] https://github.com/unixshells

rasengan··on Latch: Terminal multiplexer, like tmux, with SSH, mosh, and web access built in
Use latch to ssh, mosh or web into your machine. latch multiplexes terminal windows (like screen or tmux).

We built this for use on UnixShells [1].

All remote connections are verified against the authorized_keys and are, of course, end to end encrypted.

This is MIT licensed. There is also a relay that lets you connect to your latch sessions that are behind NAT - this has a small cost to it for infrastructure. However, you can use tailscale/ngrok or your own external IP for free.

https://github.com/unixshells/latch

[1] https://unixshells.com

rasengan··on Y Combinator CEO Garry Tan launches dark-money group to influence CA politics
I don't know if I agree or not with his views, but the fact that he's moving from complaining about something, to doing something about his beliefs, has convinced me to move from a negative to a significantly positive view of him, as a person; to reiterate, regardless of whether I agree with said views.

The will to fight for what one believes in - I think we can all agree that is an admirable human trait that would result, for those who do follow his views, in him being labeled as a hero and defender of people's rights.

Bravo, Garry.

rasengan··on Gen Z are arriving to college unable to even read a sentence
I thought I was reading the Onion. :(
rasengan··on Show HN: I built a CLI-first pipeline that turns Wikipedia into narrated videos
This reminds me of https://wiki.devilfruit.com

Cool project!

rasengan··on Memories of .us
Some IRC networks still use naming as such like "server.state.country.dal.net."
rasengan··on [dead]
This is a terrible day for the archival of the internet. Under the guise of copyright, significant information has been de-platformed.
rasengan··on How to build your own VPN, or: the history of WARP
There’s the VPN technologies and then there are VPN services [1]. Technology alone does not give you the service.

[1] https://vp.net/l/en-US/blog/The-History-of-VPNs-and-Logging

rasengan··on Apple's "notarisation" – blocking software freedom of developers and users
In the end, it's the same for Windows too since you need to pay for a cert.
rasengan··on Open Source Implementation of Apple's Private Compute Cloud
We are introducing Verifiably Private AI [1] which actually solves all of the issues you mention. Everything across the entire chain is verifiably private (or in other words, transparent to the user in such a way they can verify what is running across the entire architecture).

[1] https://ai.vp.net/

rasengan··on Dr. Daniel J. Bernstein (djb) suspended from IETF
This follows after djb pointed out that the NSA was weakening encryption by recommending and demanding PQ encryption alone instead of the hybrid PQ+ECC pair that is safer, with this being blocked despite considerable opposition by the actual experienced researcher participants in the group.

Bad times for the internet.

rasengan··on Whitehouse.gov
> At various times in history, the White House has been known as the “President’s Palace,” the “President’s House,” and the “Executive Mansion.”

I wonder how much longer the structure will be known by its current name, given the growing trend of letting slanderous/fringe uses of words dictate their dominant meanings [1].

[1] For example, the end of the master branch.

rasengan··on Happy Internet Archive Day
The way digital data is decaying [1], books are disappearing and so on, the Internet Archive is critical infrastructure.

Happy Internet Archive Day! :-)

[1] servers gone, hosting sites gone, etc.

rasengan··on [dead]
If a VPN provider can and does log when it receives complaints, it is no longer a “no log” VPN.
rasengan··on [dead]
The archived posts are literally linked in the post.
rasengan··on [dead]
Ad hominem does not change the fact that ProtonVPN admits to monitoring their users: "we check the network traffic on the server in question in realtime to verify the abuse report. If we see a VPN connection engaged in abusive behavior when we check, we find the userid associated with that connection and terminate the account." [1]

[1] https://www.reddit.com/r/ProtonVPN/comments/93pp40/comment/e...

Edit: Archived for posterity https://archive.is/xi92E

Page 1 of 34Next →