HNHacker News
TopNewBestAskShowJobs

wpowiertowski

18 karma · joined November 12, 2017

submissionscomments
wpowiertowski··on Building end-to-end security for Messenger
Read the whitepapers, the client side generates the keys and only transmits the public keys to the server. E2EE is truly end to end (as in client to client). Meta has no access to the content of your messages, same has been true for WhatsApp
wpowiertowski··on Facebook to let users turn off political adverts
In a way they already do, all political ads on facebook (in any country) are public information through their Ad Library Report: https://www.facebook.com/ads/library/report/?source=archive-...

Simply take their earning reports and divide one by the other and you'll get the percentage of revenue

wpowiertowski··on Siri, What Time Is It in London?
My usual dialog with siri:

Me: "Hey Siri, play Radiolab podcast"

Siri: Which Radiolab podcast, Radiolab or Radiolab: More Perfect"

Me: "Radiolab"

Siri: Which Radiolab podcast, Radiolab or Radiolab: More Perfect"

Me: "Radiolab"

Siri: Which Radiolab podcast, Radiolab or Radiolab: More Perfect"

...

Me: "The first one"

Siri: "I don't know >the first one<"

Me: "Siri you're useless"

Siri: "That's not nice"

Me: "Could be but it's true"

wpowiertowski··on Setting Up an Ad-Blocking VPN with WireGuard and Pihole
I setup a similar system but with IPSec (https://github.com/jawj/IKEv2-setup) and Pi-Hole on DO. The best part is that the linked IPSec setup is trivial to install and also generates profile files that leverage the OS VPN capability in any iOS device without needing to install extra apps (and also force VPN connectivity by default so you don't need to remember to enable it)
wpowiertowski··on USB Type-C to Become More Secure with Authentication Standard
There are more use cases where being able to prove cryptographically the identity of the device is very useful from security point of view, PD is simply one of them.
wpowiertowski··on USB Type-C to Become More Secure with Authentication Standard
Exactly why cryptographic authentication is required. There are fuzzing devices today that present themselves as known VID/PID/HID combinations that have generic drivers in modern OS's and can exploit that.

One of the primary drivers for this is the power delivery - imagine a scenario where you have authentic power brick and laptop and buy a counterfeit USB-PD cable, power brick sends 100W over it and it results in the cable melting since it was really a $5 knock-off and you end up with a fried USB-C port in your laptop and possibly a fire. I'm sure most people would wish that the power-brick/laptop checked that cable is genuine and build to handle the power.

wpowiertowski··on Google and Nasdaq Pursuing Nano-Second Precision in Network Time Protocol
Why not just switch to PTP (IEEE 1588)?
wpowiertowski··on A Man Who Volunteered for Auschwitz (2012)
Being Polish makes me very proud of the bravery of Witold Pilecki at the same time Russian army did some horrible things during the „saving” of eastern Europe. However if you look at the numbers they also paid the ultimate price in number of casualties: https://vimeo.com/128373915
wpowiertowski··on Potential impact of the Intel ME vulnerability
FileVault does not require a password input at EFI. It decrypts user data in memory after user login