HN user

_hyn3

1,857 karma
Posts11
Comments262
View on HN

You're right - the article says 'CPU: Intel Xeon E5-2620 v4 @ 2.10 GHz' but also says DDR3. And the specs page for that CPU (https://www.intel.com/content/www/us/en/products/sku/92986/i...) clearly says the 2620 v4 is DDR4.

E5 CPUs have their supported RAM right on the Intel ARK pages, but short version:

E5-xxxxx v1 and v2 are all DDR3

E5-xxxxx v3 and v4 are all DDR4

Not sure why Intel didn't just cut new model numbers instead of keeping them all as "e5"

More concrete example for E5-2660 (great processor) showing v1 and v2 support DDR3, while v3 and v4, DDR4 (again, different motherboards)

DDR3 v1: https://www.intel.com/content/www/us/en/products/sku/64584/i...

DDR3 v2: https://www.intel.com/content/www/us/en/products/sku/75272/i...

DDR4 v3: https://www.intel.com/content/www/us/en/products/sku/81706/i...

DDR4 v4: https://www.intel.com/content/www/us/en/products/sku/91772/i...

This also means that you need to know the processor your motherboard supports (or, easier, probably RAM) before putting in an order to upgrade the processor. (These processors are incredibly cheap, less than $10 for something that might have cost literally thousands ten years ago, so worthwhile to spend a few minutes and pick out your favorite based on cores, watts, Ghz, etc.)

(Another commenter says that there are some motherboards that accept v3/v4 but also can run slower DDR3 RAM. That's new to me and quite cool - DDR3 is extremely cheap, even now. I did find these motherboards on aliexpress, too: https://www.aliexpress.us/w/wholesale-XD3-motherboard.html?s... and one clearly says v3/v4 cpu's with DDR3 RAM. That could be very useful although memory speeds are slower since CPU performance can be boosted with v3/v4.)

v1: https://www.intel.com/content/www/us/en/ark/products/series/...

v2: https://www.intel.com/content/www/us/en/ark/products/series/...

v3: https://www.intel.com/content/www/us/en/ark/products/series/...

v4: https://www.intel.com/content/www/us/en/ark/products/series/...

Touche.. actually a good point, but actually those are two different situations. With one, I'm accessing a website and trusting that the certificate is signed by someone I trust; so the trust in my browser certificates (which include certificates from hundreds of certificate authorities all over the world, any one of which could be compromised, robbed, or controlled by an adversarial person or even government) is extended to the site that I'm visiting. To say this is weak sauce rather understates how bad this actually is. (To paraphrase Churchill, this is the worst possible design, except for all the rest.)

With the other, I'm logging into a server for the first time (and I could simply deploy the same trusted host key to all my ssh servers via an autoscaling configuration or whatever). I think it's debatable if TOFU is worse or better than your (granted clever) metaphor.

(to those who'd recommend userify, yes - great for the client login issue and definitely increases security, but to parent's point, TOFU is still needed unless you want to distribute host pubkeys)

Excellent evaluation. From reading the code, it appears that the units for the numbers column is usually milliseconds (ms)

It also looks like squinn is the clear leader for most but not all of the benchmarks.

Even though it's "not scientific", is still very useful as a baseline - thanks for taking this effort and publishing your results!

Also taking a look at monibot.io , looks cool

Trying removing consent to receive text messages on that number, or that it's only a land line and only phone calls are accepted.

You might even try to block incoming SMS. In fact, you might also try a forward with Twilio or free Google voice number, since a lot of SMS TOTP refuse to with with those numbers :)

I've even had success removing my phone number entirely from certain types of accounts, but sometimes I had to deliberately break the account (eBay) and then it tries to get you to confirm on each login which you can sometimes bypass by changing the URL or clicking the company logo.

Be sure to have strong security in other ways; strong, non repeated passwords.

But this is truly insane. Large banks don't even offer the option of TOTP but instead require far more insecure SMS. Maybe they'll offer RSA dongles, because they never bothered to remember when they all got completely leaked ten years ago or how they accepted $10M to completely compromise their constants.

What can you say, large enterprises are behind the security eight ball, as always! It's a tale as old as time.

https://www.wired.com/story/the-full-story-of-the-stunning-r...

https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...

President isn't CEO

The President is literally the Chief Executive officer in the United States.

https://people.howstuffworks.com/president4.htm

Laws and budgets are set by Congress

That's correct, under Article 1, but the President does not have to spend every dime that was allocated.

EOs do not have the force of law

"Both executive orders and proclamations have the force of law, much like regulations issued by federal agencies"

https://www.americanbar.org/groups/public_education/publicat...

You seem to underestimate the power that is vested in the office of the President as the Chief Executive.

have been invalidated by courts

As have many, many legislatively-passed laws; this is simply checks-and-balances and allows the judiciary to act on other laws (which originate from Congress) and regulations (which originate from the Executive Branch).

If the CEO of your company empowers a team to audit your work, would you 'resist'?

And this Chief Executive was elected by the majority of the country, specifically to take these actions that he'd clearly stated he would take.

The resistance is actually the violation of federal law. It's no different from contempt of court; within the President's domain, he has a huge amount of power. The President can also modify existing policy (regulations) at any time and literally make new laws (Executive Orders have the force of law) as long as they don't conflict with current law, as well as overturning previous President's Executive Orders.

Of course, then the shoe will be on the other food someday, too, just as it was when Biden took over from Trump and then they switched places again.

As President Obama said, "I've got a pen, and I've got a phone."

https://www.npr.org/2014/01/20/263766043/wielding-a-pen-and-...

How does this compare to Userify's plain-jane SSH key technique?

That agent (Python, single-file https://github.com/userify/shim) sticks with decentralized regular keys and only centralizes the control plane, which seems to be more reliable in case your auth server goes offline - you can still login to your servers (obviously no new users or updates to existing keys). It just automates user and sudo configuration using things like adduser and /etc/sudoers.d. (It also actively kills user sessions and removes the user account when they're deleted, which is great for when you're walking someone out in case they have cron-jobs or a long-running tmux session with a revenge script.)

This project looks powerful but with a lot of heavy dependencies, which seem like an increased surface area (like Userify's Active Directory integration, but at least that's optional)

About 80% of teens who use social media say they see content about conspiracy theories in their online feeds

Where conspiracy theory means what, exactly? Did they define this term for the teens (or even just for the survey)? Why is 'disinformation' (itself undefined) conflated with the hilariously ambiguous 'conspiracy theory'?

It's really just a terribly weak article, and the source "study" doesn't look much better. It really looks like it is a study set forth to push a particular agenda with "numbers".

Too many people confuse data with science, and perhaps that is what schools should actually be teaching; probably when they teach statistics, which all students should take. Pseudo-science like "critical thinking" can't really be taught, but actual science can.