America has plenty of the wrong type of oil. They need heavy oil as that's what the usa oil refinery are made to handle, but they have a shortage of heavy oil, and a oversupply of light oil. Venezuela has the heavy oil they need
HN user
aisio
2048 GPUs cost $400m? pretty sure the GPUs don't cost 200k each?
Not a sonos engineer, but its a good external analysis https://www.linkedin.com/pulse/what-happened-sonos-app-techn...
True, heres a larger collection of North and South Postage
https://www.irishmirror.ie/sport/rugby-union/times-bizarre-i...
In Ireland you can just describe the person instead of the actual address and it'll get delivered
https://twitter.com/weefeargal/status/1479069076144234497?s=...
MITM for TLSv1.3 is possible. Plenty of solutions available for enterprises to do this. The MITM occurs still happens for TLSv1.3 on key exchange, allowing for the subsequent certificate to also be MITM and be replaced and encrypted. The only real affect TLSv1.3 has for MITM is that company policies for decryption can't match on the cert to determine if decrypt should occur, but they can still use the SNI which is plaintext
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications
"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail"
All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems
One reviewers comments to a patch of theirs from 2 weeks ago
"Plainly put, the patch demonstrates either complete lack of understanding or somebody not acting in good faith. If it's the latter[1], may I suggest the esteemed sociologists to fuck off and stop testing the reviewers with deliberately spewed excrements?"
https://lore.kernel.org/lkml/YH4Aa1zFAWkITsNK@zeniv-ca.linux...
Yes it supports Kernel TLS offload support. Both in SW mode (where the kernel does the TLS operations) and HW mode https://www.kernel.org/doc/html/latest/networking/tls-offloa...
For loops are now allowed with eBPF in the latest kernels
Some interesting metrics on bpfilter, especially when combined with smart network card offloading
https://www.netronome.com/blog/bpf-ebpf-xdp-and-bpfilter-wha...