HN user

clysm

333 karma
Posts0
Comments57
View on HN
No posts found.

3. There are WAY more things to get corrupted on a computer system than tokens. And non-determinism does NOT mean it’s tolerant to faults. Random values are intentionally introduced at the right moment for LLMs.

No. It’s 100% a design choice by the manufacturer to make them look weird.

Even with the benefits of EV packaging, manufacturers chose to make them “different” on purpose, which really put off the vast majority of buyers. Tesla had so much success because they were practically the first manufacturer to make something look somewhat normal and have good stats.

Now, BMW finally learned and has their 4 and 5 series EV cars share a common platform with the ICE. There is no physical difference in style other than the front grill.

More than just IPv4 priorities, almost all other IPv6 addresses are given higher priority which makes routing between ULAs on an internal network problematic.

That draft doc seems to fix multiple problems at once.

It helps build a new system, but all existing wallets would be hackable until they migrate. And we expect everyone to have the time and resources to do that? For a “store of value” system?

All of my hardware wallets are now worthless? All of the hardware security modules used for wallets managed by corporations no longer work?

It's an absolute mess for so many reasons that a "protocol fix" just doesn't cover.

I really hate the “someone will certainly solve this problem!” mentality.

You can’t just magically update the protocol to work around the ability of someone to break elliptic curve cryptography. That not how this works. It’s not how any of this works.

I’m not seeing the security issue here. Arbitrary code execution leads to arbitrary code execution?

Seems like policies are impossible to enforce in general on what can be executed, so the only recourse is to limit secret access.

Is there a demonstration of this being able to access/steal secrets of some sort?

Absolute bull.

The writing style is exactly the same between the “prompt” and “response”. Its faked.

There was and is absolutely nothing wrong, and quite a lot right, by having the 2FA program completely separate from your password vault.

Did you read the article? That's what they say.

For maximum security, you can store your 2FA token elsewhere ... but for general purpose use, storing your 2FA in your password manager is an acceptable solution due to the convenience benefits it provides.

SSH Artwork 2 years ago

Where's the proof that this works?

It's a brute forcing tool with the goal of finding the desired fingerprint, but there's no demonstration of it actually working.

People are refusing to read out of principle. We shouldn't have to work around a bad and annoying "feature" of a site.