HN user

crotchfire

877 karma

tox:F24BB4CA08C0FC80F3555DACB585CA5AFC347BB6E433D2FAB044CAD4DBB2CB7BE26A5EE1047E

Posts1
Comments337
View on HN
DNS over Wikipedia 2 years ago

Would be interesting to combine this with a web-of-trust.

None of my one-hop trusted people are part of the cancelmob. If I found that somebody two hops away from me did something absurd it's quite easy to do something about it -- apply negative trust to whatever path endorsed that nonsense.

Unfortunately people these days seem allergic to running anything that isn't a web browser or served by an app store, and the entities that control those two channels are extremely unexcited about decentralization.

... and how they steer the discussion from "social media" to "screen time".

Wikipedia helpfully selected a picture of somebody using an ebook reader as their illustration of what "screen time" means: https://en.wikipedia.org/wiki/Screen_time

I'm just flabbergasted with the level of smokescreen that goes on in this discussion. Pretty sure reading books on ebook readers is not what is driving teenage mental health problems.

where a repo is forked but the new maintainers don't change the repo's did

A DID is a public key. If you don't know the corresponding private key you won't be able to make any updates. All you'll be able to do is mirror it.

instead just get more nodes to follow them than the original

This is like saying "but I can fork Verisign's Root CA certificate and get more nodes to follow me than Verisign!". No, you don't have the private key that goes with that root certificate. So everybody will ignore you.

Cryptography is not a popularity contest.

Oh please with the karma-farming.

Suburbs, for better or for worse, have been around for a long time. They cannot explain the massive decline in Generation Z's mental health compared to its predecessors.

PS, next time try to link to housing costs -- that one gets better karma yield. Bonus points if you can somehow denigrate cryptocurrencies while you're at it.

Protecting against "swapped devices" is simple: put a secret key in the device, ask it to produce a signature, check it with the public key. Any device other than yours won't know the secret key.

I'm not sure what attacks you refer to when you say "malicious program-binaries". I'm having trouble imagining something fitting this description which is thwarted by the vendor blowing the programming fuse but isn't thwarted by you blowing the fuse yourself.

This is Noise NK, possibly with differences in the hashing details which I did not check:

https://noiseprotocol.org/noise.html#interactive-handshake-p...

I encourage you to use their hashing details. They're battle-tested.

Wireguard uses Noise IK, which is NK plus a static public key for the initiator which is encrypted to the agreed-upon-session-key without adding additional round trips. Your protocol and Noise NK omit the parts related to the initiator's static public key, because it has none.

What about DIMMs with Error Correction Codes (ECC)? Previous work on DDR3 showed that ECC cannot provide protection against Rowhammer.

This is incredibly misleading. The paper they cite states:

When the ECC detection is used correctly 0.65%-7.42% of all bit flips still cause silent corruptions... On setup AMD-1, uncorrectable errors crash the system.

The attacker will need to cause dozens of machine halts in order to achieve even a single exploitable bitflip. Dozens of machine halts is not something that goes undetected.

Kudos for calling out JEDEC's terrible behavior on the rowhammer question, but we should not be downplaying ECC as a near-term solution.

Users are not your guniea pigs, either.

To convince people to use something, what you're proposing needs to be less-broken than what they already have. The whole "let's burn down their house because they don't want to move to the new one we built" attitude is a disgrace.

I use Sway (a Wayland compositor), but I'm embarrassed to admit that when I see the WaylandBrigade pulling crap like this.