HN user

manwithaplan

213 karma
Posts5
Comments50
View on HN

"We believe post-handshake attestation alone can achieve level three binding," Sardar told The Register, warning that newer proposals combining both approaches add unnecessary complexity without adding security. His recommendation to the IETF's TLS working group is blunt: developers should abandon intra-handshake attestation altogether.

Kelvin versioning 2 months ago

KelVer: Software versioning as decreasing integers in degrees Kelvin, with absolute zero meaning that the program is frozen (with no further possible updates), and its supporting components always strictly cooler (or themselves frozen).

I vaguely remember my training wheels were set a bit higher and not touching the ground unless I was leaning a lot. So this setup would aid training to ride properly.

Many Y2K “solutions” just borrowed 20 years, and a few of those systems didnʼt actually invest that time in a fix before the 1st of January 2020:

  One solution involved a technique called “windowing” — in which two-digit years are assigned to either one century or another based on one hard-coded “pivot year” determining where they belong. Even back in 1999, HPCWire was describing it as “highly controversial,” citing one expert who said computers using the technique were “little ticking time bombs waiting to go off.”
https://thenewstack.io/how-the-y2k-bug-returned-on-jan-1-202...

It's so difficult to scroll to the right and delete all the query parameters.

A lot of times, all that's needed is to insert a # character at the right place in the URL, then load that.

I also try to erase data from the phone before bringing it to the service shop. Recently the screen went unresponsive, luckily connecting a USB mouse was enough for some basic control.

I imagine that Repair mode is an enhanced version of their Emergency mode (which disables almost all the apps) while also encrypting the data partition (this way, cloning it to a refurbished phone would preserve privacy).

Itʼs so strange that they didnʼt manage to set up a proper certificate for an HTTPS proxy project website: https://www.ssllabs.com/ssltest/analyze.html?d=www.tofuproxy...

Edit: I guess theyʼre philosophically opposed to PKI, and are promoting instead certificate pinning, Web-of-Trust: http://www.stargrave.org/Harmful.html

This makes me wonder if itʼs possible to get `Letʼs Encrypt` to cross-sign an HTTPS certificate issued by another CA?

For 22kW "slow" chargers this is a bit simpler as the actual charger is a lot less complex, it doesn't need to negotiate, it just needs to switch one relay.

To be more explicit, the actual AC "slow" charger is built into the car, so it's guaranteed to work (and indeed, it just needs to signal a contactor to close the circuit).