HN user

robododo

229 karma
Posts0
Comments59
View on HN
No posts found.

If you're admin, you might have to install a driver to scrape all memory. So... one hoop to jump through :)

Caveat: you're still trapped in your hypervisor partition. Enclaves (e.g. SGX) are also protected from admin/root snooping. IIRC, this is the same as on Linux.

Does this all hinge on EPID? So will cloud workloads have to phone home to Intel for assertions to be satisfied?

My question is built on the presumption that SGX is the only real TEE available right now.

Also, how is Google dealing with PRM/EPC memory limitations of SGX?

Just to clarify the article a bit:

Your password hash is not sent over the wire. What is sent over the wire is the NTLMv2 response message. This, simplified, is: HMAC_MD5(Hash | challenge). If you want the gory details, check out MS-NLMP.

That said, a dictionary-attackable password + attacker with fast GPUs can still brute-forcing the HMAC, then attack the password hash (MD4). It's a bit harder than just banging on a simple hash, though not terrifically difficult.

This is the burden of having firstlast@popular.com email address.

Once, my wife had someone setup some sort of financial account with her email (CC, IIRC). They didn't verify the address!

My wife called and tried to do the right thing, but the people on the phone just didn't understand the concept that the email address was wrong. It simply wouldn't compute for them. Since my wife had the email address, she /must/ have been the account holder. Right?

How many of these have gotten new server keys? How many have invalidated all prior session ids and cookies?

I have a feeling heartbleed will haunt us for a while.

Calling the data gathering intrusive is a bit of a stretch. Considerable efforts are made to ensure you're anonymized and personally identifiable information is not gathered. There are people to actively work to ensure you're not "tracked" in any way.

Off-Topic: I'd be interested to see the number of people who turn off the Microsoft CEIP (terrible abbreviation), yet still use a Google id and/or accept DoubleClick cookies.

Definitely. Though I often wonder how much Google's apps strategy is a direct-compete with office for now?

I have a sneaking suspicion it's similar to Microsoft's Bing strategy. It feels like Bing was created to annoy Google and keep them focused on search. Microsoft could afford to throw a few billion at something to keep Google out of it's bread-and-butter. It feels like Google's doing the same with apps.

Of course, given enough time to gain feature parity, both GApps and Bing could be true competitors.

Unless you're adopted and you want some sort of information where you have none. In that case, isn't it prudent to attempt to gather data on your genetics?

It's extremely frustrating when doctors/nurses/PAs ask me about family history and I tell them I was adopted. It shuts out an entire channel of potentially helpful information.

Yes, but there is no forced curve fit.

A healthy organization will always "manage out" people who are not fit for the job. At Microsoft, folks are given the hint early enough that they can explore other internal options before leaving the company entirely.

Though, to be honest, if someone just can't cut it, they will leave the company.

Support for large projects/solutions was greatly improved. VS2012 added deferred loading for some items so you can open and get into code faster.

Of course, this is purely an artifact of overly large solutions. If you've inherited any of those, as I have, it's worth the upgrade for the improved performance, IMO.

So... plastic + blue foam + blue foam + plastic.

This sounds extremely flammable. Are any of your materials actually code-rated for a living structure (as you're using them)? Last I checked, stuff like blue foam board needs to be used in specific ways, such as behind fire-rated walls. You cannot leave any of it exposed, or it's a fire hazard.

That pretty much sums it up. The 8.1 changes, so far as I can tell, are bugfix/stability changes.

The article feels like click-bait to me. The little blurb on zdnet about the author helped me better understand where he's coming from: Matt Baxter-Reynolds is a mobile software development consultant and technology sociologist based in the UK. His next book, "Death of the PC" is out in September.

I'm actually in the windows services group now (no longer called Live). I can confirm that the author's experience is quite different from mine. Papercruncher's assessment is pretty much spot on.

Given there are 10k's of employees here in Redmond, it's not surprising that different groups are, well, different. I've noticed that rather large subcultures emerge in different areas. Once you're in the door, there's encouragement to move and find your "fit". All this blog post taught me is that I probably wouldn't be a good fit for Azure :)