HN user

sarnowski

894 karma
Posts30
Comments134
View on HN
forum.cursor.com 1y ago

Claude has learned how to jailbreak Cursor

sarnowski
71pts36
noyb.eu 1y ago

Noyb sends Meta 'cease and desist' letter over AI training

sarnowski
4pts0
noyb.eu 2y ago

(Preliminary) Noyb Win: Meta Stops AI Plans in the EU

sarnowski
2pts0
noyb.eu 3y ago

New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”

sarnowski
63pts34
techcrunch.com 3y ago

Security researchers warn of a new class of Apple bugs

sarnowski
2pts0
noyb.eu 4y ago

Austrian DSB: EU-US Data Transfers to Google Analytics Illegal

sarnowski
254pts285
privacy.twitter.com 6y ago

Twitter Android client code execution discovered

sarnowski
2pts0
aws.amazon.com 6y ago

AWS Nitro Enclaves

sarnowski
6pts1
wpa3.mathyvanhoef.com 7y ago

Dragonblood – Analysing WPA3's Dragonfly Handshake

sarnowski
1pts0
tech.zalando.com 9y ago

PostgreSQL in a time of Kubernetes

sarnowski
8pts0
threatpost.com 9y ago

Microsoft Quietly Patches Another Critical Malware Protection Engine Flaw

sarnowski
3pts0
cloudplatform.googleblog.com 9y ago

Container-Optimized OS from Google is generally available

sarnowski
2pts0
status.github.com 10y ago

GitHub down

sarnowski
64pts33
www.dw.com 10y ago

German Justice Minister Maas Terminates Federal Prosecutor Range

sarnowski
1pts1
github.com 11y ago

Swagger1st, a Clojure library for API first approaches

sarnowski
2pts0
securehomes.esat.kuleuven.be 12y ago

Canvas Fingerprinting

sarnowski
3pts0
www.spiegel.de 12y ago

Inside Snowden's Germany File

sarnowski
17pts0
bpmn.io 12y ago

Bpmn.io releases first preview of JavaScript bpmn library

sarnowski
1pts0
m.networkworld.com 12y ago

Microsoft Lync gathers data just like NSA

sarnowski
1pts0
camundabpm.blogspot.de 12y ago

It's done: camunda BPM 7.0.0-Final released

sarnowski
1pts0
www.spiegel.de 12y ago

NSA spied on UN, breaking active agreements

sarnowski
70pts20
camundabpm.blogspot.de 13y ago

Camunda BPM 7.0.0-alpha6 released

sarnowski
1pts0
www.newswire.ca 13y ago

Zalando wins Kinnevik as long term strategic shareholder

sarnowski
1pts0
trustedco.de 14y ago

Show HN: generic-ci, a lightweight continuous integration tool

sarnowski
4pts0
lists.jboss.org 14y ago

JBoss AS 7.1 released, fully certified for Java EE 6

sarnowski
4pts0
blog.primefaces.org 14y ago

IceFaces Copies PrimeFaces Line by Line

sarnowski
1pts0
svn.php.net 14y ago

PHP 5.3.9 remote execution exploit fixed

sarnowski
2pts0
arstechnica.com 14y ago

Windows Azure beats Amazon EC2, Google App Engine in cloud speed test

sarnowski
10pts0
twitter.com 14y ago

Hotmail, MSN, SkyDrive down due to power outage

sarnowski
1pts1
code.google.com 14y ago

Servlet 3.0 support for Google AppEngine accepted

sarnowski
4pts0

It is from a time when we were used to remember phone numbers, and where we shared our phone numbers to keep in touch (calls, sms). ICQ directly picked on that and it was just another „phone number“.

Unfortunately I only remember the first half of mine after so many years. In the age of smartphones, at least my brain degenerated to not be able to recall more than a handful of important phone numbers.

Draggable objects 3 years ago

Playing around with a hex based game myself, the bookmark to the Hexagonal Grid is a constant companion over the years. It was updated slightly over the years with some visual cues. Amazing presentation, and so great to learn.

The part of the cookie law that’s dumb is that it’s too narrowly scoped and should apply to all tracking technologies and techniques, for whichever purposes and vendors are or aren’t okay with the user.

A recent definition of the German authorities clarifies that with „cookies“, they don’t interpret it narrowly as the specific browser technology but any kind of beacon or mechanism for tracking[0]:

Gemeint ist damit beispielsweise der Einsatz von Cookies und anderen Technologien wie LocalStorage, Web Storage, das Auslesen von Werbe- und Geräte-IDs, Seriennummern, aber auch der Einsatz von ETags oder TLS-Session-IDs zum Zwecke des Trackings, Fingerprinting (z.B. durch das Auslesen von installierten Schriften oder Anwendungen) und vieles mehr. Der Einfachheit halber wird das im Folgenden i.d.R. unter dem verkürzenden Begriff „Cookies“ zusammengefasst.

They name as explicit examples not only cookies but LocalStorage, Web Storage, reading of any kind of serial numbers, ETags, TLS Session IDs (if used for tracking), and any other method for fingerprinting such as font profiling.

[0] https://www.baden-wuerttemberg.datenschutz.de/faq-zu-cookies...

Civilization II 3 years ago

That was Civ 1. I think they dropped it in Civ 2.

Edit: actually not sure. In Civ 1 you build up your palace, not the throne room per se.

I think/assume OpenBSD is mainly used as a server OS. Yes, passionate people use it as a desktop but those mostly read the FAQ anyway.

Currently and as far as I know, bioctl does only support user typed in passwords or key disks. You certainly want also encrypted disks on your server but requiring user typed in password is oftentimes a no-go (think of various firewall appliances doing a reboot and not having remote hands). A compensation can be the key disk but I don’t know how widely that is used.

Hardware bound encryption like with a TPM is not supported. Also Linux is still exploring here as far as I can tell (no installer offers that).

In sum: I think disk encryption in the current form is not a tradeoff many installations will take.

There are packages like image libraries, Java etc that rely on X11 libraries. The safe default is to have it around.

You can always choose to not install all X* packages. In fact, for a server oftentimes you don’t need more than the base package (you barely need a compiler either or games).

TPMs do not reveal a unique serial number or similar identifier by design for privacy reasons.

A TPM can attest that some measurements were done with it and it can attest that it comes from vendor X. You can block an entire vendor if they don’t behave but not individual TPMs via remote attestation.

You can use a scheme in which you can set up an „identity“ on first use and then on next use authenticate the same identity. But that identity is kinda per use case.

Regarding scaling: If you use 2x scaling it should be easy with any distribution. Fractional scaling is a bit trickier to get.

I am using a Framework with 1.5x scaling using Fedora KDE and it’s amazing. Didn’t find any app yet that doesn’t conform. One difference to years ago is Wayland vs X. With X it was a constant struggle for me while with Wayland and more years invested, scaling became a non-issue on Linux (for me).

Regarding burp suite, iirc this is a JVM based app. I am running Jetbrains products without any issues and no configuration needs. Assuming burp suite uses swing, I would assume no issue. Generally, you can quickly check with a VM. Using Fedora KDE is a great „Just Works“ experience.

Oftentimes you can just ask the customer service of Vodafone. If you reach a good agent, they will switch you away from CGNAT and you get a proper /56 public routable prefix on your cable line. Also works great for me. Be aware, the Vodafone modem won‘t forward the prefix for you. Use a Fritzbox or one of the other few cable modems where you get full control.

Correct, it’s officially a framework and not a protocol. It’s a framework to build a specific protocol which then is using the same patterns as other OAuth2 based protocols but not necessarily compatible. For example URL endpoints are not defined in a strict sense and the provider can also add arbitrary parameters to calls as long as the basic OAuth2 parameter are present as well. OpenID Connect 1.0 builds on that to make the framework more strict.

RFC6749 The OAuth 2.0 Authorization _Framework_

Dealing in absolute terms does not help security. It depends entirely on your threat model.

If you consider NSA or similar agencies a problem then you are in a world of pain anyway and using an entry level guiding blog post is certainly not appropriate.

For everyone else, this puts already quite a big defense layer to your arsenal even if not unhackable in absolute terms.

Not all cookies require consent. There are many legitimate reasons to collect personal data - consent is only required if you cannot find another legitimate reason.

For cookies that mean: technical cookies that you need to technical provide your offering (think of authentication session cookie, loadbalancer sticky session cookies, but also cookies to understand if someone opted into tracking) can be set with legitimate interest and do not require a consent.

A consent under GDPR is strictly opt-in. This means, by default you must not track a user (EU citizen) that just landed on your site. After consent, you can load your GA plugin.

The cookie banners come from the ePrivacy Regulation and are supposed to inform you that the website is storing data on the your device and that you can opt out (not in) of it.

Consent is required by GDPR but not for the technical circumstance that you store a cookie but that you use it for profiling. Some lawyers argue that basic web performance is legitimate interest especially in e-commerce, others don’t risk it and ask for consent (which is strictly opt in).

My vague understanding is, that the tests can also test positive for antibodies from other similar viruses. They have a significant false-positive rate that you should not rely on a positive („you are immune“) result but overall they will provide a big picture approximation how many citizens might have already resistance. They are not good enough for a rumored „immune certification“.