geogriffin | 5 years ago | on: Why I rewrote my Rust keyboard firmware in Zig: consistency, mastery, and fun
geogriffin's comments
geogriffin | 5 years ago | on: Improving DNS Privacy with Oblivious DoH
Once we say we need encryption on the first hop, then I can see the logic in using a stateless protocol instead of TLS for the second hop, to avoid TLS-in-TLS and all the round trips associated with that.
Side note: It'd be cool if these new protocols used the more generic Noise Protocol Framework [1] instead of a custom, more specialized protocol they just came up with like HPKE [2].
[1] http://noiseprotocol.org/noise.html [2] https://www.ietf.org/id/draft-irtf-cfrg-hpke-06.txt
geogriffin | 5 years ago | on: Improving DNS Privacy with Oblivious DoH
geogriffin | 5 years ago | on: Linux Developers Discussing Possible Kernel Driver for Intel CPU Undervolting
geogriffin | 5 years ago | on: Logging Everyone Out
geogriffin | 6 years ago | on: Writing an OS in Rust: Async/Await
[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
geogriffin | 6 years ago | on: Twitter says an attacker used its API to match usernames to phone numbers
Does anyone know what this actually means? If the contact discovery API doesn't return a username, what does it do? If the answer is that it returns a user ID now instead of username, then presumably that can then be freely queried for the corresponding username..
geogriffin | 6 years ago | on: The Ecosystem Is Moving [video]
Sure, something could and maybe should replace phone numbers, as the system is definitely messy wrt international dialing and countries changing numbering plans.. But the thing that replaces phone numbers in their usefulness will bring the same frustrations you express.
Email has mostly the same characteristics, especially for non-computer-people. My parents were paying $10/mo for dialup up to ten years after switching to DSL and Gmail, just to keep their old email address. I bring that up not to point out the extortion -- email could theoretically have had address providers decoupled from hosting provider through DNS, if it had been made user-friendly -- but to point out the value in the stable identifier. I know this is an anecdote, but the story of AOL email is similar, that 2.5 million people [1] were still paying $20/mo for their dialup and bundled email when "some of whom" (sorry there's no better information on this) had since switched to a different ISP, but kept paying AOL to keep the email.
> I even had to send them a government issued photo ID recently so I could keep the number.
Governments will always want to link users to their stable identifiers. It's in their policing interest, for better or worse. Switching away from phone numbers will just shift the problem.
[1] https://consumerist.com/2013/08/08/believe-it-or-not-2-58-mi...
geogriffin | 6 years ago | on: Better password protections in Chrome
I'm not sure if you're actually talking about something else, but the paper says: "Post-canonicalization, the server calculates a computationally expensive hash of both the canonical username and credential password... This 2-byte prefix—while leaking some bits of password material—provides the client with k-anonymity over the universe of all username and password pairs."
IOW, the 3-byte hash prefix sent is of the username and password concatenated. (Note that Google seems to have added another byte to the prefix versus the paper).
geogriffin | 6 years ago | on: ISOC sold the .org registry to Ethos Capital for $1.1B
You're right. I misread #2 as the inverse so misunderstood what UBI was.
> 3. It is not substantially related to furthering the exempt purpose of the organization - that one would be the toughest to prove...
Kinda a moot point given #2, but the IRS elaborates (emphasis mine), "... only when the conduct of the business activities has causal relationship to achieving exempt purposes (_other than through the production of income_)"
geogriffin | 6 years ago | on: ISOC sold the .org registry to Ethos Capital for $1.1B
geogriffin | 6 years ago | on: ISOC sold the .org registry to Ethos Capital for $1.1B
[1] https://www.hurwitassociates.com/taxation-of-unrelated-busin...
geogriffin | 6 years ago | on: ISOC sold the .org registry to Ethos Capital for $1.1B
[1] https://www.irs.gov/charities-non-profits/unrelated-business...
geogriffin | 6 years ago | on: “correcthorsebatterystaple” is guessed in less than 0.01 seconds
geogriffin | 6 years ago | on: “correcthorsebatterystaple” is guessed in less than 0.01 seconds
geogriffin | 6 years ago | on: “correcthorsebatterystaple” is guessed in less than 0.01 seconds
geogriffin | 6 years ago | on: “correcthorsebatterystaple” is guessed in less than 0.01 seconds
geogriffin | 6 years ago | on: Stop using low DNS TTLs
geogriffin | 6 years ago | on: Why async fn in traits are hard
geogriffin | 6 years ago | on: Uber made nearly $500M from a 'safe rides fee' – money went to company