rhyselsmore | 3 years ago | on: Six charged in mass takedown of DDoS-for-hire sites
rhyselsmore's comments
rhyselsmore | 3 years ago | on: Edge-compatible Serverless Driver for Postgres
rhyselsmore | 3 years ago | on: Pypi.org is running a survey on the state of Python packaging
* Dependencies are managed in a similar way to Go - where hashes of installed packages are stored and compared client side. This means that a hijacker could only serve up the valid versions of packages that I’ve already installed.
* This is still a “centralized” model where a certain level of trust is placed in PyPi - a mode of operation where the “fingerprint” of the TLS key is validated would assist here. However it comes with a few constraints.
Of course the above still comes with the caveat that you have to trust pypi. I’m not saying that this is an unreasonable ask. It’s just how it is.
rhyselsmore | 3 years ago | on: Australian drug tests show 40% of 'official cocaine' had no cocaine
Nope. Claiming that the 3g of powdered sugar is cocaine? You’re getting done with supply.
rhyselsmore | 3 years ago | on: Australian drug tests show 40% of 'official cocaine' had no cocaine
Let’s say you’re an undercover cop, and I sell you what I say is 3g of cocaine, but turns out there is only 0.1g in there. I’ll still be charged and convicted on the 3g.
rhyselsmore | 3 years ago | on: Show HN: Open-source serverless security lake powered by Rust + Apache Iceberg
rhyselsmore | 3 years ago | on: Handshake – Decentralized naming and certificate authority
CAA records provide some extra defence (https://en.m.wikipedia.org/wiki/DNS_Certification_Authority_...).
It’s not perfect, but it’s getting better.
rhyselsmore | 9 years ago | on: How to Tell a Mother Her Child Is Dead
rhyselsmore | 10 years ago | on: Dick Smith Is the Greatest Private Equity Heist of All Time