Hacker Newsnew | past | comments | ask | show | jobs | submit | markhahn's commentslogin

careful, that might lead to programming. using, you know, a programming language.

what does "integrity" fail mean in the first table? that the case didn't recover from the 2G corruption?

The current “Integrity” label is broader than the test actually proves, and I’m changing it to “Corruption probe.” FAIL means that file changed or became unreadable. SURVIVED means only that the file remained readable and hash-identical. It does not prove the entire filesystem was healthy, that every overwritten byte was allocated, or that all 2 GiB were repaired.

Thanks for pointing it.


that's the odd thing: we simply don't ask whether there's an alternative.

for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).


This is wonderful, though a little low.

Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously.


although the US Constitution does make reference to deities, the copyright section does not. its formalization is entirely pragmatic, utilitarian.

All of the powers granted to the government are through the constitution, and copyright is a form of property right... hence the phrase "intellectual property".

Has anyone found a meaningful discussion of how scraping is theft?

Obviously, reproducing works in whole is infringement. That's not what AI is doing, so the question becomes: how is scraping different from ordinary reading? Is it just that site owners want to play back history and retroactively create high-cost licenses for scraping?


A key consideration in most legal definitions of theft is “intent to permanently deprive the owner”. While this has historically meant scraping is not theft (because copying doesn’t erase the original, nobody is deprived), in this specific case the AI companies’ business plan (copy a person’s content and train on it to make their model more capable of replacing that person) could very well meet the bar of intent to deprive.

It absolutely meets the bar of intent to deprive.

Anything otherwise is willful ignorance or astroturfing.


that seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).


I'm always mystified why we haven't leveraged DNS.

I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.

Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...


No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke.

Really hard to understand why that hasn't happened yet!


You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.

But sure, keep spreading FUD like you always do on this topic.


For the last 2 years, I've tracked the Tranco Top 1000 sites, continuously checking DNS to see if any major sites have turned on DNSSEC (6% of the Top 100 do --- many of them government sites). Over those last 2 years, a total of 8 sites in the Tranco list have enabled it. It happens so rarely I could reasonably call them on the phone and share my misinformation about how moribund DNSSEC is to them directly.

https://dnssecmenot.fly.dev/

The PKI run by state-level actors isn't going to happen.


> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?


You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).


Web PKI also has not had transparency logs until fairly recently. And Web PKI revocation is a joke as well. At least a "rogue" DNSSEC signer can only sign domains they have been delegated authority over and not literally everything.


if the only evidence of a crime is on your phone, what kind of crime is it?

we should always be asking: is this the only way you can prove the accusation? just because it would make LEO life easier - that's not justification for violating the constitution.

an consider what this case teaches us: clean up your devices before you cross a border. how does that even help the goal of law enforcement?


devices already do wear management.

at most, you should configure your system and OS to give them a chance. for instance, being 100% full all the time is just bad. use TRIM and log SMART metrics.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: