Hacker Newsnew | past | comments | ask | show | jobs | submit | bigiain's commentslogin

Australia also uses pspspsps - at least my part of it and my family and friends.

(and for some Australians some of the time, "ps ps fuckin ps, ya cunting cat!" of course. ;- ) )


"Cunting"! Not just "cunt" but "cunting"! I learned so much from this thread! :D

Your phone isn't going to have a "very high end HSM" any time soon. n Not until you're paying mid range car prices or more for your very specialised secure phone (and then that phone will probably be factory backdoored AN0M-style).

Same. I wonder if my Yubikeys have anything to mitigate this sort of attack. My gut feel says that at their pricepoint and form factor, probably not.

A Yubikey is basically a single chip and a bunch of plastic. At their $50 price point, there's plenty of room for some chip manufacturer to skim off a couple of dollars per chip to add an additional metal layer for a tamper protection mesh, and some other gizmos.

That's cynical, but without doubt true for some people.

I wouldn't want to be someone the NSA is "interested in".

I wouldn't even want to be someone that a customer of NSO Group is interested in. (Just ask Jamal Kashoggi's family or friends)

Hell, where I live they're about to give cops powers to let then hack your phone with a Cellebrite UFED at roadside stops. And it's not even just cops, fisheries enforcement officers Australia have been using UFEDs at least as far back as 2017 during illegal fishing investigations.

If you're doing things that might make someone rich or powerful enough unhappy, or someone in law enforcement - you pretty much need to stop using the internet. And the bar for "how powerful" your potential threat is keeps dropping lower and lower. Just look at all the stories about local cops abusing Flock cameras to stalk ex girlfriend or people critical of them, how could anyone possibly believe those same sort of cops aren't going to use roadside phone forced data extraction tools in exactly the same petty and personal ways, and with exactly the same lack of oversight and consequences?


FWIW, GrapheneOS is the only usable phone OS that is legal and Cellebrite can't hack. That's why law enforcement are so horny to ban it.

It's a pity GrapheneOS is allowing AI code contributions...

Weird hill to die on. My understanding is they refused to 100% ban it just because it's AI, but quality standards still apply so there won't be much.

We need to differentiate "no AI because it's slop" and "no AI because fuck Sam Altman". The latter is never going to be practical because you won't reject a good change just because fuck Sam Altman. And the former is irrelevant because you wouldn't accept human slop either. A policy of "AI is probably slop, please don't carelessly submit any and we will ban you for submitting slop" makes sense and is what Graphene has. A policy of "fuck Sam Altman, we ban you if we think you're giving him money" does not make sense if you prioritize working software above ideology.


We've beer-o-clock wargamed this a bit.

If I had an "important enough" client, I think I'd store all out local (Sydney + Melbourne AWS cross region) data to AWS Singapore (to protect against Australian jurisdictional and political risks) and to a non AWS cloud provider in the EU somewhere. I reckon thatd be close to as resilient a pile of hard drives in an underground bunker, for significantly less setup and ongoing cost, while also being much more available when needed. (Can you imagine the queue at the underground bunker when multiple AWS regions get bombed? Or even imagine getting to the bunker in "a friendly jurisdiction" while a shooting war is taking place?)

We haven't worked out a decent solution to Visa and Mastercard payment network going down for more than a couple of cloud billing cycles though.


More likely than the network going down is you getting banned from the network because someone thought you were selling porn.

I'm comfortable enough with the Sydney and Melbourne AWS regions - about 700km (400 miles) apart and with (at least) 3 AZs in each. If something takes out enough AWS datacenters to lose some of work's or client data stored across all that, the uptime and resilience of the CRUD platforms I'm responsible for will not be very high on my personal priority list. (At least on AWS datacenter is within 10km of my home. I'm hoping that well before Australia gets involved in the sort of geopolitical conflict that might mean missile strikes against civilian infrastructure, I'll have headed bush to hang out with my off grid friends)

Isn't S3 claiming eleven nines of data durability?

https://aws.amazon.com/s3/storage-classes/

"Additionally, S3 stores data redundantly across a minimum of 3 Availability Zones by default, providing built-in resilience against widespread disaster."

I wonder if "can't restore some data" includes any S3 data?

I'd expect to lose EC2 instance EBS data in the event of a datacenter being destroyed, but I kinda assume I wouldn't lose S3 data? Now I'm wondering if RDS backups are more like EBS or S3...


1/f noise strikes again

I reckon there's a decent argument to be made that an authorization to scan *.tesla.com definitively does NOT extend to any hosts resolved via a CNAME chain that goes foo.tesla.com -> bah.not-tesla.com -> host-that-never-authorized-attacking.

Pretty hard to implement in practice!

% dig www.tesla.com +short

www.tesla.com.edgekey.net.

e1792.dscx.akamaiedge.net.

<akamai IP>


I'm guessing that maybe 4 of them maintain that in their "20% time", while the 99,996 other engineers are:

"The best minds of my generation are thinking about how to make people click ads." -Jeff Hammerbacher


They still run Macintosh System 7 with wireless AppleTalk, right?

Over GRE tunnels

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: