<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: pseudohadamard</title><link>https://news.ycombinator.com/user?id=pseudohadamard</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 06 Sep 2026 13:45:11 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=pseudohadamard" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by pseudohadamard in "Space industry lacks workers needed to rebuild satellites lost in war: report"]]></title><description><![CDATA[
<p>It's also whether it matters if you have people available to replace the things. Any conflict that gets to the point of taking out satellites will almost certainly trigger Kessler syndrome, at which point whether you can launch any more satellites becomes moot.</p>
]]></description><pubDate>Sun, 06 Sep 2026 12:11:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49585745</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49585745</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49585745</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain"]]></title><description><![CDATA[
<p>ai;dr</p>
]]></description><pubDate>Sun, 06 Sep 2026 12:07:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49585721</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49585721</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49585721</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain"]]></title><description><![CDATA[
<p>For anyone else reading this and rolling their own crypto (hint: don't! No really, just don't!):<p>>a lax PKCS#1 v1.5 RSA signature verifier that failed to enforce the total encoded length (256 bytes) or pin the digest to its correct length for the claimed hash, allowing an attacker to forge a valid-looking signature without the private key<p>the correct way to do this is encode-then-memcmp(). You can't get it wrong that way because a memcmp() only has two outcomes, match or no match, not a whole range of "seems to work OK on the tests we ran it on".</p>
]]></description><pubDate>Sun, 06 Sep 2026 12:06:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49585714</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49585714</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49585714</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Private German rocket makes history, reaches orbit from European soil"]]></title><description><![CDATA[
<p>Yes, but most of them in the early 1940s.</p>
]]></description><pubDate>Sun, 06 Sep 2026 05:21:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49583558</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49583558</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49583558</guid></item><item><title><![CDATA[New comment by pseudohadamard in "The Highest Point in the Netherlands"]]></title><description><![CDATA[
<p>Bit of an odd comment overall. The fact that I know that the highest point in the Netherlands is in the Caribbean pretty much demonstrates that I'm not from the US.</p>
]]></description><pubDate>Sat, 05 Sep 2026 12:43:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49576001</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49576001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49576001</guid></item><item><title><![CDATA[New comment by pseudohadamard in "RSA-260 Factorized"]]></title><description><![CDATA[
<p>EdDSA is also quite a mess, see e.g. <a href="https://hdevalence.ca/blog/2020-10-04-its-25519am/" rel="nofollow">https://hdevalence.ca/blog/2020-10-04-its-25519am/</a>. Almost no two implementations that aren't the same code base can agree on what is and isn't a valid signature. ECDSA isn't nearly as bad, there's only two forms of the same signature possible and implementations seem to generate either of the two at random (this makes for a great subliminal channel to leak the private key if you don't have the source code). With RSA PKCS #1 (but not PSS) there's one and only one form for a signature.<p>So oddly enough the supposedly really bad insecure terrible etc PKCS #1 RSA is the only one where the signature is totally unambiguous.</p>
]]></description><pubDate>Sat, 05 Sep 2026 12:38:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=49575962</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49575962</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49575962</guid></item><item><title><![CDATA[New comment by pseudohadamard in "RSA-260 Factorized"]]></title><description><![CDATA[
<p>> If you are actually operating a service relying on RSA-1024 security, it is almost certainly pwoned.<p>If you're running something with code from a large US corporation, or outsourced to contractors, or made in China, or with a web interface, or [3 more pages of stuff] and your main worry is the size of your RSA keys, then I've got a Fortigate security appliance to sell you.</p>
]]></description><pubDate>Sat, 05 Sep 2026 12:33:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49575922</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49575922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49575922</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Norway's Oil Fund Proposes Selling Roughly $80B in U.S. Treasurys"]]></title><description><![CDATA[
<p>Several of them barely even read, period.<p>Unless their name is on every powerpoint slide in a large font.</p>
]]></description><pubDate>Sat, 05 Sep 2026 09:05:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49574697</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49574697</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49574697</guid></item><item><title><![CDATA[New comment by pseudohadamard in "The auto lobby spent millions on media manipulation"]]></title><description><![CDATA[
<p>It's also a biased, lopsided report. Guy I know who was an EV pioneer in California said it was so bad that, even though his career consisted of promoting EVs, he told people to avoid watching it because it presents such a skewed picture. Imagine it's been made by Michael Moore to put it into perspective. From what I can remember, and this was 20 years ago, his summary was that the EV1 was introduced purely to meet the ZEV mandate but in practice the vehicles were "saleproof" (his words). There wasn't any conspiracy to kill them.</p>
]]></description><pubDate>Sat, 05 Sep 2026 08:12:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49574303</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49574303</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49574303</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Searching for the Best Silicone USB Cable"]]></title><description><![CDATA[
<p>Just beware that an awful lot of "silicone" cabling coming from China is actually overplasticized PVC, particular cabling used in instrument probes. It feels like silicone until it starts getting stiff while at the same time outgassing plasticizer like crazy, or you touch it with a soldering iron or similar. I would expect most or even all of the cat-ran-across-the-keyboard Amazon brands to be overplasticized PVC, not silicone (hint: Use the Knockoff plugin for Chromefox, <a href="https://github.com/Shpigford/knockoff" rel="nofollow">https://github.com/Shpigford/knockoff</a>, which will warn you for stuff that's sold on Temu West, aka.Amazon, it's warning on almost all of the pseudo-brands listed in the article).<p>I've also run into way too much cabling that's CCA or even CCS. Garbage on the outside, garbage on the inside.</p>
]]></description><pubDate>Sat, 05 Sep 2026 07:37:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49574087</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49574087</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49574087</guid></item><item><title><![CDATA[New comment by pseudohadamard in "The Highest Point in the Netherlands"]]></title><description><![CDATA[
<p>Don't ever use that word outside of a Serious Screenplay.</p>
]]></description><pubDate>Sat, 05 Sep 2026 07:20:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49573992</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49573992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49573992</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Welcome to the Porcelain Insulator Collector's World of Mud"]]></title><description><![CDATA[
<p>If you're interested in insulators you may also be interested in the telegraph poles that they're mounted on, for which we have the Telegraph Pole Appreciation Society, <a href="https://www.telegraphpoleappreciationsociety.org/" rel="nofollow">https://www.telegraphpoleappreciationsociety.org/</a>. Do sign up, it's only UKP 10 for lifetime memebership.</p>
]]></description><pubDate>Sat, 05 Sep 2026 07:18:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=49573983</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49573983</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49573983</guid></item><item><title><![CDATA[New comment by pseudohadamard in "RSA-260 Factorized"]]></title><description><![CDATA[
<p>Why not? What's the actual threat? Let's say I'm using RSA-1024 on my firewall today. What happens next?</p>
]]></description><pubDate>Sat, 05 Sep 2026 04:41:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=49573131</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49573131</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49573131</guid></item><item><title><![CDATA[New comment by pseudohadamard in "RSA-260 Factorized"]]></title><description><![CDATA[
<p>There's also the question of why anyone would bother. You can factor RSA-1024 today in about a year with a national-lab-level supercomputer. Which 1k-bit RSA key would you shut down a national lab for a year for to factor? Heck, which key would you shut it down for a week for to factor? There's no single key out there of any interest when you can just spear-phish your intended target, or get RCE on their unpatched router, or get the cleaners to plug in a USB key and let it do its thing while they're vaccuuming, or whatever.</p>
]]></description><pubDate>Sat, 05 Sep 2026 04:21:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49573044</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49573044</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49573044</guid></item><item><title><![CDATA[New comment by pseudohadamard in "The Wormhole Hall of Shame"]]></title><description><![CDATA[
<p>Philomena Cunk also discusses wormholes with Prof.Brian Cox, <a href="https://www.youtube.com/watch?v=YPX0v9NzzrM" rel="nofollow">https://www.youtube.com/watch?v=YPX0v9NzzrM</a>.</p>
]]></description><pubDate>Sat, 05 Sep 2026 04:09:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49572990</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49572990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49572990</guid></item><item><title><![CDATA[New comment by pseudohadamard in "RSA-260 Factorized"]]></title><description><![CDATA[
<p>I'd say ECDSA is even worse, because almost anything you get even slightly wrong with Schnorr schemes ends up leaking the private key. With RSA OTOH you just use a decent library and something like encode-and-compare for signing and you're done.  I'm much more nervous about something using ECDSA than RSA once I've had a look at the code and verified that it's at least somewhat competently written.</p>
]]></description><pubDate>Sat, 05 Sep 2026 04:04:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=49572971</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49572971</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49572971</guid></item><item><title><![CDATA[New comment by pseudohadamard in "The Highest Point in the Netherlands"]]></title><description><![CDATA[
<p>The Netherlands isn't that flat. Its highest point is Mt.Scenery at 870m.</p>
]]></description><pubDate>Thu, 03 Sep 2026 12:57:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49549376</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49549376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49549376</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Bank of America Vice President Fatally Stabbed in Times Square"]]></title><description><![CDATA[
<p>"Vice President of Pest Control, Nighttime Security, Non-arboreal Gardening Services, and Tenant-related Easements and Liens".</p>
]]></description><pubDate>Thu, 03 Sep 2026 12:46:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=49549267</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49549267</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49549267</guid></item><item><title><![CDATA[New comment by pseudohadamard in "If You Knew God Exists, Wouldn't You Become a Priest?"]]></title><description><![CDATA[
<p>Linus may be a bit abrasive at times but he's not malevolent. And I run Linux so I guess I'm in the clergy already.</p>
]]></description><pubDate>Thu, 03 Sep 2026 12:40:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49549216</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49549216</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49549216</guid></item><item><title><![CDATA[New comment by pseudohadamard in "Why do so many tools have JSON config files?"]]></title><description><![CDATA[
<p>A lot of that is already in ASN.1, for example for UTF-16 you've already got UTF-8 and given that even Microsoft have abandoned BMP strings I doubt any attempt to reintroduce it will get much traction, relative OIDs already exist, BCD strings are just constrained PrintableStrings and in any case UTF-8 won for all of the string types, Reference sounds like an EXTERNAL, OOB sounds like an ANY DEFINED BY, etc.</p>
]]></description><pubDate>Thu, 03 Sep 2026 08:07:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=49547232</link><dc:creator>pseudohadamard</dc:creator><comments>https://news.ycombinator.com/item?id=49547232</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49547232</guid></item></channel></rss>