<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: xori</title><link>https://news.ycombinator.com/user?id=xori</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 16 Sep 2026 12:23:21 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=xori" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by xori in "Show HN: Capsule – Single-file web apps that save their data into SQLite"]]></title><description><![CDATA[
<p>my-bookreport-v2-final-final-done.capsule</p>
]]></description><pubDate>Wed, 16 Sep 2026 00:01:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49720503</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=49720503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49720503</guid></item><item><title><![CDATA[New comment by xori in "Permacomputing"]]></title><description><![CDATA[
<p>~~Written by the same people?~~<p>EDIT: ha, confused with <a href="https://wiki.xxiivv.com/site/uxn.html" rel="nofollow">https://wiki.xxiivv.com/site/uxn.html</a></p>
]]></description><pubDate>Sat, 21 Feb 2026 21:04:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47104740</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=47104740</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47104740</guid></item><item><title><![CDATA[New comment by xori in "Windows drive letters are not limited to A-Z"]]></title><description><![CDATA[
<p>The real question is can Windows defender scan these drives?</p>
]]></description><pubDate>Sun, 30 Nov 2025 19:47:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=46099749</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=46099749</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46099749</guid></item><item><title><![CDATA[New comment by xori in "The Promised LAN"]]></title><description><![CDATA[
<p>I've been wanting to do this for ages. Originally I wanted to do this at the home router level, but that quickly got shut down when I got a test net up and running and my friends could control the Chromecasts in my house.<p>For us a "tailscale" equivalent with SoftEther is what we used to manage the DNS/Tunneling for our fileshare/services.<p>So cool to see more people playing in this space. Please post more! <3</p>
]]></description><pubDate>Wed, 23 Jul 2025 19:56:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=44663303</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=44663303</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44663303</guid></item><item><title><![CDATA[New comment by xori in "NSA spied through Angry Birds, other apps: report (2014)"]]></title><description><![CDATA[
<p>"How do you get corporate secrets out of a software engineer? Sit them next to another engineer on a plane."</p>
]]></description><pubDate>Thu, 08 May 2025 01:33:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=43922249</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=43922249</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43922249</guid></item><item><title><![CDATA[New comment by xori in "Wired is dropping paywalls for FOIA-based reporting. Others should follow"]]></title><description><![CDATA[
<p>Well they aren't in Canada for me yet, but that's probably because we aren't the public that needs to know.</p>
]]></description><pubDate>Tue, 18 Mar 2025 14:26:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=43399841</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=43399841</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43399841</guid></item><item><title><![CDATA[New comment by xori in "Show HN: my party game where AI decides if you’re funny"]]></title><description><![CDATA[
<p>"Show me what you got"</p>
]]></description><pubDate>Tue, 03 Dec 2024 16:48:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=42308228</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=42308228</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42308228</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Parallel DOM – Upgrade your DOM to be multithreaded"]]></title><description><![CDATA[
<p>I understand, but things like <a href="https://github.com/GoogleChromeLabs/comlink">https://github.com/GoogleChromeLabs/comlink</a> enable it. Similar to how iFrames don't have access to their parent page you need a facilitator. My question is why not use a js facilitator that could work in all browsers, rather than just Chrome.<p>I find it an interesting choice that the author decided to invest in new iFrame technology rather than existing multi-thread technology in the browser.</p>
]]></description><pubDate>Wed, 10 Jul 2024 00:04:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=40922582</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40922582</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40922582</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Parallel DOM – Upgrade your DOM to be multithreaded"]]></title><description><![CDATA[
<p>I see it now, I don't know how I missed it.</p>
]]></description><pubDate>Wed, 10 Jul 2024 00:03:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=40922571</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40922571</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40922571</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Parallel DOM – Upgrade your DOM to be multithreaded"]]></title><description><![CDATA[
<p>Why reach for iFrames over other technology like WebWorkers?</p>
]]></description><pubDate>Tue, 09 Jul 2024 20:51:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=40920945</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40920945</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40920945</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Storing Private Keys in the Browser Securely"]]></title><description><![CDATA[
<p>I'm confident then that you can skip the base64 encoded header and just have the server use the jwt passed in the bearer token and the new signature you propose. (As the base64 encoded version can be reconstructed from the JWT itself)<p>But I think ideally I would use a wrapped JWT with `"alg": "ES256"` and just pass it as normal in a bearer token[0] as JWTs natively support signed primitives.<p>[0]: <a href="https://jwt.io/#debugger-io?token=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTUxNjIzOTAyMiwic3VwYWJhc2Utand0IjoiZXlKaGJHY2lPaUpJVXpJMU5pSXNJblI1Y0NJNklrcFhWQ0o5LmV5SnpkV0lpT2lJeE1qTTBOVFkzT0Rrd0lpd2libUZ0WlNJNklrcHZhRzRnUkc5bElpd2lhV0YwSWpveE5URTJNak01TURJeWZRLlNmbEt4d1JKU01lS0tGMlFUNGZ3cE1lSmYzNlBPazZ5SlZfYWRRc3N3NWMifQ.7srrNIhpxeUFb3rPoOJaNQNwsO-IUGAFLSu-UTZtHugfKECt_Tccv-p9KI8h5F7yXMEQcjL7z89LqT7xKYzcWA&publicKey=-----BEGIN%20PUBLIC%20KEY-----%0AMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEEVs%2Fo5%2BuQbTjL3chynL4wXgUg2R9%0Aq9UU8I5mEovUf86QZ7kOBIjJwqnzD1omageEHWwHdBO6B%2BdFabmdT9POxg%3D%3D%0A-----END%20PUBLIC%20KEY-----" rel="nofollow">https://jwt.io/#debugger-io?token=eyJhbGciOiJFUzI1NiIsInR5cC...</a></p>
]]></description><pubDate>Wed, 24 Apr 2024 17:10:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=40147051</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40147051</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40147051</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Storing Private Keys in the Browser Securely"]]></title><description><![CDATA[
<p>When you `.get` a credential you can provide a challenge that it signs which you can make the JWT. With an added bonus that this passkey can exist on your phone or password manager which you can use to authenticate on a different device while still feeling confident in it's security.</p>
]]></description><pubDate>Wed, 24 Apr 2024 17:02:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=40146967</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40146967</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40146967</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Storing Private Keys in the Browser Securely"]]></title><description><![CDATA[
<p>Yeah that does it for new keys generated, any old keys in IDB obviously still are exposed.</p>
]]></description><pubDate>Wed, 24 Apr 2024 17:00:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=40146934</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40146934</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40146934</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Storing Private Keys in the Browser Securely"]]></title><description><![CDATA[
<p>Rather than generating key data on the client in the open, and storing it in IDB, I would recommend the Credential Management API[0]. Hand off the responsibility to proper generation and storage to the user agent. Then do your signing of the JWT with them instead.<p>[0]: <a href="https://developer.mozilla.org/en-US/docs/Web/API/Credential_Management_API" rel="nofollow">https://developer.mozilla.org/en-US/docs/Web/API/Credential_...</a></p>
]]></description><pubDate>Wed, 24 Apr 2024 14:53:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=40145082</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40145082</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40145082</guid></item><item><title><![CDATA[New comment by xori in "Show HN: Storing Private Keys in the Browser Securely"]]></title><description><![CDATA[
<p>so I don't fully understand what you're preventing<p><pre><code>    const db = await openDatabase();
    const keyPair = await getKeyPair(db);
    await crypto.subtle.exportKey("jwk", keyPair.privateKey)
</code></pre>
exports the private key if I have a XSS vuln.<p>The recommendation for IP address in the JWT is good, but I don't understand your last recommendation of 1) sending the JWT, 2) additionally sending the base64 JWT in a header 3) sending the signature in the header. The crypto.subtle api only works on https domains so you're not defending against mitm attacks on unsecure networks either. And if we can't trust TLS what can we trust on the web?</p>
]]></description><pubDate>Wed, 24 Apr 2024 14:45:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=40144994</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40144994</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40144994</guid></item><item><title><![CDATA[New comment by xori in "Rabbit R1 source code [part 1]"]]></title><description><![CDATA[
<p>Not much here explicitly in the source code dump. A little insight into their worker node infra but no "secret sauce"  imo.</p>
]]></description><pubDate>Tue, 23 Apr 2024 19:23:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=40136092</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=40136092</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40136092</guid></item><item><title><![CDATA[New comment by xori in "Overlay networks based on WebRTC"]]></title><description><![CDATA[
<p>Hyperswarm has been my go-to for stuff like this, but you bring up a good point that I don't think it's encrypted.<p><a href="https://github.com/holepunchto/hyperswarm">https://github.com/holepunchto/hyperswarm</a></p>
]]></description><pubDate>Fri, 29 Mar 2024 18:01:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=39867100</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=39867100</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39867100</guid></item><item><title><![CDATA[New comment by xori in "Moonwalkers: Shoes that make you walk faster (pre-order)"]]></title><description><![CDATA[
<p>I don't know if 5 miles is long enough for the people who actually need it, but if I was a postal worker, these would be pretty sweet. And 1400 USD is cheaper than some car insurance here in Canada for young males.</p>
]]></description><pubDate>Thu, 05 Jan 2023 19:19:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=34265018</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=34265018</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34265018</guid></item><item><title><![CDATA[New comment by xori in "IRS Will Soon Require Selfies for Online Access"]]></title><description><![CDATA[
<p>JPGs are not security, and moving JPGs can be fabricated very easily. Some v-tuber software with a deepfake GAN strapped to it I feel like would fool 1-on-1 meetings too.<p>I got my weekend project.</p>
]]></description><pubDate>Wed, 19 Jan 2022 21:50:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=30000732</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=30000732</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30000732</guid></item><item><title><![CDATA[New comment by xori in "Evervault"]]></title><description><![CDATA[
<p>> we can't decrypt your data.<p>But I thought the point of the cages, is that _do_ decrypt the data. And any government mandated backdoors would then go into that process. You're not doing any homomorphic encryption here.<p>I guess my issue, is that you see both the keys <i>and</i> data, not just one.</p>
]]></description><pubDate>Fri, 17 Dec 2021 16:35:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=29594501</link><dc:creator>xori</dc:creator><comments>https://news.ycombinator.com/item?id=29594501</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29594501</guid></item></channel></rss>