Hacker Newsnew | past | comments | ask | show | jobs | submit | spiddy's commentslogin

Joke's on you, now I know your password is 7 chars, but more importantly, I also know your password is not 7 stars.


It's seven 7s, but I've never told anyone the order, so it's safe.


Also, make sure to use official website, not just Google search, or any chat agent question, the SEO are sometimes poisoned with scam phone numbers.

I consider myself always to be wary of scams and my trust-level is zero when they call me, but I recently almost got myself hooked on an airline support call. I google searched the support number and trusted the AI summary on top and called it, they asked me my reservation number and I happily provided. With the reservation number they have public access to the entire reservation details, they knew my name, my flight, my co-passenger details everything. I called to do a reservation for my pet which is normally not done online. their problem, they got greedy and asked me more than pet travel, iirc they said there was a problem with one of my flights, it wasn't paid and I had to repay on the call. If they just followed along instead of going by the script I would have paid the pet travel amount.


you don’t need to be an aviation expert to trust the plane will fly.

likewise e-voting systems pass through cryptography experts auditing to verify it does what it says it does.

said that the voting solution can also provide cryptographic proof that your vote was unaltered, and accounted for, without need to expose your actual vote.

the claims about database altering, are also false as the vote is cryptographically signed and unalterable.

also there is another feature where you can recast vote on top of your previous one and the last vote will be the valid one. This is crucial for countries where the bad guys can come at your place and under distress (gun) force your vote. you can then recast safely invalidating the forced vote.

e-voting solutions is really interesting and in an alternate reality I think we could have had a mainstream e-voting and more even direct-democracy vs our current democracy by proxy (elected officials)


>you don’t need to be an aviation expert to trust the plane will fly.

...because when I get on the plane, I can look out the window and see that it's in the air.

With paper ballots, the systems are very interpretable - you can sign up to audit the ballot counting process and watch it happen, etc.

But you can't do that with electrons in a computer - it's really just pure trust. That's what you lose.


yes you can.

each citizen gets an anonymized private key via a secure channel (eg. postal) and use that to vote.

votes are double enveloped: outer envelop: anonymized id + inner envelop: vote.

mixnet separates the votes and cryptographically shuffles them to decouple relationships.

only at the end the shuffled votes are decrypted using the private key of the election itself that was split using shamir secret sharing (eg 5 out of 7 shares to reconstruct)

the thing that’s not clear from the article and it’s a shame is that it seems the failure was the hardware (the 3 USB keys) not the election software. This could be simply avoided by having redundancy on the hardware (2 USBs per share) or more shares themselves (5 out of 9 shares)


Weirdly this reminds me of the Raft consensus protocol: two nodes cancel each other when failing consensus as you can't tell which is the valid one, three gives you better chances, if one fails you have the other two that can get consensus. Of course in the off chance you have two failures you cannot get consensus with the only living node. Adding another two nodes make you robust to two failures.

Now replace fail with lying and you have the exact same problem.


though why treat booleans as special case and keep timestamps for them when you don’t for integers with this pattern:

isDarkTheme: {timestamped} paginationItems: 50

I can see when dark theme was activated but not when pagination was set to 50.

also, i can’t see when dark theme is being deactivated either.

seems like a poor-man changelog. there maybe use cases for it but i can’t think of anything tbh.


this. Let’s not confuse meanings. There are multiple ways to improve quality of code. Testing is one, code review is another. this belongs to the latter


I'm located in Barcelona, and yesterday lot of transactions on mini markets / pharmacies were not possible because the item prices were unknown, adding to the fact there was no phone lines available to reach out.


This reminds me of https://news.ycombinator.com/item?id=42342382 on the blog https://eieio.games/blog/writing-down-every-uuid/ they mention how they tackled various challenges such as rendering.


seems to me a survival bias.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: