Hacker Newsnew | past | comments | ask | show | jobs | submit | jobbagy's commentslogin

Microplastics found in every human testicle in study: Scientists say discovery may be linked to decades-long decline in sperm counts in men around the world https://www.theguardian.com/environment/article/2024/may/20/...


Too old (2009): "Many currently used techniques are not robust enough to prevent detection and removal of embedded data", 2019: https://digitalsynopsis.com/design/nvidia-ai-removes-noise-g...


I'm not able to find the md5 signature for Ledger Live: would you please help me?


A mobile app managing cryptocurrency, but does not sign all their release, and don't even react the situation quickly. Apparently they have no clue what they are doing in terms of security.

Since they also use react native, and npm is notorious for being exploit to distribute malware. I have a brief look at the package.json. Seems to be a typical javascript project where developers tend to put one more dependency for a simple feature rather than implementing themselves. So, if one of the hobbyist project owner's key is compromised or hand over their orphan project to somebody malicious to manage their npm, then they are screwed. Although same could apply to other language which have package management, npm is the worst among those. Do they ensure the dependencies are signed before building the binary? And always use the last known good version for building new binary? I really doubt.


The repo has a yarn.lock file, which contains the hashes of all of the dependencies, so yarn verifies the dependencies match that at least.


wow the md5 does NOT exist: https://github.com/LedgerHQ/ledger-live-desktop/issues/942 How is this possible


Shouldn't everyone use SHA2, or at least Blake 2 (same software performance as MD5) by now?


FYI: Scientist Brad Lister returned to Puerto Rican rainforest after 35 years to find 98% of ground insects had vanished https://www.theguardian.com/environment/2019/jan/15/insect-c...



Great. Https against MITM?


WIP :)



Might as well link directly to the source: https://pastebin.com/jCDFcESz which really I think should be the article URL anyway (the tweet just links here too). Very interesting find!


I checked, the pastebin link was submitted an hour ago to HN and was immediately marked as [dead].


Meta comment, but this is why it is beneficial for users to vouch for good articles so they don't get lost on the new page.


Is it still possible to link to?


Ah I expected the pastebin to just be the list of addresses, not a full wwriteup.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: