Hacker Newsnew | past | comments | ask | show | jobs | submit | fuoqi's commentslogin

The existing "big" nuclear reactors are already more or less in the "happy" range. The problem is irregular building schedule (you can have 10 reactors in works today and 0 for the next 50 years) and extreme regulatory overhead.

Ideally, you need a "pipeline" with one reactor being built every 2-5 years and streamlined regulatory environment where you can use the same project "template" with minimal adjustments. This way building expertise is not lost (i.e. the industry does not need to re-learn everything for every project, which is very costly) and even can be accumulated to reduce costs further. It applies not only to the building part, but also to regulatory bodies.

The problem is that you need to operate ~100 reactors for this, so it can work only for large economies able to provide the "baseline" demand. China and to a lesser extent Russia do this, which does result in significantly lower nuclear plant building costs for them. Europe, SK, and US have dropped the ball hard here.


I think “medium” is a key enabler for being able to sustain a regular schedule of reactor building. It’s way easier to raise $3bn every 3 years than $30bn every 30 years.

>I hope we see a different CA for each ccTLD in the future.

Completely agree with this and IMO it's how the system should've operated from the very start. Unfortunately, I highly doubt that the CA cartel will let go of the power (and associated cash flow) voluntarily.


Don't think the cartel would go against a state


Browsers have to kowtow too ...


Browsers are the cartel. CAs have zero power against browsers, but browsers can poof CAs out of existence. And it's not really a cartel - it's a monopoly, it's Google and everyone else had better copy Google.


Nope, MitMing will be done by the SORM system [0] using certificates signed by the Ministry of Digital "Development" which will be trusted the Yandex Browser, which will be widely installed out of necessity by ordinary Russians to access banks and subsequently other Web resources.

Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s

[0]: https://en.wikipedia.org/wiki/SORM


> Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s

I recognize that Russia is making this change for MitM spying, but this particular sarcasm seems incorrect. Given Verisign's willingness to bend the knee to Texas courts, one could reasonably lose faith in US PKI issuers such as Digicert. I certainly hope the EU is studying the problem US-controlled EU-trusted issuers — the EU age verification systems hinge critically on them, much less the entire web. So I empathize with the sarcasm, but best not to offer MitM proponents (whether in Russia or the U.S. or elsewhere!) an argument that could be used against your viewpoint.


>I recognize that Russia is making this change for MitM spying

Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus.

>So I empathize with the sarcasm, but best not to offer MitM proponents (whether in Russia or the U.S. or elsewhere!) an argument that could be used against your viewpoint.

If browsers truly cared about user security they would've provided reasonable conditions for supporting national CAs:

- Limit its authority only to respective national domain zones.

- Mandate use of Certificate Transparency handled by an independent third party to prevent MitM.

But this debacle only shows that western-controlled (especially financial) systems can be and will be used as a pressure tool, so any large sovereign nation will not trust them as they would in the past. And the taken actions only contribute to further fragmentation of the Internet across national and block borders.


I’d be totally onboard with TLD-locking them to legal jurisdictions they’re comfortable being bound to, except that this would underserve a great deal of the Internet. Don’t really have a great solution yet, either. Perhaps as each TLD operates DNSSEC they could sign authorized issuers by publishing TLD CAA records, which would create some legal zone accountability that’s lacking today (and give the EU a lever by which to cut off U.S. registrars from their zones). But I have no idea how to effect any of that change, and Let’s Encrypt is truly screwed in this model as a worldwide entity. The endgame might actually be “to operate a domain registrar you must be a PKI”, which would ravage the segment and probably permanently kill off Namecheap (one can dream). So, yeah, I agree: I think instead we absolutely will see fragmentation, at both software (PKI) and, eventually, hardline levels, rather than see domain registrars and PKI issuers be forcibly merged by policy.


We should let each country specify trusted CAs the way they specify their DNS signing keys. Or we should just implement DANE already and then the same key serves both purposes and we can delete WebPKI from the world.


>Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus.

So the West essentially helps Kremlin to control Russian citizens. Why is that? Incompetence or something else?


Just some Nanay Boys wrestling.

https://www.youtube.com/watch?v=ztstTo3dVp4


Allowing Russia to have a TLD is also helping the Kremlin control Russian citizens. Do you recommend that IANA should delete the .ru domain?


How so?


it lets them have websites, where they can impose controls via the internet, obviously. Should we delete .ru?


You are not making sense. What controls? They can only ban your domain name and if they do that, you already have a bigger problem.

It's not a surprise for you, you used you passport when registering the domain name and if you planned to do something Kremlin wouldn't like you could've registered it via a foreign registrar and used foreign hosting.

Contrarily, when you have to install Kremlin's root certificate to access your bank, you are unwittingly allowing Kremlin to quietly MitM any connection you make (without them specifically targeting you) and to avoid that you need:

- to be aware of the problem,

- to install those certs in a separate browser or on a separate device which you'd use only to visit your bank and state services


>I recognize that Russia is making this change for MitM spying

Not really, banks do this. FSB would love to spy on everyone of course, but all was working fine until the CAs started revoking the certificates recently, directly aiding the FSB. From the article:

>The banks first moved to GlobalSign in 2022. This June, GlobalSign began revoking certificates held by sanctioned Russian companies, and they moved on to HARICA, the Greek academic authority.

>A month ago, HARICA refused to revoke: its issuance is self-service and domain-validated, so its certificates identify a domain and nothing else; it was not, it argued, “the competent authority to make these legal attributions.” However, on July 27, Greece’s eIDAS supervisory body appeared to confirm the disputed certificates had been revoked and referred the case to the national financial sanctions unit.


> I certainly hope the EU is studying the problem US-controlled EU-trusted issuers

cough DE-CIX cough CIA cough


Nuclear submarines often operate without any escort. Russian nuclear icebreakers and floating SMRs also do not have heavy military escorts.


> Nuclear submarines often operate without any escort.

Correct. That's where the GPs comment regarding stealth comes into play.


Attempt a hostile takeover and see how long the response takes. It doesn't matter how far away the assets are if they can either make it to your position before you accomplish your goal or else credibly hunt you down after the fact. I don't think "theft of nuclear material from a russian naval icebreaker" is a realistic possibility.


I wonder how much would it cost to build a tunnel as an alternative to the Panama canal to fundamentally resolve the drought issues. 1.8 km is comparable to ~80 km (probably a shorter tunnel will suffice) and dimensions are also similar (at least for the old Panamax).


Looks like the Norway tunnel is through hard gneiss. That rock formed 100s of millions or a billion years ago. https://en.wikipedia.org/wiki/Sveconorwegian_orogeny Norwegians know how to tunnel through it, like https://en.wikipedia.org/wiki/B%C3%B8mlafjord_Tunnel and https://trid.trb.org/view/512421 .

The Panama Canal famously had to deal with a lot of mud, clay, and unstable rock, causing many landslides during and after construction.

The geology of Panama is quite complex and the isthmus is only 4 million or so years old. "The geology of Panama includes the complex tectonic interplay between the Pacific, Cocos and Nazca plates, the Caribbean Plate and the Panama Microplate" - https://en.wikipedia.org/wiki/Geology_of_Panama

Looks like Panama City is working on a monorail tunnel to go under the Panama Canal for Line 3. https://www.herrenknecht.com/en/references/referencesdetail/... mentions the complex geology for the TBM has "Heterogeneous ground; La Boca Formation: Sandstone, siltstone, tuff, mudstone, pyroclastic rocks; Tucue Formation: Basalts and andesits; Panama Formation: Tuff, sandstone, agglomerate".

That's quite of bit of soft and crumbly rock.


Because it is a "public broadcast", so it obviously "Cannot Give In To Government Pressure": https://www.youtube.com/watch?v=B9tzoGFszog


>the USD doesn't have strength and power because oil sales are denominated in dollars. You have it backwards.

Not quite. The "petrodollar" deal has helped to bootstrap and anchor the USD strength at a somewhat critical moment of history after the gold peg was "temporarily" suspended, which was effectively a default of the US government (second in the 20th century!).

Sure, today trade of oil in USD no longer plays a significant role in supporting its dominance, but it still plays a role. Together with other factors (such as increased weaponization of the USD-led financial system) rise of alternative settlement systems corrodes the network effects on which USD relies. Each blow in isolation may be insignificant, but their accumulation could become critical owning to the extreme non-linearity of the network effects.


For tracking of military ships it's much better to use radar imaging satellites (e.g. see [0]). They can cover a larger area, see ships really well, and almost not affected by weather.

I will not be surprised if China has a constellation of such satellites to track US carriers and it's why Pentagon keeps them relatively far from Iran, since it's likely that China confidentially shares targeting information with them.

[0]: https://www.esa.int/Applications/Observing_the_Earth/Coperni...


China has Huanjing [0], which is officially for "environmental monitoring", but almost certainly has enough resolution to track large ships (at least the later versions, apparently the early versions had poor resolution)

And even if they didn't, Russia have Kondor, [1] which is explicitly military, and we know they have been sharing data with Iran.

[0] https://en.wikipedia.org/wiki/Huanjing_(satellite) [1] https://en.wikipedia.org/wiki/Kondor_(satellite)


>it's literally modeled on the density of cone cells in the human retina

It's related to it, but not "literally modeled" on it. This number is from experiments where people are asked to equalize perceived brightness of two lights with different colors. The results are than averaged out and interpolated using polynomials to create a color model [0].

[0]: https://en.wikipedia.org/wiki/Color_model


>The middle for the day, on our time keeping devices, being light outside goes all the way back to the first sundials over 3,000 years ago.

Most of the world is perfectly fine with 12:00 not being synchronized with high noon [0]. And some jurisdictions still semiannually f*k with it further using DST. Generously assuming the current time keeping system will survive for ~6k years (looking at the leap seconds accumulation rate for the last 50 years) we can just shift timezones by one hour.

[0]: https://64.media.tumblr.com/4a9a4613f057d3b5f17ec548e6ac06d1...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: