HNHacker News
TopNewBestAskShowJobs

Asdfbla

963 karma · joined November 9, 2016

Nothing interesting here.
submissionscomments
Asdfbla··on Building for the Blockchain
There's more dimensions to that though. Can participants have identities? If yes, then you don't need proof-of-work, for instance but can have a distributed ledgers with conventional algorithms for Byzantine agreement etc.

Might be just my misinterpretation, but when I hear blockchain I usually just think of conventional totally trustless and identity-less protocols that necessarily require proof-of-work - which is a security level which is not needed for most applications.

Asdfbla··on Beginner's guide to longevity research
Very interesting research, but trying to derive actionable recommendations for humans seems a bit laughable at this point. Still seems tough to become immortal these days. Harvesting young blood, a rigid diet, castration and starving yourself occasionally - lots of effort your self-absorbed wealthy investor with a desire to live forever has to go through.

But then again, Sam Altman recently praised China for having fewer ethical concerns in that regard, so maybe they will get some longitudinal human studies going. The population scale full-genome analyses that are currently underway might also be helpful.

Asdfbla··on CPU Usage Differences After Applying Meltdown Patch at Epic Games
Would be funny to see a game server exploit (since this was about Epic Games here) via specially crafted network packages that look like valid game messages. Has this happened before? Seems natural that those game coordinator backends and such should have security holes too.
Asdfbla··on CPU Usage Differences After Applying Meltdown Patch at Epic Games
I suppose if a Cloud provider could ensure that all your VM instances run on the same host and no other VM is allowed there then the issue would be a bit mitigated.

Although this restriction on how the cloud provider is allowed to schedule your VMs probably would somewhat defeat the point of cloud hosting in the first place.

Out of curiosity, how many VM/container instances usually run on a physical host at any given time (for your typical cloud computing provider)?

Asdfbla··on AMD ships microcode update to disable some branch prediction
A for loop also is an implicit branch, by the way. At least it will be compiled to something with a conditional jump.

So being unsure about how many times you want to do a thing is a no-go too.

Asdfbla··on The mysterious case of the Linux Page Table Isolation patches
Just curious: Even after an attacker goes through all the effort of finding out the physical address of the memory location they want to manipulate, how would someone make sure to get an adjacent memory location to even attempt to execute the Rowhammer attack? And even then, the smallest memory units allocated are basically pages within page frames, right? So if your target memory row is within a physical page frame, does the RowHammer attack even work? (Since there's no adjacent row an attacker has access to then.)
Asdfbla··on How I went from programming to consulting (2012)
The way it reads it sounds reasonable, but ultimately it seems more targeted at aspiring consultants who were already pretty entrepreneurial minded than at the general programmer crowd. Apart from doing things 'right' (proper rates, selling yourself, networking and so on, we've all read that on HN), I think it surely requires a much different mindset towards work than what your average developer might have. I can't imagine getting into the grandstanding mindset (not meant in a negative way) required to sell myself as a consultant really, and I'd also first have to adjust to quantifying everything I do in terms of money.

But definitely good for all the people who can do it and use the corporate structure of the world for their benefit. Pretty cool. I could see myself get the required competence to consult some time in the future (though not yet), but I doubt I'd ever get the character for it.

Asdfbla··on Bitcoin and almost every other cryptocurrency crashed hard today
Is there really much there is to expect though? Bitcoin's value has no real basis one way or another, since all the purported practical uses have fizzled out once the network became incapable of actual commerce due to various factors like transaction fees, price instability, processing delays, etc.

So I guess by now, Bitcoin crashing by 50% is as surprising or unsurprising as Bitcoin growing by 50% instead. So I'm not sure if you could really expect the crash, since that expectation requires understanding the unknown speculation mechanism that currently drives it. Though in the future some analysis in hindsight might tell us how to explain what market psychology is currently influencing the price.

Asdfbla··on Bitcoin price plunges $2,000 in 12 hours as year-end rally fizzles out
I wonder if reporting on Bitcoin's random walk is really newsworthy these days.
Asdfbla··on Ask HN: Any open source code/materials on predicting future crimes based on data?
In any case, you shouldn't neglect the subtle but important sources of bias those pre-crime models can have. Here's an interesting talk about it:

https://www.youtube.com/watch?v=MfThopD7L1Y

Basically, one instance of bias is the fact that many crime-prediction models are trained on police data, which means they will predict crime in places more often targeted by the police anyway. Then the model predictions even amplify that effect, since more training data may be generated from the places now more often policed, etc.

There's lots of resources out there on AI fairness these days. I think everyone who tries stuff like crime prediction should read up on that topic.

Asdfbla··on IOTA: A tangled mess
Making them deflationary is more of a political statement than anything else I think. The crypto-currency crowd has this libertarian streak and of course those people believe that inflation is the devil, used by governments and banks to rob productive businessmen of their hard earned money.
Asdfbla··on Firefox is on a slippery slope
Very strange to see that. Are the managers responsible at Mozilla not aware that a significant part of the appeal of Firefox is user autonomy and privacy? No reason to gamble away your reputation by violating user trust like that.

I understand they need money to develop a browser, but surely there must be better ways to promote partnerships. I personally probably wouldn't have a problem with Firefox asking me to opt-in to ads and promotions in the new tab page at first startup to support Firefox, for instance.

Asdfbla··on MobileCoin: A New Cryptocurrency from Moxie Marlinspike
Seems unnecessarily adversarial of you. I think Moxie has justified his standpoint relatively convincingly, even if you may not agree with it.

And to some degree, the success of Signal, or Signal's protocol as implemented widely used services in WhatsApp, supports his approach. If cypherpunk-purists had their way, encryption would still only be a thing exclusively used by a slim minority of nerds who are capable of managing PGP and all the complications that come with its fragile nature.

Asdfbla··on MobileCoin: A New Cryptocurrency from Moxie Marlinspike
While yet another cryptocurrency doesn't sound so good, I think Moxie has at least proven himself enough with Signal (in terms of being pragmatic about usability while trying to get the maximum amount of security and privacy for users) that this sounds promising.

I'm also happy to see a currency with Byzantine agreement without proof-of-work being explored. While this may not satisfy the extreme threat model of Bitcoin etc., I'm not really convinced that this is even needed at all. (Not to mention that Bitcoin has failed as a currency anyway.)

Asdfbla··on MobileCoin: A New Cryptocurrency from Moxie Marlinspike
I still think it's an interesting approach. If you want to be more efficient and less wasteful than Bitcoin, at some point trust has to come into play. And reducing your trust to the manufacturers of secure enclaves (whose products can also be audited to a degree) is surely an improvement still, even if it doesn't have the radical threat model of conventional cryptocurrencies (which inevitably run into scaling problems because it mostly requires proof-of-work).

Also, the article mentions the de facto centralization of trust in the current cryptocurrency ecosystem - so pragmatically, it's not much better there. From centralized exchanges, to centralized mining cartels, what does something like Bitcoin have left to offer?

Asdfbla··on The Mirai Botnet Was Part of a College Student Minecraft Scheme
If IoT botnets become more prevalent (and it doesn't seem like IoT makers have incentives to make their devices more secure), I wonder if ISPs will just start monitoring the traffic patterns of their customers for possible DDoS activity and possibly throttle or cut off their internet connection to stop the attack at its source. Probably would even be compatible with most net neutrality regulations around the world, since it's a security issue.

You could probably hide DoS traffic from a single device by making it very low volume, but if the ISPs coordinate, they still know that the device recently sent packets to a victim of a DDoS attack, making it suspicious.

Asdfbla··on Ask HN: Why don't websites show password requirements at the login screen?
I'm curious how far practical implementations of the NIST guidelines take the advice to preempt dictionary attacks by not letting users choose known bad choices. Of course the advice is perfectly reasonable, but when a user can't choose 'password', they will probably try 'password1' - not really much safer against the usual password cracking software, do you check that too then? But I guess the article mentions that dilemma too. I guess it's again a tradeoff between not annoying the user and annoying the password cracker sufficiently. :)
Asdfbla··on The Case for Learned Index Structures
Sounds like an interesting approach, but just that I understand the scope or impact of the paper right: Surely data-aware indexing can't be the novel part, right? Or was it always so complicated to model the data distribution that no one managed to do it until now? It seems natural to try to adapt your index to the type of data you see more often than not.

Very cool idea though.

Asdfbla··on Bitcoin Futures Start with a Bang as Rally Trips Circuit Breaker
At least traditional modern financial instruments still have some connection to an underlying real-world market, even if they are 10 layers of financial abstraction removed from reality. They can also always sort of justify it by saying that it provides liquidity and so on.

Harder to justify what the point of Bitcoin financial instruments is though, since it can't really be used for much at all in its current state. Maybe if it stabilized and became a proper store of value (whether the incentives to keep a cryptocurrency stable are even there remains another question), but now it's just so hype driven.

I guess ultimately 'the point' of it all it doesn't matter, people can trade in imaginary goods no problem. Still exposes the strangeness of modern financial markets.

Asdfbla··on A beginner’s guide to getting started in the cryptocurrency world
Yeah, if you are interested in the technical aspects of cryptocurrencies it can be really frustrating because there's so much bullshit and unsubstantiated hype out there. It's as hyped as deep learning, but I guess at least there the field is not as politicized by economics and therefore a bit less prone to the evangelist type of person (similar amount of marketing going on though).

Maybe it's best to ignore anything in medium blog form or similar that wants to explain the blockchain to you. Fortunately, the field is mature enough that there are learning resources by people who know what they are doing out now (for instance the Bitcoin technology book by Arvind Narayanan and others seems pretty good).

Asdfbla··on Decentralized Web Primer
Pretty sure it used to be that you have to deliberately pin content that you want to share on your node. Else nodes that accessed it will throw it out of their cache if they don't need it anymore.

Maybe they changed the behavior in the meantime though, but IPFS didn't permanently replicate uploaded content in the past without some deliberate user action.

Asdfbla··on Decentralized Web Primer
I think by default IPFS also doesn't even replicate content. So you don't even have to block hash lookups in the whole network but just take down the one host that currently has the only replica.
Asdfbla··on Bitcoin: A Peer-to-Peer Electronic Cash System (2008) [pdf]
Not that creating Bitcoin wasn't an achievement, but it built upon heaps of existing systems that explored proof of work, distributed ledgers and so on.

The main innovation was the combination of ledgers with proof of work to prevent Sybil attacks in the face of a system with unidentified participants.

Asdfbla··on Bitcoin mining and energy consumption
Trust and security, maybe, but actual utility? That's far from clear. Cryptocurrencies have a rather extreme threat model and it's not clear at all that people who are not regime critics or criminals (I don't mean to disparage suppressed people here by lumping them in with criminals though) really benefit from that model.

Most people are quite happy with trust-based currencies which don't have the proof of work overhead. Cryptocurrencies have their utility, but not for the whole population.

Asdfbla··on Why Are Data Science Leaders Running for the Exit?
You're right of course, but still there is a point: For 1 'intellectually' interesting data science job created there's probably 10 that have more to do with data massaging and all the relatively boring logistical stuff that come with data science.

Doesn't invalidate your point, but the majority of jobs under the very broad 'data science' label just aren't super interesting after all. Guess you just have to be careful to examine exactly what a specific 'data science' position entails.

Asdfbla··on The Trouble with Politicians Sharing Passwords
Is deniability really good for public offices? Politicians surely need some degree confidentiality on certain documents and communications, but they also need be held accountable for their actions (while in office).
Asdfbla··on Most popular Python packages now support Python 3
Was it just the time that the ecosystem needed to adapt to the Python 3 changes or were there essential changes in the 3.x versions up to 3.6 that made it easier to switch from Python 2?
Asdfbla··on NoScript Not Available for Latest Firefox
While I can understand that the switch to the new system was necessary, I hope they improve the new extension functionality a bit further.

One negative thing that I noticed that extensions don't seem to be able to interact with the tabs before those have largely (or completely?) loaded - for instance I can't use mouse gestures in a tab that's currently loading or interact with the vimperator replacement (Vim Vixen). Is that inherent to the new system with the extension system having lower priority than the page rendering or is it just those specific extensions I use?

Another thing that would be nice to fix is extensions (at least those that I have tested) seemingly not working in Firefox-internal pages like about:addons.

Asdfbla··on Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them
Seems plausible, though regardless of whether Kaspersky cooperates (maybe under some gag order) with Russian agencies or not, it seems prudent for any government in the world to avoid using software that potentially uploads confidential data to foreign servers. Governments anywhere would probably be ill-advised to use anti-virus software from countries like the US or Russia, unless they can be sure that cloud analysis is either disabled or done in local datacenters.

I guess on the bright side at least the anti-virus market has a variety of firms based in many different countries, so you can choose your poison based on how trustworthy you find the respective governments. Doesn't help you when they themselves get hacked though.

As for the story itself, I kinda dislike the reliance on access journalism and "unnamed" sources in many of the reports. Yes, there surely are many legitimate reasons why sources have to remain anonymous, no doubt about that. But in a case that's so highly political it kinda leaves a bad taste if the story is so dependent on unnamed government sources.

Asdfbla··on Schneier: It's Time to Regulate IoT to Improve Cyber-Security
You're right that they should be liable, but pragmatically it's maybe too much of a risk for smaller companies to face some potentially frivolous lawsuit for millions of damages supposedly caused by a ddos originating from some of their devices or something.

Surely the right idea in principle, though. I'm just not sure how realistic is it to implement in a smart manner.

← PreviousPage 3 of 7Next →