HNHacker News
TopNewBestAskShowJobs

CapacitorSet

1,489 karma · joined July 27, 2016

[ my public key: https://keybase.io/capacitorset; my proof: https://keybase.io/capacitorset/sigs/3XQYiFYsETBVes6mFixMECaVoMYCJBjVFgwf6JikpeY ]
submissionscomments
CapacitorSet··on What Challenges and Trade-Offs Do Optimising Compilers Face?
I don't know about the other languages, but at least with regards to ECMAScript the specification can be accessed freely at https://www.ecma-international.org/ecma-262/7.0/index.html - though the License chapter says that "after approval all rights on the standard are reserved by Ecma International."
CapacitorSet··on Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
>How can the consumer stop someone from exploiting this hack?

[Remove Intel ME](https://github.com/corna/me_cleaner) to the largest extent possible. I don't know of equivalent tools for AMD, though, which also has similar systems in place.

CapacitorSet··on List of Printers Which Do or Do Not Display Tracking Dots
For vector graphics, I suppose you could encode information in the least-significant bits (with redundancy, error correction and whatnot) if the printer can guarantee sufficiently high precision (not accuracy, mind you: https://www.tutelman.com/golf/measure/precision.php)
CapacitorSet··on Revolution Pi – Industrial PC Based on Raspberry Pi
How industrial are we talking? Is it certified for use in industrial environments? I saw a few mentions of IEC61131-2, but I couldn't find whether it actually has certifications.

If it is suitable for use in the industry, I can't wait to ditch ladder and Structured Text in favour of modern programming languages for industrial controllers.

CapacitorSet··on Fathom: a framework for understanding web pages
>If readability is important start penalizing sites with bad readability indexes.

That's relatively easy to do when you're Google and you develop both a browser and the most used search engine; not so much when you're Mozilla and have no apparent mean to apply pressure to websites.

CapacitorSet··on Leak Suggests NSA Was Deep in Middle East Banking System
What's so special about American citizens that makes you think they are not to be spied by NSA? Why is it that eg. Europeans can be spied at will, but it takes a mandate to spy an American citizen?
CapacitorSet··on Golang SSH Security
If you want to study the background noise, I think you would have better luck reacting to it - as well as running tcpdump, set up a trivial HTTP and SSH server and observe the interactions.
CapacitorSet··on Fourier transform – A math tool used in optics, MP3s, JPEGs and more (2013)
I think it's because they're meant to explain Fourier transforms to people who aren't familiar with transforms, and therefore are much more comfortable with Fourier coefficients rather than an actual transform in the frequency domain.
CapacitorSet··on Making Ubuntu run faster by killing Evolution
Clickbait title, it should be something like "Making Ubuntu run faster by killing Evolution".
CapacitorSet··on What CSS minifiers also leave behind
I partly agree. Though removing one or two bytes more than another minifier doesn't really matter that much, what matters is being able to deduplicate CSS as well as doing the usual whitespace elimination. SASS and SCSS seem to have a bit of a problem with duplicated CSS.
CapacitorSet··on How we exploited a code execution vulnerability in math.js
Did you also write the gnuplot plugin? Because that's also vulnerable, as found by the same @denysvitali: https://github.com/LucentW/s-uzzbot/issues/9
CapacitorSet··on How we exploited a code execution vulnerability in math.js
This is what the author attempted to do: if you read the first commit linked in the article, they made it so that math.js wouldn't execute Function when it encountered it (either an actual Function or a variable that equals Function).

However, the trick is to make Javascript execute Function, through a function that math.js won't mind executing. What I found was simply using Function.apply and Function.call; the author found Function.bind, and someone in this thread found several more.

CapacitorSet··on How we exploited a code execution vulnerability in math.js
Whoops, thank you - it went unnoticed because I didn't proofread the noscript version as much as the default one. I pushed an edit.
CapacitorSet··on How we exploited a code execution vulnerability in math.js
Oh well, that would have been so much easier. Thank you!
CapacitorSet··on How we exploited a code execution vulnerability in math.js
This was actually the second fix I had in mind, after the author mentioned that they would like mathjs to have complete browser support (and therefore couldn't use the `vm` module from Node.js):

>If, anyway, you want to make math.eval resistant against arbitrary code execution, I think it would be best to have a whitelist of methods and constructs (i.e. you parse the code that is meant to be evaluated and ensure that every construct is allowed). I analyze JS malware in my free time (see [box-js](https://github.com/CapacitorSet/box-js)), and I found that it is virtually impossible to blacklist functions. For instance, if the parser forbids `[].map.constructor`, I could very well use `[].map["constructor"]`; and if you blacklist the word "constructor", I could use `[].map["rotcurtsnoc".split("").reverse().join("")]`, and so on, there's an infinity of methods one can come up with to avoid blacklists.

The examples didn't really work in math.js, but it turns out that there's still [quite a few ways to get around it](https://github.com/josdejong/mathjs/issues/821).

CapacitorSet··on Lua VM running in a WASM environment
Lua in the browser? Truly, we live in the future.
CapacitorSet··on Principles for C programming
>Do not use macros. Do not use a typedef to hide a pointer or avoid writing “struct”. Avoid writing complex abstractions. Keep your build system simple and transparent. Don’t use stupid hacky crap just because it’s a cool way of solving the problem.

Heh, good luck avoiding the use of macros in sufficiently complex projects - sometimes C just can't use some control structures in an elegant manner without using macros or custom abstractions.

CapacitorSet··on What the CIA WikiLeaks Dump Tells Us: Encryption Works
I remember reading a poll where European Parliament members claimed that encryption (esp. HTTPS and E2E) was the biggest obstacle to espionage. I'm glad to see that this is a widespread sentiment.
CapacitorSet··on Musk Bets He Can Fix Aussie Power Woes in 100 Days or It’s Free
It's free PR for Elon Musk, no wonder it's - well - public.
CapacitorSet··on Reducing Slack’s memory footprint
I think Slack is focusing on code reuse, eg. using the same HTML/CSS/JS codebase across all platforms - hence it would be preferrable to avoid having to compile for every platform.
CapacitorSet··on BlueCoat and other proxies hang up during TLS 1.3
It is really sad that one reason why QUIC encrypts protocol states is to prevent excessively eager middleboxes from meddling with the traffic.
CapacitorSet··on What happened to clockless computer chips?
They can certainly improve performance, in that eg. a NOP instruction will "lock" the processor for much shorter than eg. a JZ; the main concern at this time is that we lack the research, expertise and instruments to deal with asynchronous CPUs.
CapacitorSet··on Microsoft’s AI has learnt how to write its own code and create its own programs
This looks like an overview for laymen. Is there a more technical and detailed report?
CapacitorSet··on The “high-level CPU” challenge (2008)
This is a good time to mention asynchronous architectures: https://en.wikipedia.org/wiki/Asynchronous_circuit#Asynchron...

Intel itself [claimed](http://stackoverflow.com/a/530494) that the async CPU performs better than the sync one, but they didn't pursue the project further for lack of large-scale profitability.

CapacitorSet··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
>Cloudflare pointed out their bug bounty program, but I noticed it has a top-tier reward of a t-shirt.

Considering the amount and sensitivity of the data they handle, I'm not sure a t-shirt is an appropriate top-tier reward.

CapacitorSet··on DDoSCoin: Cryptocurrency with a Malicious Proof-Of-Work [pdf]
A bit like Torcoin, basically.
CapacitorSet··on DDoSCoin: Cryptocurrency with a Malicious Proof-Of-Work [pdf]
I can't think of more defences, but they briefly mention the possibility for websites to mine DDoS coins against themselves and I think it's an interesting perspective. I don't know the algorithms involved in the key exchange well enough, but if they support bulk optimizations like RSA does (it's faster to do thousands of signatures in a single operation, rather than one operation at a time) then the server has a noticeable advantage on clients - to the point where it could drive the difficulty insanely high and make it unprofitable to mine DDoS coins.
CapacitorSet··on DDoSCoin: Cryptocurrency with a Malicious Proof-Of-Work [pdf]
Tldr on page 4:

* The miner generates a random nonce

* It initiates a TLS 1.2 connection to the victim server, and uses the nonce as `client_random`

* The server generates an ephemeral public key (eg. using ephemeral DH or ephemeral ECDH), and responds with a 32-byte `server_random`

* The server sends its certificate chain as well as its public key, and signs the DH key exchange parameters along with `client-random` and `server-random`. This is the proof of work

* The client computes the SHA256 hash of the DH params, the signature and the nonce, and does the usual difficulty check; if it passes, it is used to make a block

CapacitorSet··on How to Set Up an OpAmp Circuit to Do Complex Mathematics
That sounds _extremely_ interesting for people who are into control theory! Do you happen to have schematics?
CapacitorSet··on Russians Engineer a Slot Machine Cheat that Casinos Can't Fix
That's the technique Linux uses, it feeds keyboard and mouse timing events into one of its entropy pools. I can't see why they wouldn't do this for slot machines.
← PreviousPage 8 of 9Next →