HNHacker News
TopNewBestAskShowJobs

CyberShadow

2,126 karma · joined June 21, 2009

I am Vladimir Panteleev, a D hacker from Moldova, Eastern Europe.

https://github.com/CyberShadow

[ my public key: https://keybase.io/cybershadow; my proof: https://keybase.io/cybershadow/sigs/iQOqJAZGCVN0DykK2PLwcTGU247dIo3aZnm6s6VOgjk ]

submissionscomments
CyberShadow··on Who keeps an eye on clipboard access?
Currently writing a clipboard manager[1], I've seen some things as well.

- So far ran into two applications which don't even implement the X11 clipboard specification (ICCCM section 2) correctly - xsel and Emacs (patches submitted).

- By far the worst offense I've seen in clipboard privacy on the Linux desktop is RedHat's virt-manager. It sends your clipboard AND selection content to all virtual machines, even when they are not focused, with no indication that it's happening, and with no GUI option to turn it off. This is at odds with the common practice of running untrusted code in virtual machines.

- X11 being network-transparent makes its protocol fairly malleable, so it's not difficult to bolt some privacy on top. hax11[2] has an option to restrict access to the primary selection for configured applications (though, for truly malicious applications, you may find X11's security model generally lacking).

[1]: https://news.ycombinator.com/item?id=29808487 [2]: https://github.com/CyberShadow/hax11

CyberShadow··on Show HN: I made a little digital circuit simulator that operates on PNGs
Very nice!

FWIW, I can't figure what to do on the "ride the line" level. I don't understand what the motors do exactly (powering both motors simultaneously makes the car go sideways) and what the sensors are sensing.

CyberShadow··on Fifth Browser
DKIM provides integrity, which is what is important here.
CyberShadow··on Fifth Browser
> SSL certificates handled in a SSH-like manner

> CAs are ignored, the only thing that matters is that the cert does not change. With today's rogue CAs and governments, this policy is better suited for detecting man-in-the-middle attacks than a browser blindly trusting a CA.

I'm not sure this is a good idea. SSH best practice is that you acquire the server's key fingerprints via a previous secure channel. E.g., Hetzner will email them to you when they set up your server.

CyberShadow··on Xorg update adds touchpad gestures and variable refresh support (2021)
Have you heard about GNOME's Client-Side Decorations Initiative? The gist is that GNOME does not want to implement/maintain window decorations (title bars, minimize/maximize buttons) in their Wayland compositor, so instead (in typical GNOME fashion) they want every other Linux desktop app to add code to draw decorations themselves (in whichever style they want).

https://wiki.gnome.org/Initiatives/CSD

CyberShadow··on Xorg update adds touchpad gestures and variable refresh support (2021)
It's worse than that. Window managers simply cannot exist in Wayland, because the compositor is the only actor which can also do window management.

This coupling is one of the biggest design faults of Wayland. The platform-specific functionality is no longer encapsulated in a stand-alone piece of software - the compositor now must do everything, because Wayland trusts only it to do anything privileged. This leads to less choice and more restrictions. If you wanted to get X11 running on e.g. your phone, you would get the Xorg server Android app, then run the window manager you want, then run the applications you want. This is not possible in Wayland: there would need to be one per-platform app per compositor / window manager, so you would need e.g. Weston for Linux, Weston for Android, Weston for iOS, sway for Linux, sway for Android, sway for iOS, ...

CyberShadow··on Xorg update adds touchpad gestures and variable refresh support (2021)
I think a big part of Wayland's limitations is in its protocol, and are "by design". Getting Wayland to have feature-parity with X would require extending the protocol, and then implementing those extensions in both compositors and clients. Because major Wayland compositor projects are unlikely to want to adopt or maintain such extensions, getting client applications to support them would also be a tough sell.
CyberShadow··on Xorg update adds touchpad gestures and variable refresh support (2021)
Here is the author's Patreon: https://www.patreon.com/p12tic
CyberShadow··on Midnight Commander Tips and Tricks
> re: extensibility -- mc does have scripting [1] (although not sure if you meant something else)

Scripting in the sense that the application exposes an API that scripts can interact with to query data or perform actions, usually to an equivalent capacity as to what the user could do themselves.

In the case of Far Manager, the Lua scripting API exposes the same API as for plugins, which allows complex integrations such as implementing custom UIs and VFSs.

> re: image viewer -- hmm how would that work considering mc is running in terminal? I guess it could interact with some sort of modal window for file previews or something like that.

Well, there's a whole bunch of methods. Many terminals support at least one protocol for drawing bitmaps, such as Sixel; ranger uses the simple method of overlaying an X11 window on top of the terminal emulator's.

CyberShadow··on Midnight Commander Tips and Tricks
Things I wish mc had:

- Extensibility (e.g. Far Manager has macros, plugins, and scripting; mc has none)

- Better file system navigation (pressing Ctrl+S every time to start isearch when entering a directory is cumbersome)

- Better history (no search; the history file is clobbered on exit, overwriting other instances' history)

- Generally better ergonomics that don't rely so much on the hard-to-reach F-keys

- Things like built-in image viewer that are present in modern file managers are absent in mc

- Development velocity seems to be rather low; not sure why, perhaps because it adopted GitHub only relatively recently.

mc features that I wish other file managers had:

- Stable (no crashes)

- Packaged in all major distributions, so can be installed and used anywhere

- Fairly good performance (asynchronous listdir/stat would make this even better)

- VFS for archives and remote hosts (FUSE/sshfs can be flaky)

- File management features which are standard for Norton clones (but not for many new file managers like ranger), such as searching in files (and operating on the results)

- Runs in a terminal, so can be used via SSH

CyberShadow··on Midnight Commander Tips and Tricks
I remember this holy war. :)

I think Far Manager wins in extensibility and being FOSS, and Windows/Total Commander wins in out-of-the-box utility.

CyberShadow··on Midnight Commander Tips and Tricks
Any suggestions for good performance and extensibility? I've tried a few but kept coming back to Midnight Commander for performance/stability and VFS support.
CyberShadow··on Black, the uncompromising Python code formatter, is stable
To reiterate, the example is trivialized; there isn't always an elegant solution that you just can't see because you didn't think hard enough.

Regarding the hard line width, "fit everything on the screen" is a poor goal to aim for; a more useful goal is to make the best use of the two dimensions you have at your disposal. Squishing things across either axis will make for a poorer experience than occasionally requiring some scrolling for some setups.

You may also find it interesting that Prettier does not interpret it as a hard limit as well: https://prettier.io/docs/en/options.html#print-width

CyberShadow··on Black, the uncompromising Python code formatter, is stable
Unfortunately Black will reformat code which has only been indented/outdented, causing false diffs even with "ignore whitespace changes".
CyberShadow··on Black, the uncompromising Python code formatter, is stable
One missed opportunity in Black's algorithm is that it currently treats the maximum line length as a literal hard limitation in number of characters. Here is a trivialized example:

    to_add = [item for item in data.new_items if item not in data.old_items]
    to_remove = [
        item for item in data.old_items if item not in data.new_items
    ]
Although the constructs are nearly structurally identical, they can be formatted very differently, which sometimes hinders understanding them.

A different approach would be to instead normalize all words to a certain fixed width. So, "to_add" and "to_remove" would have the same virtual width.

A related issue is that leading indentation counts towards the width limit. This causes refactorings which simply move code around (changing its indentation level) to change the code's shape, even when the code hasn't otherwise changed. This is exacerbated by that one often needs to mold code in such a way that Black formats it in an agreeable way, but this is generally not done during refactorings, so the readability of the code suffers.

I had the opportunity to write a formatter (for SQL, also unconfigurable/opinionated); it seems to successfully avoid these problems: https://github.com/CyberShadow/squelch

CyberShadow··on Aconfmgr: A configuration manager for Arch Linux
A more successful submission might be a blog article describing using aconfmgr in practice.
CyberShadow··on The Curse of NixOS
> Previously I used Arch, which I loved, but it was all to easy to completely shaft my setup and not be able to roll back.

Here is my attempt at solving this problem: https://github.com/CyberShadow/aconfmgr

CyberShadow··on Lst.sh – Portable Shell Array Library
ShellCheck agrees:

https://github.com/koalaman/shellcheck/wiki/SC3003

CyberShadow··on Lst.sh – Portable Shell Array Library
Another issue with the "Once Upon a Time" style is that it's impossible to distinguish an empty list from a list containing a single, zero-length element.
CyberShadow··on Geometry from Another Universe
Specifically, the video about spherical geometry: https://www.youtube.com/watch?v=yY9GAyJtuJ0
CyberShadow··on Tell HN: Reddit was showing “Blocked” when accessed with Firefox
If you saw the word "Blocked", then it did render it.
CyberShadow··on Tell HN: Reddit was showing “Blocked” when accessed with Firefox
No, that just means that there is no encoding sent in the header (or HTML http-equiv tag).

Anyway, it's back up for me.

CyberShadow··on Adversarial Wordle
Less common words which the adversary will never choose, but will accept from you. Also, the author is https://news.ycombinator.com/user?id=qntm.
CyberShadow··on Adversarial Wordle
With a greedy solver (minimize word pool for the next step), I got ARISE (168) -> BLUDY (13) -> COMET (2) -> NAVAL (1) -> CHUNK.

I think five steps is as good as it gets, as 5*5 is about the size of the alphabet.

Edit: I stand corrected. YEARN (216) -> FLOUT (12) -> CHAMP (1) -> HUMPH.

CyberShadow··on A curated list of warez and piracy links
Word of warning - I noticed that frequently enough, antivirus alerts from pirated software were true positives. Repackaging warez with a malicious payload and then using a botnet to boost its seed count and place it at the top of listings was apparently lucrative, and I've had to deal with one instance of a user's account and website compromised due to what was most likely an infected keygen.
CyberShadow··on The weight of the clipboard
I don't think a sync plugin would work. Entire parts of CopyQ's architecture would need to be redesigned, which would affect the rest of its ecosystem.

You can read the issue I filed in CopyQ's repository back when I switched to Linux and had to stop using Ditto for the justifications of infinite history: https://github.com/hluk/CopyQ/issues/510

CopyQ is also bound to use Qt's clipboard implementation, which provides the common subset of Qt's supported platforms, with all the consequent limitations. See the other issues I filed for details.

CyberShadow··on The weight of the clipboard
Yes, I'm already using SQLite! It's great. Ditto uses it too.

To make SQLite zero-out deleted pages, issue "PRAGMA secure_delete = on".

CyberShadow··on The weight of the clipboard
I don't have Microsoft Word, but most applications allow pasting just text using the shortcut Ctrl+Shift+V.

Edit: I see Microsoft Word doesn't natively have that shortcut, but there are two ways to "implement" it here: https://superuser.com/questions/988527/how-can-i-use-ctrl-sh...

Removing rich text formats is a good idea for a clipboard manager feature/plugin, though.

CyberShadow··on The weight of the clipboard
From a security perspective, I don't think it's possible to do with the standard OS APIs.

When an application makes data available in the clipboard, it's a free-for-all for every other application. The clipboard manager would have to race other applications to make a copy of the data, and then empty the OS clipboard.

APIs also may not allow making decisions based on which application requested the clipboard. It's possible to do in X11, but not Windows.

This goal could be achievable by intercepting the OS clipboard API. On X11, this can be done by MITM-ing the connection to the X server - https://github.com/CyberShadow/hax11 does this, and already has one clipboard-related security feature (disabling the selection mechanism). On Windows, the best bet is probably global DLL injection and API hooks, but applications can "opt out" by running as a different user or requesting a higher integrity level.

CyberShadow··on The weight of the clipboard
I'm using CopyQ (and SyncThing) right now. Its design limits the number of entries, and sync doesn't work very well.
← PreviousPage 3 of 15Next →