HNHacker News
TopNewBestAskShowJobs

Deathmax

500 karma · joined August 10, 2012

submissionscomments
Deathmax··on Gemini 1.5 outshines GPT-4-Turbo-128K on long code prompts, HVM author
This depends on which service you are using, any of the free products allow for training, but the paid services do not.

Allows training on input:

1. Gemini (formerly Bard): https://gemini.google.com/. Policy: https://support.google.com/gemini/answer/13594961. Can opt out of training by disabling history.

2. AI Studio free plan: https://ai.google.dev/.

Does not allow training on input:

1. AI Studio paid plan: https://ai.google.dev/.

2. Google Cloud Vertex AI: https://cloud.google.com/vertex-ai. Policy: https://cloud.google.com/vertex-ai/docs/generative-ai/data-g...

3. Gemini for Workspace (formerly Duet AI for Workspace).

Deathmax··on Statement regarding the ongoing Sourcehut outage
To expand on that, Cloudflare's standard product is their HTTP reverse proxy. To proxy arbitrary TCP/UDP traffic, you need to use their Cloudflare Spectrum service (https://www.cloudflare.com/en-gb/application-services/produc...), which is metered.
Deathmax··on The curious case of the Raspberry Pi in the network closet (2019)
Data is crowdsourced and contributed by users. On a much larger scale, Apple and Google collect data from iOS and Android devices to power their WiFi/mobile tower based geolocation services.

Android's Location Services: https://support.google.com/android/answer/3467281#location_a...

iOS's Location Services: https://support.apple.com/en-gb/102515

In fact, Google provides it as a paid API: https://developers.google.com/maps/documentation/geolocation..., but you require BSSID's and not just SSID names to try to curb abuse.

Deathmax··on I forked SteamOS for my living room PC
Battleye has integrations with Proton as well, but as with EAC, it's opt in by the developer, and not every dev enables it.
Deathmax··on Reddit’s plan to kill third-party apps sparks widespread protests
> Okta for example charges $2 just for sign in: https://www.okta.com/pricing/

You're looking at the wrong product, $2/user/month is for their Workforce Identity Cloud, so auth for employees, not end users.

For a comparable market segment, Auth0 (acquired by Okta) which serves the B2C market charges significantly less [1]. Taking the B2C Professional plan at 1000 MAU which has the highest pricing per user due to lack of volume discounts costs $240/month for 1000 users ($0.24/user/month). Scaling up to the limit of publicly available pricing, at 10000 users Auth0 will only charge $0.15/user/month.

[1]: https://auth0.com/pricing

Deathmax··on Ask HN: How does archive.is bypass paywalls?
For WSJ at least, it appears that archive.is is fetching the AMP page, which returns the full content of the article and is hidden with CSS, and modifying the page to unhide the paywalled content + hide ads.

It might be using other techniques as well for bypassing paywalls, be it referer/user-agent spoofing (some old archives of sites that echo back HTTP request headers have archive.is sending a Referer of google.co.uk).

Deathmax··on Tunnel via Cloudflare to any TCP service
You might not be on a "Always Free" account then. AFAIK, you're not subject to reclamation if you add a payment method to the account.

Here's the link to their documentation on reclamation of idle resources: https://docs.oracle.com/en-us/iaas/Content/FreeTier/freetier...

> Idle Always Free compute instances may be reclaimed by Oracle. Oracle will deem virtual machine and bare metal compute instances as idle if, during a 7-day period, the following are true:

> * CPU utilization for the 95th percentile is less than 15%

> * Network utilization is less than 15%

> * Memory utilization is less than 15% (applies to A1 shapes only)

And here's the email that I get whenever they reclaim an instance:

> Oracle Cloud Infrastructure (OCI) has reclaimed idle Always Free compute resources from Always Free customers by stopping the compute instance(s). Reclaiming idle resources allows OCI to efficiently provide services to Always Free customers. Your account had one or more idle compute instances that have been stopped. You can restart your compute instance as long as the associated compute shape is available in your region. Your Boot and Block Volumes remain unchanged and available to you. In the future, you can keep idle compute instances from being stopped by converting your account to Pay As You Go (PAYG). With PAYG, you will not be charged as long as your usage for all OCI resources remains within the Always Free limits.

Deathmax··on The UK’s Secretive Web Surveillance Program Is Ramping Up
From what I understand, checking that a certificate has been submitted to CT logs should not have privacy implications, only trust in a set of CT logs and their public keys to be able to verify Signed Certificate Timestamps (SCTs). SCTs can be distributed in one of 3 ways:

1. Embedded in the certificate itself - no communication with a third-party

2. Distributed via TLS extension - no communication with a third-party

3. OCSP stapling - the server is the party that initiates a connection with the CA, the client doesn't touch the CA

You only need the complete set of CT logs if you want to verify the logs have not been tampered with.

Deathmax··on The UK’s Secretive Web Surveillance Program Is Ramping Up
> In my opinion, most of the governments must have obtained access to numerous Certificate Authority private keys by now. As a result, they would not only be logging DNS records but also the entire unencrypted data transfer.

Certificate Transparency ensures that having control over a Certificate Authority's private keys doesn't allow for undetectable MITM attacks since both Chrome [1] and Apple (Safari) [2] will not trust certificates that have not been submitted to CT logs and stamped as such. If a government attempts to issue a trusted certificate using a CA they control, it will be logged. You can't passively decrypt TLS connections with just access to a CA's private keys since those aren't the keys involved in communication, or even the server's private key due to forward secrecy (assuming modern TLS configs).

[1]: https://groups.google.com/a/chromium.org/g/ct-policy/c/wHILi...

[2]: https://support.apple.com/en-gb/HT205280

Deathmax··on Google promised to delete sensitive data. It logged my abortion clinic visit
> I searched for a couple hours last week and couldn't find a single way to submit a CCPA request to Google.

1. Navigate to google.com

2. Click on Privacy on the bottom of the page, redirecting to https://www.google.com/intl/en/policies/privacy/ > https://policies.google.com/privacy

3. Go to the "U.S. state law requirements" section, click on the "contact Google" link which redirects to https://support.google.com/policies/answer/9581826

4. Go to "Your privacy & security controls" > "Get help with privacy-related questions" > "Contact Google's Data Protection Office", and you get a link to their web form at https://support.google.com/policies/contact/general_privacy_....

The privacy policy can differ from country to country, I had to proxy into the US to get the section on US state law requirements, otherwise from the UK it's replaced with a European requirements section instead.

> CCPA requires data brokers and large tech companies to maintain at least two channels

My interpretation of the CCPA is such that a business that operates exclusively online only needs to provide an email address and the two or more designated methods does not apply.

Deathmax··on We need better support for SSH host certificates
GitHub does have support for SSH CAs, but it's an Enterprise feature: https://docs.github.com/en/enterprise-cloud@latest/organizat...
Deathmax··on The 5GHz “Problem” for Wi-Fi Networks: DFS (2018)
In the UK Ofcom recently (2020) relaxed the rules on Band C channels (channel 140+) to allow for indoor non-licensed use. These have been a godsend in a crowded environment, as the lower non-DFS channels are very crowded, while the DFS channels are, well, DFS.

https://draytek.co.uk/information/blog/ofcom-relax-the-rules...

Deathmax··on MagSpoof: Wireless Magstrip Spoofer
> As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not.

This is very much untrue. If a merchant initiates the 3DS flow, liability for fraudulent transactions shifts from the merchant onto the issuer. Here's documentation from Stripe[1] on the matrix of possible flows and the resulting liability shift, and docs from Adyen[2] on card networks that support liability shifting with 3DS.

[1]: https://support.stripe.com/questions/liability-shift-post-sc...

[2]: https://www.adyen.help/hc/en-us/articles/5091186681500-What-...

Deathmax··on Incident report: Employee and customer account compromise
The actual TOTP secrets are (or should be) encrypted with the backup password that the user chose, so access to the backups wouldn't automatically result in compromised TOTP secrets unless the backup password was weak.
Deathmax··on Researchers discover major roadblock in alleviating network congestion
I'm guessing it's http://people.csail.mit.edu/venkatar/cc-starvation.pdf
Deathmax··on UK telecom EE blocks archive.org
EE's Content Lock is enabled by default, and is called out in the article itself. To opt out of Content Lock, you must undergo age verification, either via ID checks in person at the store, or via a credit card.

Please note: All new and existing accounts with Content Lock enabled have the "Moderate" setting applied by default. [1]

[1]: https://myaccount.ee.co.uk/app/anonymous-content-lock

Deathmax··on Fastmail is having problems again
You would want to host the status page on completely independent infra, such that if your service goes down, it doesn't take down the status page as well. This includes DNS, hence the separate domain.

For example, with Facebook's recent outage, because they hosted their status page on the same DNS server as their regular service, they weren't able to communicate the outage on their status page.

Deathmax··on Google Pixel 6 and Pixel 6 Pro
Which would justify Apple using on-device scanning more if iCloud is end-to-end encrypted, except that it isn't. Apple has the technical capability to decrypt photos stored on iCloud, so why risk the slippery slope and governments applying pressure to expand local scanning to more than just what is going to be uploaded.
Deathmax··on Twitch is hacked, and its source code leaked
Salts being exposed is not a massive risk in of itself, as the purpose of the salt is to prevent the use of pre-computed tables to reverse a hash into plaintext, forcing an attacker to bruteforce each individual hash+salt instead of being able to reuse work.

With regards to crypto mines being used for breaking hashes, if you have one based on GPUs, yes, you could reuse GPU mining hardware for cracking hashes, albeit with relatively low hashrates for current best practice hashing algorithms.

If you're looking at something like Bitcoin's hashrate and thinking that it could be used to break SHA2 hashes, as far as I understand ASIC miners, this is not possible, as ASIC miners are designed only for mining, and they don't really accept non-mining related inputs (ie, no arbitrary inputs to be hashed, unless it matches Bitcoin's specific steps for iterating over nonces).

Deathmax··on AWS Cloud Control API, a Uniform API to Access AWS and Third-Party Services
And you no longer have to worry about the meanings of positional arguments changing between versions and potentially running the wrong command.
Deathmax··on Slack is experiencing a service disruption
There's two Let's Encrypt issues at play at the moment.

The issue that your comment about cached/discovered intermediates relates to is that some servers were still manually constructing the chain that goes leaf -> R3 -> DST Root X3, and the R3 intermediate signed by X3 expired on 29 September. This chain hasn't been returned by Let's Encrypt since May 2021.

The other issue relates to the current default chain returned by Let's Encrypt that goes leaf -> R3 -> ISRG Root X1 -> DST Root X3 for Android compatibility. Most clients are able to successfully build a valid chain from the leaf to the still valid ISRG X1, however, old versions of OpenSSL (pre-1.1.0) and several other TLS libraries that don't explore the graph correctly barfs at a chain that terminates in the now expired X3 root.

[1]: https://community.letsencrypt.org/t/production-chain-changes...

Deathmax··on DoS attacks against my online game
The firewall would need to be able to handle all the DDoS traffic as well, since your current idea would still pass the game server's IP back to a client. This is doable if you're hosting on a cloud provider and let their firewalls filter the traffic before hitting the game server.

Embark Studios recently open sourced (in alpha) a UDP proxy[1] designed for games that lets you implement a load balancing layer. This allows you to remove servers in the load balancing layer in the event that it comes under attack, allowing the game server to stay up and only having to disconnect a portion of players connected to the attacked loadbalancer. Having a proxy layer is also how Steam protects game servers using the Steam Datagram Relay[2].

[1]: https://github.com/googleforgames/quilkin [2]: https://partner.steamgames.com/doc/features/multiplayer/stea...

Deathmax··on Show HN: NFC Passport/ID for remote user registration
Do you verify that the document is signed by a country's CA, and if so, do you have a list of countries and document types that you are able to validate against (since procuring the CAs is probably the more annoying bits for this type of service).

An existing company in this space would be ReadID (https://www.readid.com/).

Deathmax··on AWS federation comes to GitHub Actions
There's a lack of documentation since this isn't officially released yet, but my assumption is that you need write permissions to id-token in order to generate a JWT. As forked repos can at most get read access[1], presumably that would prevent a malicious fork job from generating the JWT.

[1]: https://docs.github.com/en/actions/reference/authentication-...

Deathmax··on AWS federation comes to GitHub Actions
GCP does allow you to sign into a service account using OIDC credentials. Docs: https://cloud.google.com/iam/docs/access-resources-oidc
Deathmax··on Unity to acquire Parsec for $320M
They don't do cloud hosted machines anymore, but the client is still free. You pay to get additional features (full 4:4:4 color, multi-monitor, drawing tablet support, and other enterprisey features). https://parsec.app/warp has the comparison between free and the other paid plans.
Deathmax··on Nordigen: API aggregator to European banks
Starling[1] and Monzo[2] have their own APIs accessible to end users which are not Open Banking[3]. Monzo has a separate set of OB APIs and AFAIK Starling doesn't have an OB API as only the big, high-street UK banks (HSBC, Barclays, RBS, Santander, Bank of Ireland, Allied Irish Bank, Danske, Lloyds, Nationwide) were forced to implement the OB spec.

[1]: https://developer.starlingbank.com/

[2]: https://docs.monzo.com/

[3]: https://openbanking.atlassian.net/wiki/spaces/DZ/pages/16385...

Deathmax··on Looking Glass: Run a Windows VM on Linux in a window with native performance
> Don't disclose to the client anything not in their view.

Either full of edges cases (how do you efficiently compute visibility, and can you prevent models from popping in as a result of latency) or computationally expensive[0]. Valorant, CSGO, League of Legends, Dota 2 are some of the games that I know about that implement server-side occluding to minimise the impact of wallhacks, but eventually a client will still need information like the position of an audio cue such as footsteps that cheats can make use of.

[0]: https://technology.riotgames.com/news/demolishing-wallhacks-...

Deathmax··on GitHub Copilot as open source code laundering?
You get to make changes without having to respect the GPL and thus no longer obligated to provide those changes to your end users, as you have effectively laundered the kernel source code by passing it through an "AI" and get to relicense the end result.
Deathmax··on GitHub Copilot
GitHub says you don't need to credit GitHub for any of the code suggestions, but since it's trained on public sources of code, anyone have a clue on potential licensing pitfalls?
← PreviousPage 3 of 5Next →