HNHacker News
TopNewBestAskShowJobs

Ded7xSEoPKYNsDd

384 karma · joined September 14, 2014

submissionscomments
Ded7xSEoPKYNsDd··on Terminal Multiplexers
> You can't re-arrange sub-windows with the mouse (drag).

Just a nit-pick:

You can configure that with tmux (and possibly screen, I don't know). It has the downside that the user needs to know to press shift while clicking when they want to route mouse actions to the terminal emulator (e.g. to select text) instead of tmux or the applications running inside of it.

Ded7xSEoPKYNsDd··on Germany raided 83 homes in coordinated raids against online hate speech
No, there is no such paragraph. The German constitution guarantees freedom of opinion - not speech.

So you can’t get prosecuted for disliking someone (and saying so) but you can for saying insulting or untrue (e.g. holocaust denial) things - those are not opinions.

Ded7xSEoPKYNsDd··on Ask HN: How do I improve my command of mathematical language?
Here in Germany early college math classes were mostly a rehash of everything from school, but with much more rigor and sometimes more detail.

So I'd recommend some college textbooks. If you live near a college, their library should have a ton of them to browse through and lend. You should also be able to find accompanying lectures on YouTube or college web sites.

Ded7xSEoPKYNsDd··on Add First Party Support for AdBlock Plus-Style Blocklists in Gecko/GeckoView
This bug is a year old, and Firefox Preview / Fenix has in the meantime gained support for uBlock. Considering that's mentioned as motivation for native support, I'm not sure this is still planned?
Ded7xSEoPKYNsDd··on Lessons learned from writing ShellCheck
The standard python linters can do it:

    $ flake8 foo.py
    foo.py:6:14: F821 undefined name 'q'

    $ mypy --check-untyped-defs foo.py
    foo.py:6: error: Name 'q' is not defined
(They also have some other complaints about your code that you'd either have to disable or adjust to.)
Ded7xSEoPKYNsDd··on HTTP static server one-liners
openssl can also do it. no dirlisting though.

    openssl req -x509 -newkey rsa:4096 -keyout /tmp/key.pem -out /tmp/cert.pem -nodes && openssl s_server -WWW -port 8443 -cert /tmp/cert.pem -key /tmp/key.pem
Ded7xSEoPKYNsDd··on GitHub’s latest security features
As someone who regularly needs to report security vulnerabilities to projects hosted on Github, I find it incredibly annoying that I can't create one of these 'maintainer advisories' (or just a regular issue that's non-public) as an outsider.

These 'security.md' files would work for me just as well to define a security contact, but I've never come across one of these in the wild... so I end up wasting my time hunting down maintainers and their email addresses, when everyone involved would have a much easier time if it were all handled through Github by allowing everyone to create a (draft) 'maintainer advisory'.

Ded7xSEoPKYNsDd··on European Court limits right to be forgotten to E.U.
No 'background checks' by private investigators in Germany. Some employers ask for a police certificate of conduct. There's a law saying which kind of convictions are listed there (nothing below a certain amount of days) and how long (to allow re-socialization).
Ded7xSEoPKYNsDd··on Fuzzification: Anti-Fuzzing Techniques [pdf]
I've seen a lot of criticism of this approach - hiding vulnerabilities, instead of actually fixing them. Other mitigations actually prevent exploits (e.g. the combination of NX and ASLR raises the bar for getting code execution: suddenly interactivity and an address leak are required in addition to a stack-based overflow) whereas your mitigation (?) just sweeps bugs under the rug.

From my own skimming of the paper, the discussion of 'why?' boils down roughly to 'exploits are sometimes used for bad things'.

Do you believe your approach will actually improve the security of any systems, or will it just allow lazy vendors to hide their shallow bugs - leaving them to the most motivated (e.g. nation-state) adversaries?

Ded7xSEoPKYNsDd··on Ask HN: Germans, how to work legally remote?
My understanding is that in your 2nd scenario (contractor), the tax/social security authorities might at some point decide that this is Scheinselbständigkeit, and therefore it's actually been scenario 1 all along. What I'm unclear about is whether they'll try to collect from the worker in DE or the company in the US.
Ded7xSEoPKYNsDd··on Why do airlines still mislay 25M bags a year?
Airlines made a business of that, too: with 'priority boarding' you get into the plane first, when the overhead compartments still have enough space. And some airlines (Ryanair) only allow so small bags in the cabin with a standard ticket that the overhead compartments don't get full nearly as often.
Ded7xSEoPKYNsDd··on Ghidra
They aren't really comparable. While IDA has some debugging features, it's all about static analysis. It has features for browsing and annotating code - you can view the code as a control flow graph, add your own names and comments to functions and variables once you've made sense of them, define structures and their members so you don't have to memorize what each offset to a common type means, jump around in the call graph, find other usages of global variables...
Ded7xSEoPKYNsDd··on Study: Coca-Cola Shaped China's Efforts to Fight Obesity
Tea! It's literally water with taste.

If you don't like hot beverages, make it iced. If you don't want to make some all the time, use a bigger kettle.

Ded7xSEoPKYNsDd··on Orange Livebox ADSL modems are leaking their WiFi credentials
https://twitter.com/bad_packets/status/1076797149524811777
Ded7xSEoPKYNsDd··on Signing Your Apps for Gatekeeper
The enterprise Linux distributions have lists with compatible hardware:

https://access.redhat.com/ecosystem/search/#/category/Laptop... https://www.suse.com/yessearch/ https://certification.ubuntu.com/desktop/

Ded7xSEoPKYNsDd··on Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
Wikipedia says that MINIX is POSIX-certified, so it's pretty close (Unix-like). It doesn't seem anyone has shelled out the money for SUS certification, so it can't officially use the UNIX trademark.
Ded7xSEoPKYNsDd··on San Francisco Denies Scooter Permits for Bird, Lime, Uber and Lyft
The sharpie thing might actually be someone trying to "reserve" a scooter for themselves. (Take a picture of the code before making it unreadable, then the scooter always stays wherever they left it.)
Ded7xSEoPKYNsDd··on Google Titan Security Key now available
(I got these at a Google thing at DEF CON.) Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google software on Android (Lineage) that can talk to them.
Ded7xSEoPKYNsDd··on Riot Games Approach to Anti-Cheat
Any phone has enough computing power to just bruteforce a 32bit value in order to recover the original IPv4 address from a normal cryptographic hash in a practical timeframe.
Ded7xSEoPKYNsDd··on When the Compiler Bites
The volatile modified on a pointer tells the compiler that reads and writes to it can have side-effects -- it is meant for memory-mapped hardware registers. Because of those (presumed) side-effects, reads and writes to that volatile pointer cannot be optimized away by dead code elimination.

Changing the address where such a variable points to, will still be optimized away when it isn't used later on.

Ded7xSEoPKYNsDd··on AMD 2nd Gen Ryzen Deep Dive
Mmap uses page faults instead of syscalls to read more data. Both these mechanisms require switching to the kernel and back, so it's not clear to me why it should be less affected by Meltdown patches.
Ded7xSEoPKYNsDd··on Questioning the motive behind the security allegations against AMD
For the first one, it's probably that they don't allow search engines to crawl their site:

http://cts-labs.com/robots.txt

The other domain does appear on Google for me.

Ded7xSEoPKYNsDd··on Show HN: Mitmproxy 3.0 released, an open-source console-based proxy
There are some Frida scripts running around for this purpose. However I don't have any personal experience with them, so I have no idea how reliable they work.
Ded7xSEoPKYNsDd··on JEP 325: Switch Expressions
I can somewhat forgive C for picking a syntax that turned out to be a bad idea. (Even if possibly some prior programming language made a better choice.) Java, on the other hand, copied that syntax knowing exactly how many bugs this would result in, for the questionable benefit that Java superficially looks a little bit more like C.
Ded7xSEoPKYNsDd··on How the JVM compares strings on x86 using pcmpestri
> Indexing code points in both UTF-8 and UTF-16 requires reading the whole string up to index location. Substrings are the same as well.

Java's String functions don't index by Unicode code points, though. Java strings are encoded in UCS-2, or at least the API needs to pretend that they are.

Ded7xSEoPKYNsDd··on NeuG USB True Random Number Generator
I remember some broken SSL certs generated during boot of some routers.
Ded7xSEoPKYNsDd··on Update: Looking Glass Add-On
They never tried to hide this - they actually thought they were building some cute easter egg, without thinking about how people would react to a phishy-looking add-on getting installed in their browser without consent or notice.
Ded7xSEoPKYNsDd··on MobileCoin: A New Cryptocurrency from Moxie Marlinspike
ARM Trustzone doesn't do anything related to remote attestation, which I'm guessing this thing is all about (even if the article doesn't seem to mention it). So I'll claim it is impossible.

Edit: You could still check the signatures signed by the trusted Intel CPUs on your ARM device of course, but any mining would have to happen on a SGX-enabled Intel CPU. (Or anything else with Intel's private key.)

Ded7xSEoPKYNsDd··on Puffs: Parsing Untrusted File Formats Safely
There are C compilers for many architectures that the Rust compiler (today) does not support. They may also be referring to the fact that you can't just drop it into existing projects with their complicated build systems in the same way that you can drop a few generated ".c" and ".h"files.
Ded7xSEoPKYNsDd··on Ask HN: Why doesn't Microsoft build its own Android “fork”?
Unlike Windows in the 90s, Android isn't a monopoly. (iOS has a decent marketshare.) So Google is free to be as anti-competitive as they want to be.
Page 1 of 8Next →