HNHacker News
TopNewBestAskShowJobs

DorothySim

47 karma · joined February 4, 2017

submissionscomments
DorothySim··on Malicious crossenv package on npm
> For example, IIRC NetBSD required new developers to meet with one or two existing developers in person to verify their identity. (Pretty much like a regular PGP WoT.)

Debian also requires OpenPGP keys and WoT for all developers.

DorothySim··on Stagit – A static Git page generator
> What I'd really like to see is a JS implementation of the "dynamic" features like diffing

That's possible. I've made something like that (dynamically fetching git info via dump HTTP server protocol) using Git.js [0] although for a different reason and it worked very well. Some caveats: the decompression must be handled in a WebWorker or the UI is stuck pretty easily. But objects can be fetched on demand so it's kind of like Microsoft's Git Virtual FS. As you've said cross origin policies apply so either have the viewer on the same site as repos or add appropriate CORS headers.

[0]: https://github.com/yonran/git.js

I see git.js even has a "repo-viewer" demo [1]. Although it's very primitive it shows the ref list and diffs.

[1]: https://github.com/yonran/git.js/blob/master/demos/repo-view...

DorothySim··on How to use BeyondCorp to ditch VPN, improve security and go to the cloud
But if you don't provision the device yourself how can you be sure it hasn't been tampered with in a way that just displays "bootloader OK, everything good" but in the mean time it was rooted? Or is that a risk calculated in the "no full amount of trust"?
DorothySim··on How to use BeyondCorp to ditch VPN, improve security and go to the cloud
Interesting design. As far as I understood from old papers client certificates are used only to identify the device while user authentication is handled differently.

Could you elaborate on the technical details on user authentication? (If that's not top-super-secret) I guess it's just like accounts.google.com for Enterprise with mandatory 2FA (username+password+U2F key?). Does it work the same on mobile/Android (U2F via NFC or codes)?

DorothySim··on How to use BeyondCorp to ditch VPN, improve security and go to the cloud
They also take into account the state of the machine you're working on. So locked bootloader and probably a client cert in TPM-like component, plus "device health". Client certs alone are good for authentication (don't work in HTTP/2 though) but they want to reach even better target - no malicious software running on your computer.

That's from reading old papers, I don't know if anything changed now.

DorothySim··on How to use BeyondCorp to ditch VPN, improve security and go to the cloud
I think the only restriction is working on Google approved hardware so no BYOD there.

(Disclosure: not a Google employee).

DorothySim··on The browser bugs and edge cases of HTTP/2 push
For people interested in specs, here's the link: https://www.greenbytes.de/tech/webdav/draft-ietf-httpbis-cac...
DorothySim··on Apache Allura — Open source project hosting platform
The "Online Demo" button brings me to the download page. Is this a bug?
DorothySim··on JSONbin.io – Simple JSON Storage (Beta)
I suggest returning 404 Not Found instead of 422 Unprocessable Entity on failed GETs: https://jsonbin.io/b/2342342 as well as Content-Type: application/json instead of current text/html.

"Entity" in "Unprocessable Entity" refers to request body and for GETs there is no request body: http://www.restpatterns.org/HTTP_Status_Codes/422_-_Unproces...

DorothySim··on Rust Memory Management
> C# and Java allocate objects to the heap and primitive types to the stack by default (...)

Note that it only applies to local variables. If you have a primitive inside an object then it's allocated on the heap as part of the outer object.

DorothySim··on Total.js Messenger – A small alternative to Slack
Looks very good and I like that they have a screenshot right on the home page. I wish there was an anonymous instance to try it out without the tedious login process...
DorothySim··on Truly Seamless Reloads with HAProxy
I've used a simple iptables approach to redirect traffic to new Docker container:

  iptables --wait --table nat --append PREROUTING --protocol tcp --dport 80 ! --in-interface docker0 --jump DNAT --to $new_target
Then removing tables for old one:

  iptables --wait --table nat --delete PREROUTING --protocol tcp --dport 80 ! --in-interface docker0 --jump DNAT --to $old_target
(repeat the same for ip6tables).

The same had to be repeated on system start but otherwise it worked flawlessly and had zero-downtime.

DorothySim··on Stop the Daily Standup Meeting
Also relevant: https://vimeo.com/110554082
DorothySim··on TLS verification vulnerability in LibreSSL 2.5.1-2.5.3
Note that it is about TLS client certificates so it's not as widespread as it seems (unless you use these certs of course :) ).
DorothySim··on Tamper Chrome extension to modify requests in flight
Probably yes. Sending scores in HTTP requests is such a low-hanging fruit for exploitation.

A friend of mine was responsible for scoring system on games. As they had some real awards (like bikes, tickets etc.) they captured the entire flow of the game with various statistics and later analyzed them for weird variations. That was in Flash and people used browser plugins to slow down the play, that was easy to spot. Of course it won't stop 100% of attacks, but it raises a bar sufficiently to thwart most attempts.

DorothySim··on Show HN: Visual Studio Code for ARM, submitted to core
Wow, very nice!

I think this comment on issues is also relevant: https://github.com/Microsoft/vscode/issues/1031#issuecomment...

DorothySim··on Golang SSH Security
...or Thunderbird (Enigmail) for people that like GUIs.
DorothySim··on Golang SSH Security
> For hostkeys on DO you can probably get a script to run that'll request a signed certificate from a server you own.

Or just embed the signed host certificate in cloud-init.

DorothySim··on HTTP/2 is not the future, it’s the present
You are not required to use SSL to do hello world. You are required to use SSL if you want to use HTTP2 (yes, I know about h2c).
DorothySim··on Secure Remote Password protocol
According to this [0] they are related ("SRP is related to Diffie-Hellman.").

[0]: http://web.archive.org/web/20130407190430/http://chargen.mat...

DorothySim··on Ask HN: Mailing lists that HN readers ought to know about?
CVE disclosure list: oss-security@lists.openwall.com (unfortunately since Mitre stopped taking bug reports via e-mails it's not as active as it has been).
DorothySim··on Binary Transparency for Firefox
Really interesting hack. It basically gives (almost) free timestamping (using Let's encrypt for cert issuance and CT logs for storing information). Previously one would use Bitcoin OP_RETURN outputs for timestamping [0].

[0]: https://en.bitcoin.it/wiki/OP_RETURN

DorothySim··on Impossible Java
The same thing exists in .NET IL where you can overload methods based only on return values (among other interesting things like modopt/modreq [0] etc.).

[0]: http://stackoverflow.com/a/5294456

DorothySim··on Using Pseudo-URIs with Microservices
a) is particularly interesting to me. I thought about giving people ability to create their own namespaces and used https://user.example.com or https://example.com/user as a namespace but tag URI looks cleaner.

By the way why did you need human readable IDs? I'm asking out of curiosity because there is certain charm to just using UUIDs everywhere (and urn:uuid).

DorothySim··on Using Pseudo-URIs with Microservices
Is there a benefit of using tag URI instead of a regular old URL? E.g. tag:blogger.com,1999:blog-555 vs https://blogger.com/1999/blog-555 The only difference I see is that URL should point to something (can be referenced in a browser) which may or may not be an additional benefit.
DorothySim··on Using Pseudo-URIs with Microservices
> The author seems to be ill-informed on the point which apparently is the only stated reason for not using the internet standard that directly applies to the use case.

That's what I also suspected. Thanks!

DorothySim··on Using Pseudo-URIs with Microservices
> As we iterated on our approach, we have decided to follow more recent recommendations and not limit our identifiers to the deprecated concept of URN.

I was not aware URN was deprecated... Is there a reference somewhere to these recommendations?

DorothySim··on Ask HN: Have you created a programming language and why?
I love creating programming languages! They're powerful tools of abstraction - designed well they make complex concepts look simple.

Couple of examples - a language that compiles to Bitcoin script opcodes [0]. Although the Bitcoin script engine is stack based (easier to follow) I couldn't resist designing a small, simple language that could be used to write transaction output scripts. This way it's easy to understand what are the conditions of moving funds to the next owner.

Another language has first-class functions, operators as functions, optional lazy computations, but more importantly a small runtime that supports tail-calls and capturing execution as a value (callcc) [1].

I've also written parser and interpreter for Prolog [2], just to get the feeling of logic programming.

Writing a small language can make you understand the paradigm (functional, imperative etc.) better and it takes a great deal of effort to decide how should the syntax look like, how will the runtime work (usually with toy languages you provide runtime too...).

Edit: Just noticed the "except toy languages" part... :-/

[0]: https://curiosity-driven.org/bitcoin-contracts

[1]: https://curiosity-driven.org/continuations

[2]: https://curiosity-driven.org/prolog-interpreter

DorothySim··on Ask HN: Have you created a programming language and why?
This reminds me of MiniMAL [0].

[0]: https://github.com/kanaka/miniMAL