HNHacker News
TopNewBestAskShowJobs

ENOTTY

2,400 karma · joined August 26, 2010

Comments are personal opinions and do not reflect the positions of any organization I am affiliated with
submissionscomments
ENOTTY··on Intel, TSMC tentatively agree to form chipmaking joint venture
This kind of government-encouraged or mandated joint venture is barely different from what China does. To be quite honest, for stuff like silicon manufacturing, it's probably a good idea.
ENOTTY··on French scientist denied entry into the U.S., French government says
Why would you absolve POTUS when it's clear his administration's policies created the environment that enables CBP officers to take this liberty?

Additionally, the CBP spokesperson[1] defended the action, and despite reporters asking questions, the administration has done nothing to walk back the action or apologize. All signs point to the administration being very okay with stuff like this happening.

[1]: This might not be widely known, but one of the first actions that happens on inauguration day is the replacement of US government agency spokespersons with new political appointees. One of the powers of the executive branch is the bully pulpit and smart administrations seek to use it from day one.

ENOTTY··on Teen on Musk's DOGE team graduated from 'The Com'
I don't think you're going to find any on-he-record first person testimony. It's going to be unnamed government officials, or front-line government employees who are talking to reporters and providing information without direct attribution
ENOTTY··on Portspoof: Emulate a valid service on all 65535 TCP ports
To speed up a comprehensive port probe with service discovery, one could use a few different systems on different IPs and divide the work.
ENOTTY··on Where have all the sacked tech workers gone?
Still on severance and chilling out maybe?
ENOTTY··on How to make sense of intelligence leaks
Per the article:

> In 1964 Sherman Kent, a cia analyst, coined the phrase “words of estimative probability”.

So that must have been even before Carter

ENOTTY··on How to make sense of intelligence leaks
This is a very useful article if you want to understand the technical language used by the UK and US intelligence communities, which is often parroted by the media reporting on topics using sources that leak intelligence from those communities. This language has been standardized within their respective communities so that all parties involved (from the President to the lowliest analyst) should be on the same page with respect to the intelligence.

According to the article there are two measures:

- a probabilistic measurement and associated language, which speaks to the assessed likelihood of an event occurring

- a confidence measurement and associated language, which speaks to the assessed quality of the source(s) of the intelligence

ENOTTY··on China has a lead over the US in 37 out of 44 critical technologies
This list seems weird. Advanced aircraft engines? The latest homegrown Chinese airliner (Comac C919) uses western LEAP engines.
ENOTTY··on Amazon packages burn in India, final stop in broken recycling system
> Laurie Smyla, a 73-year-old retiree from Sloatsburg, New York [...] Smyla has a degree in environmental science and even served as coordinator for the local recycling program in the late 1980s, as she explains when reached by phone. She was able to quickly identify the envelope as polyethylene, the most common type of plastic.

I gotta wonder, how many people did the reporters have to contact before finding the perfect subject to put a human angle on this part of the story. Kudos to them for doing the legwork

ENOTTY··on Signal Introduces Stories
The phone contact list becoming the root of trust for defining personal trust relationships is rather unwelcome. Then software taking that data and wordlessly interpreting it as a binary trust/do-not-trust decision is also unwelcome.

If I am networking at a conference, I frequently exchange contact info by entering info into each others' contact app or sending each other a text. I'm sure I'm not the only one to do this.

It's one thing to tell two users that both parties are using Signal and in each other's contact list (contact discovery). It's another thing to encourage users to broadcast messages to all of them (via Stories, and the default share setting is all contacts)

In summary, while I'm neutral on the Stories feature, I think the implementation/rollout has been clumsy.

ENOTTY··on Gmail 2FA causes the homeless to permanently lose access 3 times a year
This might not be a problem that matters to the Google bean counters, but it would be a problem that a responsible, moral, and just company would solve.
ENOTTY··on Feds seized $311M in Bitcoin, then hacker stole it back
Imagine getting done in by your own Google Glass.
ENOTTY··on SQLite: QEMU All over Again?
Frankly, as someone more interested in emulation than virtualization, I have been occasionally unhappy that most of the energy behind QEMU goes to virtualization. Some of the things QEMU has done to better adapt to virtualization do not translate well to the emulation use case.
ENOTTY··on Chess Investigation Finds U.S. Grandmaster ‘Likely Cheated’ More Than 100 Times
In case you’re looking for whether this says anything about the butt plug allegations, this report does not. It only concerns cheating on an online platform, not in person cheating
ENOTTY··on Patagonia founder gives away the company
I'm curious about the ownership, profits, and dividends to ownership for a private company. Obviously, details on this are not easy to come by. It seems like Patagonia is self-sustaining from a cash flow perspective.

So Patagonia is 50 years old and did an estimated $1.5 billion in revenues in 2022 (according to Wikipedia). From the article, it seems like Yvon, his wife, and his two children held both ownership and control. It might even have been 100% within the family, given that NYT explicitly writes that, "the family irrevocably transferred all the company’s voting stock, equivalent to 2 percent of the overall shares" and "The Chouinards then donated the other 98 percent of Patagonia"

I wonder how much of the company's profits over the years were reinvested back into the company and how much went to Yvon and the other Chouinards. Seems like most or all of his wealth derives from Patagonia and he lives modestly but comfortably.

EDIT: Even at a 1% profit margin, at $1.5 billion, that's still $15 million.

ENOTTY··on OnlyFans bribed Meta to put porn stars on terror watchlist: lawsuits
I suppose this is the dual to the OnlyFans creator who slept with Meta employees to get unbanned https://news.ycombinator.com/item?id=31447396

I think the takeaway from both of these stories is that Meta employees are easily bribed and perhaps some more internal controls are needed to prevent abuse of these platform features.

ENOTTY··on Cellular recovery after prolonged warm ischaemia of the whole body
Here's an article written for more of a layperson's audience. https://www.nature.com/articles/d41586-022-02112-0
ENOTTY··on NIST announces first PQC algoritms to be standardized
What's up with this?

> In addition, NIST has engaged with third parties that own various patents directed to cryptography, and NIST acknowledges cooperation of ISARA, Philippe Gaborit, Carlos Aguilar Melchor, the laboratory XLIM, the French National Center for Scientific Research (CNRS), the University of Limoges, and Dr. Jintai Ding. NIST and these third parties are finalizing agreements such that the patents owned by the third parties will not be asserted against implementers (or end-users) of a standard for the selected cryptographic algorithm

and

> NIST expects to execute the various agreements prior to publishing the standard. If the agreements are not executed by the end of 2022, NIST may consider selecting NTRU instead of KYBER. NTRU was proposed in 1996, and U.S. patents were dedicated to the public in 2007.

ENOTTY··on MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips
Hahaha thank you. I am humbled by your praise
ENOTTY··on MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips
Having grokked the abstract, I feel like can speculate a bit as to what is going on. Take this with a grain of salt; I have no clue what has actually been discovered.

I believe that the researchers have found a way to remove PAC as a barrier to exploitation by disclosing PAC verification results via speculative execution. This is only useful to attackers going after a target that uses PAC, and those attackers will need to have another vulnerability that enables them to hijack control-flow through modifying pointers to code that are located in memory.

The attackers can use this new Pacman vulnerability as a crash-free oracle that says whether their forged pointer worked, and once they find a working one, they can use that to hijack control flow.

PAC (or Pointer Authentication) is a security feature found in recent iPhones, the Apple Silicon Macs, and the Graviton3. It is intended as a defense against control-flow hijacks. It works by signing pointers found in memory with one of five keys that are known only to the processor. Before the pointer is used, the processor should be instructed to "authenticate" the pointer by checking the pointer's signature using its private keys. To prevent simple reuse of one authenticated pointer used in one place to a pointer used in another place in the program, code can provide a "context" value to be used during the authentication.

A great resource for learning about PAC and its usage in the Apple platforms is at [1] (it links to other resources) and if you want to play with a PAC enabled binary, check out [2]

[1]: https://googleprojectzero.blogspot.com/2019/02/examining-poi...

[2]: https://blog.ret2.io/2021/06/16/intro-to-pac-arm64/

EDIT: The attack works by:

1) Place your guess such that it is used as the pointer input to an authentication instruction

2) Causing a branch misprediction. On the not-taken side of the branch, code needs to perform a pointer authentication and usage of the pointer. On the taken side of the branch, code should not crash.

3) CPU speculatively executes down the not-taken side of the branch (misprediction) and speculatively executes the authentication instruction.

4) If your guess is correct, the authentication instruction will return a valid pointer. If your guess is incorrect, the authentication instruction returns a pointer that, if dereferenced, will cause an exception.

5) CPU speculatively executes a load (in the case of a data pointer) or an instruction fetch (in the case of a code pointer) on the pointer value.

6) If the pointer is valid, the address translation for that pointer will appear in the TLB. If the pointer is not valid, it will not (because of the exception).

7) All of the effects from this mispredicted branch get squashed when the CPU realizes that the branch is not taken. No exception is actually thrown!

8) Measure the TLB entries to determine whether the speculative address translation made it in. If it is present, you know that the guess is correct.

9) Repeat, up to 2^16 times.

ENOTTY··on MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips
As someone with a bit of experience in this area, IMO, the Techcrunch article is more confusing than it should be.

Here's a link to the actual abstract. The work will be presented at ISCA, which will start on June 18. https://dl.acm.org/doi/10.1145/3470496.3527429

Here's a link to MIT's press release. https://www.csail.mit.edu/news/researchers-discover-new-hard...

Here's a link to the vulnerability's website, as is tradition now. (Plus the paper) https://pacmanattack.com/

ENOTTY··on Microsoft will include pay ranges in all U.S. job postings
Given that most big tech companies' base salary tends to plateau and total comp begins to be dominated by stock grants and performance bonuses, just how much real transparency is actually going to be provided?
ENOTTY··on Intel can’t grow profits in a global chip shortage
EUV is coming with the Intel 4 process node. Intel is also the lead customer for ASML's High-NA EUV, which is supposed to be the next generation EUV.
ENOTTY··on Bitcoin Is Acting Like Just Another Tech Stock
When I wrote that it was fine. Now it's not.
ENOTTY··on Bitcoin Is Acting Like Just Another Tech Stock
UST's (Terra) peg is the one that is totally broken. It's an algorithmic peg, with its reserves in Bitcoin. USDT's (Tether) peg is fine right now (how much do you believe in commercial paper of unknown origin). And USDC's peg is also fine right now, and they claim to be backed by treasurys and actual cash.
ENOTTY··on Ottawa has lost control of itself
Does the government not have a responsibility to protect fair use of the commons by all people?

If you agree that the government has that responsibility, then the government needs to maintain its rule over the commons, which has clearly been lost in downtown Ottawa.

Also, the demonstrators have been there for over a week, lacking a permit for their demonstration, often honking all night long and keeping awake the people who live nearby. There have been numerous reports of assaults by demonstrators because the victims had the audacity to wear a mask while walking in the vicinity of the demonstration.

ENOTTY··on That’s how it works when you’re a woman on the internet
Putting her last name on her Twitter profile and the pronouns by which she'd like others to address her is picking a fight? By your logic, the only people not picking a fight are those who live in a self-contained box and make no impact in the world.

I suppose that is your point; that someone like her has no right to interact with the world.

ENOTTY··on California Considers Doubling Its Taxes
The messaging on this article likely comes from the Tax Foundation's political viewpoint, which is generally anti-tax
ENOTTY··on Twitter’s founder admits that shutting down the API was “worst thing we did”
Did you run @DC_TechEvents? I used to get IFTTT to deliver me alerts, but that died when the account got suspended. Sad day.
ENOTTY··on Oculus Quest is removing the Facebook account requirement
Facebook could just as easily change the policy again. Meh
Page 1 of 13Next →