HNHacker News
TopNewBestAskShowJobs

Eiwatah4

93 karma · joined August 9, 2013

submissionscomments
Eiwatah4··on OWASP Top Ten Web Vulnerabilities
Just generally, don't write SQL queries as strings. An ORM is one option, language-level extensions another. But for that you need some good macros in your language - or convince the maintainers of your compiler to add it to the language (like Microsoft did in C#).
Eiwatah4··on TrueCrypt suggesting migration to BitLocker?
There is a relatively recent audit[1] of EncFS with some damning results. I really wouldn't use it.

[1]: https://defuse.ca/audits/encfs.htm

Eiwatah4··on The correct abbreviation for Firefox is ‘Fx’, not ‘FF’
Internet Navigator
Eiwatah4··on DEFCON Capture the Flag Qualification Challenge #1
The CTFs I've played usually had a good mix of web stuff and binary exploitation.

Also, the best way to learn this stuff is to do it. Even if this seems out of your league, I'd suggest to just join a team and start playing - if that kind of thing seems interesting to you.

Eiwatah4··on Homomorphic encryption implementation
You don't have to apply the CBC mode to complete files. If it is secure for a 1 MB file, I don't see why it would be insecure for 100 parts of a 100 MB file.

If you manage to merge small files into the same blocks, you even gain some privacy because the server can't even tell the number of files anymore.

[1] also has a discussion of the trade-offs of the different modes of operation for whole disk encryption. That seems related here because nobody wants to rewrite the whole disk after changing the first byte.

1: https://en.wikipedia.org/wiki/Disk_encryption_theory

Eiwatah4··on AdBlock Plus’s effect on Firefox’s memory usage
You do have some information in the browser you can't get to from the outside. For example, the filter with the most hits for me is "@@||192.168.$xmlhttprequest", which whitelists XMLHttpRequests to 192.168.*. A proxy can't really tell the source of a HTTP request. But that kind of thing is sometimes the only indicator telling the difference between an ad and useful content.
Eiwatah4··on StartSSL, please revoke me – My private key has been compromised
What if someone hacked your server and stole, then deleted the private key? (Backing up private keys is bad practice.)

What if the CA notices they issued a fraudulent certificate?

Eiwatah4··on Game servers: UDP vs TCP
> In my opinion, most of TCP's semantics arise not out of the network, but rather the data itself. I can't have packets getting lost in the middle of an SSH session: it just doesn't make sense. My keystrokes are a stream of data that must be in order, and must be delivered: thus TCP.

Mosh[1] is basically (a better) SSH over UDP. It fares a lot better than SSH on mobile connections. It does away with hanging connections and such nonsense.

1: http://mosh.mit.edu/

Eiwatah4··on GitHub under DDoS attack right now (again...)
If Github would only host git repositories, you'd be right. But people use Github for the issue tracker, source browser, code review system. Those are just as centralized as the svn server. And in my opinion, they are at least as important as a source control server to get things done.
Eiwatah4··on Accept my accept-language
It isn't the default for most people. Download a browser and OS localized to German, French, or British English and Accept-Language defaults to that instead of "en-US".
Eiwatah4··on Google Docs Users Targeted by Phishing Scam
What's stopping the attacker from reading the user's browser data and replaying it to Google?
Eiwatah4··on Escape from Microsoft bubble
For some reason, the #content element is hidden with a `display: none`. Disable that and the content shows.
Eiwatah4··on When you see a Heisenbug in C, change your compiler's optimization level (2010)
Either that, or a race condition.
Eiwatah4··on Was the iOS SSL Flaw Deliberate?
Gcc doesn't have such a warning. Clang has it, but it has to be explicitly enabled. (It's not even in -Wall or -Wextra.)
Eiwatah4··on Servo: Inside Mozilla's mission to reinvent the web browser
In Rust, (right now) you can choose between a 1:1 or a N:M mapping between OS threads and Rust tasks. With N:M threading, the runtime necessarily does (some of) that internally.
Eiwatah4··on Git: how to use stash
That works just fine. But if you're working on a big project, a full new download can take a while.
Eiwatah4··on Your Docker image might be broken without you knowing it
My experience with cgroups is that it's incredibly difficult to get them to do what you want them to do. But systemd seems to be changing that, so maybe their use will get more mainstream soon.
Eiwatah4··on Losing graciously
It is for sysadmins. And those are probably Canonical's biggest source of income.
Eiwatah4··on OCaml: what you gain
> I don't know how other similar languages deal with GUI. It's always sort of hairy, obscure code when you look at it closely.

The best languages for GUIs I've seen are specialized declarative DSLs. Things like QML, XAML, JavaFX FXML, XUL, and even HTML. Anything else very much sucks, in my experience.

Eiwatah4··on Making syslog() not block
When there are too many messages, rsyslog will drop them in the default configuration, too.

http://www.rsyslog.com/tag/systemlogratelimitinterval/

Eiwatah4··on Why You Should Always Use === and Other Bad Practices
Who says the function call actually happens? If the function is short enough, they are a very good candidates for the JIT to inline. If they aren't short, the overhead of calling the function shouldn't matter much anymore.
Eiwatah4··on Homogenization of scientific computing – Python is eating other languages’ lunch
C has variable sized arrays. http://pastebin.com/BEgDNAhu That's no longer backward-compatible to C89, though.
Eiwatah4··on Homogenization of scientific computing – Python is eating other languages’ lunch
You don't have to simulate multidimensional arrays in C. It's just easier than wrapping your head around the weird syntax required to pass them around: http://pastebin.com/JTjQMfxr
Eiwatah4··on When Doctors ‘Google’ Their Patients
Yes, the 2-4 diagnoses he came up with in the first 35 minutes were always wrong. Only then did he get it always right.
Eiwatah4··on Shit programmers write
toString() blows up on a null value, the + operator does not.

I've written similar Java code for that reason.

Eiwatah4··on Amazon's German Workers Strike
Tuition was common for a while, but it isn't anymore. Lower Saxony is the only state where you still have to pay it and they're abolishing next year [1].

[1] https://de.wikipedia.org/wiki/Studiengeb%C3%BChren_in_Deutsc...

Eiwatah4··on GIMP Windows Installers move from Sourceforge to ftp.gimp.org
$ 5000 seems way too much.

50 TB of traffic would cost something like $ 200 (if all downloads were from the US or Europe) to $ 450 (if all of were from South America) according to this page: https://aws.amazon.com/cloudfront/?navclick=true#pricing

That's still a lot of money, of course.

Eiwatah4··on Fish shell 2.1
I had similar problems, and found a work around that works great for me:

bash is configured as my default shell. So every program that runs my default shell and just assumes it can use POSIX syntax, gets what it wants (even though it should really just use /bin/sh).

My terminal on the other hand is configured to ignore my default shell and run fish instead.

I also have a line in my .bash_profile (meaning it only runs for login shells) that checks whether it's running in a virtual terminal and in that case exec's fish in a new tmux (because tmux is a terminal emulator, which means that any bash instances within it won't know they are in a virtual terminal and behave like a normal bash).

Eiwatah4··on Extending Chrome support for XP users until April 2015
Is there any chance for that most-used software to be secure if the underlying OS is full of holes?

(I'm not completely sure myself. But I'd rather err on the safe side.)

Eiwatah4··on Why Android SSL was downgraded from AES256-SHA to RC4-MD5 in late 2010
Afaik, as long as a weak cipher is enabled on both client and server, a MITM attacker can force it to be used. It involves manipulating the handshake to tell both parties the other one doesn't support any better cipher.
Page 1 of 2Next →