HNHacker News
TopNewBestAskShowJobs

Flocular

137 karma · joined October 29, 2020

submissionscomments
Flocular··on OpenSSL Security Advisory [7th February 2023]
For cryptography it uses the ring-library which still relies on C-Code in many places. Additionally there is no API-stability (still v0.*) and the last official audit was 3 years ago.

The project has potential but isn't quite ready for prime time yet.

Flocular··on OpenSSL Security Advisory [7th February 2023]
openSSL 1.1.1 is EOL 2023-09-11 which is likely to be the bigger problem for random-distro-XYZ
Flocular··on Show HN: Generate commit messages using GPT-3
Why put the commit message there then? You could just use a git-client that adds this text as description for commits. There is generally little use to store automatically generated content in databases, the input for generation should be enough.
Flocular··on Sudo: Heap-based overflow with small passwords
Attack complexity High (chance for an attacker to get anything at all is very low), Availability None (you're not crashing any service that's running in the background) and Confidentiality Low (data leaked is not in the attackers control and not likely to be interesting). Adds up to a score of 2.9
Flocular··on Sudo: Heap-based overflow with small passwords
Come on :D CVSS of 7.1, Complexity Low, Availability and Confidentiality High. sure...
Flocular··on Optimizing images with the HTML <picture> tag
This made me look up jpeg2000 support. And then that made me sad :D
Flocular··on Exceeding 1.5°C global warming could trigger multiple climate tipping points
Mentioning Greenland ice sheet in this context is always a bit of a red herring.

It is important to note that in the language of these simulations no "overshoot" is included in the temperature trajectory. A 1.5°C global warming is talking about the long term (millenial timescale) stable temperature we reach after our little "experiment".

If we can "quickly" (a few hundred years) return to 1.0°C or even less warming, compared to pre-industrial levels, these tipping points have not actually happened yet. (https://www.researchsquare.com/article/rs-1418830/latest.pdf summarizes this very well)

Nico Wunderling shows that while for some systems (like the Amazon rain forrest) peak temperature (even over only a few years) is most important, for slower systems like the Greenland ice sheet the target, long-term temperature is most dominant.

Priotizing the most urgent matter should therefor lead us to talk about the quickly acting tipping points, often related to biological ecosystems. For those it is most important to actually stay below 2°C of warming. For the Greenland ice shield there is ample time after the year 2100 for us to prevent the worst.

Flocular··on Nuclear energy is clean
No, the original plot was in MWh. But even for LCOE wikipedia (citing lazard) shows the same 3xfactor between solar/wind and nuclear: https://en.wikipedia.org/wiki/Levelized_cost_of_electricity
Flocular··on Australian activist can't use encrypted apps, must let police access phone
Democracy dies in darkness.
Flocular··on Nuclear energy is clean
"when there's clouds and the wind doesn't blow, what happens?" Meteorologically speaking that won't happen over a large enough area like Europe or USA. When there's clouds there's always wind close by. It's also never cloudy over a whole continent (air has to come back down somewhere)
Flocular··on Nuclear energy is clean
That is just to show that nuclear isn't a magical always-on power source that some of the pro-nuclear folks make it out to be. Also: we can install twice the capacity in MW for solar and still have money left over to put into a smarter grid or storage compared to nuclear.
Flocular··on Nuclear energy is clean
A good estimate to gauge the societal investment needed to generate electricity in a certain way, is to look at its total cost in dollar/MWh. Wikipedia has a nice graphic prepared for just that: https://en.wikipedia.org/wiki/Cost_of_electricity_by_source#... (which ignores externalized costs like CO2 or nuclear waste) You can see in there that nuclear has triple the cost compared to solar.

As we need to replace as much fossil-fueled power plants as possible and as quickly as possible, wasting ressources into building nuclear power plants sounds stupid. Other interesting factors:

* Heating climate is a risk for nuclear https://arstechnica.com/science/2021/07/climate-events-are-t...

* Maintenance cost is hard to predict https://www.world-nuclear-news.org/Articles/EDF-revises-up-c...

* 30 planned + 60 unplanned days shutdown on average https://www.eia.gov/todayinenergy/detail.php?id=37252

Flocular··on Historical language records show surge of cognitive distortion in recent decades
Sentences that apparently mark cognitive distortion: "The quality of our product is not acceptable yet.", "I won't go to this meeting, because I feel nauseous.", "Children should go to school."

I can't say I agree.

Flocular··on Switzerland moves ahead with underground autonomous cargo delivery
I think this is trying to solve delivery inside cities. However, I don't see cities beeing clogged by parcel delivery services. Transportation of goods is more problematic on the inter-city level. But that's too far to build a tunnel. What is causing troubles for cities seems to mostly be human traffic (that's why rush-hour is a thing) - for that subways could indeed be a solution. Unless Switzerland's traffic is looking completly different from what I know from Germany of course?
Flocular··on Scapy: Low level packet hacking toolkit for Python
Sadly it's missing a native TCP-reassambly. Was caught by suprise by that recently, but there's always pyshark
Flocular··on Why isn't there a Swagger/OpenAPI for binary formats?
DFDL ("Daffodil") https://en.wikipedia.org/wiki/Data_Format_Description_Langua... was made pretty much exactly for describing/parsing binary formats in a schema-like format. It is however based on XML and not JSON.
Flocular··on www.userfriendly.org seems to be gone, RIP Erwin, Dust Puppy and Co :(
Got announced 2 weeks ago https://web.archive.org/web/20220225082910/http://ars.userfr...
Flocular··on ntfs2btrfs: In-place conversion of NTFS filesystem to Btrfs
In-place conversion of NTFS? You either still believe in a god or need to google the price of harddrives these days. Honest question tho, why would anybody do in-place conversion of partitions?
Flocular··on A distributed peer to peer list of bad actor IP addresses and phone numbers
It indeed doesn't cover data processed by "a natural person in the course of a purely personal or household activity" But arguably, as soon as you upload stuff to github.com you already fall outside of that narrow definition.
Flocular··on A distributed peer to peer list of bad actor IP addresses and phone numbers
No, GDPR applies to everyone. The government is proactively only enforcing GDPR vs organizations, private persons need to sue to get GDPR enforcement against each other. Also - should companies use this list, their usage would of course need to be GDPR compliant.
Flocular··on A distributed peer to peer list of bad actor IP addresses and phone numbers
You would have to ask companies that you called how they shared & used your information. You probably can't reject to the data collection as it's based on legitimate interest (fraud detection) and not consent.
Flocular··on German gov plans software company's liability for damages caused by vulns
that could still be considered negligent, if it has a CVE and you're using it, you gotta know about it
Flocular··on GDPR penalty for passing on of IP address to Google by using Google Fonts
>>You cannot make another computer do anything. You can only send messages, and the receiver decides how to act on those.

By that logic malware doesn't exist. That's the wildest west version of the internet that we gladly left behind.

Flocular··on GDPR penalty for passing on of IP address to Google by using Google Fonts
By sharing data until public relations make change necessary https://www.theverge.com/2021/9/11/22668734/google-user-data...
Flocular··on Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
Are you mitigating supply chain attacks otherwise? If yes, how?
Flocular··on Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
I could see a govermental effort be approriate too. Alot of critical infrastructure is depending on open source too. Agencies like the German BSI should embrace and invest into open-source much more strongly.
Flocular··on Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
At my current job I'm trying to establish the same. Have to say, the recent news are water on my mills!
Flocular··on Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
Imagine they introduced something worse. Could any developer explain to a manager why you needed to import this package? "Why do we need colors there?", "Why can't we make that colored ourself?"
Flocular··on Notes on BPF and eBPF
The BPF capability should really only be given to root. I don't think it really gives any new attack surface. All I could see is it giving black-hats an easier interface to "kernel-level-fuckery".
Flocular··on Almost Always Unsigned
What fans of unsigned integers seem to really want is array access in the form of x[i %mod% LEN]. While signed integers "kind of" give you an error on overflow (Except your unlucky or somebody was malicious). Is there a way to combine both? As in give me an error on overflow for "debug builds" and always mod-LEN on "release builds"?
Page 1 of 2Next →