HNHacker News
TopNewBestAskShowJobs

Randor

292 karma · joined March 20, 2019

submissionscomments
Randor··on A C++17 thread pool for high-performance scientific computing
I looked through the code and I don't see anything new at all. Looks similar to the dozens of other thread pools I've reviewed over the years.

The author is a physicist. Looks like he just decided to publish about his C++ code.

Randor··on Sandboxie: Sandbox-based isolation software for Windows NT-based OS's
Hey Rafael,

How have you been? Are you still in the Bellevue/Redmond area?

Randor··on Sandboxie: Sandbox-based isolation software for Windows NT-based OS's
Yeah, the earlier versions of SandBoxie used SSDT hooks and offered much better protection. You can completely bypass some SandBoxie protections today with a direct interrupt 0x2e or SYSENTER call. SandBoxie offers very little protection.
Randor··on A lock-free, concurrent, generic queue in 32 bits
"If for some reason a capacity of 32,767 is insufficient, you can trivially upgrade your queue to an Enterprise Queue"

Thanks for the laugh! :)

Randor··on No, we didn’t accidentally create a warp bubble
Well,

About a week ago this topic was widely in the news under variations of the title:

"DARPA and NASA Scientists Accidentally Create Warp Bubble"

That's the context of my response here in this thread. I am not sure if everyone reading this thread knows that. The new title "No, we didn't accidentally create a warp bubble" was the NASA engineer attempting to fix the misinformation generated by the journalists.

Absolutely agree with you about physics journalism. I enjoy science fiction books too, I have no problem with the theoretical FTL topic.

Randor··on No, we didn’t accidentally create a warp bubble
Yeah,

It makes me sad to think that I contribute to this process. I have to admit... that I probably do read alot of those clickbait articles giving them more views.

It makes me even more sad when I think about the platforms that are removing the ability to downvote incorrect/misleading information.

Randor··on No, we didn’t accidentally create a warp bubble
Well,

I think journalism is getting worse as the years go by. Like everybody else I noticed the title and clicked on it a few days ago. Reading the paper revealed that the team was simply interpreting/speculating what the math was showing about some hypothetical energy density structures.

Of course the sensationalized title propagated all over the net ignoring the facts.

Randor··on Redesigned Notepad for Windows 11
Hey Jeff,

Small world, I worked with you on the Windows Update team. Hope you are doing well. Good to see you here on the HN forum. I also remember the notepad incident!

Randor··on HiveNightmare a.k.a. SeriousSAM – anybody can read the registry in Windows 10
Hi,

Actually you can use the Windows Projected File System to project the registry into the file system, making registry keys and values appear as files and directories.

https://github.com/Microsoft/Windows-classic-samples/tree/ma...

Randor··on Designing a better strcpy
Absolutely,

That's not the only discrepancy.

https://pubs.opengroup.org/onlinepubs/9699919799/functions/m...

Note the following: "The memccpy() function does not check for the overflow of the receiving memory area." "If copying takes place between objects that overlap, the behavior is undefined."

The strxcpy he provides at the bottom doesn't look better at all. I'm not sure where the author got that function. I found some better variants of the proposed strxcpy function with bounds checks and that provides overflow detection.

Randor··on OpenSSH 8.6 is still vulnerable to CVE-2020-14145 and will not be fixed
Well,

I looked at both patches and didn't like either one of them. The user 'manfred-kaiser' makes a good point and I have confirmed that he is correct. However the fix he is proposing is not a very good fix. So in my opinion both of the proposed fixes are not sufficient.

The proposed fix: https://github.com/openssh/openssh-portable/commit/b3855ff05...

This proposed fix means OpenSSH is not secure 'by default' and would require HostKeyAlgorithms to be set in the config file. Furthermore... there needs to be an existing public key. Also keep in mind that SSHD refuses to use group/world-accessible keys.

So if this patch is accepted CVE-2020-14145 will continue to work on 'misconfigured' servers.

"It's not our fault, your OpenSSH was misconfigured!"

Randor··on Is 85% of US Critical Infrastructure in Private Hands?
Hmmmm,

Maybe by forming it as a question he is inviting someone to verify or revise that number.

Randor··on New x86 micro-op vulnerability breaks all known Spectre defenses
The best part of the new "defense against Spectre" is that the LFENCE instruction has been around for ~20 years. It's not even not a defense against all variants.
Randor··on A simple C implementation to stream H.264 to browser using WebRTC
Yep, it looks easy to replace the function h264_get_next_frame(). I think you could get really decent performance if you used ffmpeg to pre-extract all of the frames into sequential files and serve them statically.
Randor··on A simple C implementation to stream H.264 to browser using WebRTC
It's certainly not better than FFmpeg. But I had a look through the source code and the author seems to have a fairly good grasp of WebRTC. The library looks really useful for anyone that wants to quickly understand WebRTC and how to use librtp and libsrtp. It's mostly a bare-bone wrapper around those libs.
Randor··on Hackers used zerodays to infect Windows, iOS, and Android users
Well, I feel like you are arguing for JIT just for the sake of arguing. The topic we are discussing in this thread is "Interpreted is safer than JIT" which is absolutely true.

Yeah, there are newer ROP mitigations coming down the pipeline, I agree verifiable execution flow remains a major problem.

Randor··on Hackers used zerodays to infect Windows, iOS, and Android users
Actually with the font exploits an interpreter would be quite a bit safer. Many of the font exploit chains work by creating line vectors that result in an infinity or NaN throwing a floating point error (with the SeH handler already being overwritten). When running this by JIT... all of this is occurring on the physical CPU. If the floating point calculations were occurring inside an interpreter then the SEH chain can be protected by SEHOP/SAFESEH and the interpreter could implement bounds checks and while retaining the NX bit on everything executing.
Randor··on Problems with Eric Weinstein's “Geometric Unity”
>There is zero chance his theory has any merit.

That seems a bit harsh. There is a certain beauty in the geometry equations Weinstein presented. I find it interesting that EFE, Yang-Mills and Dirac emerge from that. He certainly hasn't shown a complete theory of everything but I wouldn't say that it doesn't have any merit.

If I had one criticism of Weinstein it would be that he's never put anything down on paper for anyone to deeply review.

Randor··on New campaign targeting security researchers
Well,

Windows Defender actively interferes with security software development. I've noticed that lots of developers either disable Windows Defender or try to whitelist the development folders. Whitelisting doesn't always work... Windows Defender will block certain behaviors such as token stealing and in-memory attacks.

Also... software developers often have 'test-signing' enabled and all kinds of other security risks that are unique to software development.

Randor··on NSA Recommends How Enterprises Can Securely Adopt Encrypted DNS
I am not misunderstanding anything. Let's terminate this conversation, I can see that it will not get anywhere.

It's amusing that you actually believe that you can 'check the logs' to detect all DoH being performed on the machine. Would you be willing to disclose your employer? "I can check the logs" sounds like something a naive systems administrator would say.

I'm glad that 'security' is your thing. The best thing about the internet is that you never know who you are talking to... Even when you meet people that wrote the parts of the operating system you're currently using.

Randor··on NSA Recommends How Enterprises Can Securely Adopt Encrypted DNS
Actually, no you could not detect that even from the machine performing the DoH. You could probably detect it if you attached a debugger and set a breakpoint on the resolve functions being used. May I ask what you do for a living?

Why even comment on things that you don't fully understand?

Randor··on NSA Recommends How Enterprises Can Securely Adopt Encrypted DNS
An estimated 18,000 companies were affected by the SolarWinds incident. Many of those companies had excellent inventory, logging and configuration control. You simply cannot detect DNS over HTTPS in the network without performing MITM.
Randor··on NSA Recommends How Enterprises Can Securely Adopt Encrypted DNS
I don't understand why people can't see the dangers of moving everything to DoH. For example if you have a 3000 user network and 2900 of them are using a local resolver. You have almost no chance of finding those 100 nodes doing DoH without MITM everything over 443.

Someone will probably respond with something like: "Just block the IP address ranges of public DoH resolvers" and that would work for the resolvers we know about.

Randor··on FDA authorizes rapid, at-home coronavirus test
Yep, I've heard that the actual cost of to manufacture that one was a little over $3 per unit.
Randor··on My fiber optical modem broadcasts a poem via ethernet frame 0x8300
Yeah,

There are dozens of ether-types that are not standardized. There is also 0x8899 which is Realtek Remote Control Protocol (RRCP)

https://en.wikipedia.org/wiki/Realtek_Remote_Control_Protoco...

There are many more but I don't remember them off the top of my head. I probably need more coffee.

Randor··on My fiber optical modem broadcasts a poem via ethernet frame 0x8300
Hmmmm,

Looks like ethertype 0x8300 is covered in this Chinese patent titled "Access-network looped network monitoring method" https://patents.google.com/patent/CN102263658B/en

Chinese version: https://patentimages.storage.googleapis.com/a3/f8/5e/8a9fcd4...

Randor··on Quantum circuit for the fast Fourier transform
> then is there anything self-existing in Nature which could be used to (or does in actuality) implement a Fourier Transform?

The lens in the human eye is continuously doing Fourier transforms via the lens:

https://en.wikipedia.org/wiki/Fourier_optics#Fourier_transfo...

Randor··on EXoDOS: Collecting every game developed for DOS from original media
Hmmm,

Does anyone know if those games come with the manual? In the 1980's DRM was implemented something like "What is the third word in paragraph 3 on page 14 of the manual?" I see several games in there that I remember having this type of protection.

Randor··on Xbox creator Seamus Blackley baked a 4,500-year-old Egyptian sourdough
Hi,

Seamus Blackley worked on the hardware team and is primarily remembered for developing the XBox controller. I didn't work with him but I am a former XBox team member.

Randor··on NASA’s Sofia Discovers Water on Sunlit Surface of Moon
Hmmm,

I am fairly certain that this does exist, I remember almost purchasing a spectroscopy adapter for my iPhone way back around 2014. I didn't buy it and I guess it wasn't too popular.

← PreviousPage 2 of 3Next →