HNHacker News
TopNewBestAskShowJobs

RustyRussell

1,432 karma · joined May 20, 2011

[ my public key: https://keybase.io/rusty; my proof: https://keybase.io/rusty/sigs/uWS-VceJTes_fyFrtfO5WNTj-smrhHV67zLX0yUDzhI ]
submissionscomments
RustyRussell··on Pikachu Volleyball
I'm sorry, I think you misunderstand the technology. Hardware virtualization covers much of the CPU cases, but there are still three attack surfaces: handling the guest instruction traps on the host side which can actually get quite hairy in corner cases, the devices the guest drives, implemented in software on the host side, and shared hardware information leakage.

These are all improving: hardware support is generally getting better and guests modified to behave nicer so weird cases can just fail, and devices are often now specifically designed for virtualization (plug for my old project VirtIO here!). But it's still software, and asserting there are no bugs left seems incautious.

The information leakage problems are an ongoing whack-a-mole which depends on your setup: they may or may not result in escapes, depending on the nature of the secrets.

Of course, higher level bugs are still there: convincing people or software to change settings, install software or pass too much information through existing channels which are perfectly secure!

RustyRussell··on Ask HN: What underrated open source project deserves more recognition?
https://tdb.samba.org/

Trivial key/data database with great performance and robustness. Embedded in surprising places (e2fsck!) and my go-to unless I need Sqlite3.

RustyRussell··on So you think you understand IP fragmentation?
Perhaps. I would have phrased it "Nobody understands IP fragmentation", but sometimes when delivering to a room of experts you need to increase the volume a little bit.

Of course, it really depends on whether you can actually back this up! And in this case Val does, quite clearly.

RustyRussell··on Three virtues of a great programmer
I always said the fourth virtue is fear (of complexity). Keeps the others in check, particularly hubris:)
RustyRussell··on Ask HN: Does anyone care about OpenPOWER?
Despite the brilliant work by some IBM engineers (much from my ex-colleagues at OzLabs) there was no strategy to get commodity Open power. Even opening up was more a "throw over the wall" rather than a sustained effort.

Developing a proper Linux little-endian ABI was a major engineering feat, across kernel and toolchain, but nobody understood what to do with it.

RustyRussell··on Ask HN: Does anyone care about OpenPOWER?
Dropped in the latest Power chips I believe.

I had a friend who worked on it: he called it simply "decimal floating" because there was no point :)

RustyRussell··on My favourite Git commit (2019)
I was told by a recent contributor that my approach (i.e. requirement) to git messages is "unique". Apparently my Linux kernel background is showing, but all my commit messages look like the one shown here!

If about existing code, the comment belongs with the code. If it's a process thing (e.g. code that is removed or didn't work), it belongs in the commit.

Most importantly, while commit messages can reference issues for convenience, they MUST reproduce the critical details: GitHub is transient, git messages are not!

RustyRussell··on Macaroons Escalated Quickly
Oops, I read further: you did use unique ids, and blacklists! I did that too. Now you're not db-lookup-free on use, so you need to think hard about what all this actually gains :(
RustyRussell··on Macaroons Escalated Quickly
Compulsory plug when someone uses macaroons: using an HMAC is overkill.

See https://github.com/rustyrussell/runes for a simpler alternative and implementation (this has C and Python, but there's also a Rust implementation because why not?)

However, the "no db access" property has proven to be untenable in practice. Users end up wanting to see what runes are issued, blacklist them, know when they were last used, and have rate limits. The last two are a killer, requiring some state to be kept (unless your system allows you to return a modified rune to the user, which is a different workflow from normal bearer creds).

RustyRussell··on Real estate giant China Evergrande will be liquidated
This is ridiculous, sorry. The NY AG investigation showed Tether was actually mostly backed at the time (surprising me, too!)

And the Blockstream FUD is tired (I am the longest serving technical employee at Blockstream)

RustyRussell··on How I got an O-1 visa as a software engineer
For those who don't know the jargon: an O(1) Visa gives you constant-time access to the US.
RustyRussell··on We build X.509 chains so you don't have to
This looks great!

I wanted to bundle a chain of certs, check that the leaf was <some domain> and its key signed <some data>, and that the bundle provided a path to a locally-trusted root. This allows third-party serving of signed data, rather than having to trade your IP address for validation.

Doing so with existing tools was so terrible that I was pretty sure my result was grossly insecure :(

I look forward to the promised lower-level APIs!

RustyRussell··on Memory leak proof every C program
Hilarious!

But I remember the first time I saw such a program which never freed anything: jitterbug, the simple bug tracker which ran as a CGI script.

It indeed allows a very simple style!

Meanwhile, use ccan/tal (https://github.com/rustyrussell/ccan/blob/master/ccan/tal/_i...) and be happy :)

RustyRussell··on Tether reveals partnerships with Secret Service, FBI in letter to U.S. Senate
Yes. The history of authorities protecting users before failure in the cryptocurrency world is fairly empty, however.

TBH I'm not sure if they're allowed to operate in NY though.

RustyRussell··on Tether reveals partnerships with Secret Service, FBI in letter to U.S. Senate
Yes, the NY investigation was all about this: they patched up the loss and quietly changed their terms to being backed by cash or equivalents.

And they later detailed the $1bn Tether printed for Celcius in return for collateral (once Celcius collapsed and they claimed it was fully repaid).

Understand: for modern banks this kind of fractional behaviour is considered normal. It's only from the weird Bitcoin perspective that full reserve would be a requirement.

RustyRussell··on Tether reveals partnerships with Secret Service, FBI in letter to U.S. Senate
This could well be true!

But remember, the crypto exchange market is also extremely large and profitable, and yet exchanges keep turning out to be massive frauds.

The number of people who promised to keep your money safe and had long term incentive to do so and yet failed miserably used to astonish me. Now I assume it's the norm.

RustyRussell··on Tether reveals partnerships with Secret Service, FBI in letter to U.S. Senate
Except we know of occasions they printed tether in return for collateral promises, rather than actually for cash. Not to mention filling a hole with Bitfinex stock when one of their processors got raided.

Now, it's just a question of degree: they're so profitable they can recover from being fractional rapidly. OTOH, why mess with a working formula?

RustyRussell··on Bitcoin Core 26.0
You keep saying this. It's not true.

(I work for Blockstream, and we have no current employees in the top 10 contributors for this release AFAICT)

RustyRussell··on Bitcoin Core 26.0
instagibbs has worked for Blockstream in the past, but that's all I can see.
RustyRussell··on Bitcoin Core 26.0
This is blatantly false. And Luke never worked for us.

(I am the longest serving engineer at Blockstream).

RustyRussell··on Mastering Emacs
I would learn a lot, but I really want a printed version! Maybe I can convince the local print shop do to it double sided and bind it?
RustyRussell··on Debugging a Futex Crash
Ok, I did a double take. It's a different Rusty playing with futexes!!
RustyRussell··on Milk Sad Disclosure
Sigh. I did not know that, thanks :(
RustyRussell··on Milk Sad Disclosure
Worth noting: libbitcoin is an obscure project with an impressive name.

In that it's not used by bitcoind or any wallets I know of: it's mainly of interest here because the book Mastering Bitcoin used it for examples.

RustyRussell··on Distcc: A fast, free distributed C/C++ compiler
Wow, it's still active! I remember when MBP wrote it while we were working at OzLabs together.

One day I'll get back to that rewrite of ccontrol using modern distcc's features...

RustyRussell··on Most Bitcoin Inscriptions belong to a single person
This first paragraph is simply untrue. You are always holding a valid signature to spend the latest funds.

The additional assumption vs simply holding your own funds is a throughput requirement: that miners not censor your transactions for some (up-front-chosen) period of time.

With normal funds there is a non-censoring requirement, but it's more vague since the miners may have to censor you forever to make your funds useless.

RustyRussell··on Most Bitcoin Inscriptions belong to a single person
Well, in practice the mining subsidy is highly variable, as most miners' costs are in local currency, so fees are already set by the market.

But I agree that the NFT thing is really a side-effect of fees being low (thus, cheap distributed storage) which probably at best provides a price floor, rather than a sustainable source of revenue.

RustyRussell··on Most Bitcoin Inscriptions belong to a single person
Yes, Bitcoin is designed to migrate from the current inflation subsidy to fees paid by the users of the system.

https://rusty-lightning.medium.com/the-three-economic-eras-o... for more detail that you probably want...

RustyRussell··on Most Bitcoin Inscriptions belong to a single person
Oops, too late to edit, but apparently this is a paid inscription service, not a single whale user: https://twitter.com/mononautical/status/1663383996561072129?...
RustyRussell··on Most Bitcoin Inscriptions belong to a single person
Someone is creating tokens with the hope of selling them onwards. Most of them are created by a single entity, who spent about $30M in fees to do so, so presumably they expect people to buy them, and thus profit.

The only reason most Bitcoin users care is that they pushed up fees for everyone else (there is limited block space, so miners take the highest bids). Such few pressure is expected to be the norm eventually, and has happened before, but there's been a prolonged period (years) of low fees so it was a bit of a surprise to many.

← PreviousPage 3 of 10Next →