HNHacker News
TopNewBestAskShowJobs

Thriptic

3,517 karma · joined February 3, 2014

submissionscomments
Thriptic··on A hacker's mom broke into a prison and the warden's computer
That's exactly why social engineering works: biases and assumptions. People are absolutely generally more willing to help a woman than a man for a variety of reasons (perception of harmlessness as you point out; people assuming women are incompetent; guys wanting to help to increase sex appeal; etc). Men can exploit different social vectors (eg large, imposing men being demanding or aggressive will get obeyed more than other people because we automatically associate size with authority).

It's not the pentester's job to fix social policy, merely to point out that threats can come from a variety of vectors that people don't expect.

Thriptic··on Facial recognition company Clearview’s client list stolen by “intruder”
Agreed. Maybe if the company wasn't doing the things they were doing they wouldn't have been targeted. I have about as much sympathy for them as I do for Hacking Team, FinFisher, et al after their respective breaches.
Thriptic··on To get good, go after the metagame
It's a complicated situation. In our case, the regulations were complicated because:

1. There was no one place that held all the data one was expected to know. Regs were strewn over legislative artifacts, departmental implementatikn documents, best practice documents, and international standards. Also, more than one class of regulations potentially covered efforts in the space. There was also no one site listing the locations of everything.

2. The regulations had evolved from an earlier time where an existing regulatory framework was adopted to try to fit new classes of things, and the mapping didn't work perfectly.

3. The regulations were written in a very high level manner to allow freedom of implementation and to make sure that the regulations didn't constrain tech development. Unfortunately, that meant that there were no suggested implementations which made it difficult for new entrants to the space (especially startups who can't afford to hire consultants) to understand how to actually comply simply.

4. There was ambiguity about what systems fit into which regulatory class as systems were advancing quickly and were changing state over time (ie updates) so traditional regulatory class lines were blurring.

That is where we stepped in. We were making a product that was ambiguously regulated and so we pulled the regs to understand them. Once we figured out how time consuming this was, we tried to make a software system to provide suggested basic implementations to be compliant and which helped companies properly bin their products into regulatory classes. Ultimately the entire regulatory system was changed rendering our product irrelevant, but I hope this shows why the system was as complicated as it was and helps demonstrate that the complexity was not a function of large players going for regulatory barriers to entry but rather a result of natural evolution and technical advancement over time which rendered existing regulations poorly suited for the current environment.

Thriptic··on To get good, go after the metagame
It's more complicated than that. Largely, it just seems that way because most people never bother to understand the rules past a cursory Google whereas big companies have teams of very experienced regulatory professionals from the agencies themselves who are all about it and therefore know every way to tweak inputs so that they trigger certain regulations rather than others. I was working on a regulatory compliance product for a bit and the first thing I did was pull every applicable regulation, standard, and rule governing the space and read them. This took about a month and made me much more knowledgeable than the vast majority of people in the field who didn't even try. Being an expert is about taking the time to sit down and read the RFCs, basically. We don't have many experts because no one wants to do it.
Thriptic··on Haven: turn old Android phones into security cameras
That's going to be hard to deal with, principally because I'm sure many of the control apps only search for devices on your local subnet and don't allow manual specification of IP. If they do allow manual specification of IP, then you could probably do what the other person who replied to your question suggested: multihome a router, establish a hardened second network, and leverage port forwarding. If they don't, then you need to put them on a separate network and put a controller on that second network too (eg an old phone, tablet, smart speaker).

Alternatively, you could set up a bridge by hardwiring the device to a raspberry pi and then use the pi's WiFi to connect to your existing network. You then set up traffic forwarding across the NICs, man in the middle all the traffic, and only allow certain traffic in and out. This avoids the need to create a new network.

Thriptic··on Haven: turn old Android phones into security cameras
Put it on a private VLAN (eg guest Network that can't be reached from main network), pull the Sim card, uninstall all non-essential software, turn off all non-essential services.
Thriptic··on South Korean police impose curfew on late-night studying (2011)
I stand corrected, thanks
Thriptic··on South Korean police impose curfew on late-night studying (2011)
If your goal is to optimize for equality of outcome then the only solution which works is a random lottery. Make the application process multifaceted and what you described happens. Make the application process all about one exam and you get what happens at magnet high schools in the US where 70%+ of students are middle class+ Asians and the rest are middle class+ White people. Throwing more resources / time at an application process and education in general will always yield an advantage no matter what you do.
Thriptic··on South Korean police impose curfew on late-night studying (2011)
As the article notes, this is treating the symptom rather than the problem. When you have a system which dramatically favors graduates from top schools, entrance criteria solely based on single exams, and punishment for single exam failures for life (ie if you don't do well on exam 1 you are effectively booted from the prestigious track forever), of course everyone is going to cram relentlessly for exams. If you send people home from cram schools, students will simply be forced to study at home. I'm not sure what the solution is for this (other than to create more slots at good schools or more good schools) but curfews certainly will not work.
Thriptic··on Jeff Bezos Commits $10B to Address Climate Change
I don't see any mention of Bezos agitating for consumption reduction in that article. I don't see any mention of his personal consumption habits so I'm curious where you got the data on which you are basing your claims (for all your know he has made personal sacrifices). Your entire argument appears unsound as a single individual's consumption has basically negligible impact on the environment (so it is trivial to "offset" it and massively reducing quality of life is basically just virtue signaling) whereas a cash grant of this magnitude could actually have an outsized impact.

> I dislike gross displays of privilege.

You appear to simply dislike people who have much more money than you.

Thriptic··on Activate this ‘bracelet of silence,’ and Alexa can’t eavesdrop
I follow, but what exactly is the real privacy threat here? If we look at an echo for instance:

* The device is hardwired to light up whenever it is listening so you can't be eavesdropped on without some indicator.

* The device only transmits when it is in listening mode. This has been validated independently by multiple people.

* The device has a mute function (granted, software).

* The device can be registered under a bogus account.

* You can turn off all phone call capabilities / external listening capabilities.

* You can pihole it so it won't reach back to Amazon's ad services.

* You can delete any conversation you don't want stored manually, including one click deleting your entire history.

* You can have all content automatically deleted after X days.

So what exactly are people concerned about? Out of all the convos someone could have, a negative one just happens to probabilistically be recorded, you don't notice, and within 90 days someone in law enforcement or entity X figures it out and uses it against you? Someone at Amazon decides to look through your stored conversations and sees you turn on the lights at 5 PM each day?

I'm not saying there are 0 privacy implications with this device, as any device that has a mic and can record remotely has privacy implications. I just feel like the level of angst generated by smart speakers isn't warranted in the grander scheme of things.

Thriptic··on Activate this ‘bracelet of silence,’ and Alexa can’t eavesdrop
This is what I don't understand. Everyone runs around terrified of these smart speakers but have no problem talking around their phones which have mics, their computers which have mics, other devices which have mics, CCTV cameras which are ubiquitous, etc

Do people realistically think attackers are going to start burning zero days against these things to listen to the average Joe's kitchen conversations or bedroom chatter? What is the threat model here?

Thriptic··on U.S. Officials Say Huawei Can Covertly Access Telecom Networks
> The "good guys" (telco/law enforcement) have strict criterias to access it, like court order.

The good guys have a non-transparent approval mechanism for permission which no one can audit. In reality, you have no basis for claiming it's an effective overall control mechanism because none of us can see most of the data. Further, there have been numerous documented cases of abuse like intelligence officials spying on their significant others, parallel reconstruction on cases where secret data shouldn't have been used, etc.

An administrative policy control where application of the control is handled by the people holding the data with 0 auditing by anyone outside the system is not a strict control. Do I trust American intelligence more than the Chinese government or Huawei? Definitely, but that does not let American intelligence off the hook or justify what they are doing with mass data collection.

Thriptic··on Hacked from a lightbulb
Just set firewall policy to allow new / existing connections from your trusted machine to your untrusted ones and only existing connections from your untrusted machines to your trusted one.

Granted, an average user will not be able to figure out how to do this and a standard private VLAN guest network is going to prevent this from working.

Thriptic··on Hacked from a lightbulb
Netgear also has VLAN config through the GUI on some of their higher end consumer routers (eg Nighthawk).
Thriptic··on Online School Ratings and Segregation in America (2019)
It isn't that simple. The public high school I went to is one of the best in the country and was largely comprised of middle class and upper middle class families. The very wealthy largely sent their kids to nearby private schools. The parents of the children at my school were largely professionals / tradesmen / small business owners, worked incredibly hard to get access to the school district (I know mine certainly did), and placed a large priority on education. This resulted in a culture of parental involvement in the schools / their childrens' education and a competitive academic spirit which kept standards high. High property taxes also produced a funding model where at least 95+% of funding was coming from local taxes, local bonds, and communal fund raising by engaged parents. Local people supporting their community schools because they cared. These were being levied against regular homes as well as large homes.

There were attempts made to bus in people from outside but they were fought tooth and nail by families across the income spectrum in the district because the perception was that it was unfair that they had to work extremely hard to get access to these resources but other people could simply show up and get it for free.

Thriptic··on No engineer has ever sued because of constructive post-interview feedback
Even that in a way is useful to them. If they are constantly getting confused, bemused, or angry responses to what they think is honest feedback, it is a red flag about their hiring process.
Thriptic··on No engineer has ever sued because of constructive post-interview feedback
They gain the goodwill of a prospective employee who might cycle back and be a great fit later on in their career (and who has more skills then). It's also about what they don't lose, which is not only me but potentially other prospective candidates. Know what happens when someone mentions they are considering applying to a place that never got back to me? I tell them don't apply there, they waste your time / they don't care about candidates / their interview process sucks. How many people does that person then go tell? I've absolutely punted on applying to places which my friends have said similar things about.

Reputation matters a lot.

Thriptic··on No engineer has ever sued because of constructive post-interview feedback
I disagree with this. I've had two companies contact me and offer legitimate feedback after interviews, and I always left feeling happy and with good feelings about them.

I applied to one company and got a response back which was effectively "we really like you as a candidate, but it doesn't seem like you would be the right fit for this job / it doesn't seem like the interests you expressed in your interviews [which they correctly restated] matched up well with the duties we would have you perform. We will likely have jobs opening up which would align with what you like and you will be on the shortlist of candidates if you apply for those". Was it truthful? Who knows, but it left me feeling happy about how things went and I would consider applying there again.

Similarly, earlier on in my career after taking a few CS classes I applied for a different job, and the response was effectively "You are smart but you don't have the skills we require yet which are [x, y, z]. Come back when you do". What they said was true and I appreciated the feedback.

Contrast that with the myriad companies I applied to and never heard a response back from or didn't get a response back for many months from. I will never apply to these places again because it is clear that they don't respect prospective employees enough to even send a perfunctory email. Boiler plate rejections aren't as irritating but they are definitely still irritating. If you don't provide reasons for not hiring then employees will construct their own reasons, and they may not be true and / or favorable towards your company.

Thriptic··on What to know before you buy or install an Amazon Ring camera
Remote access? Display solutions? Alerting? Availability? Backups? Ease of config? It's totally dependent on your use case.

Did you have to Port forward or set up a VPN for local viewing? Just that will stop 95% of users.

Thriptic··on No One Gets Rich by Shunning New Cars and Lattes
This seems like a silly article. No one is making pronouncements like "you should never ever buy a new car regardless of your income / wealth" or "not making small daily purchases like lattes is the cornerstone of a sound financial plan". What they are saying is that you should be aware of how much those purchasing habits ultimately cost you and make an informed decision. A lot of people who are not Kawhi Leonard never consider how such purchases impact their financial well being.
Thriptic··on OpenSnitch is a GNU/Linux port of the Little Snitch application firewall
Security through obscurity is one reason. A lot of script kiddies will blast away at services on well known ports. Simply changing the port off the default cuts down on a lot of script based attacks, inhibits generic port scans, and makes it easier to differentiate a deliberate, human attacker from a script.

In this specific case, I don't know. Perhaps rotating through ephemeral ports is done to mess with simple traffic filtering rules on firewalls?

Thriptic··on Young people are funneled into fields that don’t reward risk-taking
Agreed, these sorts of pieces really irritate me because they almost seem to be blaming young people for following basic incentives. Want people to go into an abandoned field? Great, pay them more than jobs they are equally well suited for, give them autonomy, grant them social status, or give them a great lifestyle. No one with other prospects is going to come to a profession if they are paid like shit,treated with no more deference than a fast food worker, saddled with a million regulations from the government, given no autonomy, and / or granted no job security without commensurate upside potential. This is not hard to understand.

The government / employers simply don't want to put their money where their mouth is.

Thriptic··on Sci-Hub users cost ASA journals thousands of downloads
I assume most of the users of scihub have legitimate access to some content. Even the most well funded universities don't subscribe to every journal. When doing a lit search, it is very common to wind up with many potentially interesting papers you don't have subscription access to. Getting access to these papers legitimately involves writing request forms for each individual paper (as access typically costs something like $40 per paper) and then sitting around for between a few hours and a few days before being granted access. Frequently the papers don't even contain the data you want (which you can't know in advance because you can only see the abstracts before paying), rendering the entire exercise a waste of time. It's far easier to simply jump on scihub, get the data you need immediately, and sidestep this process.

It's also not like there was no piracy before scihub showed up. When I encountered a paper I didn't have access to back in the day, I would ping all of my friends at various universities / companies / hospitals and request that they check if they had access. If so, I would ask that they download it and send it to me. They would do the same when appropriate. Even doing this was more efficient than going through official channels, and every time this was done it represents another lost sale. From a user perspective, the piracy has nothing to do with money and is instead entirely about friction.

Thriptic··on 82nd Airborne unit told to use Signal or Wickr on government cell phones
What data is known exactly? Phone number? IP?
Thriptic··on U.S. surveillance laws have proven ineffective at countering terrorism
Assuming that surveillance works (and I'm not really sure it works well) then the alternative is terrorism and crime. I agree we need some level of surveillance, but the question is at what point do the risks of the surveillance (suppression of democracy / dissent, self-censorship, loss of privacy / liberty, concentration of rich data for misuse by bad actors, etc) outweigh the risks of terrorism and crime? Just because we can bring terrorism and crime to zero with max surveillance, doesn't mean that it's in the best interest of society to enable such a system.

Personally, I'm willing to accept a level of risk from terrorism and crime if it means that I get to live my life the way I want to without being constantly monitored by government.

Regarding checks and balances, it's extremely hard to have robust authorization when the group calibrating and performing the authorizations is the same group or adjacent to the group who wants to look at the data. To do it well you need true, apolitical, independence between gatekeepers and users, and users can never be in possession of the actual data because access control can be easily bypassed if this is the case. We have never had that in this country, countermeasures against misuse always seem to be non-transparent and policy based rather than technical (ie secret courts and warrants that no one can actually audit), and data is repeatedly misused over and over with no consequences (eg parallel reconstruction, people spying on partners, people spying on celebs, etc).

Thriptic··on Cloudflare is turning off the internet for me
Somewhat of a topic hijack and a naive question, but assuming Cloudflare is a government entity, wouldn't they still have to comply with whatever their terms of service / contracts with their users are? As they are a US company, barring illegality, theoretically they can't actually do shady shit without being in breach of contract right? They would also open themselves up to shareholder lawsuits.
Thriptic··on Ask HN: Courses/resources to improve my self-esteem and believe in myself more?
As a powerlifter who has dealt with depression many times in the past, I totally agree. The beauty of lifting is that it gives you a set of goals with very clear success metrics that are readily attainable. There are also well proven programs for success into the intermediate level that don't require much tuning regardless of discipline (bodybuilding, powerlifting, weight lifting, strongman, etc). No matter what happens in your professional or personal life, the iron will always be there for you :)
Thriptic··on Students defeat new 'Barnacle' parking clamp, skip fines and get free internet
The school should pay for it out of their capital funds from their endowment. A lot of Midwestern schools have literally no public transportation so if you want to go anywhere you need a car. Stop looking at basic services as cash flow generators.

Also, schools frequently are in charge of public transportation in the form of shuttles, buses, safe rides, etc.

Regarding subsidies, yes everyone should pay because it's a community and that's how communities maintain large collections of shared infrastructure equitably. Spreading the costs over a large group keeps them down for the individual users. Also, you can extend that logic infinitely. Why did I have to pay for football fields I never got to play on? Why did I have to pay for performing arts theaters I never used? Why did I have to pay for community facilities that weren't targeted towards my race or religion? Why did I have to pay for expensive research labs in departments other than mine? If you abandon the community model then everyone ends up getting slammed with highly variable usury taxes that they may not be able to pay.

Thriptic··on Students defeat new 'Barnacle' parking clamp, skip fines and get free internet
Junkyard denial of service, amazing
← PreviousPage 3 of 29Next →