HNHacker News
TopNewBestAskShowJobs

ZephyrP

630 karma · joined January 10, 2011

submissionscomments
ZephyrP··on Against an Increasingly User-Hostile Web (2017)
my account is a year older than yours and I've never been asked by shadowy interest groups to astroturf, do you have any tips to improve my account's brand appeal?
ZephyrP··on Signal threatens to dump US market if EARN IT act passes
For the purposes of entropy, you need only consider 10 valid choices for each symbol of a phone number so it's closer to 33.21 bits (10 * (log(10) / log(2))) and smaller still when discarding impossible area, trunk & subscriber numbers.
ZephyrP··on Microsoft is retiring its MCSA, MCSD and MCSE certifications
I think Cisco certifications, even the CCNA, are suspended from scrutiny by many, even in disciplines famous for their cert-skepticism like infosec.

There exist other prestigious certifications, but they generally lack the reputation for seriousness that Cisco is credited with, even crystallizing into a semi-mythological reputation for playing unfair on behalf of recipients with refusals to license IOS ELX and even lucrative hardware sales to organizations which don't have CCIE on staff.

ZephyrP··on Sarah Connor, in hiding before the war
purchasing a corporation with the intention to liquidate it's assets for profit, often found seated next to "leveraged buy out" & "pharmaceuticals price hike" in the American Lexicon Association.
ZephyrP··on The general value of typed functional programming lies in leaving no edge cases
plenty of other languages do so, but it's both unfairly diminishing to the parent & questionably correct to refer to it as "basic type safety stuff"
ZephyrP··on The general value of typed functional programming lies in leaving no edge cases
If you compile with `-Wall` GCC will emit a warning for failing to exhaustively check enum values inside a switch statement

(I don't remember the specific underlying feature flag name, sorry).

EDIT: It's called `-Wswitch`

ZephyrP··on Vice Ventures is investing in taboo industries that other funds won’t touch
I actually just happened to be hanging out downtown and found myself at a convention for people devoted to answering just that question!

DeltaFOSB is a gene transcription factor and is the precursor for the development of all forms of what is clinically called "addiction". However what the other commentators suggested [food is not addictive] is not actually true, it has a measurable affect here. In fact, Delta-FOSB can be and often is used as a biomarker of addiction in patients who are already deceased (and can have their brains broken open).

Now, as to the question of addictiveness, nobody mentioned anything about pornography there, but I did hear an interesting anecdote about the raw power that certain addictions have that clearly isn't present in pornography; Delta FOS-B accumulates in the ventral tagamental area and nucleus accumbens, two central regions of the brain, and many drugs have the action of creating floods of FOS-B precursors there, for example, this effect is so strong in heroin addicts, that they nearly always throw up upon recent re-exposure (sometimes newer Methamphetamine addicts as well) where the mechanism here is the flood of FOSB, which an outer region (she had mentioned but I have already forgotten which) interprets as "poisoning". So while it may be true that pornography is "addicting" - when is the last time you saw someone throw up when they looked at pornography (modulo ordinary "disgust").

What was doubly interesting was that she said the change in dopamine regulation (meaning the introduction of new dopamine-like substances + the change in the rate that your body "reuptakes" dopamine) in the most powerful addictions -- benzodiazapines and opiates, aren't actually that high, and compared with drugs like methamphetamine and cocaine aren't much different from marijuana.

It's this secondary affect that creates these changes in reasoning and reward structure with these drugs (she also mentioned that both have "withdrawal", which while technically unrelated to addiction is extremely painful and sometimes life-threatening).

However, to be fair, it was repeatedly stressed that the "secondary" affect was more than just Delta-FOSB. There were changes in signaling, new kinds of peptides that unaddicted people can't produce (???), something about phosphoration of camp ("new notes on camp") and bunch of change to "Dendritic Spiny Structures".

Among the living, questions like "drug-use reinstatement likelihood", "place conditioning preference" (the more addictive the drug, the more you want to use it in a safe, known place), increase in use over time, etc. are how this stuff is generally measured with reasonable economics.

ZephyrP··on Structure and Interpretation of Computer Programs (1996) [pdf]
There's a case to be made for alternatives to MIT Scheme. A good example of this is the exercises where you might employ the OOP system that SICP describes like the constraint-solver or metacircular evaluator but realize that you could be much more productive if you had some kind of controlled method for generating similar piles of code from some base implementation, something which is found in the object systems like CLOS like GOOPS or ChrisH's SOS or even Emacs's EIEIO here [2].

There's no impediment to completing Chapters 1 & 2 in Clojure, but the first chapters are not what is called to mind by "Structure and Interpretation of Computer Programs" [1].

- Function redefinition is extremely useful required if you want to write your code in a linear fashion as intended. Clojure automatically sets up a major hindrance here.

- A few subchapters explore parallel computation, Clojure is likely to lead you astray here as you try to find directly corresponding functions and why exactly the authors are suggesting.

- Several chapters explore mutable lists in detail. Serious complaints have been made about the suitability of Racket here, where there exists no more of a barrier than that methods which operate on mutable lists are prefixed with a specially named qualifier. Clojure would be functionally impossible here.

- On the plus side, the "JIT" meta-evaluator will be a much more interesting challenge!

You'll notice that all of these issues can be worked around. However, SICP with exercises will take you about a year if you're a serious student.

[1] Huffman trees exercises excluded.

[2] Doing the whole thing in Emacs Lisp is potentially fantastic. I don't know if I can wholeheartedly recommend it, but I would be really pleased if someone wrote tests and built the metaevaluator, compiler and really went the whole nine yards here.

ZephyrP··on The cost of parsing JSON
JSON is a syntactic subset of Javascript in ES2019 [1].

https://github.com/tc39/proposal-json-superset

ZephyrP··on Algorithm No One Knows About (2016)
Good eye, `input` should be replaced with `result` when building the subkeys within the loop.

Here's a working implementation:

  function feistel(ctr, lr, ll) {
      let result = ctr;
      for (var i = 0; i < 8; i++) {
          let l = (result / ll)|0;
          let r = result % ll;
          let temp = r;
          // alter round fn's multiplier & increment accordingly.
          let fn = (r * 16807 + i) % lr;
          r = (l + fn) % lr;
          l = temp;
          result = lr * l + r;
      }
      return result;
  }
  
  let rsize = 8;
  let outputs = new Set();
  for(let i = 0; i < rsize * rsize; i++) outputs.add(feistel(i, rsize, rsize))
  for(let i = 0; i < rsize * rsize; i++) if (!outputs.has(i)) console.log('failure: ', i);
ZephyrP··on Algorithm No One Knows About (2016)
You can draw the cards in a random order by using the output of an accumulator fed to a block cipher as an index. The fixed output size of a block cipher does entail extra work in filtering numbers outside the range you'd like, just as you would with an LFSR. (as a direct power of 2, you could directly use an LFSR or some ECB-mode block ciphers as if it were format-preserving, but that is "coincidence").

You can produce an exact random permutation with a Feistel network for any number, in this case selecting every number between 0 and 2^64 exactly once, with no appreciable space requirements.

   procedure feistel(input) {
      result = input;
      h = 2<<32;
      for (let i = 0; i < 8; i++) {
          l = (input / h)|0;
          r = input % h;
          temp = r;
          fn = (r + i) % h;
          r = (l + fn) % h;
          l = temp;
          result = h * l + r;
      }
  
      return result;
  }
ZephyrP··on The Soul of Erlang and Elixir [video]
BEAM doesn't do everything containers or a container orchestration system can, but in view of my relatively short time as a regular Erlang programmer (definitely less than 10 years), the spirit of tidepod's point accords with my experience (with a weaker interpretation of his term "node clustering"). BEAM and OTP don't do automatic load distribution between nodes, but can be fashioned to do so easily with application support.

We never used pool. The nodes were mapped onto heterogenous machines sharing the host with a 3rd-party daemon. It's configuration changes even took place through a module update hook written in Erlang itself. We both deployed new code and distributed work "manually" across them entirely on OTP.

[NOTE] It it surprising, or was to me, that there are problems with having a fairly small number of nodes fully connected. I'm lucky enough to have avoided learning this the hard way, but imagine this could serve as a painful backbone to an "Erlang deployment war story".

ZephyrP··on What's Deoxyribonucleotide in Sign Language?
I once asked a deaf programmer how technical concepts were communicated. He explained that most non-practitioners would use finger-spelling but that a parlance among deaf programmers existed to convey a variety of technical terms. I vividly recall the sign for "Port Scanning" made by tracing an oblong ellipse oriented upwards with your index finger and then "pushing" that finger through the imaginary figure 3-4 times from the top going downwards.

I imagine a similar set of signs arising in different disciplines.

ZephyrP··on Racket Is an Acceptable Python
He's making reference to Steve Yegge's riff on Eric Kidd's post, which kicked off the whole "Are Xs acceptable Ys" blogpost template.
ZephyrP··on A better zip bomb
I work at a threat intelligence firm which provides services for aggregating desktop antivirus engines & specialized malware detection tooling; I've submitted dozens of public and manually constructed compression-bombs for analysis (including this one). Many antivirus engines, even very small vendors, handle this case better than you might imagine.
ZephyrP··on Modern SAT solvers: fast, neat and underused
When considering a small number of possible operations, I've found the optimum way to work this is to simply enumerate all binary expression trees of increasing length and determine if some valid assignment exists for any of them.
ZephyrP··on Modern SAT solvers: fast, neat and underused
This is a description of what lead to it: https://www.reddit.com/r/ReverseEngineering/comments/5h23u3/...

If you want more information about the vulnerability and mechanisms of exploiting it, project members assigned it CVE-2016-10253 .

ZephyrP··on Modern SAT solvers: fast, neat and underused
I found two remotely exploitable 0days in the Erlang VM with the use of a SAT solver.

They can trivially break lots of hash algorithms. You can also find bitwise equivalents to functions which you wouldn't naturally expect to be easily definable in terms of bitwise operations. You can extend existing concepts with a lot of extraordinary new functionality.

ZephyrP··on Mathematics as thought
so performance is ability plus the contribution of all other factors that are not ability.

tough to argue with that one.

ZephyrP··on Paul Graham on SICP (2000)
The lectures are good but I think the book is really unparalleled in it's original format. It stresses building the intuitive sense of deep structure, which I think other formats would have difficulty communicating.

I personally thought the biggest barrier was the mundane, so I tried to write up some tips, test cases and helpful utilities for doing SICP ( https://github.com/zv/SICP-guile ).

ZephyrP··on Massacring C Pointers
> I'll bite: argument from authority can be reversed - if Brian didn't mess up the language design, these sort of "code drivels" wouldn't have appeared

i dont know, awk has its faults -- but blaming it for C?

ZephyrP··on Massacring C Pointers
I always wondered about the C tutorials Brian Kernigan mentions in his talk ( https://www.youtube.com/watch?v=8SUkrR7ZfTA ) , many of the examples seem intentionally designed to be incorrect by some trickster spirit.

Now I know the even darker truth.

ZephyrP··on Pentagon Puts Cyberwarriors on the Offensive
Are there any credible cases of an individual coming forward with damaging state secrets or leaks that Wikileaks had refused to publish?
ZephyrP··on Teach Programming to become a better programmer
I had almost exactly the (almost the exact?) same experience.

I was 12 when I picked up a "Head First Java" at the library. The first chapters on for loops and variables were a breeze, but after a few more the book started a new program of loosely analogizing various function specifiers to real-world ontologies; all against the background of a writing style that emphasized that programmers can also write (and poorly photoshop) in a "WILD & ZANY STYLE THE KIDS WILL LOVE'. Yes, I'm starting to remember the trauma now: "Vehicles and Cars" or 1-Stripe Zebras vs Zebras-with-many stripes vs a Zebra with a stripes attribute...

I had no problem with a for loop to print "FUGAZI SUX" 99 times, but the book wasn't communicating how these concepts were important to making a nontrivial program in Java; which I desperately wanted to do so badly.

A bit later, I downloaded a book about writing computer exploits, which was very basic and very direct. Strangely, dealing with computers at this extremely basic level of stored instruction pointers, buffer overflows and assembly language actually let me gain the skills required to be an "actual programmer".

ZephyrP··on Crystal 0.25
Erlang absolutely does have this 'in common', and it makes this faculty known every time you start up the Erlang REPL.

In fact, I think there's a case to be made that it may have the most refined implementation for scheduling M:N processes (along with more advanced thread affinity, alternative RQ dispatching, SMP awareness, etc).

ZephyrP··on Crystal 0.25
I get where you are coming from (although, in the case mentioned above at least, an order of magnitude faster places it within 150% of the speed of Java). I think you're only scratching the surface of Erlang here though. I believe "networked services", "millions of connections" and "hot-code reloading" are a meme that hides the Erlang's real utility.

Along these lines, the most popular open-source subdivision 3d modeling software package is, outside of the shaders, written top-to-bottom in Erlang (including the engine).

ZephyrP··on Crystal 0.25
The benchmark game's "results" peg some toy programs in Erlang an order of magnitude faster than Python 3.

Of course, you probably foresaw another classic interpreter-speed justification coming from a mile away, but.... There are very well-developed methods of interfacing with fast native code, ranging from C nodes to nifs. The documentation is circumspect about using C code, but nevertheless provides you with the good, bad and the ugly on these various different methods.

If anything, I think Crystal could crib a page from Erlang and elevate what it calls "Fibers" and "Channels". Erlang made these first-class in both design & syntax, which allowed Pids and messages to be not just building blocks of concurrent interaction patterns, but also architectural utility-knifes in consecutive Erlang code. The more Erlang you read, the more you see this really powerful method of dividing concerns "physically" rather than "structurally", in which you can be doing everything from implementing Objects (for some definition of OOP) to representing recursive data structures with lightweight threads as the "backing primitive". This may be obvious to some old-head Lisp programmers, but I about choked on my latte when I saw this demonstrated at the first Erlang shop I worked in. It's a cool and extremely powerful idea that can be implemented in any language, but is best if the spawn/message syntax is concise.

ZephyrP··on Why emergency braking systems sometimes hit parked cars and lane dividers
Reading this comment (and the many like it) I get the feeling that something essential must be getting left out when we're speaking of the "far-off mass-deployed self-driving tech". Mostly because it directly contradicts my day-to-day experience.

I've personally seen a few "self-driving cars" on the streets of SF and I suspect many of you reading this have as well (particularly if you live in the Mission or South Park).

Just last year I was talkng with engineers at the self-driving car company "Cruise" which had a free internal app to taxi employees around with a self-driving car. I personally saw the tech demoed. One of the engineers called one up to go drinking the weekend prior (sans drinking buddies - company policy). He claimed his coworkers come to work in them occasionally. The cars and engineers could be a grand charade but it seems like "self-driving cars" are already used by non-daredevils every weekday.

I learned to drive on backroads of rural Colorado; It may be these cars are safer than I in the sometimes "adverse" driving conditions of San Francisco.

Is this really how a distant technology looks?

ZephyrP··on VFS shim that allows a SQLite database to be appended to another file
There exists an Erlang unikernel (of sorts): http://erlangonxen.org/
ZephyrP··on LocationSmart Leaked Location Data for All Major U.S. Carriers in Real Time
I have never seen him code, but I personally spoke with weev a number of times while he was a regular at a (in)famous SF hackerspace.

He demonstrated a thorough familiarity with ptmalloc internals, enough to correct someone else's remark about fastbins (meanwhile taking frighteningly large hits of whippets).

Additionally, he was the first person I had ever heard mention Rust.... wayyy back in 2012 (I'm embarrassed to say I thought he was talking about Racket and tried to correct him - I was 19 and thought I knew everything). He seemed to know quite a bit about the language even then.

He continued to discuss other topics arising from this with other hackers. One such conversation I remember more clearly was his exchange with another hacker (a quite skilled one by my estimation) where he seemed to speak rather cogently about the relative merits of a complete semantic tableaux and SMT solvers to determine "real ptr lifetime" (beyond just adhering to a set of idioms that enable a constraint solver to verify reference use).

So if he can't code PHP, then that's even more impressive.

 

As an aside - in person, he came across as very warm, funny, charming and even deliberately inclusive.

It feels strange now, but long ago, if you looked at him with the right shades on, he'd seem to give a nudge-and-a-wink that the "trolling", including his iconoclastic project of the time: the posthumous baptism of Muhammad's remains via becoming a Mormon deacon (of some sort??) were all intended to be thought-provoking irreverence rather than chaotic evil. No matter what was discussed he always gave the impression there was something more there, something almost hermetic.

In those intervening years my view of him has assumed a different proportion. Those weren't all harmless culturejamming tricks pulled off in the name of some Discordian spirit which lies somewhere behind the neocortex of the hacker mindset. At that time, and many years before then, there were pranks, tricks and trolls that were unimaginably cruel, purposeless and petty.

Since, prison has hardened him further into a wicked racist, who, lacking a better word, is insane.

← PreviousPage 2 of 8Next →