HNHacker News
TopNewBestAskShowJobs

_phred

262 karma · joined January 18, 2009

http://weblog.fredalger.net
submissionscomments
_phred··on Remove TypeScript
A very cursory internet search shows that your history is entirely wrong:

https://agileforall.com/history-of-tdd-as-told-in-quotes/

Djikstra proposed the idea in the 1970s. Rails did not in any way pioneer TDD. They were very vocal about it but “[stood] on the shoulders of giants.”

_phred··on Apple HomePod 2nd Generation
Very helpful y’all, thanks! Gonna see if I feel up to tackling the repair (good excuse to buy a reflow setup) and or get in touch with this gentleman. Cheers!
_phred··on Apple HomePod 2nd Generation
I’ve got two first gen HomePods here which died slightly out of warranty, and AppleCare wanted $300 a piece just to take a look at them. Makes me quite gunshy about spending yet another $300 on a product which may not last more than 2-3 years.
_phred··on N.S.A. Foils Much Internet Encryption
Hmm, yes, I think I conflated the asymmetric vs symmetric cases.

Shor's algorithm is very tasty, but when the real world demonstrations at top research facilities are saying, "yes, we factored 21 into 7x3, but WITH ENTANGLEMENT"[1] it makes me think that scaling to RSA-size prime factors is still a good way off.

Listen, the US government is powerful, but building a full scale quantum crypto decoder ring in complete secrecy _decades_ ahead of everyone else? I just don't think so. Maybe I'm a sheep for not wanting to believe the government so powerful and corrupt, but the whole thing sounds like a tin foil fantasy.

I don't doubt they would if they could, though. And they've done as much as they can with present day tech: supercomputers, mass data collection, penetration of target systems, exploiting SSL's many weaknesses, tapping undersea lines, and legally strong-arming perceived threats into giving up their encryption keys. I just don't think we need to get science fiction involved.

[1] http://www.nature.com/nphoton/journal/vaop/ncurrent/full/nph...

See http://en.m.wikipedia.org/wiki/Shor's_algorithm

_phred··on N.S.A. Foils Much Internet Encryption
Ah shoot, you're right. I'm an armchair crypto geek at best.

In any case, you can choose a public key exponent large enough to still make it a hard problem to crack in a reasonable amount of time. Barring some huge vulnerability in RSA that hasn't been discovered in 30 years of public scrutiny, of course.

_phred··on N.S.A. Foils Much Internet Encryption
The best publicly known attacks on RSA reduce the attack time by a few orders of magnitude at best. A functional quantum CPU could reduce that by a few more orders. Your 4096-bit RSA key is still 2^3072 times harder to break, so even with reductions we're still talking about "heat death of the universe" amounts of time to brute force.

RSA has issues but as of yet hasn't yielded entirely to cryptanalysis.

As the article says, it's easier to attack the system and try to get the plaintext, or coerce you into giving up your key through legal means.

Edit: adding a link to Wikipedia's article on post-quantum crypto, it's a good place to start understanding how to answer these type of questions:

http://en.wikipedia.org/wiki/Post-quantum_cryptography

_phred··on Using Phones/SMS as 2FA – Why I am not a believer
Yes: call/SMS forwarding. It depends on how good your first factor (e.g. password policies) are, and how your reset process works. Getting someone's phone number and setting up call forwarding doesn't require much social engineering savvy to pull off.

http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona...

_phred··on Getting Docker to run on Linode
Looks like it's built around KVM (Kernel Virtualization Modules), i.e. "containers", rather than full-blown virtual machine emulation like Xen or VirtualBox/Vagrant.

It appears to be a configuration management / deployment tool for KVM containers. New to me too, gonna dive in and check it out.

_phred··on Cryptography is a science, not engineering
Wow, that comment thread... does not lend itself to confidence in their project's security.

It also illustrates a really key point about crypto: because it looks simple (oh, just run the bytes through that function/hash/send them over SSL), people assume that it is simple they know enough to hack together a decently secure system.

At the very least, a healthy respect of crypto theory is called for. In my experience most developers do not have this healthy respect and see crypto as a magic black box that makes data unreadable.

I find attacks on cryptosystems illustrative for the "oh CRAP" moment. Oh CRAP salted hashes are a terrible idea. Oh CRAP you can pad a hash to make a remote system accept "signed" data. The more I learn and the older I get, the more cautious I am.

_phred··on Facebook Releases Data, Including All National Security Requests
Hackers built Facebook. They hire hackers. If there's a group that's hardest to pigeonhole in terms of beliefs it's hackers.

The idea that a company composed if hackers could have not a single whistleblower, no single person that objects so strongly that they must speak up regardless of their personal situation is betting against human nature. Nay, hacker nature.

Freedom ain't looking good nowadays, but this is not the vast conspiracy it may seem.

_phred··on iOS 7
Interesting, thanks!
_phred··on iOS 7
I have a theory that the accelerometer-linked 3D "layer" effects might make the flat interface more usable in person. As in, the subtle perspective shift would make it obvious that a button is a button, etc. Can you comment on that? Are those effects extended to all of the UI elements?
_phred··on You are dangerously bad at cryptography
A lot of API authentication is half-assed, like the examples in the article. "OAuth is hard, roll your own" is a common approach. Even with, e.g., OAuth 2, who's to say that the scheme is completely safe and that your implementation is correct?

As far as API vs. user account, it depends on the loot. An API might let me do more damage faster, or subtly lurk and alter/steal data over time. It might also be harder to detect from the UI, no "last logged in" giveaway.

Also, some API vendors recommend disabling SSL cert validation client side. Even for credit card gateways, unbelievably. Since it's a script talking to a script, no one is going to see the cert problems from a MITM until it's too late.

_phred··on You are dangerously bad at cryptography
Right. If the attack vector is "break SSL" I'm going to try some other attacks first. There's an underlying assumption in the question: my app (and everything else hosted on the box) is safe from XSS, CSRF, injections, and other information leakages. Is it really? How do I know for sure?

And who's to say that your forum server (for example) is just as secure? That could be a foothold into your environment too. And let's not forget social manipulation of your staff and users. Maybe I'll just steal the machine in question, or your laptop.

After I try all those avenues, I'm either finding another target or ramping up for a protracted attack on your SSL connections.

If your site attracts this dedicated of an attack, you'd better get that high paid security consultant. ;)

_phred··on Ask HN: What comes to your mind when you see the name "Talentrue"?
O, cruel fortune! I rue my talent.
_phred··on Five researchers deal SSL/TLS a biggish blow
So as a sort-of-amusing counterpoint to this article, I know at least one ASV who insists that the only way to mitigate BEAST is to disable all ciphers but RC4. Still scratching my head on that one.

That tool you posted is great, hugely helpful for anyone who has to deal with this stuff.

_phred··on How I spend my first 5 minutes on a server
There's nothing like good old plain text. :)

Nowadays I'm downright spoiled and use org-mode[1] to keep my systems journals. Org files are plain text as well, and org-mode takes care of setting up the tree by date. I can also add a journal entry from anywhere in Emacs with just a couple keystrokes, which makes it incredibly low-friction to use.

Like I said, the most important thing is to TAKE NOTES. Even pen and paper. It's one of Limoncelli's big points in Time Management for System Administrators.

Tooling doesn't really matter, the important part is being able to remember what the heck I did and when I did it. Invaluable for troubleshooting.

[1]: http://orgmode.org

_phred··on How I spend my first 5 minutes on a server
I'm throwing my hat in the ring. I took the author's original post and implemented it as an Ansible playbook in a little less than an hour.

http://practicalops.com/my-first-5-minutes-on-a-server.html

Happy to answer questions about it. :)

_phred··on Run sudo -k, set your clock to 01.01.1970, run sudo su and boom you're root
Very, very difficult, unless the host relies on a single timesource. Best and common practice is to use 3-4 sources from different organizations in the ISC pool. It also wouldn't surprise me if most implementations of ntpd would have further safeguards about going 40 years back in time; at the very least the skew factor would make the clock change take a longgggg time to happen.

There are much easier attack vectors.

_phred··on Why Use Make
Whoa, your terminal playback thing is pretty neat. Did you use GNU Screen to record the session?
_phred··on Show HN: Build your own Heroku on your own servers
Your last point is DEFINITELY a +1 over Heroku. Although I'd be pissed to lose my deployment & monitoring tools and have to piece it all back together (especially after I thought it was "solved").

Just sayin', this is a tough business, and people get very cranky when things break. :-)

All that said, this is a huge space for new business, and I'm glad to see you guys throw your hat in the ring. Definitely an interesting take on things. Best wishes!

_phred··on Show HN: Build your own Heroku on your own servers
At $9/month I suspect you are drastically under-valuing the service you provide. Sysadmin time is expensive, and your value proposition is the same as Heroku: pay us so you don't waste time sysadmining your boxes. Time is unimaginably precious for small SaaS shops, and if you deliver what you promise, it's worth far more than $9/month.

Not to nay-say, but if you don't price according to value delivered, you don't stay in business long. Your income should grow faster than the infrastructure that you need to run the business.

It's also not clear what company is backing this service and how you're structured. Are you VC-backed? What happens when the money runs out, am I left holding the short end of the stick?

_phred··on Start a timer via the url
Now, on alert completion do this:

  window.location.href = 'nyan.cat';
Neat little app, nice to see a simple non-Flash version of http://e.ggtimer.com
_phred··on Fabrice Bellard: Portrait of a super-productive programmer (2011)
Flip side: don't feel tiny in comparison to this guy's achievements.

Did he bang out LZEXE the first time he sat down at a terminal? Probably not. But over time, through pursuit of a passion and hard work, his skill has progressed incredibly.

We can get there too, with persistence. And we can have fun on the way.

This is as much a reminder for me as anyone, I have a tendency to compare myself to amazingly talented and productive people and get discouraged with where I am now. But you know what? I'm farther along than I was a few years ago, and that ain't nothing. :-)

One of my favorite quotes on the subject:

   "Never compare your beginning to someone else's middle."
_phred··on Why you shouldn't do what Aaron did
>> Depression robs you of the ability to: 1. remember happiness 2. feel happiness 3. anticipate happiness 4. make considered decisions

Just a friendly reminder that depressed people cannot, for the most part "snap [ourselves] out." If the solution was to double down and power through I'd have cured my own depression years ago.

The shitty thing is that it's a long-living subconscious emotional drain. It's a downward slide that for me happened so slowly I didn't even notice until I'd lived at the bottom, completely burned out on life and barely functional for two years. It's not only a mental disorder, it's technically called "psychomotor depression" because it will by degrees affect mind and body in a downward spiral.

I've never lost sight of the bigger issues, the disorder and opportunity for change in world-at-large, but it's impossible to make meaningful progress toward /anything/ whilst waking up every day with a gnawing emotional emptiness and pain thrusting itself into the center of my consciousness. It's care about those bigger issues and for my family that has kept me in this world.

My point is this: whether you mean to or not, you suggest that people can get themselves out of depression. In general, this doesn't happen. Therapy, medication, and support of friends, combined with healthy living have begun to move me forward in my own struggle.

I hope to see in my lifetime an elimination of the social stigma of depression. We're not miserable entitled bastards that need a reminder of our incredible opportunities. We're folk who feel sad and whose brains work in a way such that we can't always see the way forward. That's all there is to it.

_phred··on Make the Metric system the standard in the United States
Yep, learned metric as well as imperial, and how to convert between the two. Primary school was ~20 years ago for me.

High school science was all in SI, of course.

_phred··on If I was your cloud provider, I'd never let you down
See whoownsmyavailability.com for details.
_phred··on Patent #7028023: Linked List
Somewhat like a Skiplist, which is introduced in a 1990 paper: http://en.wikipedia.org/wiki/Skip_list

I'm certain that at least one older algorithms text I own mentions skiplists, and there is no doubt much other prior art here, seems like the kind of thing that might find its way into kernel scheduling queues.

_phred··on Making Twilio calls from Zabbix
Nice to see Zabbix getting some love, it's a good and simple monitoring system. I've already got my Zabbix install talking to Hubot, Twilio integration is next on the list. :)
_phred··on The weakest link by far is Apple
"Oh, shoot, I have so many credit cards... is it this one? This one? This one?"

Seeming clueless when doing malicious things is unquestionably a form of social engineering.

Page 1 of 3Next →