HNHacker News
TopNewBestAskShowJobs

a1a

549 karma · joined February 24, 2013

submissionscomments
a1a··on Arch Linux on MacBook Pro Retina 2014
It's like when you are buying a new suit.

You have the mass produced suits that sort of fits you. They are not designed for your needs, they are designed to (almost) fit as many people as possible.

Then again if you want something customized for your needs -- that really looks great on you -- you will have to hire a tailor. This will take some time. No matter what year it is.

a1a··on Show HN: A simple “stateless” password manager for Chrome
Please tell me I am missing something. There is no salt. The hashing algorithm is hence vulnerable to a simple dictionary attack. It does not matter if you do a gigazillion rounds. Someone can still pre-calculate a list of common passwords and then test that list against each and every user.
a1a··on Linux x86 Program Start Up
It might as well say "Real hackers use vi", "Real programmers use vi", or whatever. I do not see why it needs to be gender related.

The author should write whatever he pleases. But I believe it would be proper to use a language directed to a broader audience when writing a public blog post. I also believe that the author was trying to be funny and had no bad intents what so ever, but either way these tiny things matter if we ever want to see diversity in our field.

I would also like to add that your argumentation is quite unpleasant to me. I read it as you believe that diversity is this annoying thing that destroys the good ol' "all dude internet". Would you care to clarify what you meant?

a1a··on Say hello to x86_64 assembly, part 4
Not really answering you. But I feel like sharing the method our lecturer had.

We learned MIPS first and then when people had a grasp of the basics we had lectures (along with intel manuals, abi reference, and some minor internal documents) explaining x64, partly in a "compared to mips" perspective. I believe this method served us pretty good and most had no problem picking up on x64.

a1a··on Doxxing defense: Remove your personal info from data brokers
You should really consider making a non-js version of your website. The noscript googletagmanager iframe is not really screaming "we care about your privacy" either.
a1a··on Introducing Snapcash
It's deserved. Gotta give it to them though, pretty bold move considering.

http://www.wired.com/2014/10/the-snappening-is-not-your-faul...

http://www.foxnews.com/tech/2013/12/27/snapchat-ignored-secu...

http://gibsonsec.org/snapchat/index.html

a1a··on Outernet: Humanity's Public Library
Remember that much of wikipedia (and the internet in general) are considered 'illegal data' in some countries.

In this sense -- I believe that the idea here is to indeed broadcast illegal data. I find this project very interesting because it exploits the fact that we still have national laws in an increasingly international society. Because let's face it, whatever data they might broadcast it will likely be illegal somewhere.

a1a··on Elon Musk’s SpaceX Is Raising Money at a Valuation Approaching $10B
I'd say (without much knowledge of SpaceX's financials) that it probably shouldn't be valued any higher. I'd argue it's fallacious to compare with WhatsApp because it's obviously overvalued.

Adding some perspective:

Ferrari enterprise value: $6.03bn

Heineken enterprise value: $11.857bn

American Airlines enterprise value: $10.666bn

KFC enterprise value: $19.492bn

Audi enterprise value: $17.731bn

Clean water for the entire planet: $10bn

Top 50 college football programs: $15bn

World's music industry: $16bn

Mozambique's GDP: $18.9bn

Sources:

http://www.thedrum.com/news/2014/02/20/19-brands-facebook-co...

http://list25.com/25-things-facebook-could-buy-with-19-billi...

http://www.telegraph.co.uk/technology/facebook/10652397/Face...

a1a··on Show HN: Replace CAPTCHA with Proof-of-Work
$url = 'https://hashcash.io/api/checkwork/' . $_REQUEST['hashcashid'] . '?apikey=[YOUR-PRIVATE-KEY]'; $work = json_decode(file_get_contents($url));

Pretty sure this code is vulnerable to local file inclusion. Running file_get_contents on unchecked user input is a terrible idea, even more so coming from a "security solution".

a1a··on But why can't I send people their passwords?
>>(Question 5) What? No! Why use algorithms that have been broken for years? It’s ridiculously fast to break both, along with many other simple algorithms.

I'd remove the emphasized text. Yes they are vulnerable to collision attacks but that's completely irrelevant in this context.

a1a··on How the NSA can 'turn on' your phone remotely
Second question: I recently spoke with a guy working right now on analyzing off-the-shelf usb-sticks from all kinds of vendors. He called it "night-shift malware" and his advice was to fdisk the hell out of all devices before even considering to use it. This might be old news(?), but my point is that it's not only free electronics you should worry about. Of course free electronics contains another security aspect as these might be used to attack you specifically while night-shift stuff is directed at "as many as possible".

Last article: This is why you should put tape over your smartphone cam. Imagine what criminals (ex. burglars) could do using such technology. Correct me if I'm wrong here -- but I find it surprising that most people care to put tape over their laptop cam but not on their smartphone, why is this?

a1a··on Introducing Pseudo IPv4
Thank you. Sorry for directing the comment improperly.

Feel free to argue the actual argument presented.

a1a··on Introducing Pseudo IPv4
Either way it's an unnecessary risk. People with access to a /smallnumber might still be able to exploit it. I find it quite ironic that they are all like "Common guys, use this new stuff, old stuff is bad!" -- then they go on presenting a solution that makes use of md5.
a1a··on Do It Yourself Whiteboard
Did some quick research out of interest. Melamine and porcelain steel seems to be the most common.

References:

http://mywhiteboards.blogspot.se/2012/06/melamine-vs-porcela...

http://www.whiteboardsetc.com/laminated_panel.htm

http://dryeraseboard.com/aluminum-trim-porcelain-steel-marke...

http://www.usmarkerboard.com/s/Unframed-Whiteboard-Material/...

a1a··on Facebook Hidden Friends Vulnerability?
To be fair it would really be misleading as he wasn't the one who "discovered" America.

>>He was the first person to establish long and meaningful

>>connection with the New World that would eventually tie

>>Europe to the Americas, but it is a misconception that he

>>was the first to “discover” America.

http://sites.psu.edu/mmancini/2012/09/08/1-columbus-was-the-...

Additional source: http://web.dsbn.edu.on.ca/~William.Randall@dsbn.edu.on.ca/FO...

a1a··on Important Notice to Our Users
Possibly, but why wouldn't they say so? It seems reasonable to me that they would blame the heartbleed bug instead of taking the blow themselves.
a1a··on Why I'm sending back Google Glass
I call Poe's law.
a1a··on Why I'm sending back Google Glass
Recording and remembering are not the same thing. You cannot publish, replay, run algorithms on, .. a memory, this should be pretty obvious? Invading peoples privacy by recording them is not part of your rights. It has been possible for quite a while now to record people -- it has never been okey without their consent -- just because "new" technologies allow sneakier ways todo so doesn't magically make it okey.
a1a··on Arecibo Observatory Detects Mysterious, Energetic Radio Burst
Considering that most people couldn't even read regular text back then it was definitely pretty sound, but that's not really my point.

We do? Got any references for that? Take RSA -- it's not even proven that breaking it is equivalent with integer factorization. Even if it was, there are no proof that integer factorization needs to be time consuming at all, there might very well exist an algorithm with polynomial complexity.

a1a··on Arecibo Observatory Detects Mysterious, Energetic Radio Burst
Possibly. We should keep in mind that our knowledge of number theory is very limited. They are probably not really interested because it's all really obvious to them -- and has been for quite a while. It's quite amusing to think about how they might laugh at our encryption systems relying on simple discrete logarithm-problems etc. Not unlike we laugh at Julius Ceasar for relying on simple substitution.
a1a··on How a German Soda Became Hackers' Fuel of Choice
>>I'm English, it has to be done

To be fair it's not quite right anymore: http://www.wolframalpha.com/input/?i=british+coffee+vs+tea

a1a··on John McAfee releases secure anti-surveillance messaging app ‘Chadder’
Not really my topic either but I guess messaging via TOR or alike is the best solution.
a1a··on John McAfee releases secure anti-surveillance messaging app ‘Chadder’
SSL is not only for secrecy, it provides integrity as well.

For example: You cannot be sure the links are valid. The javascript- and/or youtube iframe might be modified/malicious.

a1a··on John McAfee releases secure anti-surveillance messaging app ‘Chadder’
Signing. I.e. Bob encrypts a dummy message or whatever with his private key.
a1a··on John McAfee releases secure anti-surveillance messaging app ‘Chadder’
I think the biggest problem here is that the application claims to be "anti-surveillance" yet it doesn't really solve the surveillance problem, namely meta-data.

If anything this application helps surveillance by filtering out the communication from "regular" communication.

We have had encrypted messaging for ages now. I cannot tell what's new here.

a1a··on John McAfee releases secure anti-surveillance messaging app ‘Chadder’
I do not know what your objections are. It's pretty straight forward.

I guess it's something like:

For messages: AES

Key exchange: RSA

Alice and Bob both generates their own RSA keypair (the server do not have their private keys). Alice generates the AES key to be used with Bob, encrypts it using Bobs public RSA key and then sends it to him.. done

a1a··on The MIT Lockpicking Guide
Burglars in general do not read MIT guides. Even if some might, security is still a weakest link problem. The easiest way into a house is by window, the letterbox, etc, speaking of locks in general it's easiest just to use a bolt cutter.
a1a··on Extend Python 2.7 life till 2020
Fair point. But I'd like to quote my own post above:

>I rarely write anything high language besides small scripts. Python 2 does the job. If I ever were to need

>functionality of another language, great, it's fun to learn something new. Our time is limited and we must

>prioritize. Sadly we cannot invest time to learn everything (well I guess it's possible, but I rather be

>awesome in four languages than mediocre in twenty).

a1a··on Extend Python 2.7 life till 2020
I do have a big toolbox, it contains all kinds of screwdrivers etc for low level programming. But I only need one hammer for the few problems I face that is best solved by scripting languages.
a1a··on Extend Python 2.7 life till 2020
Nor have I done research on Perl, Scala, etc. Your missing my point. I am successfully getting my things done in Python 2. I do not have any use for Python 3, Perl, Scala, or any other language. I might have in the future, and hey, some language might be better suited to solve the problem - but as long as it's not drastically better the sensible tradeoff is to stick with Python 2.
← PreviousPage 2 of 6Next →