HNHacker News
TopNewBestAskShowJobs

aaronmdjones

1,749 karma · joined November 30, 2014

[ my public key: https://keybase.io/aaronmdjones; my proof: https://keybase.io/aaronmdjones/sigs/ZTD3j_Pf4JemZ_1AxOdN02-qKw8l--60w_Cp85zQOag ]
submissionscomments
aaronmdjones··on US Revokes Limits on Power Plants' Climate Pollution
The UK has Dinorwig power station, a pumped hydro station capable of storing over 9 GWh of energy. This alone rivals the entire combined 10.5 GWh of battery storage across the whole country. It certainly seems much more feasible when you have the terrain to allow it.
aaronmdjones··on Flock is rolling out a voluntary severance program
Some of their customers have even asked them to redesign their cameras so they don't look like Flock cameras.
aaronmdjones··on Rust is tier-1 language at Microsoft
No. Your calculated landing speed doesn't change depending on the winds, so you'll always be touching down at roughly the same airspeed for the same aircraft type, weight, and flap setting. Touching down with a headwind just means you don't need to use the brakes as hard.

It's beneficial on takeoff because headwind already factors into your airspeed before you even start rolling, which gives you more lift for the same groundspeed yes, enabling you to rotate sooner than you otherwise would.

aaronmdjones··on Rust is tier-1 language at Microsoft
Correct. See e.g.:

https://www.businessinsider.com/3-aircraft-fly-new-york-to-l...

aaronmdjones··on NTSB issues investigative update on B-767 runway excursion accident in Miami
No, they're reprimanded for continuing.

https://skybrary.aero/tutorials/stabilised-approach

aaronmdjones··on NTSB issues investigative update on B-767 runway excursion accident in Miami
That they passed their minimums and still weren't set up correctly is shocking, yes. How can you commit to landing instead of going around when you're not configured for landing?

The more egregious thing to me though is ignoring the GPWS callouts on approach because they were chasing the glideslope. If you can't maintain a stable approach, you need to go around, it's the first thing you learn.

You expect this behaviour from a first-timer in the sim, not a commercial cargo pilot.

aaronmdjones··on Rust is tier-1 language at Microsoft
This is true for takeoffs but not for landings. You want to land with a headwind because this means that for the same airspeed you have a lower groundspeed, i.e. when you actually touch down you're going slower on the runway than if you touched down at the same airspeed but with a tailwind.
aaronmdjones··on NTSB issues investigative update on B-767 runway excursion accident in Miami
> (unclear how speed didn't increase)

Large high-bypass turbofan engines take several seconds to spool up from idle (as they would be on landing) to full thrust. The 4 seconds that the thrust levers spent in the full thrust position in this accident was not long enough.

aaronmdjones··on RSA-260 Factorized
RSA operations are performed modulo n, where n is the product of 2 primes. A 2048-bit RSA key is an n that is 2048 bits long (with the most significant bit set by definition).

There are no consumer CPUs that have 2048-bit-wide registers; even AVX10 tops out at 512 bits. Thus, mathematical operations on RSA keys are performed using arbitrary precision integer libraries like OpenSSL's own BN (BigNum) library, or GMP (the GNU Multiple Precision Arithmetic Library) as used by GNUTLS, in software.

For example, adding 1 to an arbitrary precision integer is not a CPU add or increment instruction, nor is multiplying 2 integers (or an integer and a constant factor) a CPU multiplication instruction.

aaronmdjones··on Qantas Airbus A380 engine failure in 2010 (2023)
Sort of. Rolls Royce voluntarily developed this software modification in response to learning that their reasoning about it never being able to happen was incorrect and being unable to concretely account for how it happened. EASA, which was not even the relevant safety authority for this incident, upon learning of its existence, only then required it to be installed on all A380 Trent 900 engines.
aaronmdjones··on Fixing a bricked Framework laptop
Yes, but there are free resources available that guide you on how to go through the process without consulting a hallucination machine.

Judges don't like their time being wasted, and they doubly don't like plaintiffs and defendants who don't even go to the effort of trying to follow decorum.

And, I'm just throwing this one out here; contempt of court is one of the vanishingly few civil offenses you can be held in custody for.

aaronmdjones··on Judge sets framework for Nine PBS to retrieve archival data
I have to agree with GP here, this is pretty incredible. They contracted with a vendor to store their data, not to back it up. It's not a backup if you can lose it in the same instant you lose the data.

You're right, they are. If your data can't survive a single storage host vanishing from existence, you don't have a backup. If your data can't survive one predictable or regularly occurring catastrophic act of nature, you don't have a backup. If your data can't survive a piece of malware -- with all of the credentials you have -- erasing it, you don't have a backup.

EDIT: Also, if you don't regularly test that your backups actually work, you probably don't have a backup. Lots of companies learn that one the hard way.

aaronmdjones··on Incident with Github.com
Oh nooo! Anyway...
aaronmdjones··on Extreme 220GHz+Broadband Silicon Capacitor X2SC 0201M 22nF BV11
Same here. That's made my week.
aaronmdjones··on DMARC has been public since 2012 but most company domains still don't enforce it
No, it doesn't.

In the following SMTP conversation:

  MAIL FROM: foo@example.net
  RCPT TO: victim@example.com
  DATA
  From: service@paypal.co.uk
  To: victim@example.com
  Subject: We are updating our Terms of Service
  [...]
SPF checks whether the sending host is allowed to send e-mail from example.net (the envelope sender).

The recipient sees service@paypal.co.uk (the From address on the inner message), because most ESPs do them the great disservice of not indicating that the sender identities are not aligned.

Adding a DMARC record to a domain requires that e-mail whose inner messages claim to be from that domain must have sender alignment to the envelope sender.

The above message would pass SPF (if the spammer owns example.net and has created SPF records for themselves) but would fail DMARC (paypal.co.uk's DMARC record exists, so alignment is required, and yet example.net != paypal.co.uk, so they are not aligned). In this case their DMARC policy says to reject the message, so (if the recipient is checking DMARC) it would either be rejected outright or it would land in Spam/Quarantine rather than Inbox.

aaronmdjones··on DMARC has been public since 2012 but most company domains still don't enforce it
This is true, and yet DMARC v1 does not require you to use them in concert. Either one (a valid DKIM-signed message with sender alignment or a message that passes SPF checks with sender alignment) is enough to pass DMARC.
aaronmdjones··on FAA lets Boeing sign off on 737 MAX, 787 airworthiness certificates again
The addition of MCAS to the 737 MAX received type approval by the FAA in response to Boeing's documentation, not in response to anything Boeing approved or issued. No aircraft manufacturer has ever been allowed to issue a type certificate.

The self-certification process (airworthiness certificates) is the manufacturer (rather than the regulator's inspectors) stating "this one specific aircraft with serial number _______ has been built according to the design covered by its type certificate". Nothing more.

In other words, an airworthiness certificate only specifies that a specific aircraft is airworthy /because/ it is built according to an airworthy design. Whether the design is safe or not has always only been up to the regulator to decide. In this case, the regulator dropped the ball and approved an unsafe design. If Boeing was not allowed to self-certify their own aircraft, the FAA would still have issued airworthiness certificates for them, including the two aircraft that would have gone on to kill hundreds of people, because they were built according to the design the FAA approved.

aaronmdjones··on US Supreme Court rules geofence warrants require constitutional protections
You can also revoke Location permissions from your Camera app. I've done this.

https://i.postimg.cc/LRd1KbPf/scrot-20260630-085733.png

aaronmdjones··on Framework's 10G Ethernet module exposes USB-C's complexity
I'm afraid I don't know anything about ThinkPads.

Hazarding a guess I'd say it's using Thunderbolt (hence the specific port requirement) which allows you to tunnel PCIe over it.

Though it is odd that they wouldn't just go with the WiFi on the motherboard option.

aaronmdjones··on Framework's 10G Ethernet module exposes USB-C's complexity
vPro requires the NIC to be connected directly to the PCH (over PCIe/CNV). This is going over USB, which won't cut it.

An Intel WLAN card in an M.2 slot on the mainboard might work (given your givens; a vPro enabled chipset).

aaronmdjones··on AI errno(2) values
`errno` is a userland concept; the kernel returns negative error numbers that libc then turns into -1 and sets errno. Thus the correct manpage is errno(3).
aaronmdjones··on Hardware Attestation as Monopoly Enabler
> Am I understanding correctly that [...]

What I took away from the thread is that they're against services forcing attestation in general, and also pointing out that Play Integrity isn't about security, but rather about control, because Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't.

aaronmdjones··on Dirtyfrag: Universal Linux LPE
You don't need any setuid binaries. You could just as easily use the vulnerability to add a job to crontab(5) that causes the cron daemon to run whatever you want as root.
aaronmdjones··on For Linux kernel vulnerabilities, there is no heads-up to distributions
If they don't have world-execute permission, an access(2) check for executability would return negative, leading to things like shells not tab-completing it. The kernel would also deny attempting to execute it, as it is not executable for your fsuid.

  $ sudo chmod 4700 hello
  $ ./hello
  bash: ./hello: Permission denied
You need execute access in order to launch it, but in order for it to run, the user it is running as (not you) needs read access; you don't.
aaronmdjones··on For Linux kernel vulnerabilities, there is no heads-up to distributions
> Without read permissions you cannot execute the binary

This is not correct, as when the binary is setuid-someone-else, you are not the one executing it; they are.

  $ cat hello.c 
  
  #include <stdio.h>
  
  int main(void)
  {
      (void) puts("Hello, world!");
      return 0;
  }
  
  $ clang-21 -Weverything hello.c -o hello
  $ sudo chown root:root hello
  $ sudo chmod 4711 hello
  
  $ ls -l hello
  -rws--x--x 1 root root 16056 Apr 30 22:22 hello
  
  $ ./hello
  Hello, world!
  
  $ id
  uid=1000(aaron) gid=1000(aaron) groups=1000(aaron),27(sudo),46(plugdev),100(users)
Removing world-readability from all setuid-root binaries on the system would be sufficient to kill the PoC script provided for this vulnerability. It would not be sufficient to prevent exploitation though; there are many ways to abuse the ability to write to files you have read access to in order to gain root, for example by using the vulnerability to alter the cached copy of a file in /etc/sudoers.d/, or overwrite /etc/passwd, or /etc/crontab, ... the list goes on.
aaronmdjones··on Easyduino: Open Source PCB Devboards for KiCad
A substantial portion of the things you need to know about layout are summarised quite nicely in the 4 YouTube videos in a previous comment of mine

https://news.ycombinator.com/item?id=44549063

Note that the audio in the first video doesn't start until 40 seconds in.

aaronmdjones··on The electromechanical angle computer inside the B-52 bomber's star tracker
... and yet on more than one occasion, pilots have taken off and prematurely retracted the flaps when they meant to retract the gear!

Humans fascinate me sometimes.

https://assets.publishing.service.gov.uk/media/578defbae5274...

https://assets.publishing.service.gov.uk/media/578def27ed915...

(Two separate incidents in the same year, on the same day, even)

EDIT: Updated links to point to incident reports

aaronmdjones··on WireGuard makes new Windows release following Microsoft signing resolution
> and had to go through the normal process?

There is no normal process. The error message clearly states "There are no appeals available, we have closed your application".

If the company makes it impossible for you to communicate with them, the only recourse is to draw public attention to it in order to shame them. This only works if you can gather enough public support and kick up enough of a stink about it. All of the small developers still locked out of their accounts are screwed.

aaronmdjones··on Veracrypt project update
The website formerly known as Twitter has never cared about the username part of the URI; it only looks at the status number and will redirect you to the canonical version if it wasn't.
aaronmdjones··on ‘Energy independence feels practical’: Europeans building mini solar farms
> Answer #1: Many UK RCDs/RCBOs are actually single-pole devices and don't disconnect the neutral.

This is not correct; all type AC and type A RCDs used in British consumer units disconnect the neutral as well. Some RCBOs do not disconnect the neutral and this is a problem in some circumstances. The datasheet I linked for Wylex NHXS1 RCBOs explains that these ones do disconnect the neutral.

> Answer #2: It looks like some/many one-module wide UK RCBOs _do have_ electronics in them [...] but if backfed for longer than the disconnect time that might be enough to toast the solenoid or the driver

This is correct. For an example of this construction in an RCBO, see [1]. This illustrates that if the supply is connected to the "To Load" part of the schematic (toward the end of the video), as it would be if the supply is a solar PV inverter with battery storage, then it can continue powering the electronics and be shunted out by the thyristor after it has supposed to have tripped, very quickly burning itself out.

Bidirectional RCBOs are not designed in this manner. They have more complicated circuitry that makes them more expensive to manufacture, but are absolutely required in situations like this if you don't want your protective devices to burn and/or explode when they operate.

> Notably neither of these has anything to do with the direction of power flow.

Yes it does, because if the power is flowing backwards to how they designed it, that is backfeeding it, keeping its circuitry powered after it should have been disconnected.

[1] https://www.youtube.com/watch?v=8kWIITspYvk

Page 1 of 23Next →