HNHacker News
TopNewBestAskShowJobs

ahomescu1

1,384 karma · joined July 13, 2012

submissionscomments
ahomescu1··on Translating Quake 3 into Rust
We added the transpiled code in a new branch at https://github.com/immunant/ioq3/tree/transpiled/quake3-rs and also a more cleaned up refactored code base at https://github.com/immunant/ioq3/tree/refactored/quake3-rs
ahomescu1··on Translating Quake 3 into Rust
We added the transpiled code in a new branch at https://github.com/immunant/ioq3/tree/transpiled/quake3-rs and also a more cleaned up refactored code base at https://github.com/immunant/ioq3/tree/refactored/quake3-rs
ahomescu1··on Translating Quake 3 into Rust
Author here: I wanted to let everyone know we made some small edits to the text, and added two new branches to our repository: transpiled containing the raw transpiler output [1], and refactored containing the same code [2] after a few refactoring commands.

1. https://github.com/immunant/ioq3/tree/transpiled/quake3-rs

2. https://github.com/immunant/ioq3/tree/refactored/quake3-rs

ahomescu1··on WannaCry in-memory key recovery for Windows XP
Right, I see that now. Adding an additional layer of RSA and per-file keys is an interesting twist. Generating a public/private key pair instead of a symmetric key seems to let them encrypt as many files as they want without keeping the private key in memory (which they relied on Windows to erase).
ahomescu1··on WannaCry in-memory key recovery for Windows XP
> Just ship your ransomware with the attacker's public key, generate a symmetric key K locally, encrypt the data with K, encrypt K with the public key, offer to decrypt K for a ransom.

It seems that what they're doing is generating a local Kpub/Kpriv pair, encrypting Kpriv itself and then offering to decrypt it. The files are encrypted with Kpub (approximately, see comments below for details). This has the advantage that they can encrypt all they want without knowing Kpriv, which only needs to live in memory long enough to get encrypted.

ahomescu1··on WannaCry in-memory key recovery for Windows XP
I don't know the exact details of how WannaCry encrypts the files, but ransomware generally works like this: when hitting a new machine, it generates a random key K1 and then encrypts all the user's files with AES (or some other symmetric key encryption) using K1 as the key. It then encrypts K1 itself using some public key Kpub embedded in the ransomware, then stores the encrypted K1 on disk. When the user pays the ransom, they receive the corresponding private key Kpriv that allows them to decrypt K1, which then lets them decrypt all their files.

I think what this tool does is read the unencrypted K1 directly from memory, which means Kpriv is no longer needed.

EDIT: One correction: the user doesn't receive Kpriv, instead they send the encrypted K1 to the ransomware owner who decrypts it and sends back K1.

ahomescu1··on O(1) Data Lookups with Minimal Perfect Hashing
There doesn't seem to be anything dynamic about the algorithm in the article. They still need to precompute the perfect hash function(s) from the entire input data, whereas the hashing approach you linked to can handle adding data incrementally (hence the "dynamic" part).
ahomescu1··on Iron law of oligarchy
> And who runs foreign policy? How do state secrets work? Is there still a president and a bureaucracy and cabinet ministers?

All of those seem tied to the Executive branch, whereas direct democracy would replace the Legislative (Congress in the US, Parliament in other countries). The current Executive follows the laws that Congress passes, direct democracy wouldn't change that.

ahomescu1··on Mexico supreme court rules ban on marijuana use unconstitutional
I was following and agreeing with you (and was going to upvote you), until the last 2 sentences. You could have made your point without bashing "CS types" and CS/engineering education.
ahomescu1··on Scholarship, Security and ‘Spillage’ on Campus
1. and 2. are OK points, but your point 3. is atrocious. In my opinion, destructive behavior isn't really a legitimate form of protest, and as rubidium wrote, you'd be hurting people who are innocent in all this.
ahomescu1··on Efficiency up, turnover down: Sweden experiments with six-hour working day
> Historically, states and credit-based money came first. THEN came the unit of account and medium of exchange money that you are talking about.

Actually, the Wikipedia page on "fiat money" (if that's what you're referring to) says: "Fiat money originated in 11th century China" [1]. There were many commodity currencies before that.

> Going back to the original point, can you go to a deserted island and make "money"? No. You need society. You need government. You need an economic system. The money is only partially "yours".

That's if there is only one person on that island. If more people live on the island, they might start trading services and use some some improvised currency, e.g., coconuts or seashells. In this case, you have a society and money, but not necessarily a government.

1. https://en.wikipedia.org/wiki/Fiat_money#History

ahomescu1··on Efficiency up, turnover down: Sweden experiments with six-hour working day
Anything that is valuable, fungible and divisible could be used as money (you could even use barrels of oil). For examples, see [1]. Again, a great contemporary example is Bitcoin (not sure why you're ignoring that, it's a great example of money that exists in spite of government, not because of it).

Perhaps what you're referring to is legal tender, which indeed requires a government to exist. However, not all money is legal tender (for example, euros are not legal tender in the US, afaik).

1. https://en.wikipedia.org/wiki/Commodity_money

ahomescu1··on Efficiency up, turnover down: Sweden experiments with six-hour working day
Money is both a "unit of account" and "medium of exchange". You can certainly have both of those without government. In some societies, people used seashells, salt, gold coins, or many other things as money. Bitcoin certainly counts as a "non-government money".

Since money is used as a medium of exchange, it's essentially a placeholder for your labor (when you receive it from your employer/customers as payment) or value provided to others. It is arguable whether society has as much right over an individual's labor as he/she does, I think they don't (while society may have a contribution, it might be significantly below 50%).

One last and minor thing we'll have to disagree on: I don't think government equals society. An individual can be a part of society without being part of government, and I also believe government sometimes represents its own interests at the expense of society.

ahomescu1··on Ignition: V8 Interpreter
AFAIK, V8 already has 3 tiers: full-codegen (the basic non-optimizing JIT), crankshaft and turbofan. With ignition, they're replacing full-codegen with an interpreter.

It's strange that there's only one mention of crankshaft in the entire document, but turbofan is all over the place. Are they also planning to get rid of the former?

ahomescu1··on Should I Use Signed or Unsigned Ints?
size_t is also unsigned (no idea why). The signed equivalent is ssize_t.

Edit: Sorry, missed the "i-- > 0" at first. The code works, but not because of changing "unsigned" to "size_t".

ahomescu1··on The Magic of RPython
If you mean run RPython code as regular Python code, that doesn't always catch typing problems. For example, returning a None where an int is expected works fine in Python, not so in RPython.
ahomescu1··on The Magic of RPython
I used RPython on my own interpreter project a few years ago (stopped working on it around 2013). It's a very interesting approach to writing interpreters/JIT compilers, and produces very fast code, but developing RPython code was very painful for a few reasons (back then, maybe they got fixed in the mean time):

1) Huge compilation times, and compilation is non-incremental. Making even a small change to the source code causes it to be fully re-compiled, which on our project took 15-20 minutes (I can only imagine how painful this is on PyPy, which took me around 2 hours to build the time I tried it). I think the root cause of this is the static analysis and type inference, which needs to run again on the entire source code, and proved to be really slow on a huge code base. This was painful for development, so much time wasted on waiting on the compiler.

2) My experience with error messages was not as positive as the OP's. Sometimes, I'd make a type error in the code and get a cryptic error message, and have to guess by myself what caused it. Perhaps things have improved since then (I see some new details in the errors in the article that weren't there when I used RPython).

ahomescu1··on In Iraq, I raided insurgents. In Virginia, the police raided me
> It's an open question. For the last 6 years I've refused to set foot in US (and even declined free tickets to a very important tech conference in my field) because of your unpredictable trigger-friendly police [1] and your guantanamo-friendly interviews at border control [2]. I wonder it your unstability could reach me in Europe.

This seems excessive to me, you're not going to run into the cops going to a tech conference. I've lived in the US for the past 5 years, and never had any issues with police or border control. In fact, I'd go as far as saying that the part of California I live in (Orange County) is safer than my home country in Europe.

ahomescu1··on The Case of GCC-5.1 and the Two C++ ABIs
> Out of curiosity, an example? The only programs I've compiled that remotely approach an hour are the Linux kernel, GCC, and ATLAS.

Don't know about GP, but I can think of a few more: KDE, OpenOffice, Firefox (that alone takes about 2 hours on my quad-core Phenom), Chromium.

ahomescu1··on Google, Microsoft, Mozilla and Others Team Up to Launch WebAssembly
Earlier discussion on this topic: https://news.ycombinator.com/item?id=9732827
ahomescu1··on Apple’s Bitcode Telegraphs Future CPU Plans
I mean the writing is identical, but the pronounciation varies wildly.
ahomescu1··on Apple’s Bitcode Telegraphs Future CPU Plans
> The ordering of digits in Arabic is not obviously relevant, per se, since spoken English ("one hundred twenty one") matches the order of the Arabic numbers, too.

I think it is relevant. It is possible that Western mathematics copied the Arabic notation (with right-to-left numbers), without also copying the correct way to read it (also right-to-left). For a similar situation in language, think of accents and the many different ways you can pronounce the same word.

ahomescu1··on Apple’s Bitcode Telegraphs Future CPU Plans
After looking up some German for beginners (German speakers, feel free to correct me), I found out that 1042 is read like "one thousand two and forty".
ahomescu1··on Apple’s Bitcode Telegraphs Future CPU Plans
The problem is that perfect disassembly (figuring out where every instruction starts, and if bytes are instructions or data) of an arbitrary program is undecidable. Emulators get around that problem by only disassembling instructions that actually get executed at run-time (and therefore can safely be called "code").
ahomescu1··on Apple’s Bitcode Telegraphs Future CPU Plans
> Because big-endian matches how most humans have done it for most of history ("five hundred twenty one" is written "521" or "DXXI", not "125" or "IXXD").

Actually, it is possible that that was nothing more than an accident. We use Arabic numerals, and Arabic languages are written right-to-left. Then there are languages like German where digits are read in reverse, so "42" is read as "two-and-forty".

ahomescu1··on European Parliament TTIP vote postponed ‘because of huge public pressure’
> Corporations are created for the benefit of the corporation, and as they get hyper-large they don't even serve the needs of their own employees; they become self-aware, and their survival and growth becomes their reason for existence.

I think this is getting a bit out of hand. Corporations aren't alive or self-aware, in the end humans make all the decisions, and most of the time for the benefit of those same humans.

> Governments can be concerned with my interests. It's impossible for corporations to play that role.

Corporations are led by CEOs (and other officers of the company) and by the board, while government is led by the president (or equivalent from other countries) and the legislative (Congress in the US, Parliament in others). How much does POTUS or the average Congressman care about your interests? They only care as far as it wins them the next election, but that's not much different from a corporation: a corporation might care about your interests as long as you're a paying customer. Government ceases to care about you when you stop voting, companies cease to care when you stop buying.

ahomescu1··on The Death of the Von Neumann Architecture
> Until someone uses ROP-widgets turning stack return addresses into executing what the attacker wants.

That's like saying there's no point in locking your doors because thieves can go in through the window. Instead, you're better off applying separate defenses against separate attacks: read-only code against code injection and other defenses (like CFI or randomization) against ROP.

> Besides, any secure JIT will only keep a page either writable or executable, but not both in the same time.

Sure, but it's amazing how few actual JITs do that. V8, for example, actually maps its entire code cache as RWX.

ahomescu1··on The Death of the Von Neumann Architecture
There's also a counter-point: Harvard architectures are more secure. If the application has the ability to execute data as native code, attackers will find a way to exploit that.
ahomescu1··on The Night Watch (2013) [pdf]
Ah right, forgot about his Bane talk. For those who haven't seen it, also great: https://vimeo.com/95066828
ahomescu1··on The Night Watch (2013) [pdf]
He has written 6 of these and they're all available on his page (scroll down to the line on the USENIX online magazine): http://research.microsoft.com/en-us/people/mickens/
Page 1 of 20Next →