HNHacker News
TopNewBestAskShowJobs

aj3

731 karma · joined June 6, 2020

submissionscomments
aj3··on Crypto brothers front-ran the front-runners
The strategy that MEV bots use is not a law. It is not even defined or endorsed by Ethereum standards, and arguably is not an intended feature of the network.

You could alternatively claim that the guys defined their own protocol which addressed market inefficiency (which MEV is). Imo it's insane to claim that a trading technique you invented should have zero risk, and any losses you take are an indication of theft.

aj3··on Crypto brothers front-ran the front-runners
> Tokens are property.

What law says this? Technically, tokens are smart contracts, basically OOP classes with both data and behavior. They also by design have public methods which are meant to be triggered by anyone on the chain. It's not at all obvious that triggering these methods in an unexpected order or with unexpected data is breaking any laws whatsoever. It's bytecode anyway, so there's no human readable EULA's or explanations on what you're allowed to do with the token.

aj3··on Crypto brothers front-ran the front-runners
I bet this indictment will be used as a case study to justify the need for government oversight and taxation.
aj3··on Crypto brothers front-ran the front-runners
But you're not signing EULA's in order to participate in the network. Moreover, there are no real "laws / regulations" within the network either, specifying what you are or are not allowed to do. Ethereum standards merely determine how the software is supposed to work, but even then I'm sure Ethereum devs would oppose treating their docs as an agreement (because they don't offer any warranty, licensing or attestation). Moreover, there is an express goal to have a diverse set of software clients, so even developing your own software to be interoperable with existing standards can't be constructed as "an attack".

All this to say, I just fail to say how this can be constructed as "changing the terms of the transaction". There was no legal agreement between parties and no existing precedent to treat this as a malicious attack at all.

All I see is a Wall Street establishment pulling strings in order to protect their investment, by asking for a sudden government oversight in the system that was built with the express goal of not requiring any government oversight.

aj3··on Ask HN: Help, any US-based companies that allow you to work from Europe?
It's weird to consider paying taxes as a tradeoff. "Digital nomad" isn't a code for tax avoidance, is it?
aj3··on My Pinephone Setup
Android has different security guarantees compared to desktop/server Linux. E.g. people should expect that none of the installed software can hijack the phone completely and that most damage from malware should be mitigateable by uninstalling malicious app.
aj3··on PSA: uBlock/AdBlocks on Chrome to lose function thanks to Manifestv3
There were over a dozen of 0day exploits this year alone. Some used in water hole style attacks, so not even that targeted. And these are state of the art incidents which would have pwned even users with all the updates installed.

After the patch has been pushed out, exploits become progressively cheaper so letting users to postpone security updates is a crime.

aj3··on Tell HN: Lost then regained access to Google account, with correct credentials
Right. Session is stored either in cookies or in Local Storage. Both get cleared when you "clean cookies". If there is no device session, next time you're trying to log in, service will ask to show the second factor (so that hacker can't steal your account through finding the password on some other website).

Firefox didn't work, because person deleted session and didn't have second factor (nor backup auth methods). Chromium worked, because it still had device session.

I'm traveling and using TOR and VPNs just like everybody else and haven't faced any issues. There most definitely is a problem with communicating security/accessibility tradeoffs to the public though, so I'm not putting blame on the op here.

aj3··on Tell HN: Lost then regained access to Google account, with correct credentials
It's not user agent, it's session (cookies, localStorage) that they didn't have in Firefox, but still had in Chromium. And this isn't Google specific at all.
aj3··on Tell HN: Lost then regained access to Google account, with correct credentials
Most probably they've added MFA and lost it. Devices that have been authenticated already can be used with the bare login & password, but new sessions will ask for the MFA they can't access.
aj3··on Tell HN: Lost then regained access to Google account, with correct credentials
Well yeah. If the recovery process is weaker than regular authentication, that's what bad guys will use for account takeover. You don't want to lose Gmail because someone bruteforced your backup code?
aj3··on Price increase on .io domains on January 1, 2022 (Renewal: $55.00)
AFAIK, there are exactly two ways to avoid getting phished. One is using physical security keys (not implemented everywhere and we can't expect everyone in the world to buy one). The second one is checking the domain you're in.

Please, do elaborate on what other ways of phishing preventions you have in minds.

aj3··on Price increase on .io domains on January 1, 2022 (Renewal: $55.00)
That's awesome for phishing.
aj3··on Pixel sent to Google for replacement. They used it to post wife's nudes online
The official repair shops that Apple Repair will guide you to should never ask for the pin, afaik. There is that mode for diagnostics which you need to approve, but you don't need to provide the pin - just unlock the phone and press approve button yourself.
aj3··on Pixel sent to Google for replacement. They used it to post wife's nudes online
Android has exactly this feature, two in fact: "Safe Folder" for regular files and "Locked Folder" for photos specifically.
aj3··on FBI's ability to legally access secure messaging app content and metadata [pdf]
Employer might have been defense contractor. Most jobs without clearance don't even have "threat assessment coordinaror".
aj3··on American spy hacked Booking.com, company stayed silent
Counter example where companies didn't stay silent: https://en.wikipedia.org/wiki/Operation_Aurora
aj3··on American spy hacked Booking.com, company stayed silent
Archived version: https://archive.md/z3t8O

Note that it uncritically accepts report from 2009 which according to company was meant to be risk modeling exercise. Authors outright dismiss everything either KPL or CapGemini has to say themselves and does not even try presenting mitigations that presumably have been put in place, changes in infrastructure since 2009 and other more contemporary reports.

aj3··on Canonical Multipass – Ubuntu VMs on demand for any workstation
From the security perspective both snaps and flatpaks are preferable to dep/rpm for browsers, email clients, office suite, document viewers and other stuff that is used to parse untrusted data often (due to [wip] sandboxing and auto update).

Snap packages are better maintained (more often with direct involvement of the app developer) and generally receive updates a bit earlier than flatpak. In both cases you need to pay attention who the app maintainer is and I'd argue that in case of unknown maintaners deb/rpm packages are safer choice.

aj3··on NFT's aren't the answer to the problems of digital art
Nice story, but it's just a coincidence that the platform you found uses NFTs, as far as I can see just as easily it could have been regular centralized platform operating over Stripe or PayPal.
aj3··on NFT's aren't the answer to the problems of digital art
Your last sentence reads like FOMO. Not sure if it's intended, but it seems that you are making an argument for NFTs as a tool for speculation.
aj3··on NFT's aren't the answer to the problems of digital art
That's exactly what's happening right now. But before NFTs the most plausible ways were either opening a business accepting crypto (not unlike meatspace money laundering involving cash-accepting businesses) or having lucky strikes on gambling platforms (where you can play against yourself).

For a larger operation going business route is still preferable but on an individual level NFTs are much easier due to ridiculously high margins that have been normalized there.

aj3··on NFT's aren't the answer to the problems of digital art
What's the benefit of making those resellable? To encourage scalping?
aj3··on NFT's aren't the answer to the problems of digital art
How do you check who was the first in practice? Blockchain is large and will grow larger. NFTs hold URLs not hashes, so the same artwork could be represented by multiple hashes. The url could also point to a different artwork now compared to what was there before.
aj3··on NFT's aren't the answer to the problems of digital art
Artist still could sell the same artwork multiple times on a single or multiple exchanges. Or someone could steal their keys and sell the artwork multiple times.
aj3··on NFT's aren't the answer to the problems of digital art
More importantly people don't work like that. In practice most "fake news" are based on quote mining which is easy to disprove without any knowledge of cryptography whatsoever by just checking the original source, but people share this crap without any verification because it conforms to their beliefs.

Technical solutions won't fix social issues.

aj3··on NFT's aren't the answer to the problems of digital art
Yes, but if you buy the watch you can put it on your hand, use it and show it to me. NFT is more akin to a photo of an invoice from the workshop you attended - it might have some sentimental value to you, but it's not a watch, does not have intrinsic value and I don't have to respect it.
aj3··on NFT's aren't the answer to the problems of digital art
So what? Say you have an account X which holds funds from criminal operations (e.g. ransomware payments). If you cash it out directly there's no doubt you're a criminal. But if you use that money to pay yourself for an NFT, now you can possibly deny that you have any knowledge about source of X income.

Better yet send money from X through a bunch of privacy oriented tokens like monero, tumblers and mixing services, losing 20-50% in the process and consolidating the rest in account Y. Now you have plausibly clean money but you can't pay taxes yet as there's no paper trail for this income. Solution is easy, buy an NFT from yourself, declare it, pay taxes and buy a new yacht.

aj3··on NFT's aren't the answer to the problems of digital art
So in other words NFTs are scams just like designer clothes, luxury watches and fancy cars.
aj3··on NFT's aren't the answer to the problems of digital art
Well, you're wrong. Seller declares income and pays taxes, but they don't have a duty to track down buyers real identity and check their income sources. Thus you could easily be both buyer and seller but only declare seller part.
Page 1 of 9Next →