HNHacker News
TopNewBestAskShowJobs

alksjdalkj

389 karma · joined November 6, 2020

submissionscomments
alksjdalkj··on Technical Introduction to the Use of Trusted Platform Module 2.0 with Linux [pdf]
My point is that's already happening now, so I don't understand the fear that TPMs will enable some sort of draconian DRM. They don't enable anything that isn't already possible with respect to DRM and locking down machines.
alksjdalkj··on Technical Introduction to the Use of Trusted Platform Module 2.0 with Linux [pdf]
I always see people claim that TPMs will enable DRM, but aren't we already subject to plenty of DRM? There's a lot of content that I'm blocked from accessing because I use Firefox on Linux, and AFAIK none of that DRM makes use of my TPM. What kind of DRM are people worried the TPM will enable, that we aren't already subject to?
alksjdalkj··on Master’s degrees are the second biggest scam in higher education?
I think immigration laws play a big role too, a lot of people seem to use a masters as a way of getting a visa - I believe having a masters improves the chances of getting an H1-B, and also being in school in the US makes it much easier to apply to US companies.
alksjdalkj··on Undocumented x86 instructions to control the CPU at the microarchitecture level [pdf]
I only skimmed this but if I understand correctly the CPU needs to be in debug mode to access these instructions right? If so then it's hard to see why the authors present these instructions as dangerous - I imagine once the CPU is in debug mode you would have unfettered access to the system even without these instructions.

(not that it isn't still interesting!)

alksjdalkj··on Carlos Ghosn: How I escaped Japan
> I would bet that Japanese in the U.S. evince rates of criminality more similar to those of Japanese in Japan than to the rest of American society

What makes you believe that? If true, what might cause that to be the case?

alksjdalkj··on Google Compute Engine VM takeover via DHCP flood
I wish that were true but it's really not. At least not within the public sector, maybe wealthier private firms can afford to do that level of verification.

Anyway, even then you still need to make trust decisions. How do you verify the ICs in your HDD haven't been tampered with? How do you know the firmware wasn't built with a malicious compiler? Or that a bad actor didn't add a backdoor to the firmware? Realistically there's a lot of components in modern computers that we have no choice but to trust.

alksjdalkj··on Google Compute Engine VM takeover via DHCP flood
Right, I'm familiar with the hack. My point is Target almost certainly didn't decide that the HVAC firm could be trusted to have access to the credit terminals - the fact that they had access was the result of poor security design, not Target's threat model.
alksjdalkj··on Google Compute Engine VM takeover via DHCP flood
Did Target really trust their HVAC firm or was their network just poorly segmented?
alksjdalkj··on Google Compute Engine VM takeover via DHCP flood
Supply chain is still an issue in sovereign clouds. At some point there's still a trust decision, whether that's to trust the cloud provider, the hardware manufacturer, the chip manufacturer, etc.
alksjdalkj··on Amazon is using algorithms with little human intervention to fire Flex workers
Workers were convinced that the jobs are better based on advertising from these companies. That doesn't mean the jobs actually are better options.
alksjdalkj··on Classified Ministry of Defence documents found at bus stop
> I also think it's downright odd that they're printed --- most high-level classified documents seem to exist on secure, airgapped, immobile computer systems.

I think it's pretty common to print classified documents, since as you say the electronic copies normally live on specific airgapped networks. If you'll need them somewhere without access to that network (e.g. most meetings) printing is the easiest option.

alksjdalkj··on Tour of the server room in the Airbus 350
Could be wrong but I think there's a lot of equipment for things like radios, radar, sensors, etc. that makes it look like there are more servers than there actually are.
alksjdalkj··on Starlink dishes go into “thermal shutdown” once they hit 122° Fahrenheit
I'm not sure, it seems like 110+F is pretty common nowadays in parts of the US. Adding a dozen degrees if the dish is in direct sunlight seems pretty realistic.

(not saying things won't break at that heat, just that it's not unrealistically high)

alksjdalkj··on Start Your Own ISP
It seems like there should be a lot of potential for something like this in cities. The site says that line of sight and apartment buildings are problems but in the east coast cities I'm familiar with there's lots of neighborhoods consisting mainly of row homes or 2-3 story multifamily houses. To me places like neighborhoods like those would be a natural fit, more so than suburbs.

Also for me the main appeal of this is the potential for a not for profit, co-op style ISP. I.e. owned and operated by the customers. Although if the fiber is still coming from a Comcast or Verizon I'm not sure how different it would be vs. just buying consumer internet direct from Comcast/Verizon.

alksjdalkj··on Reality Winner, NSA contractor in leak case, out of prison
There's a play "Is This A Room" based on the transcript of her arrest - I haven't seen it but This American Life has an excerpt: https://www.thisamericanlife.org/696/low-hum-of-menace/act-t.... For some reason I found it really unsettling.
alksjdalkj··on DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
More info: https://krebsonsecurity.com/2021/06/justice-dept-claws-back-...
alksjdalkj··on Remove left turns for less dangerous city traffic
I'm a little skeptical that it would be safer for pedestrians and bikes. Bikes need to merge with traffic already in the roundabout instead of simply going straight through an intersection, and pedestrians would need to always check for oncoming cars rather than being able to mostly rely on lights telling them when they can cross.

But then most of my experience with roundabouts is with large, multilane roundabouts so the traffic is still pretty fast - maybe smaller roundabouts with significantly slower traffic would be safer than I'm picturing.

alksjdalkj··on Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
alksjdalkj··on Etsy to buy fashion reseller Depop for $1.63B
But there's a difference between turning down a bid because you want to maintain control over your vision and because you think your company is just worth more than the offer. The point is just that if you get what you think is a fair offer, and it's a very large offer, it would be hard for most people to say no.
alksjdalkj··on On Smoking
This is such a perfect description. I quit years ago but still whenever I see someone smoking I get a craving and when I'm stressed I find myself wishing for a cigarette. I've accepted that it's just something that'll be with me the rest of my life.

Seriously, don't start smoking. It's a mistake that you really can't undo.

alksjdalkj··on US Soldiers Expose Nuclear Weapons Secrets via Flashcard Apps
Shouldn't we just assume that anything we upload to the cloud could be made public? Either through a hack, an employee, a misconfiguration, etc. If something is sensitive enough that you don't want it public it probably shouldn't be in the cloud, period. Regardless of what the default visibility is.

e: On second thought there probably are exceptions - I'm not worried that something backed up to Backblaze will be leaked, for example. But a random flash card app? I'd assume that info is public. Maybe I'm just paranoid.

alksjdalkj··on Eric Carle has died
I really doubt that's the issue. As if a fly or an ant has never set foot on a menorah before? It's a non issue. It's not like we eat menorahs anyway.

I assume it's an AI mistake, but I don't get what the AI thought it was seeing.

alksjdalkj··on SimpleVisor – Intel VT-x hypervisor in 500 lines of C code
Probably not, I think that would require a lot of complexity that I assume this doesn't implement (e.g. resource partitioning and time sharing).

I think the premise is just that there's not a lot of simple hypervisors available for learning. VT-x is on its own a lot to comprehend so this lets you not worry about code complexity and focus on understanding the workings of VT-x mode.

alksjdalkj··on Show HN: I wrote my own RTS game engine in C
Not sure if this is the author's reason but I find it helpful to have a single return point from functions. Much easier to follow code paths.

You'll see this in some places in Linux's source too.

alksjdalkj··on IBM employee forced to stop kernel work under personal email address
Anyone surprised by this should check with the IP agreement they signed with their own company - I bet it would also forbid this. Generally anything related to work you do as an employee can be considered IP owned by the company.
alksjdalkj··on Firefox 88.0
NY state tax forms have all sorts of verifications and automatic calculations that I assume are implemented using PDF JS. Previously you had to use Adobe Reader, hopefully this means I can use Firefox now.
alksjdalkj··on WeWork documentary explores a decade of delusion
You know there are non-white Jews, right?
alksjdalkj··on A professor declined a $60K research award from Google
I respect the gesture but I think it would be more useful if accompanied with some plan of action for improving the current state of ethics in CS. It's a field-wide problem, not a Google specific problem.

Also, let's be clear here on who bears the brunt of these actions - when a lab is short on funding, it's the grad students who lose out first. Vijay tweeted as much, saying he'd rather his grad students need to TA an extra semester or two rather than take Google's money.

alksjdalkj··on Someone is hacking the hackers
You'd be surprised, after 10+ years worth of accounts and online presence it's easy to trip up - reuse an account name from years earlier, use their real email to register for a domain, etc. Krebsonsecurity.com has a few articles where he tracks down an attacker's real identity - e.g. https://krebsonsecurity.com/2020/07/twitter-hacking-for-prof...
alksjdalkj··on Blue Beads in the Tundra
The difference is being able to solve crypto puzzles has actual uses whereas the beads are inherently worthless. A better comparison would be if the aliens offered us some shiny space junk.

Any deal involving something that one party doesn't know or understand is probably unethical. It's also questionable whether the aboriginal people understood the implications of trading their land.

← PreviousPage 3 of 4Next →