HNHacker News
TopNewBestAskShowJobs

alufers

1,317 karma · joined June 9, 2018

submissionscomments
alufers··on Hitachi launches CO2 heat pump water heaters with solar-friendly tariff controls
How does cleaning of the heat exchanger work? From my experience with Jaccuzzi-style baths anything that recirculates bathwater gets very nasty very quick and is a nightmare to clean.
alufers··on [dead]

    The copy of The Garbage Collection Handbook at ~/Documents/Books_on_vm/ is the 2023 second edition, and it covers G1, ZGC, and Shenandoah by name with dedicated sections. What follows is read directly from that PDF (page numbers are the book’s own page numbers, printed in each page header — the PDF file’s own page index has a fixed +37 offset from these, front matter accounts for the difference).
Why should I keep reading an article if author the couldn't be bothered to read it themselves after copy-pasting it from a LLM?
alufers··on Everything Is BOM: Bill of Materials Encyclopedia
The few pages I've looked at seem to be mostly (if not completely) AI hallucinated, with semi relevant photos from WikiMedia linked. Despite the name there is no way to edit the articles or even log in.

Also the "BOMs" are provided for such generic objects as "Excavator", which makes no sense. Different excavators will be made of different parts. If you want to get the general idea you can ask an LLM yourself instead of going to that website.

alufers··on Copy Fail
Update: Checking the kernel config indeed confirms this.

   adb shell zcat /proc/config.gz | grep CONFIG_CRYPTO_USER_API
   # CONFIG_CRYPTO_USER_API_HASH is not set
   # CONFIG_CRYPTO_USER_API_SKCIPHER is not set
   # CONFIG_CRYPTO_USER_API_RNG is not set
   # CONFIG_CRYPTO_USER_API_AEAD is not set
alufers··on Copy Fail
I rewrote it quickly to C [1] (and changed the embedded binary to be aarch64).

Unfortunately it fails on calling bind() on my device, so probalby Android doesn't ship with that kenrel module by default :(. So no freedom for my $40 phone.

Putting it out here, maybe somebody else will have better luck.

[1] https://gist.github.com/alufers/921cd6c4b606c5014d6cc61eefb0...

alufers··on NYC wants you to stop taking traffic cam selfies, but here's how to do it anyway
A bit tangential, but in Poland we also had such traffic cameras with public access (it wasn't a live feed, but a snapshot updated every minute or so). It was provided by a company which won a lot of tenders for IT infrastructure around roads (https://www.traxelektronik.pl/pogoda/kamery/).

What is interesting to me is that the public access to the cameras has been blocked a few months after the war in Ukraine started. For a few months I could watch the large convoys of equipment going towards Ukraine, and my personal theory is that so did the MoD of Russia. I haven't seen any reports about that, just my personal observation.

alufers··on OpenWRT One Released: First Router Designed Specifically for OpenWrt
Wouldn't a switch with ONIE [1] and Sonic NOS support [2] do the trick?

(I don't know the prices of such switches or whether they are available to prosumers, which would explain why almost nobody has them in a homelab)

[1] https://opencomputeproject.github.io/onie/ [2] https://sonicfoundation.dev/

alufers··on Is Telegram really an encrypted messaging app?
I don't know how much you have used Telegram, but it's ridden with absolutely vile stuff.

You open the "Telegram nearby" feature anywhere and it's full of people selling drugs and scams. When I mistyped something in the search bar I ended up in some ISIS propaganda channel (which was straight up calling for violence/terrorism). All of this on unencrypted public groups/channels ofc (I'm pretty sure it's the same with CP, although I'm afraid to check for obvious reasons).

I think there is a line between "protecting free speech" and being complicit in crime. This line has been crossed by Telegram.

alufers··on Show HN: I am building an open-source Confluence and Notion alternative
Not OP, but have to use the cloud version of Jira and Confluence. My biggest complaint is that they put the "Yes! Send me news and offers from Atlassian about products, events, and more." checkbox in the place where I would expect the "Remember me" checkbox.

Absolutely psychopatic behaviour.

alufers··on What the damaged Svalbard cable looked like
Some gun calibers are measured with inches, so maybe they have some imperial markers on hand to measure bullet casings?
alufers··on T-Mobile employees across the country receive cash offers to illegally swap SIMs
Probably one time use recovery codes you are supposed to print and keep in a safe place. In case of a bank this could also mean a trip to the nearest branch for ID verification.

The same issue you mentioned applies to other 2FA methods. Your TOTP codes and passkeys also live on your phone, Yubikeys can be stolen too.

alufers··on T-Mobile employees across the country receive cash offers to illegally swap SIMs
I know everybody says how bad SMS 2FA is, and how we should replace it with the next cool thing $BIGCORP invented (thus requiring you to have an account with them, which only defers the problem).

But couldn't we pressure the telecoms to improve it?

I have an idea that would make SIM swaps way harder to execute. Namely a website that wants to authenticate you should be able query the telecom for some kind of SIM card ID. This would happen before sending a 2FA code.

With such a feature it would be easy to store the SIM card ID in a database when enrolling the phone number. Later when the user tries to authenticate and the ID does not match what saved before, the account is locked out. For enterprise accounts you would need to explain yourself to IT and for personal accounts a fallback 2FA would have to be used. Alternatively the authentication would be delayed for a few days to give the legitimate owner of the SIM card time to react.

Another thing that could be added on top of this is to send a SMS to the old "inactive" SIM, alerting the original owner of the attack.

EDIT: To add to this, here are some advantages of SMS 2FA over time based OTP or passkeys:

1. My grandma can use it with her dumb phone and poor digital skills. 2. Your SIM card will most likely survive if your phone is destroyed due to water or physical damage. (Sadly not true for eSIM) 3. You can dictate an SMS/OTP code over the phone, or forward it to somebody you trust. 4. Banks can append a short description of what you are currently authorizing. It can tip you off in case your computer is infected with malware, or you are victim to one of those TeamViewer scams.

alufers··on Backdoor in upstream xz/liblzma leading to SSH server compromise
Is that true? Large companies producing software usually have bespoke infra, which barely anyone monitors. See: the Solarwinds hack. Similarly to the xz compromise they added the a Trojan to the binary artifacts by hijacking the build infrastructure. According to Wikipedia "around 18,000 government and private users downloaded compromised versions", it took almost a year for somebody to detect the trojan.

Thanks to the tiered updates of Linux distros, the backdoor was caught in testing releases, and not in stable versions. So only a very low percentage of people were impacted. Also the whole situation happened because distros used the tarball with a "closed source" generated script, instead of generating it themselves from the git repo. Again proving that it's easier to hide stuff in closed source software that nobody inspects.

Same with getting hired. Don't companies hire cheap contractors from Asia? There it would be easy to sneak in some crooked or even fake person to do some dirty work. Personally I was even emailed by a guy from China who asked me if I was willing to "borrow" him my identity so he could work in western companies, and he would share the money with me. Of course I didn't agree, but I'm not sure if everybody whose email he found on Github did.

https://en.wikipedia.org/wiki/2020_United_States_federal_gov...

alufers··on Ask HN: Why does it seem hard to buy an ONT for fiber?
I'm not sure where you live (probably the US), but here in Europe you can easily get GPON ONTs from different manufacturers. There even are whole communities dedicated to replacing your ISP's ONT+modem combo: https://hack-gpon.org/quick-start

In some countries (Germany) it's super easy, because there are laws forcing the ISPs to allow customer provided equipment, while in other countries you need to do some hackery with spoofing serial numbers and such of the original modem. People even make utilities to scrape that information via the administrative interface, and make the process semi-automated: https://github.com/StephanGR/GO-BOX

The biggest problem for me about the ISP routers is their sheer size, they probably make them big so that they seem "powerful" to the average person and he chooses that ISP believing that their router provides superior Wi-Fi. New apartments built here (in Poland) even have nice boxes with the incoming fiber and an electrical socket where you are supposed to hide your Router, but the shoebox-sized devices don't fit there and you have to put them on the floor, or somewhere else. I myself have bought a SFP+ GPON (LEOX LXT-010S-H) transceiver, which is the smallest form-factor you can get. It goes inside my Banana-Pi R3 router, together with an LTE modem for backup connectivity. And this setup is still smaller than the box provided by my ISP, which only served as a bridge between GPON and my router.

alufers··on Gitlab's ActivityPub architecture blueprint
For me as a person who learned programming in the times of Github/lab/whatever, the idea of sending patches via email is fucking ridiculous.

The typical interface for handling merge/pull requests adds so many useful things over just sending a patch - if the project has CI I can immediately see if it even successfully builds before even going into the details of the PR.

Same for reviewing, each comment can be replied to separately or resolved, which serves as a nice TODO list for the original author.

I know there are some things people don't like (I think Linus was pretty vocal about it), but it seems to be they could be easily fixed by modifying the available open-source forges. This proposal here for example fixes the concern about centralisation, so I guess it's a good step forward.

Or maybe I'm just young and like shiny things and will eventually have a spiritual awakening and learn about the virtues of sending in patches via email.

alufers··on Dynamouse: Mouse driver for Mac studios
Does it work for touchscreens too? When I plug in a portable monitor with a touchscreen into my macOS laptop the touch input gets sent into the screen where the cursor is (ie. I touch the touchscreen but it clicks something on the internal display, because this is where I left the cursor), instead of always inputting on the physical monitor associated with this touchscreen.
alufers··on Tour of new custom M1 macOS runners racks with Christina Warren [video]
I wonder how bulletproof Apple's macOS license is. Perhaps one could find a country where the "you can't run it on non-Apple hardware" clause is not valid, and get some good lawyers. Then just run a standard data center with normal multi-socket virtualization servers, and for each one buy a dead mac to have the rights to the software. Perhaps one could hot glue a powered off Apple motherboard inside of this server and claim that it is Apple hardware now.

Maybe it's risky, but you could easily compete on the per hour price with these shops, that have to buy actual macs, disassemble them and run all this custom infrastructure to support this.

alufers··on Valetudo – Cloud replacement for vacuum robots enabling local-only operation
You can just use the browser.
alufers··on GM says it's dropping Apple CarPlay and Android Auto because they're unsafe
I still have a drawer full of phone holders and bluetooth receivers that I used in my previous car with a "dumb" radio. All of the holders were annoyingly rattling when driving over potholes and finicky to insert or remove the phone. From all the bluetooth receivers I tried (3 of them), none of them had a decent microphone, which meant making phone calls a no go, and the first 2 of them had poor power filtering resulting in a high-pitched hum (I suppose it was from the alternator).

Now I have a car with wireless Android Auto and when I start the car I immediately get a google maps view without having to search for the app, including two recommended destinations (usually places I go to frequently, or the last searched place on Gmaps). The whole interface is easier to use while driving, because of the limited feature-set and larger screen than on the phone itself. Same story with calling, it just works - I can answer calls from the buttons on the steering wheel and the mic is decent and in the right place.

Can we stop pretending that every innovation since 2010 is evil? I get it that it locks in you in Google's/Apple's ecosystems, but their solution is simply working well. For me the alternatives don't cut it, and I believe that their shoddy practices (data collection, monopoly etc.) should be fought with legislation and not by refusing to use their stuff on principle.

alufers··on Hardening cellular basebands in Android
I used to live in an old apartment block with thick concrete walls, and away from a cellular base station. VoWifi was really helpful if I wanted to make calls from my home. I guess I could use WhatsApp/Facetime/Signal, but the insurance agent won't call me on WhatsApp from her landline phone :)

And it is not handled by an app on your phone, because of legacy reasons. I believe that, before LTE was introduced, 2G and 3G had a distinction between IP and voice traffic, so the baseband handled the voice transmission. Then they thought that LTE should be IP only and voice should be sent as VOIP over it, but it still had to be handled by the baseband for backwards compatibility with 2G and 3G. And then they came up with the idea that the VOIP traffic could also be piped over Wi-Fi (through the main processor of the phone), and so VoWi-Fi was created.

alufers··on All design and engineering of the original Tesla Roadster is now open source
Huh, their diagnostic software is a Puppy Linux ISO that you are supposed to run in VMWare. That's one way of software distribution :O

https://github.com/teslamotors/roadster/blob/main/Diagnostic...

alufers··on Linux and TPMs with systemd measured boot [video]
If you take some basic precautions - disable interrupting the boot process, serial console, etc. then bypassing that requires significant effort. As an attacker you need to know the versions of the software working on the server, know some exploit and then have the experise to use it.

For example I know that the police in my country use off the shelf disk cloning devices and then some basic forensics software for analyzing the disk image. This can be done by an average computer technician, and such a TPM scheme would totally prevent them from extracting data. Of course for bigger cases they can invest some more effort, but they would have to be sure that there is some important data there to justify the cost.

alufers··on Linux and TPMs with systemd measured boot [video]
Convenience, faster boot. Or if you have a headless server with disk encryption, but you want it to come back online without intervention after a reboot or power failure.

It's all trade-offs.

alufers··on OpenIPC: Alternative open firmware for your IP camera
Yup, also the userspace application that does the actual streaming is closed-source as well: https://github.com/OpenIPC/majestic

(The git repo is for bug reports only, no source-code there)

alufers··on The Philips Hue ecosystem is collapsing
Why is the proposed solution HomeKit? It requires an Apple device to control it and an iCloud Account.

Are account requirements from some companies better than other?

alufers··on I2c-USB-hub: An i2C Controllable USB 2.0 Hub
I've tried a few Amazon Basics ones, and on all of them power switching per-port worked. Uhubctl's compatibility list. seems to confirm my experience. The only problem is that the 7 port ones are in fact two 4-port hubs in a trenchcoat, which makes port numbering a bit weird. Nothing a couple of stickers can't fix, though.

https://github.com/mvp/uhubctl

alufers··on Chrome now tracks users and shares a “topic” list with advertisers
I'm kind of torn on this. The general idea that the user's browser tracks him by itself instead of utilizing cookies or fingerprinting seems like a step up for privacy. Obviously the devil is in the details - Google controls that whole algorithm, and there obviously is a conflict of interest.

But the alternative that the people who are against it are proposing is either to keep the status quo or kindly ask Google (and other ad companies) to stop existing, which is not gonna happen. They seem to ignore the fact that ad-tech is a huge industry and a large part of the internet relies on it. Basically the only way to make it go away would be to outlaw it.

(Also so nobody accuses me as being pro-ads: I hate ads and tracking, but sort of in a way like I hate being sick. I can reduce my exposure to ads and tracking (adblock, not using certain apps, etc.), but I know that complaining about it won't make it go away)

alufers··on List of Unix binaries that can be used to bypass local security restrictions
Out of curiosity: What sensitive things does the root account protect on your workstation?

On my desktop (and probably 99% of people's desktops here) getting access to the user account is game over. The password manager? Runs as my user - one ptrace and the key can be extracted. Cookies for all my online services? Sitting right there in the home directory.

The only thing root access would give somebody on my machine is to uninstall some random packages or corrupt my install.

And don't get me wrong, I don't like this situation - I tried running some high-risk programs (browser, Libre Office) under flatpak to achieve at least some separation - but it breaks too many things.

alufers··on Google has a secret browser hidden inside the settings
There even is a "remote version" of this by the same person: https://github.com/liriliri/chii

By using it you can open the devtools on another computer and all the information is synchronized over WebSockets. I used it once to debug an issue on a customers machine.

alufers··on Robot can rip the data out of RAM chips
They literally freeze them with liquid nitrogen, which makes them preserve their state.
Page 1 of 5Next →