HNHacker News
TopNewBestAskShowJobs

artemist

40 karma · joined November 19, 2016

submissionscomments
artemist··on San Francisco’s vaunted tolerance dims amid brazen crimes
It's really strange (though logical if you think about who controls them) seeing these articles from supposedly neutral news sources with a very strong right slant. If you look at actual data there is no crime surge and thefts from retailers hurt almost no one (except maybe investors for insurance companies making slightly less money). On the other hand large retailers such as Target blatantly steal millions from employees through overtime violations and minimum wage violations. In fact, if you look at the numbers, both completely legal civil asset forfeiture and illegal (but not criminal and extremely lacking in enforcement) theft from employees outnumber total value stolen from burglaries.

And for feces and needles: There's an obvious solution more effective than arresting people: public toilets. Many of these cities like to think of themselves as "liberal" while refusing to do the absolute minimum for any of their poorer residents.

artemist··on GM tells some Bolt owners to park 50 feet away from other cars
Luckily we have a solution to the huge issues with batteries and we've had it since 1883: overhead wires. Not practical with cars but cars aren't practical in a societal sense in cities (too much pollution, even from electric cars, take far too much sates, too much noise, etc.)
artemist··on 25 Gigabit Linux internet router PC build
Interesting. I had only looked at RouterOS 6. I have had trouble with mikrotik software before though. (I have a CSS 610 and a lot of its core features were completely broken before)
artemist··on 25 Gigabit Linux internet router PC build
This is a switch and switching is hardware accelerated. While you can theoretically route with this this, it is incapable of routing at gigabit speeds, let alone 10 gigabit speeds, once you need even a few rules.
artemist··on Ask HN: How would you store 10PB of data for your startup today?
You almost certainly should not have 10PB of data. Not just is it extremely expensive, it is unlikely that millions of people have each allowed you to take gigabytes of their data. You are sitting on a huge violation of CCPA, GDPR, and other privacy laws, as well as copyright issues. If you are scraping data off the Internet you likely have content illegal to poses in several different countries (such as child sexual abuse material or videos of ISIL killings). As a startup you do not have the legal and technical capabilities to manage this data so you should not have it.
artemist··on Critical Bluetooth vulnerability in Android
I can think of one phone with a great camera and a headphone jack: the Pixel 3a
artemist··on Frab – free and open conference management system
I believe it is more focused on educational conferences. the CCC uses this for all its conferences, including Congress and Camp.
artemist··on Reverse engineering a custom CPU from a single program
There was a server that we socat'ed into. (I made some minor contributions to solving this problem on PPP)
artemist··on JDK 9 modules voted down by EC
NXP makes smart cards, which frequently run JCOS. This is an embedded OS for microcontrollers which runs on Java bytecode. However, they use Java bytecode version 1.2 and language level 1.3 with Stirings removed, so I don't know quite why they would be influincing later Java versions.
artemist··on Ask HN: Is there a “ground-up” explanation of PGP/GnuPG?
If you have time and are fine with it being a bit dry, you can read RFC4880 [0], the RFC for OpenPGP.

This is something I have done some work on (I wrote a basic implementation in an attempt to understand a while ago [1]), but I don't have a nice writeup.

An OpenPGP file, whether it is a public key or encrypted file, consists of a list of packets. Generally it is a binary file, but an armored file consists of this binary in base64 and then a checksum. You can get these packets with gpg --list-packets <file>

Example output from a signed and encrypted file

  gpg: encrypted with 2048-bit RSA key, ID 09FBFEF359DD186F, created 2016-11-30
        "asdfas <sdfasdfasd@asdfasd.asdf>"
  # off=0 ctb=85 tag=1 hlen=3 plen=268
  :pubkey enc packet: version 3, algo 1, keyid 09FBFEF359DD186F
	  data: [2047 bits]
  # off=271 ctb=d2 tag=18 hlen=3 plen=377 new-ctb
  :encrypted data packet:
	  length: 377
	  mdc_method: 2
  # off=293 ctb=a3 tag=8 hlen=1 plen=0 indeterminate
  :compressed packet: algo=2
  # off=295 ctb=90 tag=4 hlen=2 plen=13
  :onepass_sig packet: keyid 0D3B106118D1EFBE
  	version 3, sigclass 0x00, digest 8, pubkey 1, last=1
  # off=310 ctb=ac tag=11 hlen=2 plen=19
  :literal data packet:
  	mode b (62), created 1480523012, name="file.txt",
  	raw data: 5 bytes
  # off=331 ctb=89 tag=2 hlen=3 plen=284
  :signature packet: algo 1, keyid 0D3B106118D1EFBE
  	version 4, created 1480523012, md5len 0, sigclass 0x00
  	digest algo 8, begin of digest 05 c4
  	hashed subpkt 2 len 4 (sig created 2016-11-30)
  	subpkt 16 len 8 (issuer key ID 0D3B106118D1EFBE)
  	data: [2046 bits]
The pubkey encrypted packets contain a key used to encrypt the data. The encrypted data packet includes that symmetrically encrypted data.

When I have more time, I may do a more useful writeup on my site, but currently I am too busy.

[0] https://www.ietf.org/rfc/rfc4880.txt [1] All I could find was my file parsing code, I dumped it at https://github.com/artemist/mupg

artemist··on Show HN: World class unlimited email hosting for all your domains from $4/month
Strangely, both seem to use the same IP addresses (Maybe there is a load balancer there?) So, as far as I know, both are in France.
artemist··on Show HN: World class unlimited email hosting for all your domains from $4/month
If you are wondering about jurisdiction, according to their FAQ they are in Switzerland, and according to geoip their servers are hosted by OVH in France.
artemist··on I can’t just stand by and watch Mark Zuckerberg destroy the internet
The problem with telling people to stop using Facebook is that they want some way to communicate with extended family and former friends.Before you can tell people to simply stop, you need a replacement. I have not yet seen a solution which would be able to replace Facebook for that purpose. Email is much clunkier and does not work to communicate with many people. IM and other messaging, including Signal, are quite different and can't be used to communicate with many people. There have been a few attempts, such as dispora, to federate Facebook but they have not caught on and may cause some problems with e.g. searchability.
artemist··on Subgraph OS: Adversary resistant computing platform
Having a subgraph TemplateVM will get easier with Qubes 4.0, as Qubes switches over to HVM (I think just HVM with PV drivers, PVH in Xen is not ready yet). grsecurity and PaX do not work with paravirtualization, which is pretty limiting in terms of memory management and such (It also opens up some vulnerabilities, which is why Qubes is switching).
artemist··on Tech firms seek to frustrate internet history log law
Yes, it is possible, if your attacker isn't too powerful. However, there will be a lot of tradeoffs and the software is not quite finished yet.

The software which is currently closest to this is ricochet [0] which communicates directly between Tor hidden services. Since there is no central server, there is no one to record metadata (at least in a trivial fashion). However there is still a lot of work left to do before ricochet is something that could be mainstream. Also, some metadata can be leaked, such as when one is online, and (until proposal 224 is out) how much people are communicating based on the number of lookups on the hidden service directories corresponding to the service (since there is no randomness in the system yet, afaik, you can brute force values to get into the right place in the ring. I haven't read the Tor specifications in a while tho, so I may be wrong)

You could also use some sort of mixnet system, although you would probably end up leaking who is sending messages to their ISP. To stop the ISP from determining when, you could send o constant stream of encrypted traffic, although that would be inefficient. (I need to read more research on this)

However, weather people will actually use these systems is in entirely different problem.

[0] https://ricochet.im