HNHacker News
TopNewBestAskShowJobs

besselheim

222 karma · joined March 19, 2016

submissionscomments
besselheim··on Dutch secret service tries to recruit Tor-admin
Still, he'd have been better off staying quiet about it, in case he changed his outlook in years to come.
besselheim··on Stanford historian uncovers a grim correlation between violence and inequality
Who are these mythical self-made 0.0001%? All the ones I've heard about relied on family wealth and connections, inheritance, and most often worker exploitation.

The filthy rich do enjoy this ego-feeding narrative that it was all just talent and hard work that gave them a disproportionate slice of the world's wealth, but it's not borne out by the facts.

besselheim··on Dutch secret service tries to recruit Tor-admin
Sounds like he just turned down a rather nice job offer, and burned his bridges by being publicly disgruntled about it.
besselheim··on Automatic HTTPS Enforcement for New Executive Branch .gov Domains
It should really be .gov.us rather than a top level domain.
besselheim··on There is no WhatsApp 'backdoor'
Android apps can also contain native code. Indeed, WhatsApp includes such libraries, to help with Curve25519 encryption, video encoding, voice over IP, and other functionality.
besselheim··on TINY: VNC for DOS
I remember setting this up about a decade ago on some old electroplating control system front end. It worked very well - unlike the rest of the software on there.

Unfortunately the DOS program it was being used to remote was highly picky on the hardware being used, and would refuse to communicate with the PLC if the PC was too new. Due to the harsh environment of the plant, we'd go through two or three computers per year. So there was a lot of digging around for old hardware until we realised it would run reliably in DOSBox with a suitable CPU speed set.

After that, our use case for TINY was no more, and we just used a VNC server for Windows. Saved a great deal of site to site travel and plant downtime while it was set up though.

besselheim··on Why HTTPS for Everything?
You can use the -quiet or -ign_eof options to disable this.
besselheim··on Why HTTPS for Everything?
You could type them over openssl s_client instead.
besselheim··on Intel Committee Releases Declassified Snowden Report
I really don't see the resonance between these events.

The damage to signals intelligence capabilities, through the leaking of classified documents, was deliberately and maliciously done through the actions of Snowden himself, most likely in response to a bruised ego.

In contrast, the engineers involved in the Challenger shuttle did their very best to try to avert disaster - albeit to no avail - through their selfless adherence to professional ethics and engineering safety concerns.

The two scenarios couldn't be more different really.

besselheim··on Intel Committee Releases Declassified Snowden Report
I'm suspicious of his primary motivation being a distaste of global mass surveillance. This passage is especially damning:

> Snowden would later publicly claim that his "breaking point" - the final impetus for his unauthorised downloads and disclosures of troves of classified material - was March 2013 congressional testimony by Director of National Intelligence James Clapper.

> But only a few weeks after his conflict with NSA managers, on July 12, 2012 - eight months before Director Clapper's testimony - Snowden began the unauthorized, mass downloading of information from NSA networks.

Given that Snowden claimed his motivation was seeing Clapper "lie on oath", there's some irony in seeing Snowden caught in a lie about this claim, as at that point not only had he already downloaded and exfiltrated much of what he later leaked, but had already been in contact with Greenwald and Poitras for two to three months.

besselheim··on Intel Committee Releases Declassified Snowden Report
Interesting read, and sheds some more light on Snowden's motivations and attitude. I thought it quite ironic that while he complains about supposed privacy violations of Americans, he was doing the exact same thing - on a smaller scale - to his co-workers. Of most concern is the huge excess of documents exfiltrated that had nothing to do with mass surveillance.

Also interesting is how well the accounts of his work behaviour match up with these posts from an HN user earlier this year, who claimed insider knowledge: https://news.ycombinator.com/threads?id=buttcoin

besselheim··on Malicious tweet gives journalist Kurt Eichenwald an epileptic seizure
I imagine if he'd been the victim of a deliberate hit-and-run, you'd be saying something like "so to be clear, you want someone to be imprisoned because they drove a car."
besselheim··on Amazon workers sleeping in tents
Not always. For example the village built up by the Cadbury family in Bournville was designed to favour the wellbeing and living standards of their workers: https://en.wikipedia.org/wiki/Bournville
besselheim··on Support for better symlink handling in Windows 10
They already emulate a Linux kernel, in recent Windows 10 releases: https://msdn.microsoft.com/commandline/wsl/about
besselheim··on Windows 10 in-place upgrades are a severe security risk
I think the Linux equivalent would be more like interrupting the boot process at the GRUB menu, then adding "init=/bin/sh" onto the kernel command line, so Linux boots into a root shell.
besselheim··on Everyone who can now see your entire internet history, including the taxman
Only the connection history - hostname and date/time of access, and only if authorised for an investigation.

It's akin to the phone companies logging each number called. This isn't as intrusive as people are making it out to be.

besselheim··on Compulab Airtop – Natural Airflow Desktop
I had a couple of machines from Hush Technologies (long since out of business), also ~10 years ago. They were passively cooled through a finned chassis, connected to the CPU and other hotspots by heat conducting pipes.

Like yours, sounds like the same sort of thing as these Airtop machines.

besselheim··on How to contribute to an open source project on GitHub
Agreed, it's much easier for quick bugfixes on code that you otherwise don't want to invest your time into.
besselheim··on Disclosing vulnerabilities to protect users
I don't think this is the case here though. It's been a few days since reporting the vulnerability, not months.

We don't yet know if this was being widely exploited (versus being a niche exploit used by an APT, for example), but it will be now either way.

besselheim··on Disclosing vulnerabilities to protect users
The problem is that Google also said this:

> The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.

Which is enough information for someone to write an exploit from scratch.

If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.

besselheim··on Disclosing vulnerabilities to protect users
The future patch that Google should have coordinated their disclosure with.
besselheim··on Disclosing vulnerabilities to protect users
This is flawed reasoning, as the vast majority of people will defend against it by installing the patch.
besselheim··on Disclosing vulnerabilities to protect users
No, just sceptical of their claim to be protecting users by disclosing early.
besselheim··on Disclosing vulnerabilities to protect users
I can't imagine that Microsoft have refused to fix this vulnerability though, otherwise this would have been mentioned in the blog post.

There's no good reason for Google not to respect coordinated disclosure here. Making an arbitrarily tight deadline their policy isn't protecting users.

besselheim··on Disclosing vulnerabilities to protect users
Looks like a conveniently written policy for hitting their competitors with to me. What is certain is that Google pick and choose when to apply these disclosure time limits, they're not set in stone.
besselheim··on Disclosing vulnerabilities to protect users
At the same time it allows exploit writers to quickly add this to their kits.

I'd expect AV vendors to already have signatures for this given that it's being actively exploited, which means there must be malware samples to know this.

besselheim··on Disclosing vulnerabilities to protect users
Yes, I believe what you describe in your second paragraph is most likely to be the case, given that coordinated disclosure is the standard approach to protecting users.
besselheim··on Disclosing vulnerabilities to protect users
Advertising the details of an exploitable vulnerability before the vendor has patched is protecting users now? I don't buy this motive at all.
besselheim··on Microsoft is now a braver, more innovative company than Apple
There's this Technet article, which also tells you how to dial it down or disable it: https://technet.microsoft.com/en-gb/itpro/windows/manage/con...

I don't see the problem with ignoring the hosts file, if that is indeed what is happening. It's not really intended as a blocking mechanism.

besselheim··on Microsoft is now a braver, more innovative company than Apple
Anonymised telemetry reports are not the same as being spied upon. Anyway, Apple has the same kind of thing in iOS and OS X.
← PreviousPage 2 of 4Next →