HNHacker News
TopNewBestAskShowJobs

biturd

626 karma · joined July 13, 2010

submissionscomments
biturd··on How Doomed is NetApp?
What I don't understand is on their flagship product, an all SSD drive array, they claim 500,000 IOPS (sustained I/O rate), yet i have heard of many people doing more than 1 million IP's/s in http and in database. If others can do a million how are they if something that is seemingly as fast as can be with an all SSD system can only do half that at a pure I/O level no less.
biturd··on How the NSA’s Firmware Hacking Works and Why It’s So Unsettling
Why can't the HDD vendors publish a md5/sha1 hash of the firmware so we know what the value should be?

If the NSA ( or anyone ) are going to modify the firmware and hide malicious or preparatory exploit code in that area, the end user will have little recourse post-exploit. Though, beforehand, if the HDD vendor published, for example: the md5/sha1 of the firmware the OS vendor could then write a "control panel" or application that the number has been entered/seeded by that vendor. If the hash on boot does not match the hash in storage, alert the user the drive has been hampered with. Alert the vendor, they send you a new drive, and you throw away the old drive.

I'm not entirely sure how to do this if they happen to not modify the firmware but instead just store in the areas wasted space. I can think that you would use sized to make values you could then hash. As long as the vendor knows the values of of what they did, those can always become keys to compare to make sure they have not been modified. ( I hope at the very least. I don't want a stalemate or a loss when it comes to this type of security, it has to be a win for the consumer. )

Is there any reason this approach wouldn't work? What other alternatives are there if they are writing to the firmware area of the HDD?

What if this were the firmware of the hardware itself. There are firmware(s) within your USB bus, wifi chipset, cpu chipset, keyboard chipset, display, power management, some cables, everywhere. Those can be leveraged individually or via a RAID style merging of all these firmware areas to give you, hundreds of MB of super difficult to locate storage space.

If no one is looking, you can get away with anything you want. And in this case, even if someone is looking, it will take a very good set of eyes a few times over, as it seems one voice is never loud enough to get the word out. Be prepared to go to jail for talking about any of their methods, even in a theoretical sense.

biturd··on The Tyranny of the Forced Smile
Could still be weather as the Parent stated. San Diego, warmer, nice weather. Seattle, rainy, snowy, gloomy, could be Seasonal Depressive/affective Disorder from not enough sunlight.
biturd··on Re: Yesterdays post on cli tools being near 100x faster than dedicated systems
or crap, basic returns are not part of markdown, and my editor sucks I guess.
biturd··on Re: Yesterdays post on cli tools being near 100x faster than dedicated systems
markdown not supported?
biturd··on I love this product, but can we discuss if this is bad pratice
can an admin fix my bad .md for the url then delete this comment. Also, an explanation as to what I dud wrong as this is how I do .md on Stack and other sites, reddit, it always works fine.
biturd··on What do most use for IMAP backup
Fanboy is what I wanted in a way, someone who knows a system in and out, and like me has run mail systems in the past.

If you know this well, and it is working for you, and you used it to dev clients, then that says a lot, as if you are dev'ing a client, you need a defined corpus and easy way to roll in and out of certain things you have done.

I wish I had this when I was trying to make a webmail based IMAP reader in php.

biturd··on Ask HN: Best registrar only and why
Thanks! This was the other name I was trying to remember, as I know a lot of people like them. Thanks again.
biturd··on Ask HN: Best registrar only and why
Thank you so much. I will check it out, I have a feeling these are not going to be 7.99 each with all the above. I also hope they are giving away domain privacy, as charging for that in this day and age is insane.
biturd··on Screenr Business is Closing on July 1, 2015
Great service, too bad they aren't looking to work around the need for Java, which is the main reason they claim to be closing, in that most browsers no longer support it, and installing Java is something most won't be bothered with. Funny how fast Java on the web can die but flash is still everywhere.
biturd··on Is DropBox Decrypt something we need to worry about?
Thanks for the reply. One of my main issues is just knowing what the files are and what they can be used for against me potentially.

They are in ~ in a dir that is a .dir so hidden from 90% ( guessing ) of most casual DB users. If someone were to delete their home files, by putting them in the trash, they may think they deleted their DropBox data too, but they would be wrong.

It was that scenario I was concerted about, or at least, wanted to know more about so I could be sure to delete those files and know it is safe to do so, and won't harm the files stored in my DropBox on other machines, or in a recovery procedure.

biturd··on The impossible post to find
You did it! thank you.
biturd··on Breaking Spotify DRM with PANDA
I know very little about encryption aside from general principles on what it is, why we have it, and what it's goals for existence are. That being said, piracy, love it or hate it, it's here to stay for the time being.

I see the "problem" as a simple one. If there is chance that a systems DRM can be broken by merely one person, all efforts by that provider, and now most other providers, at least those that share methodologies, is pointless.

If a song, book, or movie are locked down, only legitimate subscribers can use that media under the terms the owner or distributor of that media define. But if only one person of the potentially millions is able to break that encryption, one person has now made all the work and man hours of into said encryption completely worthless.

If it takes a few weeks to break encryption that took months of multiple man hours to create, was that time wisely spent? Once it's broken, the data is now open to everyone. That being the case, I feel were in a "why bother" scenario.

The main reason I see illegally pirated material not proliferating even more is the technical barrier to acquiring the files. And often times, applications and protocols like bit-torrent, tor, VPN's, SSL links, etc. have too high a technical barrier for the common user to start pirating their media.

Once that burden is removed, it's game over and everything will be free at a click of the mouse, until something new comes along or a better business model that works with the fast changing technology world we are in.

When you are waging a war of one against millions and the one can actually win without putting themselves in harms way, you have a war that many will think is a sure fire win for the millions. A million against one is a pretty good ratio. But in this case, the one has a very good chance of annihilating the millions.

Eventually we will learn there is no point. In the meantime, people do this type of reverse engineering for a number of reasons I imagine. Curiosity, the challenge, making a political statement, and most importantly, to learn.

From this, perhaps something new is learned. And from that a new library is made which then gets adapted to detect intrusions on our personal computers and embedded devices. Who knows what may come of this research.

In the end, my position on piracy doesn't matter. What I do know is it will happen, encryption will be reverse engineered or broken, and those who can't learn the technology to use the new research will continue to find the barrier to piracy too high. Others won't, and will get their media freely, sans any lockdown from what you want to do with what you purchased.

Cars can go well over the speed limit. Some to speeds that make no sense to even exist. But they are legal, and most people follow the speed limit laws. The cost and barriers of breaking those laws are too high so people follow the rules. With DRM, the cost is negligible, so the rules will be broken.

But mainly, I think the answer to your question is that curiosity drives a lot of this. Aside from curiosity it could be a lack of trust. Researchers want to know what is going on with their media and hardware.

How do you know an encrypted file is not up to nefarious deeds? The common user never will. But a researcher like this would discover that the file was up to more than just DRM, and that could potentially help those millions of people become more aware of security, and learn to be more skeptical of what they buy.

biturd··on Ask HN: Bank says it fixed openSSL/HB, can those claims be tested?
I just found a tester and it states this: http://dl.dropbox.com/u/340087/drops/04.27.14/Screen%20Shot%...

'Regenerated 2 years ago', does that mean they in fact did not revoke, regenerate, and re-issue?

biturd··on Avow-CI Is No More
I am near certain I have read Appple taking entire projects away from employees who made apps at home, and these apps were unrelated. For example, a game versus working in Apple's iMessage department.
biturd··on Fixed – The easiest way to fix a parking ticket
If you contest a ticket and the officer does not show up you win a default judgement. Perhaps they are playing on the fact that unless they are on duty on the scheduled date, they are probably not showing up at court.
biturd··on Dear HN — if php blogging platforms are junk, what do you suggest?
For me, there is a lot of work setting it up, getting the themes where you want them, then finding one of 100 various plug-in's for SEO or twitter or whatever, and figuring out which is the best, and which has the least security holes.

You are right, at the core, it is simple, but it is time consuming to me. And it falls over under load unless you have a bit of time or money to throw at it, or both.

I like the idea or working in a text editor of my liking, knowing that quote marked in code aren't auto converted to smart quotes, knowing that the raw markdown is raw, and I can move it anywhere.

I am sure you can do all this in Wordpress, I am just looking to remove all that overheard, as starting a blog again is feeling more daunting than ever given my current medical issues. If I can just get it off the ground I will be happy.

But I feel I have to do something, so I want to do something that gets me to my end goal as quick as possible, but allows things to possibly grow without me thinking about what a Varnish, CDN, Cloudfront, etc all are.

biturd··on HTMLy: Databaseless Blogging Platform (Flat-File Blog)
Perhaps using sqlite as the "backed" in that you build it like any other blog, so you get the simplicity of building it out, using one good sql framework etc.

But then, when you click "post" it rips through the database using a library of markdown -> HTML or whatever the case may be. Thhere can't be must overheard to a single include to pull in the html, but you could render the enter page. I just can't see php falling down too much with a few includes and functions being called to generate a header, the included rendered HTML, and a footer with some design elements.

It's not much fun building your own database out of flat files. I cut my teeth on a Mac only system that more or less only talked to Filemaker, which was only as fast as the actual screen could redraw and search out the data. It could be painfully slow.

In a way I am glad, as I learned how to do things and think differently when most were just running a "select * from foo where bar = 'x'" which was a 15 minute luxury I didn't have. There were no joins, no tables, you actually ran applescripts on the database and it returned the data somehow back to a web server on the Mac.

So we used the database on the backend, where admins could be more patient, or do more intricate things, but almost always generated out some HTML, so in the end, the site was semi-dynamic. I think I was doing "caching" of data as a result almost 15 years ago.

The rule was, no more than 2 database calls per page, ever. And you couldn't do things like update foo set name = 'me' where id = 1, because there was no exposed notion of a record id, it was internal, so you had to select name from foo where name = 'whatever' which would return the name, but also a RedID value, which you then got to run another query to update foo set name = 'me' where if = <special RecID token>

Made me think a bit different.

biturd··on Square talking to banks about possible 2014 IPO
CC merchants are not supposed to ask a minimum CC charge. Call the merchant and complain, they have to take a one cent sale or a million dollar sale.
biturd··on Show HN: My embarrassingly simple printscreen weekend webapp
Yeah, you could actually mess up a workflow. The current instructions would over-write your clipboard, maybe you had something you needed in it really bad.

I use a clipboard manager which is nice, and past copies are saved for a defined few hours or additional entries.

biturd··on Show HN: My embarrassingly simple printscreen weekend webapp
Not to take away from the OP but you can enable a new feature in DropBox where screenshots are immediately moved to your DropBox directory, uploaded, and a share URL is stuffed in your clipboard. A notice is given on screen and on Mac OS X you get a notification center alert. I think I also hooked it into growl.

The screenshot is only moved, not deleted. It's in the DropBox preferences — and along with this feature you enable photo syncing and all your phone taken pics get put in your DropBox folder in "Camera Uploads", or the "Screen Shots" directory. You also get a good deal of bonus space for enabling these features.

You won't have time to grab the screenshot and edit it or draw on it. It happens fast. I use Skitch, which is a screen shot collaboration and editing tool. Once done, you can drag and drop the image to DropBox and get a share URL. Or drag and drop out of any app onto "Droppings", a small "app" I wrote.

I wrote a small script that fishes out your DropBox ID, which is used as your ID in a URL ( this is done once on install ). On receipt of a resource, the script creates a directory and time stamps it. This script is wrapped up in an app that accepts drag and drop. Drop a batch of jpg and gif etc., images, and it will copy them to the DropBox public folder, and put unique URL's to imgur on your clipboard. Full support for maintaining Mac Resource forks and all that as long as you compress on the Mac.

Drag and drop a zipped or compressed set of files, and it will do it's best to look and see if they are all web displayable, extract them, and give you a set of public links. If it contains other zips, binaries, etc, the original format is maintained.

All these actions are logged. I engage with Skitch, a screenshot type app, which I've also integrated logging for and created "cron" ( Launch Items in my case ) actions to clean up the mess Skitch leaves behind. I don't use Skitch as an image storage app, so it keeping multiple copies of everything only ads confusion.

It's pretty handy. If I want to send anything to anyone, I just find it, drop it on an app in my dock, it's 99% bash, the rest is an app that is made to take a shell script and give you same basic UI controls to make a pseudo app.

I started to have tons of link rot on DropBox. Screenshots to CSS questions that I would see posted by others but the screenshots were long since deleted.

My ~/DropBox/Public/drops/date-stamp/the-files.{html, htm, CSS, jpg, gif, png, tif, eps…etc. } directory has been filling up from this droplet for two years now. I think I have about 500MB of stuff that will forever resolve.

I do remove huge files via a "find" command that looks for specific things that I would not want in DropBox beyond a certain date or that I know were meant for specific people and the file will never be needed again. Sort of how I do IMAP image attachment maintenance in gmail but have to use a desktop app to remove attachments.

biturd··on USPS: ZIP Codes are “proprietary business information”
I understand that the post is more about the USPS holding onto something seemingly trivial. Kinda like when we tell google to block out certain places of security. But we already have so many ways to get around it, like going there and taking a picture, or renting a plane, who knows. Or the Streisand Effect kicks in and everything is a mess.

At any rate, I have had to do a lot with zip codes in the past, long before anything like an API was a common term let alone something every company was happy to let you hook into and use their services. Heck, this was back when it costs a few grand to take CC's on a website and had to deal with that awful Authorienet API. That used to be thought of as crazy talk. Now we have amazing stuff like this: http://www.geonames.org

biturd··on USPS: ZIP Codes are “proprietary business information”
Sorry to keep replying, I don't have an edit button for some reason. This one is cool too: http://api.zippopotam.us/us/ma/belmont

I found a town called Bakersfield that has more than one zip fro the town, it does JSON back with more data than I thought would be part of free plan.

For some reason I could not get "san_francisco","san-francisco", "sanfrancisco", or "sf" to work.

biturd··on USPS: ZIP Codes are “proprietary business information”
Looks like USPS API data is free and usable only for package shipping. Not that I bet they would notice. At any rate, this seems to be a great start with a great API recommendation: http://stackoverflow.com/questions/7129313/zip-code-lookup-a...
biturd··on USPS: ZIP Codes are “proprietary business information”
According to the USPS website, API usage is free here: https://www.usps.com/business/web-tools-apis/list-of-apis.ht...

One of the API's relates to zip codes.

biturd··on USPS: ZIP Codes are “proprietary business information”
Which makes sense to me, or at least those do not ever enforce this patent on infringers…

I have had to do zip code to location lookups to find ( I think it's called the Great Circle Calculation ) "within x miles of $zip_code".

I found plenty of companies wiling to sell me the data, sell me updated data quarterly, or API that after testing did not have data change in over a month, though from what I know about zip codes, and for our application, missing a zip code was not the end of the world, I just picked another close one. When drawing a radius around a point, if the point is missing but with so many zip codes, there was aways one close by.

1) How can they sell this? They don't apparently own it. 2) Why not use ones of the many zip, lat, long, databases that I seem to remember being pretty easy to find?

There's some logic behind the zip codes and how they are dished out. Unlike IP that has BGP to find the best route from IP to IP, USPS has none of this, so i imagine this was like trying to solve that "Traveling salesman" quandary with constantly changing and unknown locations. They had to make a sort of zip code prefix that at least gets them to the county level.

Lot's of good data here http://en.wikipedia.org/wiki/ZIP_code

This is like how telco's issues numbers, it was all well thought out ahead of time. You could get kinda dirty and run a loop from zip_code_1 to zip_code_1+1 with each one polling the USPS for a zip code lookup. You would have a pretty accurate database. At one "scrape" of data taking 5 seconds, in a month you would have your data. After that you would only have to test the gaps between numbers to see if new ones were added or just follow some usps page to keep up on new and deprecated zip codes.

There are too many sites that use geolocation with zip to not have this be a solved problem on the very cheap. Probably just another API, where in the future apps will just be lego like API's you copy and paste JS snippets to and from. :)

biturd··on Apple hides a Patriot-Act-busting "warrant canary" in its transparency report
What if Apple, google, etcetera were to make the processes that these warrants ask for, part of a trigger.

As long as the warrant requests the same data or less than all the data, then performing those actions trigger an email to the user stating "A third party has requested access to your account.".

I would guess it would be best for these companies to add a few buttons to their internal tools to export user data. Then it's a part of their business process.

Many "third parties" can ask for and get your data legally. And letting them know is also legal. So there is a user value to this user feature.

Now, the next request goes from legal to top guy to tech guy to some guy who clicks a button in a browser.

biturd··on W3C green-lights adding DRM to the Web's standards
isnt this the equivalent of greying out the "view source" menu item or removing the developer menu item?

You can still get the entire page, it comes in over the wire. If they do this, I would assume we can just capture the raw data, and new apps that decode that raw data and give the same tools as the browser developer tools offer.

If not, hopefully there are browsers who refuse to implement, and hopefully it takes less time than it took Adobe to learn their lesson.

biturd··on Apple iOS 7 surprises as first with new multipath TCP connections
Does this mean that if all end points support this, connections could be split all over the place?

A 10 IP round robin setup, if I'm correct, could show stats for 10 different locations. Or does it work differently?

biturd··on Reeder 2 for iOS
Same. No support, no bug fixes.
← PreviousPage 3 of 8Next →