HNHacker News
TopNewBestAskShowJobs

bkallus

809 karma · joined September 1, 2020

https://kallus.org
submissionscomments
bkallus··on Waze will now warn drivers about crash dangers using historical data
Curious to hear your objections to the black box.

Black box data (speed, steering+pedal input logs) were invaluable in determining fault in an accident involving one of my family members recently. As long as the data doesn't leave the car under normal circumstances, what's the harm?

bkallus··on Technology holy wars are coordination problems (2020)
except (Error1, Error2) as e still works in python3.
bkallus··on Debian discusses vendoring again (2021)
C makes it too inconvenient to pull in 300 dependencies. I think the recipe for dependency hell is insufficient stdlib + decent included package manager.
bkallus··on Show HN: Paclear – A Fun Twist on the 'Clear' Command with Pac-Man Animation
In Alacritty, ctrl-l clears the screen but does not clear the scrollback buffer. Clear also clears the scrollback buffer. This is useful for running programs with lots of output containing escape codes that may get mangled by less; just run the program and press shift-home to scroll to the top of the buffer.
bkallus··on F-Droid version of KDEConnect uninstalled by PlayProtect
The biggest one is the Firefox ESR build from the pmOS repos with the custom userChrome.css that tries to fit everything onto the Pinephone's screen. I pretty consistently encountered pop-up prompts (for example, in the built-in password manager) that ran off the edge of the screen in both portrait and landscape. Zooming out sometimes helped, but then the text was unreadable and the buttons too small to press. There was also no forward button in either the overflow menu or the nav bar. The Phosh settings app had similar problems.
bkallus··on F-Droid version of KDEConnect uninstalled by PlayProtect
In the past year, I have used a pinephone+keyboard with Arch, a oneplus 6t with postmarketOS, and a pixel 7a with GrapheneOS. In my opinion, Graphene is significantly easier to daily drive because the applications are designed for a phone's form factor.
bkallus··on HAProxy is not affected by the HTTP/2 Rapid Reset Attack
I had the privilege of reporting a few bugs in HAProxy in the last few months. Willy's a real treasure; he's friendly and knowledgeable, and he clearly cares a ton about HAProxy even after 22 years of development.
bkallus··on Lenovo PC boss: 4 in 5 of our devices will be repairable by 2025
What stops you from desoldering the bad connector and soldering on a new one?
bkallus··on Decomp me: Collaboratively decompile code in the browser
Definitely still a day job for some people. These DARPA and IARPA programs all have a decompilation component:

1. https://www.darpa.mil/program/assured-micropatching

2. https://www.iarpa.gov/newsroom/article/annotated-malicious-b...

3. https://www.darpa.mil/program/recovery-of-symbolic-mathemati...

bkallus··on Pixel 8 leak promises 7 years of OS updates
Android updates often do not come with kernel updates. Major kernel updates are difficult because of the tangle of proprietary modules in most Android kernels.

To partially answer GP's question:

Unofficial major kernel updates have happened in the past. OnePlus 6T, for example, shipped with 4.9.x, but supports mainline on pmOS.

bkallus··on When URL parsers disagree
RFC 3986 provides a generic URI grammar that is not scheme-specific, though other standards that define URL schemes may choose to subset the subset that grammar as they see fit. If a URL parser does not recognize a scheme, I would expect it to parse the URL using the generic parsing procedure.
bkallus··on When URL parsers disagree
A student and I have been using coverage-guided grammar-aware differential fuzzing to discover bugs in URL parsers for a while now. There is extreme variation in this space; it's trivial to turn up meaningful bugs in widely-used URL parsers.

".://" is a particularly egregious example. (and, by the same principle, "evil.com://good.com")

- Python 3.6's urllib.parse sees the "." as the URL's scheme, and an empty authority.

- Python 3.11's urllib.parse sees the entire ".://" as the URL's path.

- urllib3.util.parse_urlsees the "." as the URL's hostname, the ":" as the separator for an empty port number, and the "//" as the path. (this is one of the most downloaded packages on PyPI)

- Boost::URL rejects the URL outright.

If you're going by RFC 3986, then only Boost::URL is exhibiting the correct behavior. If you're going by the WHATWG URL standard, then I don't know which one of these behaviors (if any) is correct.

If you're interested in collaborating on this project, please send me email. My address is in the footer at https://kallus.org

bkallus··on Now it's PostgreSQL's turn to have a bogus CVE
I do :)

Until recently, LiteSpeed parsed Content-Length values using strtoll in the base-0 mode. Thus, by sending Content-Length values prefixed with 0, you can get it to interpret the value in base-8. Most HTTP proxy servers strip leading 0s from Content-Lengths, rendering the bug in LiteSpeed not exploitable. Until recently, HAProxy didn't do this, which made HAProxy + LiteSpeed vulnerable to request smuggling.

I put together a PoC demonstrating how this can be used to bypass any HAProxy ACL with default configurations for HAProxy (except the added ACL) and LiteSpeed.

Clearly, LiteSpeed is more responsible for this problem than HAProxy, but the bug in LiteSpeed violates HAProxy's security model, not its own.

bkallus··on Now it's PostgreSQL's turn to have a bogus CVE
The CVE system is all kinds of messed up.

We need (at least)

- A clear policy from the CNAs that describes exactly which bugs should be assigned CVEs.

- A process by which bogus CVEs can be invalidated, and CVE spammers can be banned from further submissions.

- A way to register CVEs for vulnerabilities that span multiple programs.

  - e.g. an HTTP proxy has a low-risk bug, and an HTTP server has a low-risk bug, but when the proxy and the server are deployed together, the bugs become exploitable.
- An appeals process for CVE description updates.

  - e.g. You would not know from the description that CVE-2023-34188 is trivially exploitable and can reliably lock up vulnerable servers because MITRE refuses to update it.
bkallus··on Now it's PostgreSQL's turn to have a bogus CVE
This works only for programs that are publicly available.
bkallus··on The technical merits of Wayland are mostly irrelevant
I switched my 2012 thinkpad from dwm+st to sway+alacritty a couple years ago and noticed no difference in input latency.
bkallus··on Ohio LinuxFest 2023 Conference Speakers
I'm also in the New England area. In Boston, there's LibrePlanet, which is in March. I went for the first time this year; it was a lot of fun.

I'm still trying to figure out if I'll fly out to Columbus for OLF this year. I went last year and the year before. It's worth the travel to me, but I have a flexible schedule. The talks are good, but the people are the real reason to go. A lot of the people who go to these conferences work on really interesting stuff. There are of course also big names like maddog and Doug McIlroy.

bkallus··on Ask HN: Why do functional programmers hate loops (for, while, etc.)?
Functional languages support this type of operation in a few different ways.

One is through constructs like Clojure's `take-while`. Instead of setting a vairable when you want to exit the loop, you define a predicate that is false when the loop should exit.

Another is through `any` and `all` (aka `some` and `every`), which work in a similar way to `take-while`, except they reduce OR or AND across the returned values from the predicate as they go.

EDIT: grammar and clarity

bkallus··on Node.js HTTP Request Smuggling via Empty Headers Separated by CR
Dang; I found and reported this vulnerability on June 5 (after this report was made, but before it was made public or patched), and was told that they were already aware of the bug and working on a fix. I didn't realize I'd been beaten by only 10 days!

https://github.com/aio-libs/aiohttp/issues/7312 https://github.com/nodejs/premature-disclosures/issues/4

bkallus··on Ask HN: Did studying proof based math topics make you a better programmer?
Taking a course in abstract algebra is a good first step. A first course in abstract algebra is supposed to introduce you to groups and rings, so you won't be out of place.

You might also consider taking a proof-based course in linear algebra.

bkallus··on Ask HN: I Want to have a small Linux laptop. What are my options?
This is good advice in general, but the Asus screenpad does work in Linux and it's extremely cool. Shows up just like a normal display!
bkallus··on Tell HN: Cancelling HP Instant Ink prevents cartridges from being used
Arch. I have hplip installed as well, and I'm not sure if that's necessary or not.
bkallus··on Tell HN: Cancelling HP Instant Ink prevents cartridges from being used
I use a LaserJet 1012 that was thrown out at a local law firm. It's almost 20 years old, and still prints great. I used it through high school, college, and now grad school, and haven't once changed the toner. It's plug and play on Linux, but is a pain to get working on Windows >7.

I don't know who still makes decent printers today -- I see a lot of people recommend Brother -- but why buy new when there are tons of cheap old laser printers from the days before they all became anti-consumer garbage?

bkallus··on Is infinity an odd or even number? (2011)
It is. The cardinality of the power set of a set S is 2^|S|.
bkallus··on LeanQt – GUI is here, Widgets are near
I don't know, but one could implement this without too much difficulty as a wrapper around afl-showmap.
bkallus··on Weed Is Coming to Circle K Gas Stations in US Next Year
My understanding is that that attacker wasn't using bath salts, and that the connection to bath salts was all speculation.

Also, I think bath salts is usually synthetic cathinones, i.e. functional analogues of khat, and not derivatives of meth, cocaine, ecstasy, or pcp.

Could be wrong, I'm just some guy on the internet.

See https://www.foxnews.com/us/medical-examiner-rules-out-bath-s... and https://en.m.wikipedia.org/wiki/Miami_cannibal_attack

bkallus··on Sound
I haven't taken beyond high school physics, so this question is probably obvious, but I haven't been able to find the answer (probably don't know the right terms to search).

When I increased the slider that allows you to change the flow of time for the gas in the cube, it really looked like visualizations I've seen of increasing the temperature of a gas. Is there a deeper relationship here? Could an observer tell the difference between a cube $A$ of gas in which the flow rate of time were doubled and a cube $B$ of gas with normal time passage, but a correspondingly increased temperature? If so, what would give it away?

bkallus··on Blender: Wayland Support on Linux
I just tested running gtk3-demo and gtk4-demo in sway. gtk4-demo does draw its shadows on other windows, but I wouldn't have noticed that if you hadn't brought it to my attention. Each has only the GTK title bar (no sway title bar) in both floating and tiled mode (but not full screen), which is, imo, a reasonable way for things to work.
bkallus··on “UBO Minus (MV3)” – An Experimental uBlock Origin Build for Manifest V3
Both.

"We will continue to support Manifest v2 to the extent that we can"

"Brave's adblocker (Brave Shields) is not an extension, and is natively implemented. So, it will be totally unaffected."

Source: https://www.reddit.com/r/brave_browser/comments/rdab12/how_w...

bkallus··on Don't ignore the janitor
I went to an American private high school that also did this, although not everyone was thorough, so they had custodians clean every so often. In retrospect, it was kind of cool.
← PreviousPage 2 of 3Next →