HNHacker News
TopNewBestAskShowJobs

blumentopf

1,046 karma · joined May 12, 2011

hn2.20.melitta@spamgourmet.com
submissionscomments
blumentopf··on More Apple Car Thoughts: Software Culture
Based on my experience (from working there), car manufacturers often do not implement stuff themselves, they outsource. E.g. the HTML5-based infotainmemt system in the Porsche 918 was not created by Porsche (though they market it as if it was), but by S1nn.

From a software engineer perspective, if you work at a car manufacturer, you usually do not write software yourself, you're hired to write specs for external companies and verify that the results are conformant. Which honestly is boring.

The car manufacturers should react to the influx of new competitors (like Apple, Google) by becoming software companies themselves, but management is too stupid to see that. S1nn is a perfect example: Apple or Google would have bought the company right away, so should have Porsche. Guess who bought them instead? Harman.

blumentopf··on Why Some Security Experts Use Mutt
Subscribe to LKML or one of the subsystem mailing lists (e.g. dri-devel). Pretty much the majority of Linux kernel developers seem to be using Mutt. (Disclosure: Me too, since 1997 in fact when I needed to replace ELM.)
blumentopf··on Ask HN: How do you deal with social media pressure on your GitHub project?
I think parent referred more to contentious issues (e.g. sexism, systemd hate) rather than uncontrollable growth of a project. That said, excellent post, thank you!

The opposite of course are projects with too few contributors that accept any patch out of desperation, be it reasonable or not. (ZFS on Linux comes to mind, it's a super nice community and Brian Behlendorf does a great job as project lead but sometimes features and patches creep in of which I'm wondering why nobody dared saying "no".)

The Linux kernel community solved growth by delegating responsibility to subsystem maintainers. Such a hierarchical model is not supported by GitHub. Also, the kernel community's process of submitting and discussing patches on mailing lists, while somewhat arcane, raises the barrier of entry and keeps at least a portion of the Twitter mob out.

blumentopf··on [dead]
Because this is Europe's Lehman weekend. Those who think that contagion is not an issue anymore may be in for a surprise. In combination with this week's record plunge at Shanghai Stock Exchange and a general slowdown of the world economy this could spiral out of control fairly quickly.
blumentopf··on Ask HN: Who is hiring? (May 2015)
Incidentally I checked your hiring page a few days ago and found only non-engineering jobs listed. Will definitely send you an e-mail though.

I hope you don't mind me saying, the hiring page required me to turn on cookies. For a privacy-focused company I think it would look best to not set cookies at all. (Or use cookies only for personal settings like language selection, like DuckDuckGo does.)

Edit: Can't find a public key for Frank nor Travis on pgp.mit.edu, will e-mail JshWright, okay?

blumentopf··on List of April Fools' Day Announcements
The Hurr Durr Archives

https://www.kernel.org/

blumentopf··on Ask HN: How Do You Maintain Security When Working Remotely?
Retrieving wifi passwords from NVRAM:

    /usr/libexec/airportd readNVRAM
Alternatively:

    nvram 36C28AB5-6566-4C50-9EBD-CBB920F83843:current-network
    nvram 36C28AB5-6566-4C50-9EBD-CBB920F83843:preferred-networks
    nvram 36C28AB5-6566-4C50-9EBD-CBB920F83843:preferred-count
blumentopf··on Ask HN: How Do You Maintain Security When Working Remotely?
Can't speak for other OSes but OS X constantly phones home to Cupertino, sometimes not even using encryption, thus leaking data when you're booked into a public Wifi.

I literally spent weeks last year grepping the entire Mavericks base installation for hardcoded URLs, domain names and IP addresses and setting up entries in /etc/hosts and NAT rules to hardwire that stuff to 127.0.0.1. I also had to disable lots of LaunchServices/Agents to get the OS to shut up. Can put this up on Github if there is interest. It's only for Mavericks though, couldn't be bothered to upgrade to Yosemite as long as there are security updates for Mavericks.

Oh and another thing a lot of people don't know: The OS stores Wifi passwords in EFI boot variables. This is used for Internet Recovery. So if your device is stolen or just lent to someone else, consider your Wifi passwords compromised, regardless if the disk was encrypted.

blumentopf··on Why people were enthused about GCC early on in its life
It wasn't free for universities, but in the first half of the 90s, SGI offered so-called "Varsity" contracts, which was basically a campus license for OS updates and unbundled products like compilers, NFS/YP and the "Documenter's Workbench" (a fancy name for troff/nroff).
blumentopf··on Against DNSSEC
Of course it does, Safari uses the resolver provided by OS X, which is mDNSResponder. (It superseded the stub resolver in libSystem.dylib starting with 10.6.)
blumentopf··on Against DNSSEC
mDNSResponder supports DNSSEC validation, please look at the source code:

http://opensource.apple.com/source/mDNSResponder/mDNSRespond...

blumentopf··on Against DNSSEC
Reaction when @tqbf, again, claims DNSSEC is NEVER GOING TO HAPPEN

http://dnsreactions.tumblr.com/post/92623693242/when-tqbf-ag...

blumentopf··on Against DNSSEC
> Browsers and operating systems aren't going to add full DNSSEC resolving caches.

Actually they already did. OS X for instance has this baked into mDNSResponder.

blumentopf··on The Dot-Com Bust’s Worst Flops Were Actually Fantastic Ideas
I worked at an ISP in the late 90's which was bought up, together with several other small ISPs. Before the acquisition it was a bunch of techies working their asses off. After, dozens of non-technical staff came on board who all got huge paychecks and a BMW, bossed the techies around in clueless Outlook 98 fullquote e-mails but contributed zero to the bottom line.

The money, in our case, came from a large north-european telco with deep pockets. They turned a blind eye to the burn rate for almost 2 years before pulling the plug.

I've heard of a German tech company hiring a philosopher, you know, just for fun. On a superficial level, this might seem comparable to Google hiring Ken Thompson, Guido van Rossum and tytso. In reality however these folks not only boost Google's reputation among developers, they innovate and make a technical contribution to the company. That precisely is the difference between 90's dotcoms' thrift-spending habits and how companies work today. The article misses that completely.

blumentopf··on Canon printer hacked to run Doom
Apple LaserWriter 16/600 PS (1994)

Got it on eBay for 1 Euro. Eats standard HP LaserJet cartridges that you can find on eBay for just a few bucks.

blumentopf··on The State of ZFS on Linux
Source? Edit: Found it.

http://lists.freebsd.org/pipermail/freebsd-hackers/2013-Sept...

blumentopf··on The State of ZFS on Linux
You need to tell the kernel if you need larger-than-default SO_SNDBUF/SO_RCVBUF, e.g. for 4 MByte (default is 128 kByte):

  sysctl -w net.core.rmem_max=4194304
  sysctl -w net.core.wmem_max=4194304
Documentation: http://git.kernel.org/cgit/linux/kernel/git/stable/linux-sta...
blumentopf··on The State of ZFS on Linux
I use ZFS on a dual-boot Mac to cross-mount the Linux partitions on OS X. ZFS is pretty much the only file system that allows this: The XFS OSXFUSE plugin is read-only, the ext plugin only supports ext2 with unstable write support and BtrFS can't be mounted on OS X at all.

The ZoL-derived OpenZFSonOSX port inherits ZoL's maturity, runs in kernel space and the OS X integration is really nice (Notification Center integration in ZED, custom icons, etc).

Lovin' it!

blumentopf··on OkCupid’s Unblushing Analyst of Attraction
"Rudder's blog went on hiatus between April 2011 and July 2014 while he wrote Dataclysm: Who We Are (When We Think No One's Looking), a book based on the same ideas that inspired the blog."

Source: https://en.wikipedia.org/wiki/Christian_Rudder

blumentopf··on The Lowdown on Lidar
I'm surprised they exonerated him, considering his driving history...

Turns out he apparently blew a red light with his Boxster in 2010 and hit another car:

http://attitudeofgratitude.typepad.com/attitude_of_gratitude...

blumentopf··on Ask HN: Who is hiring? (June 2014)
Hm, that page doesn't provide a PGP key for the iwanttohack address, neither is there one on pgp.mit.edu. :( I do find two keys of you personally on pgp.mit.edu, 0x1DBE9880 from 1999 with an mit.edu address and 0x6BA33506 from 2000 with a mindspring.com address, but none with a duckduckgo.com address. Typically public keys that old without a contemporary e-mail address are no longer in use and the corresponding private key has often been lost.

It would be nice if you could make a new key available (RSA with 3072 or 4096 bit) for either the iwanttohack address or your own address, and preferrably link to it on your hiring page. It would underscore your privacy credo and help you stand out from the crowd. (Sadly, even here in the HN Who's Hiring thread, few people have a PGP key and even fewer include it in their job postings.)

blumentopf··on Ask HN: How bad is it to use a self-signed SSL certificate?
If your zones are signed with DNSSEC, just add a TLSA record for the self-signed certificates to the zones. Clients with DANE [1] support will then recognize that the self-signed certificates are valid.

Of course, very few clients support DANE as of yet. Nevertheless, that is the most modern solution and you'll spur adoption of DNSSEC and DANE if you offer it to clients.

[1] https://tools.ietf.org/html/rfc6698

blumentopf··on The desktop and the developer
This. Tweakability isn't the issue. Simply catering to pro users is the issue. I moved from Linux to OS X in 2004 and am now on the fence about moving back.

When OS X came out, Steve Jobs promised an OS that would cater to pro users as well as amateurs. He literally said so in one of his keynotes. But around 2006, Apple started focusing on the upcoming iPhone and downprioritized OS X development. Nowadays it's all about making OS X more and more like iOS. They no longer care about pro users.

Case in point: If you're doing pentesting you need a machine that stays silent when connected to a network. With OS X you always have mDNSResponder blaring out. Prior to 10.6 you'd just solve this with a simple "launchctl unload" and be done with it. From 10.6 however, unicast DNS resolution was moved into mDNSResponder, so you need to keep it running or you lose the ability to resolve anything in the DNS. Of course it's possible to filter the multicast DNS announcements with pf, but it turns out that mDNSResponder will occasionally resolve various apple.com and Akamai addresses and that can't be disabled.

Same with IPv6 link-local addressing, it used to be possible to disable it completely, now that's no longer possible because they've dumbed down the UI. And when you use WiFi, OS X will regularly send 802.1X EAPOL messages out. That can't be disabled even with pf because pf doesn't filter on layer 2. Under these circumstances I find OS X to be unusable for pentesting.

And don't get me started on the laughable HFS filesystem and the non-existence of a package manager.

blumentopf··on Fedora 21 To Have DNSSEC Validation Enabled By Default
The concern that the Lybian TLD registry might fake NS and/or DS records of 2LDs applies equally to unsigned and signed zones. So if that is a concern, why use an untrusted TLD, or why use DNS at all?

If you do not trust the Lybian TLD, configure a negative trust anchor for that TLD in your resolver.

Alternatively, if you want to pin that TLD to a particular KSK, configure that KSK as a (positive) trust anchor in your resolver.

If you do not trust the IANA at all, disable the IANA root in your resolver and add trust anchors for the domains you trust. Use lookaside validation if you find that too cumbersome and want to let others do that work for you.

blumentopf··on Fedora 21 To Have DNSSEC Validation Enabled By Default
By definition a tree has a single root. Please specify what you mean be "roots".

The private key of the DNS root was split in seven parts held by seven people [1]. It is stored in two HSMs, one on the east coast of the United States, one on the west coast. Could the NSA or some other agency have gotten hold of the private key? Probably. But spinning that as "the DNSSEC root is controlled by the governments" is FUD.

[1] http://venturebeat.com/2010/07/28/seven-security-experts-get...

blumentopf··on An open letter to Eric Schmidt from Mathias Döpfner, CEO of Axel Springer
Döpfner is trying to pivot the Axel Springer publishing house into a digital media company but their efforts are laughable. They sold some of their newspapers and magazines and are investing the money in dotcoms, but compared to Google or even Yahoo they're just small fish. They're clueless about technology so they resort to whining about the oh-so-evil Google.

For a quick laugh, watch this video of a tourist trip to Silicon Valley they did last year: https://www.youtube.com/watch?v=ug4Rcip9SHg

blumentopf··on .ng is the most dangerous cctld
Related: Counterexamples of good ccTLDs: https://gun.io/blog/secure-your-domain-where-is-safe-to-regi...
blumentopf··on DNSSEC surpasses 50% of root domains
Your zones need to be either online-signed by the authoritative DNS servers for these zones or offline-signed (using e.g. OpenDNSSEC) and then pushed to the authoritative DNS servers. Offline-signing is obviously more secure but signatures need to be refreshed regularly, so it's not sufficient to sign the zone once and be done with it. The zone needs to be resigned and pushed out to the authoritative DNS servers continually. If that process fails somehow, the signatures will expire and your zones will no longer validate. It's like a self-inflicted DoS. Setting this up properly is a nightmare.

The ISP you're hosting your domains at needs to support this.

blumentopf··on Ask HN: Sick of your bank? Want to build a open source, non-profit, online bank?
There are so-called "sustainable banks". The largest in Europe is Triodos, they also have a British subsidiary. Globally they are networked through the Global Alliance for Banking on Values (http://gabv.org). Key features of those banks are transparency as to how much money is lent to whom (there's a Google Maps based tool on Triodos' website to discover their borrowers), non-financing of certain industries (e.g. weapons), non-participation in food speculation, etc.
blumentopf··on Bzr is dying; Emacs needs to move
> it doesn't paint Stallman very well as the head of a project

Is this news to you?

Cf. e.g. http://www.jwz.org/doc/lemacs.html

← PreviousPage 2 of 6Next →