HNHacker News
TopNewBestAskShowJobs

bm98

400 karma · joined December 27, 2008

submissionscomments
bm98··on Firefox exploit found in the wild
I've run Firefox in a Red Hat/Fedora SELinux sandbox [1] [2] for the past 5 years or so. It is a little more tedious for things such as file uploads/downloads and cut-and-paste -- but worth it, IMHO.

[1] http://danwalsh.livejournal.com/31146.html

[2] http://www.bress.net/blog/archives/195-Firefox-in-a-sandbox-...

bm98··on Improve your touch typing
Ctrl-a Ctrl-k in Emacs moves to the beginning of the line and then erases the line. In screen, that key combination kills the current window! At some point, screen added a "Really kill this window [y/n]" which was a terrific enhancement...
bm98··on Why your 'A' grade SSL is 'outdated cryptography' on Chrome
It's worse than that. They've trained users to ignore the RED "X" on the little lock and the RED strikethrough on the "https" that Chrome shows for sites with SHA1-signed certs that expire after 2016[1]. Reasonable or not, some sites can't or won't update their certs and have no choice but to tell Chrome users to ignore those warnings.

[1] http://googleonlinesecurity.blogspot.com/2014/09/gradually-s...

bm98··on Why Is 'avast Web/Mail Shield Root' Listed as CA for Google.com? (2014)
My experience is that the Avast installation process will install its Trusted Root certificate if the "web scanning" option is enabled (which is the default) during installation. Even if Avast browser extensions are disallowed, and even if the web scanning feature is later turned off, the Trusted Root Certificate will still be there and will still be utilized.

As noted in the comments of the accepted answer on SE, this is not necessarily a security problem as long as the certificate is unique on each PC. But to me, in order for this whole Antivirus-MITM scheme to be secure, the AV vendor has to get a lot of things right. If the certificate generation during AV installation is flawed (say, with a weak RNG), then it could easily be exploited to perform MITM on anyone with the flawed certificate in their trusted root store.

bm98··on The Linux Security Circus: On GUI isolation
The very first comment below the article (correctly) contradicts the author's claims about SELINUX sandbox. The author acknowledges the comment, and criticizes the SELINUX implementation, but does not dispute the fact that SELINUX sandbox ("sandbox -X xterm" in RHEL/CentOS/Fedora/SL) does in fact defeat the keystroke logger attack described in the article.
bm98··on Ask HN: What are you working on and why is it cool?
So are you going to sign Business Associate Agreements with your customers? They won't be HIPAA compliant otherwise, under the latest HITECH rules. That's where the analogy to PCI breaks down.
bm98··on Let’s help Airbnb rebuild the bridge it just burned
The "creepy questions" -- in the USA at least -- are just another revenue stream for the three credit reporting agencies. They (or third party companies paying them for the data) pull data from your credit report and then ask multiple-choice questions based on the data. It's absurdly insecure given the large number of people who have subscription access to credit reports (landlords, car dealerships, employers, etc.). Even more ridiculous is that the questions are based on data that is often false. A scammer who applies for a credit card in your name provides a false address; that false address is added to your credit report and now can become part of the identity verification scheme. And of course the onus is on you to fix the bad data held by these companies.
bm98··on Pixels don’t care
Agreed, but I think you're selling yourself short on your percentile: http://www.cdc.gov/growthcharts/data/set1clinical/cj41l021.p...
bm98··on Please Learn to Code
It's the "knows enough to be dangerous" problem.

It applies to a lot of professions. We see it applied to the legal profession all the time here on HN.

No lawyer likes to find out that the Accounting Dept. has been drafting contracts, any more than an IT person likes to discover that the CPAs have developed a pseudo-enterprise accounting "system" in Microsoft Access.

But I think there is a middle ground: It's not practical to consult a lawyer for every click-through agreement you encounter on the web, just like it's not practical to launch an enterprise IT project every time you need to automate some tasks in a spreadsheet. Some basic skills in these areas are good to have. Just know your limits...

bm98··on Harvard 1869 entrance exam
An 1869 MIT entrance exam was posted here a while back and the typesetting was similar:

http://news.ycombinator.com/item?id=1967040

http://bm98.posterous.com/did-they-have-latex-in-1869

bm98··on Richard Stallman on Steve Jobs: correction
Stallman comments on HN are so heated, in part, because a big part of his message is that developing non-free software is unethical. Not just wrong or misguided or foolish, but unethical. Morally wrong.

What percentage of HN readers develop non-free software for a living, or for part of their living?

So it hits a nerve, I think. And I am consistently drawn to Stallman threads on HN because people's reaction to this is so interesting.

bm98··on Ten years of Windows XP: how longevity became a curse
Actually I would say 5GB is a more reasonable minimum.

I recently installed an old XP Home CD in a VM with a 4GB disk. The only way I could get enough space for SP3 + updates was to compress the disk.

AFAIK, there is no easy way to resize the primary partition without reinstalling the OS or using third-party partitioning software, so I get by with my 4GB primary and a 2GB secondary for applications.

And I thought my days of running "Disk Cleanup" and manually cleaning out "\WINDOWS\SoftwareDistribution/Download" were over...

bm98··on The Tyranny of Silly Expense Control Rules
http://www.google.com/search?q=%22now+find+the+umbrella%22
bm98··on Ask HN: Screwed out of $12.8 million. Being Extorted. No Money for attorneys.
You clearly aren't trying to be anonymous, since you named the company and your patent is easy to find. Congratulations, I guess, for being the first to patent the idea of authenticating a web app based on a password plus a cookie from a prior session, and requiring additional authentication if the cookie isn't there. Hard to imagine that that wasn't obvious in 2004, but maybe it just seems that way in retrospect.
bm98··on Girls sweep at Google Science Fair
The top three winners were all in the health sciences. Had they been in engineering, physical science, or computer science then it would have been more newsworthy given the gender gap in those fields.
bm98··on Walt Mossberg Tells Adobe CEO To His Face That Flash Sucks On Android
I'm surprised that there isn't more talk about Flash efficiency and its impact on global energy consumption and the environment. My desktop CPU burns an extra 50 watts when it is pegged at 100% (and in a typical day, Flash is the only thing that pegs my CPU for a prolonged period of time). Multiply that by hundreds of millions of computers running Flash -- many whose owners don't realize their CPUs are at 100% -- and it adds up to potentially millions of extra pounds of CO2 emissions every day.
bm98··on Now, to Find a Parking Spot, Drivers Look on Their Phones
If I am the only person who has access to the app, it will get me off the street and into a spot faster.

If everyone has access to the app, then nothing will change.

Think about it. How quickly are open spots snatched up in downtown San Francisco at peak hours right now? There's not much room for improvement there.

The problem is simply that there is more demand than supply of on-street parking, and people are willing to wait 30+ minutes to "win" a spot.

A much more effective solution is to just raise the price of on-street parking.

Philadelphia did this in 2009 [1]. I don't know if they've done any studies to evaluate the impact, but my own personal observation was that it opened up just enough spots during peak hours to eliminate the need to "cruise" for parking almost entirely.

[1] http://www.nbcphiladelphia.com/news/local/Phila-Meter-Parkin...

bm98··on Cheating and the Honor System
> "If you prevent cheating by having a person who's job it is to catch you then you feel like if you don't get caught you have won."

Given the time of year, when I read about cheating and the honor system, my first thought is about taxes, specifically, paying state sales tax on items bought online and shipped from out of state.

Most states don't have an easy way of catching sales tax cheaters, so it usually comes down to the honor system: When you file your state income tax return, you are supposed to add up all your "mail order" receipts for the year and pay sales tax on them.

How many HNers actually do this, I wonder? This seems like an instance where there is an honor system, but everyone cheats anyway.

bm98··on Auto submission bots on Hacker News
OK, now I'm confused. The average karma on my HN profile is blank. After reading "hey, the average karma score is gone"[1] I thought that HN had done away with it, but now I see that pretty much everyone has an average karma except me. Could it be because I have only comments but no submissions?

[1] http://news.ycombinator.com/item?id=1944871

bm98··on Mach's designers simply assumed that systems would be rebooted often enough
My favorite Linux bug (since fixed):

https://bugzilla.redhat.com/show_bug.cgi?id=97373 (System UPTIME reported incorrectly):

"Steps to Reproduce: 1. Boot Linux system; 2. Go away for 497 days; 3. check uptime"

bm98··on I'm a pregnant hacker. Please review my side project.
FYI - I just received an invitation to a baby shower with a reference to www.amazingregistry.com. Your site looks much more pleasant than theirs, and you have a more narrow focus... but since their URL ended up on a real baby shower invitation, I'd say they are your competition.
bm98··on WHAAAAT? Unlimited storage for $4.99 a month not a viable business model?
It depends. When "Unlimited" service is sold with a Terms of Service that includes an "Excessive Use Policy" like Mozy's [1], the heavy user is operating in an ambiguous zone where continued use of the service at the advertised price is at the whim of the provider.

We've seen this with unlimited data plans with the cable ISPs; they're not really unlimited.

To me, it's similar to having a traditional credit card versus one with no pre-set spending limit. Which would you rather have? The latter has a limit, you just don't know what it is until you hit it.

---

[1] http://mozy.com/terms/ "....excessive use of the Service, which means usage over a given period far exceeds the average level of usage by users of the Service generally..."

bm98··on Why I Left Google
The individual insurance market is not quite so bleak for _everyone_ in the US. Some US states, such as New York, New Jersey and Massachusetts, have "community rating" or "guaranteed issue" laws on the books.

See: http://en.wikipedia.org/wiki/Community_rating

It's complicated, of course. There are varying degrees of community rating, and these laws (particularly without a mandate for everyone to buy insurance) sometimes cause insurers to drop out of the market.

bm98··on My Experiences as a Female Software Engineer
One of the beauties of programs that teach Scheme and ML (or OCaml or F#) in introductory CS is that they level the playing field. The typical high school computer hot shot has never seen anything like functional programming before, and is no better off than anyone else in the class. Follow that with the theoretical foundations of CS and you have plenty of hot shots at the bottom of the class. A professor of mine once said, "Some kids just can't hack the math."
bm98··on Why So Many Rich People Don’t Feel Very Rich
People between the 70th and 90th percentiles feel squeezed by a lot of expenses that cost less for those lower on the scale, due to price discrimination, progressive taxation, subsidies, etc. College tuition is a good example. It's high enough to take a big chunk of the income of a 70-90th percentile earner, but it doesn't hurt as much to someone higher (spare change!) or lower (financial aid) on the income scale.
bm98··on Why Chinese Mothers are Not Superior (from a female Chinese engineer)
> It also makes me wonder why WSJ published such an apparently ridiculous article.

Chua is trying to drum up interest for her new book on the same topic which goes on sale today. Her publisher, Penguin Books, is owned by Pearson PLC. Rupert Murdoch and News Corp (which owns the WSJ) has plenty of history with Pearson -- owning a significant stake in the company in the 80's, buying HarperCollins from Pearson in the 90's, competing with Pearson's Financial Times lately. I don't know if there is any Murdoch ownership in Pearson now, or any publishing agreements between the two companies, but I doubt the WSJ article was published based on editorial reasons alone.

bm98··on Retracted autism/vaccine study an 'elaborate fraud,' British journal finds
You are incorrect: In the US, two 2009 H1N1 vaccines distributed in multi-dose vials were approved for children >= 6 months. See:

http://www.cdc.gov/h1n1flu/vaccination/dosage.htm#table1

bm98··on Retracted autism/vaccine study an 'elaborate fraud,' British journal finds
In most US states, a parent can apply for a religious exemption that will allow them to enroll their child in school without one or more of the required immunizations. Some states even offer "philosophical" exemptions.

The National Conference of State Legislatures maintains a list of exemption statutes by state:

http://www.ncsl.org/default.aspx?tabid=14376

bm98··on Ask HN: What's your favorite IDE?
Emacs
bm98··on Microsoft Outlook ruins my evening
My company uses IMAP and has some employees who came from jobs with Outlook/Exchange, so we hook them up with Outlook/IMAP in the hopes that they'll be comfortable in that environment. But it's a far cry... it's like moving them to a whole new client anyway.
← PreviousPage 2 of 3Next →