HNHacker News
TopNewBestAskShowJobs

chc4

3,088 karma · joined September 25, 2015

sickeningsprawl on infosec.exchange
submissionscomments
chc4··on The Raft Consensus Algorithm (2015)
It is darkly amusing to me that Paxos is still cited by people as a "good algorithm" to choose and understandable - including the cutesy island metaphor from the paper to appear approachable - and the Raft paper opens with a paragraph more or less going "ok we had a bunch of people try to understand Paxos and none of them could figure it out". Anytime I see someone recommend Paxos I silently am judging if they've actually ever read the paper or just parroting advice from when it was the only game in town.
chc4··on There is no memory safety without thread safety
This is one of the things that I'm also looking on at Zig like a slow moving car crash about: they claim they are memory safe (or at least "good enough" memory safe if you use the safe optimization level, which is it's own discussion), but they don't have the equivalent to Rust's Send/Sync types. It just so happens that in practice no one was writing enough concurrent Zig code to get bitten by it a lot, I guess...except that now they're working on bringing back first-class async support to the language, which will run futures on other threads and presumably a lot of feet are going to be fired at once that lands.
chc4··on Alan G. Hassenfeld, former CEO of Hasbro, has died
Following Magic the Gathering and DnD is always fun, because the dynamics are they are the two products that Hasbro make a profit on and keep the company afloat while they repeatedly lose money on every other toy line...while everyone is also alarmed about how they're running MTG and DnD into the group in favor of short-term profit.
chc4··on Mercury: Ultra-fast language models based on diffusion
Oh neat, thanks! The OP is surprisingly light on details on how it actually works and is mostly benchmarks, so this is very appreciated :)
chc4··on Mercury: Ultra-fast language models based on diffusion
Using the free playground link, and it is in fact extremely fast. The "diffusion mode" toggle is also pretty neat as a visualization, although I'm not sure how accurate it is - it renders as line noise and then refines, while in reality presumably those are tokens from an imprecise vector in some state space that then become more precise until it's only a definite word, right?
chc4··on Private sector lost 33k jobs, badly missing expectations of 100k increase
ADP say that they handle payroll for one in six of all companies in America. That is both a large sample size, and probably broadly representative of the economy. There will of course be some business segments that are over or underrepresented but that is different than disregarding the entire report as noise.
chc4··on XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
I'm generally pretty bearish on AI security research, and think most people don't know anything about what they're talking about, but XBOW is frankly one of the few legitimately interesting and competent companies in the space, and their writeups and reports have good and well thought out results. Congrats!
chc4··on Dev jobs are about to get a hard reset and nobody's ready
See, using AI as the equivalet of super-IDE snippets or to generate things in isolation is probably really good! It's also categorically not the same thing as what all of the AI hypemen (including the OP) are describing, with it replacing wide swathes of software developers. It devolves into a motte and bailey argument where it is actually possible for AI to be a useful tool in a programmer's toolbox, and make people more productive in isolated ways, without also agreeing with frankly anything the OP thread is saying.
chc4··on Dev jobs are about to get a hard reset and nobody's ready
While everyeone is just unilaterally asserting things, I'll jump in: no they won't. Practically every output of LLMs I've seen (even the "cutting edge" agentic ones that everyone says you have to evaluate or else your opinion don't count) has been poor quality with baffling bugs. These things do actually matter. Especially for anything that can be remotely described as "niche" or "research" they are astonishingly bad - maybe they're great for Go microservices or webdev, but there's a huge gap from there to "the entire software developer industry is doomed". Just calm down, man. You don't have to either breathlessly praise AI or start doomsaying, or say they're flat worthless, but a bit of humility over how uncertain the future may turn out is a noble trait to have.
chc4··on A different take on S-expressions
These definitely are extensions that you could add to S-expressions, no one can disagree there.
chc4··on US-backed Israeli company's spyware used to target European journalists
Are you somehow under the impression that Android devices aren't hacked as well?
chc4··on Xlibre project's fork of the Xorg xserver
Relevant background for the fork is https://gitlab.freedesktop.org/xorg/xserver/-/issues/1797
chc4··on Dystopian tales of that time when I sold out to Google
"Privacycoins" exist and lots of anarchist cypherpunks are able to use them to buy drugs, so I'm liable to say yes
chc4··on Dystopian tales of that time when I sold out to Google
It does seem slightly silly that a through-line of the article is disgust at societal power dynamics and surveillance, and then not recognize that Bitcoin and other proto-cryptocurrencies were invented by anarchist cypherpunks as a solution to the same thing in the monetary system.
chc4··on Ask HN: What do you spend your money on?
Nothing really. I invest the majority of my money. I'll buy the occasional $50 video game and get take-out a lot, but I don't have any large expenses (modulo rent and utilities) or expensive hobbies. I have the money to go travel on vacation or attend live concerts, I just don't want to and would rather stay at home.

I make ~$190k/yr. I work 32hrs/wk instead of 40hrs though, and I like it a lot more for my mental health - which I'm able to do because my salary is high enough to support my lifestyle with the trade-off of earning less per week.

chc4··on Using obscure graph theory to solve programming languages problems
The "equivalent-but-more-efficient program" example given at the top is almost exactly that, though
chc4··on Using obscure graph theory to solve programming languages problems
You don't need to compute dominators. A topological sort of the graph gives you a computation order where your definitions are computed before their use.
chc4··on Why not object capability languages?
Microsoft DCOM is a network RPC system that includes distributed GC, ftr.
chc4··on Some novelists are becoming video game writers – and vice-versa
One of my personal favorite examples is Seth Dickinson, who wrote some of the lore for Destiny, including the Book of Sorrow and Marasenna in-game lore books, which are IMO some of the best parts of the universe.

He then went on to write The Traitor Baru Cormorant, which I enjoyed a lot, and more recently Exordia - which is amusingly similar in themes and specific plot elements to the Book of Sorrow and really feels like Seth went "wait I wasn't done with that yet".

chc4··on Linux Kernel Exploitation: Attack of the Vsock
Going for the pipe spray is a kinda weird technique, and I'm honestly surprised that it worked. Usually just the fact that you are able to spray over the allocation at all isn't enough, and you also have to worry about your sprayed data containing additional pointers or things that also have to be valid.

I probably would have gone for turning the UaF into an type confusion style attack: if you spray more sockets you'll end up with two files, the original and the new one, that have aliased sk members, but the vsock code will incorrectly cast the new one to a `vsock_sock`. From there you can probably find some other socket type that puts controllable data over some field that vsock treats as a pointer or vice versa, and use it as both a kaslr leak and data-only r/w primitive.

chc4··on Unauthenticated Remote Code Execution in Erlang/OTP SSH
I'm vaguely surprised that https://www.runzero.com/sshamble/ didn't find this. They did a scan over the entire internet trying invalid SSH state machine transitions, which I guess didn't cover this sequence.
chc4··on Ask HN: Why is uptalk intonation so prevalent in ChatGPT voices?
nothing much, what's uptalk with you?
chc4··on The Practical Limitations of End-to-End Encryption
They're making a joke about how Matrix e2e is so high friction and unreliable that even if you should have access to a channel you'll get "unable to decrypt message" errors from key or identity issues - not that they would be rightfully unable to be decrypted by third parties (all the e2e programs they mention have that property).
chc4··on Specializing Python with E-Graphs
You don't have to actually saturate the egraph, or compute a globally optimal extraction. There are schemes that drive the rewrite exploration by "expected value" of the rewrite, for example, to avoid bloating the egraph with identities that are probably useless - I'd be surprised if that is much heavier than normal graph rewriting optimizers.
chc4··on Grease: An Open-Source Tool for Uncovering Hidden Vulnerabilities in Binary Code
Thinking about it more, a lot of bugs come around downstream of your initial function inputs, and you'd still be able to catch things like "heap allocation and then out of bounds read from that allocation with an offset derived from input" just fine since your least-constrained model only infers for the inputs. That probably covers a lot of the normal use-cases for Angr plus automatically harnessing inputs to reach that, which sounds pretty useful
chc4··on Grease: An Open-Source Tool for Uncovering Hidden Vulnerabilities in Binary Code
I'm suspicious of the effectiveness. Most people are doing symbolic execution to find bad pointer dereferences as bugs, whereas this tool is doing it to build the least constrained model and then checking the code against that same model. Wouldn't any code paths that are discovered as part of symbolic exploration and have out-of-bounds read/writes then be infered away as constraints, instead of bugs? Or being unable to detect memory corruption in the form of controlled pointer value overwrites, since you can't say that all pointer dereferences derived from your symbolic input are bugs that allow for attacked controlled memory corruption, because you don't have a concept of what inputs are under user control unlike most uses of Angr or other symbolic tainting tools. Is there a better list of the types of bug classes or heuristics that this is able to catch? Are there any numbers on the false positive/false negative rates against a dataset?
chc4··on CVE-2024-9956 – PassKey Account Takeover in All Mobile Browsers
The diagram in the post has the user device talking to the attacker device over Bluetooth, and the bug description explicitly says "An attacker within bluetooth range" - which heavily implies to me your device actually is pairing with the attacker device somehow! If already being paired with the attacker Bluetooth device is a prerequisite for this attack that's much less of a concern imo.
chc4··on CVE-2024-9956 – PassKey Account Takeover in All Mobile Browsers
The attacker controlled proxy is the one that logged in, and so captured a valid session for the user account that they can use afaik
chc4··on CVE-2024-9956 – PassKey Account Takeover in All Mobile Browsers
I don't use BLE PassKeys, but wouldn't the user also have to be paired with the attacker controlled BlueTooth device to get the connection request? Does the "The victim’s Authenticator connects to the attacker’s Client" step's authorization include pairing to a new device and not only allow a log-in with an already connected one?
chc4··on Show HN: I made a tool to port tweets to Bluesky mantaining their original date
Your PDS webmaster has a signing key for your repo, because they for all intents and purposes are you. That's the trust structure of how PDS' are setup. If you don't trust someone else to modify your repo don't give them your private (sub)key.

The fact it's a subkey means that you are also able to rotate the key that the PDS has access to and modify your repo back to pre-defaced state if need be.

← PreviousPage 2 of 17Next →