HNHacker News
TopNewBestAskShowJobs

cleeus

239 karma · joined May 23, 2016

submissionscomments
cleeus··on A plan for open source software maintainers
I few years ago I envisioned exactly this, something like a cross between bugzilla and kickstarter/patreon. I want something fixed/done and want to pay someone a small amount to do it.

Even registered a domain for that. If someone wants to implement this, I would donate the domain (5-letter flattr-like .com/.org).

cleeus··on Atmospheric CO2 levels accelerate upwards
I have seen some solar companies in my region, but I honestly am not convinced yet that solar is the way to go. Does anyone know if solar can sustain itself? (Does a photovoltaic panel produce more electric energy during its lifetime than was required to produce it?)
cleeus··on Kent Beck: “I get paid for code that works, not for tests” (2013)
at which point we first need to talk about the type of coverage ... tree coverage or line coverage (or something else?)
cleeus··on Kent Beck: “I get paid for code that works, not for tests” (2013)
well, not at all times. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3416
cleeus··on Epson customers report Google Cloud Print causing printers to power down
As a counter example: My Kyocera Mita FS1020-D is working well since 2004. Reliable things (printers) with moving parts can be built.
cleeus··on Show HN: Fun tool that cut my family and friends tech support time in half
I moved three relatives who's computing skill vary between "What is a file, again? Help me, my Internet is gone?!!" and "How do I use this scanner to get that document into a PDF file and send it via Thunderbird?" over to Xubuntu (Ubuntu with XFCE, 14.04). They all dutifully do the upgrades and it's very rare that I have to intervene.
cleeus··on George Hotz Is Giving Away Self-Driving Software
doesn't look to bad except: - I can't find automated tests - The vision module is a binary blob (of course this was also stated in the previous HN discussion)

The rest is basically just a bunch of glue and bootloader code.

cleeus··on George Hotz Is Giving Away Self-Driving Software
Do you happen to know where the code is? Can you post a link?
cleeus··on Best Wifi Mesh Network Kits
One thing to note: usually there is no OpenWRT support on UniFi hardware. I tend to go with TP-Link and flash.
cleeus··on Schiaparelli landing investigation makes progress
negative altitude ... so integer overflow it was ...
cleeus··on The status of Linux kernel hardening
One thing I routinely do is compiling a monolithic kernel without module support (and exactly the modules the hardware needs). This way injecting a module into the kernel should be a little harder.
cleeus··on Bahmni – Open-source Electronic Medical Records and Hospital System
Same thing in germany: you won't get a hospital to use this, ever. Selling to hospitals is enterprise sales ^10 - we see sales cycles between 3 to 8 years (that is from initial lead to project delivery).

It might have a chance in developing countries with less regulation in place.

cleeus··on Bahmni – Open-source Electronic Medical Records and Hospital System
at that point ... maybe you just want to go bare metal?
cleeus··on Project Shield
It's the feudalism age of the internet. Everyone needs a lord for protection.
cleeus··on Mitigating the HTTPoxy Vulnerability with Nginx
btw, the reference FastCGI C library libfcgi also alters the environment to emulate legacy CGI and may also be vulnerable (haven't checked).
cleeus··on Mitigating the HTTPoxy Vulnerability with Nginx
I think the CGI "standard" is to be blamed.

Whoever the f*ck had the briliant idea to alter the environment variables of a server child process through incoming HTTP headers should have his browsers environment variables altered by the servers responses.

cleeus··on Differential Fault Analysis of SHA3-224 and SHA3-256 [pdf]
tl;dr if an attacker can flip certain bits in one of the last phases of a SHA3 execution (e.g. through power glitching on a device) and can compare the result with that of a correct execution, the internal state of the function can be fully recovered. With short inputs, the whole input can be recovered. This may pose a risk for MAC protocols where the attacker might be able to reveal the secret.

Nothing to worry about outside of the hardware world.

cleeus··on ARM founder says Softbank deal is 'sad day' for UK tech
aha, they intend to keep the ARM HQ in the UK. Well ... let's see what they say in 10 years because you know, once a company is sold, the buyer can do whatever the fuck he wants with the thing he just bought.
cleeus··on Zeroing Memory is Hard: VC++ 2015 arrays
At this point we must ask which Update of VS 2015 as MS just replaced the Optimizer with an SSA based one. https://blogs.msdn.microsoft.com/vcblog/2016/05/04/new-code-...
cleeus··on USB 3.0 Radio Frequency Interference on 2.4 GHz Devices (2012)
Wireless input devices usually talk in the 2.4GHz and 5GHz bands of wifi. They are allowed to, since the spectrum is basically open for anything (AFAIK) but they effectively jam wifi when in use. So this is intentional while the USB3.0 cables jamming wifi seems unintentional.
cleeus··on Likely hack of U.S. banking regulator FDIC by China covered up: probe
everybody repeat after me: reliable. attribution. of. hacks. is. impossible.
cleeus··on Is Ego-Depletion a Replicable Effect?
love this quote:

> Every researcher knows about publication bias, but the practice is so widespread that it is not considered a serious problem.

cleeus··on Home Computers Connected to the Internet Aren't Private, Court Rules
in germany, the highest court ruled exactly the opposite: https://de.wikipedia.org/wiki/Grundrecht_auf_Gew%C3%A4hrleis...

rough translation: "The right to confidentiality and integrity on IT systems"

google translate link: https://translate.google.com/translate?hl=de&sl=de&tl=en&u=h...

As far as I remember the CCC wrote an expertise in the ruling and mentioned computerized implants. That was the point were the judges understood that there should be an expectation of privacy on home computers.

cleeus··on The European Union is updating its electronic signature laws
I didn't read anything about the notion of trust levels in the directives text. Can you point me to the law?

As far as I can see, any signature that is/appears to be qualified (regardless how it came to life) is considered equal to a signature under notary oversight (at least in germany) and shifts the burden of proof. This is heavy!

cleeus··on The European Union is updating its electronic signature laws
If you use a smartcard, you should use a class2/class3 card reader with pin-pad and never enter the pin on you computer. So the machine can replace the hash that is to be signed, but cannot intercept and replay the PIN.
cleeus··on The European Union is updating its electronic signature laws
On the one hand, eIDAS (the e-signature part) is definitely a good thing as it will replace a lot of weak national signature laws with something modestly safe. On the other hand it will also replace strict signature laws (e.g. german) with something much weaker. In the core of e-signatures is the so called human-machine transfer (Schneiers term). A human expresses his legal declaration of intent through a machine. In germany this required a (certified) qualified signature unit and software which de-facto meant certified smartcard from certified trustcenter with secure pin entry (on the card-reader, not the computer).

According to eIDAS this can be replaced with much more weaker forms like server-side keys and signature after 2FA. And this is where folks from DocuSign (and others) will come in and place cryptographic signature on documents exchange for username+password+click (maybe with 2FA, I doubt that).

So you formerly needed smartcard (possession) with PIN (knowledge). Now you may only need username+password (knowledge) and maybe a second factor like mobile phone. I doubt that having control over a smartphone is on the same security level as control over a class 2/class 3 smartcard reader.

cleeus··on Mise en abyme
compiler bugs - use of uninitialized memory
cleeus··on What happens when you try to publish a failure to replicate in 2015/2016
Yes, but there is just not a way to regulate journals other then by market forces - which seem to fail through information asymmetry about the journal quality and maybe some monopoly inducing positive feedback effects.

Maybe law could break the information asymmetry between sellers and buyers of the journals by adding new clauses to the copyrighted works of state-sponsored scientists...

cleeus··on Even Mark Zuckerberg puts tape over his webcam
corporate IT security policy?
cleeus··on A Third of Valve Is Now Working on VR
> Or maybe too many devs thought VR was the coolist project to work on and moved to it.

I think it's this. That's the problem with hype waves in majority-ruled organizations. Or I'm wrong and people will soon be sitting in the subway with a VR headset on and playing Fruit Ninja in VR.

← PreviousPage 2 of 3Next →