HNHacker News
TopNewBestAskShowJobs

clwg

669 karma · joined February 23, 2014

submissionscomments
clwg··on Claude Opus 4 and 4.1 can now end a rare subset of conversations
This argument mischaracterizes the notwithstanding clause. Invoking s.33 is highly visible and carries political consequences. It shields a law only from being struck down on certain Charter grounds and must still comply with all other federal and provincial legislation (like PIPEDA).

It’s not perfect, but it does provide some flexibility to accommodate provincial differences. And the concerns people raise about the notwithstanding clause can just as easily occur in countries without it. Personally, I’d be much more concerned if we had FISA courts.

clwg··on Claude Opus 4 and 4.1 can now end a rare subset of conversations
> Which have failed horrendously.

I'm Canadian, so I can't speak for other countries, but I have worked on the security of some of our centralized health networks and with the Office of the Privacy Commissioner of Canada. I'm not aware of anything that could be considered a horrendous failure of these systems or institutions. A digital ID could actually make them more secure.

I also think giving kids devices that identifies them automatically as children is dangerous.

clwg··on Claude Opus 4 and 4.1 can now end a rare subset of conversations
This may be an unpopular opinion, but I want a government-issued digital ID with zero-knowledge proof for things like age verification. I worry about kids online, as well as my own safety and privacy.

I also want a government issued email, integrated with an OAuth provider, that allows me to quickly access banking, commerce, and government services. If I lose access for some reason, I should be able to go to the post office, show my ID, and reset my credentials.

There are obviously risks, but the government already has full access to my finances, health data (I’m Canadian), census records, and other personal information, and already issues all my identity documents. We have privacy laws and safeguards on all those things, so I really don’t understand the concerns apart from the risk of poor implementations.

clwg··on Frequent reauth doesn't make you more secure
This requirement is in section 8.3.9 of the PCI DSS[0], and only applies to single-factor authentication implementations, two-factor auth removes this requirement.

[0] https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard...

clwg··on Trying out Zed after more than a decade of Vim/Neovim
I use tmux and neovim along with the copilot plugin[0]. I prefer it over the VSCode copilot integration, to me it feels less obtrusive and out of the way, which is what I want. You're also not dealing with API costs since it uses the regular Copilot subscription.

[0] https://github.com/github/copilot.vim

clwg··on Justin Trudeau promises to resign as PM
In Canada, we have the inherent right to assemble as granted by the Canadian Charter of Rights and Freedoms; therefore, I don’t need permission, which is discretionary.

Permits in this context represent authorization that establishes procedures for exercising this right on property administered by government, which ensure things like public safety without infringing on any rights or freedoms of the protestors or other citizens.

clwg··on Justin Trudeau promises to resign as PM
Perhaps bad phrasing, it is an emotional issue having lived through it.

I like to think that I don't live in a country ruled by a King but rather in a community of citizens who have collectively agreed on a way of doing things. This includes the right to express dissent against other citizens to whom we have delegated certain decision-making responsibilities. A permit isn't about seeking permission; it's about ensuring an orderly process so that things don't devolve into chaos and bouncy castles.

At the time, I think we were also in stage 2 lockdown(which should have been enough to stop it), so the people bearing the brunt of these actions, whatever you want to label it as, were not the ones making those decisions. Our elected officials don't live inside Parliament Hill.

clwg··on Justin Trudeau promises to resign as PM
I live in Ottawa. We were failed by all levels of government, our police services, and our intelligence services.

The convoy drove across the country, broadcasting their intentions on social media. Yet, everyone acted shocked when they did exactly what they said they were going to do.

I hesitate to call them protesters because I don't think they had a permit or a cohesive message beside F* Trudeau, but they were completely disrespectful to other citizens, and I could never defend their actions. However, irrespective of how unpopular their actions were, the courts have deemed the federal government's response unreasonable and unconstitutional, and I agree with that assessment.

The government could have dealt with this earlier and more directly, but whatever passes for "leadership" these days in Canada has proven itself completely inept.

Personally, I would like to see an inquiry into foreign interference in our elections, but I guess that’s not considered a pressing issue anymore.

clwg··on The Future of Htmx
I did something similar but I took it entirely the other way, I built a full CRUD application with no javascript.

The app is fully SSR and integrates with a fairly complex inline data enrichment and analysis system. I used Tailwind alongside regular CSS for the layouts and some visual enhancements. Eventually, I gave in and added a bit of JavaScript to submit a form when a dropdown is selected—usability is important to me. Other than that, everything works as needed.

clwg··on The Unisys Icon: One Canadian Xennial's Memories of Ontario's Obscure Computer
I grew up in Ottawa, where QNX originates. My high school must have had someone with family connections to the company, because we could have built a significant Beowulf cluster with all the Icons.

These systems had numerous problems, one of which was the school board's severe lack of resources to manage them. The teachers were limited in what they were allowed or able to do, so if a lab went down, it typically took about a week to get someone to fix it. As students, we used this to our advantage. I have fond memories of causing all sorts of issues on these systems as a kid. Another perk was that my school wasn’t air-conditioned, except for the computer labs, so during the hot months it's where you wanted to be.

clwg··on iTerm2 critical security release
My only issue with kitty and tmux is that I always have to copy over my terminfo files manually or else I get a 'xterm-kitty': unknown terminal type error.
clwg··on The UnitedHealthcare Gunman Understands the Surveillance State
https://archive.is/r90rE
clwg··on D-Link says it won't patch 60k older modems
Just opensource the firmware and redirect the update url.
clwg··on PRC Targeting of Commercial Telecommunications Infrastructure
I’ve updated my link to include the site and wish I had searched more thoroughly as it would have saved me hours; This visualization was more of a personal thing after I stumbled upon it while working within MISP and the raw data(so that's what I initially attributed it to), and just wanted to see it visualized outside of MISP, it's really good analysis.

I've also added the references to the individual institution at the unitracker site as well.

To answer your question, the visualization is just a simple cross-filter. I guess the differences are the categorized and topic-based breakdowns/filtering, filtering by description and it includes a map. I did consider adding a network graph, but my focus isn't really visualization.

clwg··on PRC Targeting of Commercial Telecommunications Infrastructure
I was working with MISP[0], an open-source threat intelligence sharing platform, and came across a really interesting dataset from the Australian Strategic Policy Institute on China's technology research institutions[1]. I liked the data so much I built a quick cross-filter visualization on top of it to help explore it[2].

The data offers a fairly comprehensive and interesting perspective on China's research priorities and organization, I can't speak to the effectiveness of the programs themselves, but it does make me concerned that we are falling far behind in many areas, including cyber security.

[0] https://www.misp-project.org/

[1] https://raw.githubusercontent.com/MISP/misp-galaxy/refs/head...

[2] https://www.layer8.org/8541dd18-ff05-4720-aac7-1bd59d3921dd/

clwg··on Nvidia and its partners built a system to bypass U.S. export restrictions
In the event of a invasion TMSC in Taiwan will cease to function. "TMSC and its Dutch chip machine supplier ASML have made joint plans to remotely disable the machines in the event of an invasion."

https://9to5mac.com/2024/05/21/chinese-invasion-of-taiwan-ts...

clwg··on Avoiding a Geopolitical open-source Apocalypse
I'm not really following — is the author discussing funding/foundations for Open Source software and supply chain security? The rise of "communities" in other countries doing open source development? Or how the East can't trust the West, and vice versa? The geopolitical aspects and cyber norms discussions are already happening[0] but in ways and at a pace that usually frustrate technical people.

I like DHH's take on Open Source[1]: "Using open source software does not entitle you to a vote on the direction of the project. The gift you've received is the software itself and the freedom of use granted by the license."

We should welcome these new communities and thank them for their contributions and perspective. As long as I have the freedom to choose, and censorship isn't a barrier I don't see an issue - they can do what they want. With OSS I can at least review the code and form my own opinion on who and what I should trust.

[0] https://www.csis.org/analysis/creating-accountability-global... [1] https://world.hey.com/dhh/open-source-is-neither-a-community...

clwg··on Open source maintainers underpaid, swamped by security, and going gray
CVSS is not not really meant to measure risk, it primarily measures the severity of technical vulnerabilities. It should be used in conjunction with other factors such as system exposure and threat sources to determine the probability of exploitation. This should then be combined with impact and costing data to fully assess the risk.

Regulatory requirements also need to be contextualized similarly. If they become burdensome, efforts should focus on reducing the exposure of your systems to those risks.

That said, patch and configuration management should be second nature and performed continuously so that when a real issue arises, you're prepared and not worried about your environment falling over because you're unsure how it will respond to an update, or whether your backups will restore properly - which are risks as well.

I saw more than a few organizations struggle with log4j because they only patched server systems when a vulnerability was publicly exposed, and a Metasploit exploit was available.

clwg··on The Continued Trajectory of Idiocy in the Tech Industry
It's not just about security; it's about how democracy, in certain forms (i.e. canton type voting, certain diaspora communities, etc.) is implemented[0].

I'm not advocating for any anarchist ideals, and I believe cryptocurrency should be banned if for no other reason than to deal with cybercrime. However, I also recognize legitimate use cases for the underlying technology that are drown out by all these grifts.

https://en.wikipedia.org/wiki/Direct_democracy

clwg··on The Continued Trajectory of Idiocy in the Tech Industry
The author’s premise brings me to a different conclusion. First, they detail Big Data, then the building of infrastructure to support it. New technology was then developed to harness insights from Big Data, and along the way, blockchain and smart contracts were developed, which are essentially cryptographically verifiable distributed state machines. Both of these innovations have also driven the development of hardware to support those activities. This seems like a solid trajectory.

I'm a Trekkie, so having an interactive conversation with a computer still makes me smile, even if it's just a stochastic parrot. I'm also super interested to see what AR/VR and AI can do together. Additionally, I look at the Swedish model for direct democracy and see blockchain and smart contracts as viable technological solutions to make that process more efficient, secure and hopefully increase adoption of that sort of governance.

The tech industry's main problem is grifters, and I think they mostly (not always) come from other industries (marketing, finance, crime). Somehow, they have convinced everyone that tech needs them to succeed (with their grifts). To me, the actual underlying technology is mind-blowing, but it’s the grift implementations that are the problem and make everything else look bad.

clwg··on Hezbollah pager explosions kill several people in Lebanon
Except for oil, the Middle East produces allot of oil and has for quite some time.
clwg··on Tcl under fire: report suggests its QLED TVs might not have any quantum dots
I'm sorry, but that is incredibly prejudiced. Are Western companies such as Boeing and FTX more truthful?
clwg··on Max Headroom and the World of Pseudo-CGI (2013)
Piling on a bit, but it was also the first video they played when they launched MTV Europe.

https://direstraitsblog.com/blog/30-years-ago-money-nothing-...

clwg··on Elasticsearch is open source, again
Here is the reasoning they gave at the time.

"So why the change? AWS and Amazon Elasticsearch Service. They have been doing things that we think are just NOT OK since 2015 and it has only gotten worse. If we don’t stand up to them now, as a successful company and leader in the market, who will?"

https://www.elastic.co/blog/why-license-change-aws

clwg··on Defcon stiffs badge HW vendor, drags FW author offstage during talk
It seems to have been Dark Tangent[0] (aka Jeff Moss), the creator and organizer of Blackhat and Defcon.

https://x.com/dmitrygr/status/1822126826606739678

clwg··on Microsoft technical breakdown of CrowdStrike incident
The functionality does seem intriguing, that doesn't change it's security profile which was poorly thought out and implemented.
clwg··on Microsoft technical breakdown of CrowdStrike incident
First thing that comes to mind is that Recall stuff from a month ago, they also release updates[0] that crash machines.

[0] https://www.tomsguide.com/news/windows-11-update-causing-blu...

clwg··on Canadian women's soccer team loses six points, coach banned over drone scandal
As a Canadian, this is utterly embarrassing. I can't believe it was happening for years, even at the under-16 level, and was common knowledge.

I think they should withdraw from the Olympics voluntarily. I get that it sucks for the athletes, but at this point, the best thing they could do is set an example for younger kids. I've seen high school teams get booted from tournaments for less.

clwg··on Free DDNS with Cloudflare and a cronjob
You should run both.

Consider Cloudflare (and large scale infrastructure providers like TLD operators) point of view on the traffic: If your private resolver is using root hints, it's IP is now correlated with the lookup of that domain even if they don't proxy the website. That's you and your users, and they can do that at scale - So it's important to point queries for your assets directly to your authoritative servers or rewrite inline without ever querying a internet source.

dnsdist[0] (also PowerDNS) allows you to load balance and apply rules across upstream resolvers which opens up allot of possibilities on the recursive side.

Trusted resolvers with a healthy number of users originating iterative queries from non-descript and changing IP's is probably the best way to anonymize your recursive traffic.

[0] https://dnsdist.org/

clwg··on Free DDNS with Cloudflare and a cronjob
A bit of a tangent, but something like PowerDNS authoritative server comes with an API[0] that can be leveraged for similar functionality to what Cloudflare provides.

Decentralization of the internet has to start with Authoritative DNS. I know it's not free to host an authoritative server like this on a VPS, and there are DDoS considerations. But the flip side is that DNS is a metadata protocol and contains a wealth of information that anybody privacy focused should think twice about. It's also an incredibly powerful and important protocol to understand.

[0] https://doc.powerdns.com/authoritative/http-api/index.html

Page 1 of 5Next →