HNHacker News
TopNewBestAskShowJobs

computer

1,747 karma · joined July 4, 2013

submissionscomments
computer··on TrueCrypt suggesting migration to BitLocker?
> WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues

I see many readers here and on Twitter who interpret that as "TrueCrypt has security issues". That's not what it says. It says that it might be insecure. That does not make too much sense right now, but considering this webpage would be meant to stay up, unchanged, for years, that makes a lot more sense: security problems may be found, and will not have been fixed in the version on the page.

So, it's a deprecation warning, not a security issue warning.

computer··on Dijkstra on Dutch TV (2000)
At 12:14 the original Dutch on-screen text says

>"We should not add bugs to a program out of nonchalance. We should do so systematically and with great care".

The translator translates this to

> "We should not introduce errors through sloppiness, but systematically keep them out",

which I found unfortunate, since it completely loses the original meaning.

computer··on Ask HN: Are we using the final numeral system?
Your question contains a very teleological narrative, in that you assume/recognize a natural evolution from the first to the last, with cause and result. Partially because you take all of mankind as one group.

Then, to look at your question: who's your "we"? The Chinese already use another system (in many contexts). African cultures use their own systems. And who knows what might happen in the future.

computer··on AT&T’s GigaPower plans turn privacy into a luxury that few would choose
Do it on your router, so that all devices that connect over wifi are automatically router through your VPN.
computer··on Review of the First Three Johns Hopkins Coursera Data Science Courses
You wouldn't consider a traditional degree to have value in the field of "data science"? So to you, "data science" is indeed truly defined as "statistics without a proper statistical background"?

(It's an honest question, since that's my impression of "data science" as a statistician)

computer··on If You Can Read This, You're SNIing
How is it a step down? Without SNI, the public IP you connected to also uniquely identified the domain/cert you were visiting.
computer··on The homogenization of scientific computing (2013)
R is by far the most commonly used for statistical sciences. As far as I know, the list continues as follows: Matlab & Labview for experimental physics. SPSS for social psychology. SAS for the pharmaceutical industry/medicine research.
computer··on Google Nest
It's fake-- domain registered at eNom, hosted at namecheaphosting.com.
computer··on Ask HN: have you ever seriously learnt something through online courses?
A specific fun example: I learned the insight that you can make a cryptosystem (stream cipher) out of a PRNG by using your secret key as PRNG seed, and then XORing your data with the PRNG output stream. The Coursera cryptography course was quite good in general.

More in depth: I definitely picked up some concepts in the lectures that I watched. I thought they were better than normal university lectures, mostly because you could skip ahead through them. But in general I think that for me, long assignments are a much more valuable teaching method, and most of the courses I followed/looked at had much too simple multiple choice fact-based questions for the practical part.

computer··on Ask HN: Best current Linux-compatible laptop?
Only issue I have with mine is that they have non-expandable 4 GB memory, since it's soldered onto the motherboard. I think some of the later models can be manually expanded up to 10 GB.
computer··on Distracer.io – Browser distributed ray tracing
The underlying technology here is CrowdProcess (https://crowdprocess.com/). Their business model is to use CPU time of visitors of websites to make money, by selling access to that CPU power to people who want to run parallel jobs, like mine bitcoins.

I think they should consider the possibility of legal action against them, considering what happened to the guys doing this with a bitcoin miner: http://www.techdirt.com/articles/20140205/17512926103/new-je...

computer··on Popcorn Time is back
Your time4popcorn runs code with full access to your computer directly from a server controlled by unnamed individuals who are acting in completely mysterious ways. I.e. on every load of the app, it downloads code from a server controlled by the time4popcorn guys, and then executes it locally with access to your entire system.

I would never trust such an app.

computer··on Freelancer.com is destroying my life
No, it's not the same. The poker sites you mentioned did try to pay (albeit with some delays); what did them in was that they spent their customer money on running their business, among other things that are in hindsight completely incredible.

They did have a lot of payment delays later in time, but that was not because of ill will, but because of issues with payment processors. Those processing companies were getting shadier and shadier as time went on, often getting their bank accounts seized, processors running away with tens of millions, et cetera. The lack of decent payment processors was what caused most of their delays by far, and incidentally also what caused them to resort to things like miscoding credit-card transactions and semi-bribing banks, which in turn resulted in them getting indicted in the US.

There's some other companies that did leave players waiting for months for their withdrawals because they were short in funds, but that wasn't the major issue at FTP or AP before their government-triggered collapse.

Source: I intimately know the business.

computer··on Home Built Laser Projector (2004)
Would it be possible to use three color lasers, and create full-color images?

On a second thought, that would probably require variable brightness, or being fast enough so you can move slower on regions you want to appear more bright...

computer··on Telegram team left Russia and looking for a country to work from
I have friends in Tanzania, and you could also consider South-Africa, and probably a lot more that I don't know anything about. But it depends on exactly what kind of "Wild West" you're looking for, and I'm no expert on Africa.
computer··on IBM, Microsoft, Facebook, Google, others pledge $3.6 million to fund OpenSSL
> "IBM, Microsoft, Facebook, Google, others pledge $3.6 million to fund OpenSSL (arstechnica.com)"

The title of this submission is incorrect. The funding goes to the general fund, not specifically to OpenSSL.

Here's the press release this article is based on:

http://www.linuxfoundation.org/news-media/announcements/2014...

And here's the actual initiative:

http://www.linuxfoundation.org/programs/core-infrastructure-...

Discussed here:

https://news.ycombinator.com/item?id=7639835

computer··on Please review my project
You forgot to escape your HTML output.

http://fastask.it/%3Cscript%3Ealert%28%22asdf%22%29;%3C/scri...

Also, there's SQL injections too:

http://fastask.it/%27

http://fastask.it/%27%20OR%201=1;--

And you can vote more than once, because there's no server-side check: (ignore the question text)

http://fastask.it/register_votephp

Also, including a slash in a question (like "Red is good, yes/no") breaks your layout due to relative paths:

http://fastask.it/a/b

The maximum length of questions is also only validated on the client. This question is longer than the normally allowed length:

http://fastask.it/asdf-asdf-asdf-asdf-asdf-asdf-asdf-asdf-as...

Your server side cuts too long questions off at some point too; this was originally 8kb of periods, plus the string "8kb":

http://fastask.it/8kb

I think it's now 225 periods, so that might be the size of your "ask" column in the question table.

Also, if you click a vote button really fast you can vote multiple times (until a request success callback is called and the button is faded away).

Also, the "No"-button seems to have stopped disabling itself entirely, at least for me.

You should probably read up prepared statements for MySQL, about input sanitizing, and security in general :)

In terms of the non-technical side: I had no idea what was going to happen after I clicked "Create". If you promise Instant answers, why would the button be named "Create" and not "Answer"? But the questions are not answered Instantly, so I would remove that term from your entire site.

I'd term it "polling" instead of "asking a question"/getting "answers" as well, since it's just yes/no. And what use-cases do you have in mind? If it's for group emails or quick polls or whatever, perhaps add a comment box for responses that are more than just yes or no.

computer··on Telegram team left Russia and looking for a country to work from
A bunch of countries in Africa probably fit much of your wanted model. Not everything there is hunger, murder and poverty.
computer··on Taking e-mail back, part 4: The finale, with webmail and everything after
An alternative is to use some email server from a host/domain registrar/google apps/zoho/etc as secondary MX server. It saves you from having to maintain a second server, and you still get 99% of your messages through your primary server.

I had a similar setup for a while, and it was interesting to see that some messages (spam, mostly) picked the secondary MX by default. Spam servers also seemed to cache the (secondary) MX for much longer than the TTL.

computer··on Android OpenSSL has heartbeats disabled
Does PURIFY get rid of the warnings by suppressing them, or by disabling code temporarily for debugging purposes (since it mentions macros)? The FAQ seems unclear on that point.
computer··on Heartbleed is about to get worse, and it will slow the Internet to a crawl
Doesn't work, since rekeyed certificates are often (mostly?) backdated to have the same valid-from date as the old certificate.

I updated my key and certificate, and for the browser-visible certificate metadata only the fingerprint changed.

computer··on Safe: Free Easy File System Encryption
I would probably think twice before using anything based on EncFS. See this audit for a lot of detail: https://defuse.ca/audits/encfs.htm
computer··on Show HN: Poor Man's VPN With a Cheap VPS
How is a commercial VPN that claims not to keep logs more deniable than running your own VPS that definitely doesn't keep logs?
computer··on Does your browser rejected revoked certificates?
The site doesn't load here, what does it say?
computer··on Green tea benefits memory
Sigh, blogspam from a non-scientific source, about a study with a tiny sample size. Everything is wrong with this one:

The study made them eat 27.5 grams of green tea extract (dissolved in a liquid), then measured brain connectivity by MRI. This MRI-measured brain connectivity was slightly higher, whatever that might mean in practice-- actual memory performance was not measured, it seems.

As pretty much always for such articles: the title is incorrect, the findings are probably wrong, and the article was written by someone without scientific understanding and/or integrity.

computer··on Akamai release source to their custom secure_malloc for OpenSSL
Modifications made to non-distributed GPL code are not automatically GPL. Only distribution of code derived from GPL-licensed code requires a GPL license for that derivative. But even on publication a modification/derivation of GPL-licensed code is not automatically GPL. It can also just be copyrighted code published in violation of the GPL.

So, it's also not true that "any employee of the company can publish the modications to the GPL-licensed code".

computer··on Akamai release source to their custom secure_malloc for OpenSSL
How I read it is that this code already protected their private key, but the Heartbleed bug still disclosed other private details (such as submitted user data).
computer··on What Heartbleed Can Teach The OSS Community About Marketing
He did because this is the worst internet bug in the past 10 years, not because the page was so masterfully written. Private keys and user passwords/data being disclosed will be cared about by systems administrators even without such a fancy page.
computer··on "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
Those documents do not say they can break SSL. They say they focus on SSL, and can break some specific SSL-using services.
computer··on "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
This bug was added 2 years ago, the Snowden documents are from before that, as far as I know.
← PreviousPage 3 of 11Next →