HNHacker News
TopNewBestAskShowJobs

conformal

449 karma · joined December 18, 2011

submissionscomments
conformal··on OpenSSL is written by monkeys (2009)
well, i appreciate mr dipropyl tryptamine having linked this. anyone who has looked at openssl source knows the score.

to quote one of our devs (davec) on the topic of openssl:

"funding openssl won't stop it from happening again... openssl is largely unmaintainable is the problem"

the ifdefs alone in the source make it nigh unreadable, much less the inconsistent variable naming, inconsistent indentation/nesting and inconsistent overall style.

conformal··on OpenSSL Security Advisory: TLS heartbeat read overrun
not sure what you have to maintain, but it sure sucks having to scramble and fix this right away.

our (quick) fixes are almost all done:

- recompile openssl where necessary (web, chat, mail, windows binaries) without heartbeat support

- roll related certs and keys ASAP

and then comes the painful process of suggesting all web service users roll their certs and auth.

oh, and rotate personal passwords at other sites that issue a warning about openssl...

conformal··on Dai/Nakamoto emails
hi there. i'm the management behind btcd, an alternative full node bitcoin implementation, and i can say that it is very unlikely the original code is the product of a single person. additionally, the amount of work that must have gone into testing and setting the myriad constants for bitcoin is huge, far more than a single person is capable of in a few-year period.

i won't share all the magic but consider this: have you noticed how there are big and little endian flips littered throughout the code, especially in the script code? do you think that a single dev would just arbitrarily assign endianness throughout the code, then have the script code be big endian?

conformal··on The inexplicable rise of open floor plans in tech companies
something that this article does not address is all the other things that need to happen to give employees private offices, e.g. architect, permits, construction.

i have previously leased and built out a high-end office in a building in downtown chicago and the amount of time burned with the architect, waiting for permits, and construction is serious. after doing that once, i will never do an office build-out again unless i actually own the building. when you add in the fact that the building is "union only", the delays in construction become ridiculous.

after going through this part myself, i'm all for open-plan offices, despite their being less than ideal for developers. the majority of our developers work on remote anyhow.

conformal··on How British satellite company Inmarsat tracked down MH370
based on the region where this occurred, you can rest assured that one, if not several, state intelligence services knows exactly what happened to the plane and has near continuous knowledge of its position. the area of asia where this occurred would likely be of interest to US, CN and RU.

the fact that none of these countries gave information about the whereabouts of the plane in a timely fashion suggests to me that they have a vested interest in not sharing what they know.

conformal··on Coming Soon to Hacker News: Pending Comments
it's pretty clear to me that HN is already an echo chamber in many respects - the consensus VC and corporate views are frequently those that get the most upvotes. requiring approval from 'old guard' users will only exacerbate this echo chamber property of HN and will, imo, likely degrade the quality of discussions more than it will help.

what has made HN and reddit so popular is the ability for anyone to participate, even if their comments get downvoted. by removing this open posting property, you are going to switch from a "burning man" culture to a "popular nightclub" culture. i would like to think that most of the developer types on HN recognize this as a bad thing.

i, for one, will not bother participating in discussions with the same frequency if i know that it requires approval from a karma overlord. i expect this chilling effect will be similar with many users of your site.

conformal··on Did Malaysian Airlines 370 disappear using SIA68/SQ68 (another 777)?
agree, something very valuable was on that flight, whether it was a person/people or the cargo.

the 50 blocked-out seats indicate a heavy and/or oddly distributed cargo.

let's get real here - this is definitely not the work of hijackers, this is some intelligence service stealing a plane with something _very_ valuable on it. there are far too many what-ifs for even a large criminal or terrorist organization.

conformal··on Did Malaysian Airlines 370 disappear using SIA68/SQ68 (another 777)?
totally agree. it must be a what/who scenario by merit of the lengths to which they went to get the entire plane. this is surely a state-level intelligence action.

the blocking off of passenger seats often indicates an especially heavy or oddly weighted cargo.

something else that is notable is that you know several large world governments have continuous satellite tracking of this flight but are not sharing any information about it.

conformal··on Billionaires With Big Ideas Are Privatizing American Science
i absolutely hate paywalled sites and refuse to read the articles.

that said, this is entirely unsurprising since scientific and mathematics research were almost entirely patronized fields until the rise of the modern university. this is very similar to computing in that first monolithic centralized computing was the path, then it was the PC, then it was the cloud, now it's moving back to a decentralized network. these things are bound to yo-yo and academic research is no different than most human-designed processes.

conformal··on What I learned from an unfortunate incident with the NYPD
fuck the police. they are just another gang and do little to stop real crime in most urban areas. i would venture to say that police actually facilitate more crime than they prevent on the average.

in chicago, i have never received anything from a police officer besides disrespect and questionable tickets.

i am very excited for the next 20 years since i predict we will see the end of human policing and instead have robotic law enforcement.

conformal··on A Brief Rundown Of The Spying Questions Intel’s CEO Won't Answer
a favorite song of mine by kool keith comes to mind: "i don't believe you" ( https://www.youtube.com/watch?v=Bc5cOohfHhA ).

the world's largest cpu manufacturer, which also happens to be based in the US, _not_ having NSA-mandated backdoors is entirely out-of-the-question. even if the cpus are not backdoored, you can bet all the NIC firmware "happen" to have a remote update path enabled, despite it not having a legitimate application in non-development environments.

intel is tre-owned and always has been.

conformal··on Redecentralization: building a robust cryptocurrency developer network
bitcoin is obviously a great system, but to just accept it as the next financial system is missing the larger point with cryptocurrencies: they are a significant step in the evolution of banking, an industry that has traditionally been very slow-moving and centralized. accepting a new system where the developers, who essentially replace the central bankers, are a small group who wield substantial power and can act without a wide consensus seems like a step backwards after taking a step forwards.
conformal··on Ask HN: How to fire your co-founder?
funny. i was in this position many moons ago with 50/50 ownership between me and my partner.

it blows and there is never an easy way to dissolve such relationships. i had to threaten 'going nuclear', i.e. closing the business, to get him to leave.

conformal··on Bitcoin paradise
ken and his staff are really cool easygoing people.

it is great to see an article about them in the economist.

conformal··on Trevor Perrin requests removal of NSA from IETF Crypto Review
TPM uses 2048-bit rsa keypairs that are hardwired into the hardware. gee, i wonder if someone can get into them...

derp

conformal··on Go away Cameron – Bypass UK's porn filter
first, i'd like to say i quite enjoy the UK, both as a country and its people. however, politicians in the UK have a history of doing some very extreme and very stupid things. since i am not a citizen of the UK, i cannot vote to try to change the current censorship regime, but i can say that (1) i will not be visiting the UK unless absolutely necessary until these rules change and (2) i think this is a further reason for Scotland to secede from the UK.

this is a great plugin and i commend the author's defiance of these draconian internet filtering rules. while i agree that, fundamentally, this is a political problem and not a technological one, a technological solution is needed to prevent smart people from being drowned in an ocean of stupidity. if you're a UK citizen, don't forget that you need to mobilize politically to truly fix this. talk to your friends, develop a consensus.

cameron (and everyone who supported this censorship crap) needs to go, he is a muppet of the highest degree and a disgrace to the legacy of the UK. keep jerking off and carry on.

conformal··on A Crypto Challenge For The Telegram Developers
consider that every factory-default mobile OS has vendor backdoors, if not ISP, firmware and hardware backdoors. no need to keylog everyone, just remotely take over on-demand using vendor backdoor.
conformal··on A Crypto Challenge For The Telegram Developers
not going to buy you much if an attacker has dma, which is what a proper backdoor will give.
conformal··on A Crypto Challenge For The Telegram Developers
ding ding ding!

you have won the prize! expecting anything to be secure on a mobile device is a serious mistake.

in some ways, textsecure and redphone actually induce behavior that puts people at risk: no amount of encryption can make a mobile device safe.

the only possible exception to this is a device that is built from zero and has fully in-house gsm stack, etc.

conformal··on A Crypto Challenge For The Telegram Developers
this is a reminder that prizes or cash for breaking crypto products is a silly PR stunt. mega did the same thing, ended up paying out some money, then their product is "secure" by the same sort of argument. same deal with cryptocat and several other cryptoturds.

i do find it amusing to hear moxie ranting about how much better textsecure is when the license on it is such shit. can't argue with the fact that it's open source, but there is no point in contributing the codebase due to the licensing.

conformal··on Advanced cryptographic ratcheting
great blog entry, moxie et al. it is wonderful to see what i consider to be legitimate improvement in crypto protocols.

NOTE: i still think it's a really poor idea to assume that encrypting stuff on your mobile device / smartphone will actually protect you since every default mobile OS has, at a minimum, an OS-vendor installed backdoor.

conformal··on Researchers say U.S. Internet traffic was re-routed through Belarus
i have long suspected that BGP routes can be altered on-demand to push domestic traffic outside national borders and justify its recording and use by intelligence services.

it is entertaining to see this done in the wild.

conformal··on The first Bitcoin post on HN
hah. nice try, satoshi!
conformal··on Hack of MacRumors forums exposes password data for 860,000 users
it confirms that most mac users have extremely short passwords (airhorn)

-> the mac user

conformal··on The second operating system hiding in every mobile phone
completely agree, it's long overdue.

hardware manufacturers should be less concerned about what their firmware reveals about their IP and more concerned with what not revealing their firmware source code reveals about their security.

the fact that you can get DMA by compromising _any_ device on the bus is a problem too. imo, none of these peripherals should have unmitigated DMA.

conformal··on Hawala
interesting, i wasn't aware that the medicis pioneered the double entry accounting methods.
conformal··on TSA union calls for armed guards at every checkpoint
>> i fucking hate the tsa and couldn't possibly give a shit about one of their ppl getting killed >I sincerely hope that someday you will be ashamed for writing this.

i'm sure the tsa sheds a dramatic native american tear every time they hear about someone else getting injured or killed on the job. people die every day and the fact that it's a member of the tsa changes the general feeling of indifference into amusement because the tsa actively reduces the quality of my life on a regular basis.

if it was me that died and all you know is that i'm some member of a group that is generally shitty to you on a regular basis, i don't think you're going to be all emo about it. grow up

conformal··on TSA union calls for armed guards at every checkpoint
> Note that a mass casualty event at a checkpoint, where hundreds of people are concentrated, standing around exposed, hasn't prompted called to eliminate that structure for checkpoints.

that an incident like you describe hasn't happened is an indication of the fact that terrorism is really a spectre and not a real threat. dumb people will claim "this hasn't happened because the nsa/cia/etc catches all the bad guys!".

conformal··on TSA union calls for armed guards at every checkpoint
the tsa has never been about security - it staffs its checkpoints with rude incompetent dimwits. the actual agenda is and has always been smuggling.

some crazy person can pull out a gun _anywhere_ you go. that does not mean that there needs to be armed guards everywhere. "why do we have an armed guard at this coffee shop?" "oh, some dude got shot here 6 months back."

conformal··on TSA union calls for armed guards at every checkpoint
> Or we could dissolve the TSA and homeland security theater while we are at it.

excellent idea. i fucking hate the tsa and couldn't possibly give a shit about one of their ppl getting killed after all the bullshit i have had to go through just to travel in the US.

← PreviousPage 2 of 6Next →