HNHacker News
TopNewBestAskShowJobs

conformal

449 karma · joined December 18, 2011

submissionscomments
conformal··on Google Is Developing Its Own Uber Competitor
i assume you've read the recent article by nafeez ahmed from vice, etc, about how google's search algorithms were funded via the NSF/CIA/NSA for 2 years before google ever existed and that sergey reported to someone working for the CIA's ORD for that period.

https://medium.com/@NafeezAhmed/how-the-cia-made-google-e836...

if you haven't read this, it's a long but great read.

the best thing google ever did was create go (golang). huge props to robert griesemer, rob pike and ken thompson for getting it all going.

conformal··on Cultivated Disinterest in Professional Sports
predictably well put from mr chomsky.

to effect a classic double flashback, fight club style, here's a dose of bread and circus from juvenal from CE 100:

"'It is scarcely possible that the eyes of contemporaries should discover in the public felicity the latent causes of decay and corruption. This long peace, and the uniform government of the Romans, introduced a slow and secret poison into the vitals of the empire. The minds of men were gradually reduced to the same level, the fire of genius was extinguished, and even the military spirit evaporated.' Now that no one buys our votes, the public has long since cast off its cares; the people that once bestowed commands, consulships, legions and all else, now meddles no more and longs eagerly for just two things----Bread and Games!"

http://www.tertullian.org/fathers/juvenal_satires_10.htm

conformal··on They Live
they live is one of the best john carpenter films, and that includes the epic 10-minute on-concrete wrestling match before keith david will don the glasses.

being extremely entertained to see a blog entry about they live aside, making privacy simple is super hard. similarly, making people care about privacy is super hard. killing the aliens is even harder.

ubiquitous surveillance has a pretty obvious response in the long run: ubiquitous encryption.

conformal··on Secure Secure Shell
space-alien technology speculation aside, i've been aware of openssh's less-than-reassuring default selection order for Ciphers, HostKeyAlgorithms, KexAlgorithms and MACs for a few years. for most modern computers and cpus, using these stronger algos amounts to, at most, a 10% speed loss when scp'ing and a 10% increase in cpu usage. even machines with weaker cpus will barely show any signs of fatigue with these stronger algos. despite this, at least 2 of the openssh devs have rebuked my suggestion to change the default algorithm selection order.

it's not exactly clear (to me) why anyone who runs a project that so many ppl depend on for security would stick to such old and crufty algos. since openssh and openbsd are intertwined, it does make me wonder if this is being done so that openssh can run on the latest vax, etc (omg! but it will take a week for it to generate the right sized keys!).

EDIT: openssh in 2nd paragraph changed from openbsd, a typo.

conformal··on Open Whisper Systems partners with WhatsApp to provide end-to-end encryption
this work from 2011 by IVT doesn't exactly inspire confidence.

http://theinvisiblethings.blogspot.com/2011/05/following-whi...

conformal··on Open Whisper Systems partners with WhatsApp to provide end-to-end encryption
oh, you mean like VT-d etc on intel cpus.

what reason could you possibly have to suspect that the IOMMUs from a company named "intel" are backdoored? :)

conformal··on Open Whisper Systems partners with WhatsApp to provide end-to-end encryption
good luck detecting baseband attacks in the wild. i hope you've got a transceiver with you and a rainbow table for cracking the A5/1 etc on your cell link.
conformal··on Open Whisper Systems partners with WhatsApp to provide end-to-end encryption
i really am a fan of what moxie et al are doing with textsecure. i am less of a fan of redphone, but that's another matter (zrtp, woof).

while i trust textsecure, it is hard to trust any mobile OS and mobile hardware.

conformal··on Alexander Grothendieck has died
while i am generally loathe to comment on HN, i consider it truly sad to see the passing of grothendieck.

he was a truly revolutionary mathematician and his contribution to the (hard) science of mathematics cannot be overstated. people who live on principle are rare, and those willing to go without salary as part of that protest are even rarer [1].

[1] - http://www.fermentmagazine.org/Quest88.html

conformal··on U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data
i hear they are going to ban air soon because pedophiles can use it prey on children.
conformal··on U.S. Law Enforcement Seeks to Halt Apple-Google Encryption of Mobile Data
i think it's great to see ppl being skeptical of security claims from phone manufacturers. trying to secure a normal cellphone is pretty much impossible and if you're storing sensitive information on one, you are just waiting to get fucked.

i think all this "sound and fury" is likely a ruse to entice ios and android users into a false sense of safety post snowden disclosure. being able to encrypt your drive doesn't matter if your OS and its applications are exploitable. last time i checked, there is almost zero open source firmware out there, so your application processor can encrypt stuff hitting disk and the baseband processor can be used to get dma.

time to roll out the hypothetical child molester straw man...

conformal··on Can a Computer Replace Your Doctor?
your characterization of visits to the doctor is spot on: they are gatekeepers to medication and treatment and they have a warped incentive structure that biases them to under-treat anyone they don't "believe".

on top of what you describe, i find most doctors to be biased towards "i know better than you" behavior. i have found that being an intelligent person makes dealing with doctors especially difficult since you need to be strategic to convince them and at the same time appear to not know too much about your own health problems. i have had incompetent resident doctors argue with me just because i know more about my illness than they do, and their ego is such that they cannot admit to themselves or me that they are wrong.

any technology that leads to me spending less time interacting with doctors is a huge win.

conformal··on Goodbye to Sasha Shulgin, Godfather of Psychedelics
even better, how about you name the compounds he "discovered" and demonstrate that they were not the subject of prior work.

maybe i should write a book about a whole bunch of stuff other ppl did, not give proper attribution, then demand that people prove that i did not invent it.

conformal··on Goodbye to Sasha Shulgin, Godfather of Psychedelics
it's not slander, it's the truth. someone else discovered and tested MDMA many decades before sasha, but he is credited with "discovering" the compound.
conformal··on Goodbye to Sasha Shulgin, Godfather of Psychedelics
just like most people who are sasha fanboys, you obviously have zero domain knowledge on this subject.

try them out yourself, see what happens.

conformal··on Goodbye to Sasha Shulgin, Godfather of Psychedelics
i know i'm going to get downvoted, but illumen is completely correct.

there is nothing so american as downvoting the truth.

conformal··on Goodbye to Sasha Shulgin, Godfather of Psychedelics
entirely untrue. do your homework.

sasha almost exclusively synthesized compounds that were already in the academic literature. he reproduced others' work and gave minimal attribution.

conformal··on Goodbye to Sasha Shulgin, Godfather of Psychedelics
it is sad to hear that sasha passed, he was a great man. he did a lot of really positive work for expanding the public's knowledge of hallucinogenic compounds, mainly 5HT-2A agonists of various varieties.

that said, he is typically over-attributed as being the 'godfather' of this field in an academic context when nearly every single compound he synthesized was originally synthesized and researched by someone else. there are thousands of researchers from the pharma industry and academia who spent huge parts of their adult lives just synthesizing a few of these compounds who often receive zero attribution for their life's work. knowing this, i find it rather offensive that an academic institution would provide such a trumped-up tribute to sasha shulgin.

oh, and for the record, a lot of the syntheses in tikhal and pikhal have _intentional_ omissions and errors, which makes those texts mostly useless from a synthetic standpoint.

conformal··on Computer Science and Math
if anyone thinks that a few semesters of introductory mathematics or science courses is "not relevant" for a CS program, they have completely missed the point. this is a fool's complaint, like saying that "because i'm a political science major, i don't need to learn anything about actual science".

in reality, the point of introductory level math and science courses in college is to show you a rather narrow skillset: you are given what amounts to a toolbox with a couple dozen tools and asked to use this small set of tools to solve problems that require application of, at most, 2 or 3 of these tools in succession. a fair analogy is that it is a multistep "put the round peg in the round hole" problem.

if assembling a small toolbox of skills and trying to apply the correct tools in short succession is too much for you, just quit university and code some stupid app. is it really that hard to understand why basic math and science is relevant?

DISCLAIMER: i was a teaching assistant for undergrads for 3 years during undergrad and grad school.

conformal··on Show HN: bitcoin-akka – a btcwallet client, written in Scala and built on akka
nice to see btcd getting more usage, goldmar :)

for the related blog entry with some more details, check out

http://markgoldenstein.com/building-websocket-client-btcwall...

we just recently released a small library that makes using the JSON-RPC much easier, and it should work with both bitcoind and btcd

https://github.com/conformal/btcrpcclient

this makes some of the things mark mentioned a bit less painful, e.g. marshal/unmarshaling the JSON, error handling, async replies. it is in go, so it might not be immediately useful to scala devs.

conformal··on LocalBitcoins received an attack against the site infrastructure
i always advocate for FDE, but that often has issues with remote serial console. the threat model of running without disk encryption is far worse for most bitcoin-related sites than the complexity associated with redundancy. if they get hacked, they are likely going to eat downtime anyhow.

as far as low-end solutions are concerned, a usb serial console adapter plus a few machines runs about USD 5K. set machines to redirect console to serial and have an OOB machine for unlocking downed servers.

i'd be interested to hear what kind of solutions there are for onsite tamper-resistant components.

conformal··on LocalBitcoins received an attack against the site infrastructure
i strongly suggest that sites concerned with their security use (1) full-on colocation services and (2) encrypt the partition they store user data on or encrypt the entire disk.

if you have proper disk encryption, it is non-trivial to game the remote physical access to the machine, e.g. attacker convinces someone to use 'remote hands' to reboot server and then gets console redirected pre-boot. if you have disk encryption in this scenario, whether it is on the user data partition or the whole disk, you will surely be notified of the unscheduled reboot and can investigate it.

it is always best to host your own machines (_not_ VPSes) and be able to provide some level of compartmentalization to your hosting setup.

conformal··on Tptacek's Review of "Practical Cryptography With Go"
DISCLAIMER: i know and have worked with kyle (the author).

while the factual content of tptacek's review may be spot on, his overall tone is very negative and smacks of "only experts allowed" logic. while he could have easily helped improve kyle's book and shared these comments privately, he instead chose to lambast kyle publicly, which doesn't really help anybody: tptacek looks like a total jerk and kyle now has a lot of negative attention on (this version of) his book.

this pervasive "experts only" attitude is a big part of why "secure" open source projects have hard times getting and keeping contributors. it is par for the course for people to be super rude and negative to new participants instead of trying to encourage them to improve and learn. this lack of contributors then has a whole array of negative secondary effects, like less people reading the code for the project.

conformal··on My Ideas, My Boss’s Property
i'm in my 30s and i am in total agreement with you: the modern helicopter parents are so preoccupied with "bullying" that the next generation of kids are going to be soft-minded nitwits on the average. catching a beatdown on the playground now and again made me who i am today and i would never have had it any other way.

having the balls or wisdom to walk away from a situation where you're being bullied, whether literally or figuratively, is becoming rarer nowadays.

conformal··on The Heartbleed Challenge
i suspect the memory accessible by this bug depends a lot on the software, OS and possibly hardware, e.g. on openbsd and bitrig amd64, the amount of memory leaked per exploit is less than 64 KB, closer to 32 KB. if you go much past the 32 KB mark on these OSes, it segfaults.

running an exploit script against one of our own services showed only 1-2 KB of information, most if it being the (public) cert, and the rest zeroed out.

conformal··on The Heartbleed Challenge
we appreciate your supportive comments :)

there are about 10 of us at conformal.

conformal··on The Heartbleed Challenge
nice write up. we saw similar results in that the keying material never made it into the memory leaked.

i've never felt so thankful for a memory allocation pattern.

conformal··on The Heartbleed Challenge
what i am expecting ppl to see is that you can't actually get to the tls private key itself. we have done some testing with our backup service, cyphertite, and have yet to attack and actually compromise any keying material.

EDIT: forgot to cite neel mehta https://twitter.com/neelmehta/statuses/453625474879471616

conformal··on "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
^ this!

back in 2010, my business partner, marco peereboom, submitted a patch to openssl to add support for aes-xts. it was coded by joel sing, now a google employee and golang dev. they _didn't even respond to the mailing list email_ and after marco nagged for a reply the response was "we have a different plan for how to implement XTS" (i'm paraphrasing). _2 years later_, they added XTS support.

the openssl dev team is not responsive, doesn't accept contributions and generally speaking suffers from "you're not an expert" syndrome. look how expertly they've managed their project!

conformal··on OpenSSL is written by monkeys (2009)
i don't think the NSA works like that :)

remember "national security" equates to "we will watch you all the time and steal all your dataz". it would obviously be great if "national security" meant what it was supposed to...

Page 1 of 6Next →