HNHacker News
TopNewBestAskShowJobs

danielvf

9,793 karma · joined December 13, 2013

daniel at leancoder dot com

Long time builder: - Web applications - Embedded firmware - Blockchain applications and security.

submissionscomments
danielvf··on Canadian math prodigy allegedly stole $65M in crypto
The physical universe advances from state to state, but we define still can call certain behaviors illegal.

https://xkcd.com/1494/

danielvf··on Canadian math prodigy allegedly stole $65M in crypto
My favorite is one of the text files on the attacker's computer:

A file labeled "Decisions and Mistakes," in which he wrote, "Going On the run / Yes / Chance of getting caught<Payoff for not getting caught / (NA) / Risk is typically underpriced in modern world.

danielvf··on Canadian math prodigy allegedly stole $65M in crypto
The camera shows night in the Wild West.

A masked man creeps through the shadows of a sleeping town.

He looks both ways, then uses a knife to unlatch a door from the outside. He slips into near pitch blackness. He moves confidently in the darkness - he's worked for this bank before, checking on their security from theft.

Out comes his lock picking tools - the bank president's office door opens with a quick rake. Cheap lock.

Inside, with no windows to betray him, he lights a candle. There in the corner stands the safe. He knows it inside and out, and has been practicing. Five minutes later, the lock is picked, and he loads up the gold, cash, and bonds inside.

He puts the candle out, slips back outside, and returns to his room at the lodging house, climbing in through the window.

The next morning, with the discovery of missing gold, the town looks like someone kicked over a fire ants nest. It only takes 30 minutes before people start wondering about "bank security expert" who had just been in the bank every day.

A crowd heads over the boarding house, growing in size as it goes.

"Did you steal our money?", they ask?

"ABSOLUTELY NOT," he replies, "I merely used my immense mental powers to out hink several flawed physical security measures, breaking no laws of physics, in such a way that the gold, cash, and bonds previously belong to you are now in my possession, and now belong to me. No theft has taken place, only the movement of certain levers, of which anyone who knew how could move, and the movement of afterwords of certain goods."

"So you stole our money!!", the town shouted.

"No, no, I just interacted with the universe according to its very own publicly available rules. No theft has occurred!"

An old cowhand, covering him with double barrel, spoke up, "Walll, guess he's right. We deserved to lose all that money. He did nothing wrong at all."

Everyone left, impressed with his genius.

danielvf··on Writing my own dithering algorithm in Racket
To some extent I think this comes down to a preference, like many things in dithering. If the black and white results look good, that may be the right answer!

I've played with dithering tools that provide both options, and I prefer the output of the simple version..

danielvf··on Hunt for Red October 1990 (2016)
A normal ballistic missile submarine has one pressure hull, with a large section of ballistic missiles taking up the middle of it. This submarine has two pressure hulls, on either side containing no missiles, but sandwiching the missiles between them. In theory this means that you can torpedo the sub from a side, and the missiles are still okay. But it also means that the sub has ludicrous amounts of space available. No missiles taking up pressure hull space, and two, not one pressure hulls. So everything on this sub got to be more spacious and there was room for extras.
danielvf··on Nearly $13M stolen from Abracadabra Finance in crypto heist
Maybe it's just semantics, but to me hacks and rug pulls are different things.

Team backdoors in code to steal funds tend to be obfuscated, and access to run them locked down. This is quite different than a hack that exploits "well intentioned" code. I think very few actual exploits are by the team - there's just much easier ways to steal funds than leaving a bug open in the world for a long period of time that anyone could find and use.

danielvf··on Nearly $13M stolen from Abracadabra Finance in crypto heist
Tornado Cash was essentially irrelevant to the attack. Just a way the attacker worked to hide themselves.

The attack was able to happen as a result of two separate bugs.

First, a user was able to use something as collateral with a price that could be manipulated. This allowed them to make the collateral to instantly manipulated to appear worth less than the amount borrowed, allowing it to be liquidated.

The second bug was that they had code that should not allow a user to do a series of interaction with the contract that end in bad debt for the user, however since they were able to liquidate their own bad debt from inside the series of interactions, the liquidation cleared out the bad user debt, and moved it to bad protocol debt. This made it so the whole process was checked at the end of the transaction, the user debt looked fine.

Or I could be slightly wrong - it was an usually gnarly attack.

danielvf··on Coordinating the Superbowl's visual fidelity with Elixir
There was even more color correction happening then - cameras were worse and more analog! It just was not being controlled from offsite, instead there was a dedicated room and engineer in the broadcast truck doing camera configuration + color correction.

The usual technique was to start by holding up a color card on the stage/floor then use a vectorscope[1] and get all the dots to line up in the right place. Then with a waveform monitor for exposure. During the event, there would be fine tuning by eye, or as things drifted out of line.

[1] https://en.wikipedia.org/wiki/Vectorscope#/media/File:PAL_Ve...

PS: You can also see modern vectorscope / waveform monitor images in this photo from the cyanview blog. Look for the black and white X-ray looking things on the screens. https://www.cyanview.com/wp-content/uploads/2022/10/20221006...

danielvf··on Starlink satellite part hit a Canadian farm when it fell from orbit
Note that this was from a failed launch - this debris was not from old starlink satellites falling out of operating orbits.
danielvf··on My Scammer Girlfriend: Baiting a Romance Fraudster
One warning, this scam, with it's fast timeline and request for funds to be sent to the girlfriend is a classic, but modern scams can be quite different than this.

"pig butchering" scams can run for months of contact with no requests for money, and then instead of asking for money, the user "invests" into what appear initialy to be profitable investments alongside the scammer.

danielvf··on Bill could redefine self-defense in California
Going out and starting fights is already a self-defense disqualificaiton in Californa.

To quote the current official California jury instructions and legal commentary:

"No Defense for Initial Aggressor: An aggressor whose victim fights back in self-defense may not invoke the doctrine of self-defense..."

danielvf··on Regulatory gridlock in the U.S. risks losing the drone arms race
Ukraine announced a two weeks ago that they built 2.5 million drones last year. Maybe that number got garbled somewhere?
danielvf··on SEC Declares Memecoins Are Not Subject to Oversight
A meme coin is a subset of crypto currency stripped down to remove everything but belief or lulz.

There is no "utility" (the coin is not used to run some crypto system).

It's not attached to something that earns profits.

It's not even expected to retain value.

It's essentially a global apples to apples game. Those who are best at recognizing ahead of time what everyone else will find funny, get more money. In theory.

danielvf··on SEC Declares Memecoins Are Not Subject to Oversight
The headline currently shown here "SEC Declares Memecoins Are Not Subject to Oversight" is wrong, which is throwing discussions off here.

The actual decision is that memecoins are not "Securities", and therefor not subject to regulations that apply to Securities. This makes a lot of sense.

If you pick up a cool rock off the ground, and just sell it to someone, it's not a security. If people are buying and selling wheat, it doesn't make wheat a security.

As skybrian said, the US test for a security is the Howely test.

* It is an investment of money * There is an expectation of profits from the investment * The investment of money is in a common enterprise * Any profit comes from the efforts of a promoter or third-party

Memecoins don't fit it at all.

danielvf··on Reflect Orbital: Sunlight after dark using a constellation of spatial reflectors
I don't think they are aiming to be lighting things up at night, just twilight. It's a day extender.
danielvf··on Reflect Orbital: Sunlight after dark using a constellation of spatial reflectors
I did a bunch of my own math on this a while back related to this.

1. On of the big tradeoffs is the sun sync orbit altitude chosen. The higher up you are, the slower you have to tilt to track, the longer time possible on a given customer, and bigger range of possible customers you have as the sat goes around. But, as you are higher, the size of sunlight you send gets bigger and bigger. A 5km by 5km circle is going to waste a lot of energy on not-solar panels all but the largest solar installations. If you double the light radius, you quarter the intensity.

2. Most of the earth is water. Of that land left, most of the land is quite uninhabited. This means that most of your time orbiting is going to be over areas with no paying customers.

3. I think the EEVBLog video overestimates the cost per sat, but I still didn't get the economics to work out to something profitable.

danielvf··on A Cold War Satellite Program Called Parcae Revolutionized Signals Intelligence
Here's an excerpt of McNamara's famous speech in San Francisco, 1967.

> The cornerstone of our strategic policy continues to be to deter nuclear attack upon the United States or its allies. We do this by maintaining a highly reliable ability to inflict unacceptable damage upon any single aggressor or combination of aggressors at any time during the course of a strategic nuclear exchange, even after absorbing a surprise first strike. This can be defined as our assured-destruction capability.

> Security depends upon assuming a worst plausible case, and having the ability to cope with it. In that eventuality we must be able to absorb the total weight of nuclear attack on our country -- on our retaliatory forces, on our command and control apparatus, on our industrial capacity, on our cities, and on our population -- and still be capable of damaging the aggressor to the point that his society would be simply no longer viable in twentieth-century terms. That is what deterrence of nuclear aggression means. It means the certainty of suicide to the aggressor, not merely to his military forces, but to his society as a whole.

https://www.atomicarchive.com/resources/documents/deterrence...

----

McNamara used the term "assured destruction" over and over again it became a cornerstone of his policy. Later a civilian added an "M" to MAD, and the term caught on.

Here's an interview transcript from much later, in 1987:

INT: Much has been made during this period of the term 'MAD', Mutually Assured or..

RM: Yes..

INT: ......Destruction. Can you explain what was meant by that?

RM: It's not mad! (laugh) Mutual Assured Destruction is the foundation of deterrence.

RM: Today it's a derogative term , but those that denigrate it don't understand deterrence. If you want a stable nuclear world -- if that isn't an oxymoron -- , to rephrase it, to the degree one can achieve a stable nuclear world, it requires that each side be confident that it can deter the other.

danielvf··on Should we use AI and LLMs for Christian apologetics? (2024)
I found this a remarkably well written take.

It's quite a different level of commitment to truth than one usually runs across these days. Instead of a world of meme and vibes, a costly commitment to only say things that are true.

danielvf··on Ships must practice celestial navigation
Note that they were staying roughly 2 miles within the actual track, while having the bulk of the work being done by a combo of officers and newbs that they had just trained. That's high accuracy standards for celestial nav, not even counting that this is most of other people's first time doing this in anger.
danielvf··on Notes on the New Deepseek v3
Given that we have open weights on it, the costs to run it relative to other open source models are fairly transparent.
danielvf··on Bus Number – The GitHub plugin my coworkers asked me not to write
Just going to second this. Good code reviews (not just typo nitpicking) can be a great way to simplify down code, and spread knowledge horizontally across the org. Not to mention catching bugs.

Unit test aren't a substitute because unit tests check that the success paths are good. That's a good start, but it's not the same as verifying all the possible ways code could go wrong in a complex system, and one of the cheapest ways to spot those problems is with people familiar with complex system looking at new code.

Code review give you the double benefit of building more people who understand the whole system, and having the code looked at by people who understand the whole system.

danielvf··on We're only beginning to understand the historic nature of Helene's flooding
It was a bad disaster. I was scheduled to be there, but took a look at the NOAA rainfall map the night before and canceled my trip.

Calling it unthinkable is really overselling it though. Mountain towns and roads flood when it rains a lot. If you search past years google search results for Chimney Rock, it floods with 3" to 5" inches of rain. The town is just a few feet above water level - I've walked along the river.

danielvf··on A Burrito Is a Monad
Monads are just function chaining worshiped in the holy language of category theory.

You have an array of state, and you can call a method on it that returns a new array of state, that you can call a method on, that returns a new array of state, etc. And that concept of doing state -> function call -> state is the holy Monad.

A JS pleb would write instead:

burrito = (new Tortilla()).addMeat(Chicken).addMissionBurritoIngredients().holdThe(Cheese)

No one would be confused about what was going on, and it would be basically the same thing.

danielvf··on Hezbollah hand-held radios detonate across Lebanon, sources say
Just a few months ago, Hezbollah exploded a rocket in soccer field with children playing, killing 12 children. Doesn't get much more "exploding devices in public spaces" than that.

https://www.timesofisrael.com/11-killed-mostly-children-doze...

danielvf··on Tell HN: DanBC has died
Cancer (outside behavior related cancer like lung cancer) is on the rise.

In spite of better treatments, a twenty year old today is more likely from cancer while in their twenties than at any time before. Each younger age cohort has an increase risk of cancer, and at younger ages.

Cancer deaths overall are still going down though, as the smoking generation still alive goes out.

danielvf··on Athletes and musicians pursue virtuosity in fundamental skills
I agree that practice can be tremendously valuable in knowledge work, but at some point in the skill curve, once you have built up a the ability to accurately self-evaluate the value of practice goes down because the work itself is the practice.

Benjamin Franklin was referenced in the article, and there are far more examples in his life than just the writing exercises where he employed deliberate practice to improve his ability in an area. But he didn't continue these once we was rocking these skills at a world class skill level - instead he switched to practicing new skills he wanted to add.

But if you haven't tried doing so deliberate practice - I'd highly recommend it.

danielvf··on Athletes and musicians pursue virtuosity in fundamental skills
Programming is a fractal of tasks. There's big stuff like how you architect a program, then down to how you write functions, and then down even further into grit below that.

And one of the joys of programing is that at each level, there's not one right answer. But even with there being different things you can optimize for, there's also a ton of poor choices that could be made as well.

Practice lets you focus on one aspect at one level, and improves your ability there. If you were to practice writing a function focused on correctness, another time on readability, and lastly writing the function based on performance optimization, you would almost certainly be able to write a better function later. You've expanded your tools, you've learned new techniques, and you've consciously evaluated your work from different perspectives.

danielvf··on Apple to Replace CFO Luca Maestri on Jan. 1
Agreed - this is very clearly someone wanting less workload, and the company wanting to keep them around. It's also not a rush. This gives four months for a smooth transition.
danielvf··on AI photo editing raises trust issues in photography
Note that Canon has been shipping cameras that intend to do this since 2002.

However, clever people figured out to break it. [1]

[1] https://www.usa.canon.com/support/canon-product-advisories/a...

danielvf··on The U.S. Navy's $100M checkbox (2019)
Imagine you have a system that ignores taps a substantial percentage of the time (either because it required more precise finger placement, or because that's life). Also most successful taps complete quickly, with only some having 250ms latency. Combine these two and most of time when nothing has happened after 250ms, it's because the tap failed to register and a new tap attempt is needed.

There's been plenty of research for decades showing that 250ms response time in UX is a noticeable slowdown.

← PreviousPage 2 of 34Next →