HNHacker News
TopNewBestAskShowJobs

dcsommer

759 karma · joined July 5, 2013

[ my public key: https://keybase.io/dcsommer; my proof: https://keybase.io/dcsommer/sigs/WrpLJLeW4-5GKHB2gaxmZ10bdgdMoE57HegeZXkC8S8 ]
submissionscomments
dcsommer··on The need for memory safety standards
CWE Top 25: https://cwe.mitre.org/top25/archive/2024/2024_cwe_top25.html

Out of bounds write and read are more prevalent then UAF. There are multiple types of bugs that can produce OOB read or write though.

dcsommer··on Asahi Linux lead developer Hector Martin resigns from Linux kernel
Zig brings developer velocity benefits over C, but developer velocity is not the reason R4L exists. Until Zig has an easily segmented part that is memory safe, there is no demand for its potential benefits in Linux. Memory safety is the only reason a new language was considered within Linux.
dcsommer··on US children fall further behind in reading
Thank you for your educational service. I hope we can streamline money to teachers better as a country so we don't keep losing institutional knowledge and experience like yours.
dcsommer··on US children fall further behind in reading
What's to say it wouldn't have been even worse workout the money? I don't think you can draw that conclusion from just this data point.

That said, education certainly needs major reforms. I like how Sweden is going full Luddite for learning: https://www.theguardian.com/world/2023/sep/11/sweden-says-ba...

dcsommer··on Portspoof: Emulate a valid service on all 65535 TCP ports
Accepted cryptography is also security through obscurity. The thing is that the amount of obscurity must be quantified. Cryptanalysis allows one to calculate these quantities of "obscurity." Then, a full study of effectiveness combines that with the costs associated with brute-forcing the bounds arrived at by the cryptanalysis.

Other parts of infosec are the same, but often with less well-quantified measures of effectiveness. E.g. memory hardening techniques like FORTIFY_SOURCE and MTE are effective in raising the difficulty of exploiting memory vulnerabilities, but under some conditions the vulnerabilities may still be exploitable.

Before using labels like "security through obscurity" one has to first answer: how much does the technique raise the cost for attackers? This is what articles about security systems (including this one) should focus on. In the end, hacking, like most things, comes down to economics.

dcsommer··on Supernovae Evidence for Foundational Change to Cosmological Models
Sounds fascinating. Anywhere I can read more about the build-up to this moment? Has David Wiltshire written about this?
dcsommer··on How WhatsApp became an unstoppable global cultural force
A conspiracy involving thousands of people lying and no one speaking up over many years (it's been over 9 years since the acquisition) is incredibly unrealistic. Your hypothesis that WhatsApp shares the addressbook with Meta is not at all probable.
dcsommer··on How WhatsApp became an unstoppable global cultural force
This is not me making some grand new commitment. It's right in the privacy policy and also summarized here: https://faq.whatsapp.com/1303762270462331

> We need your contacts to provide the service, but don’t share your contacts with Meta.

I'm frustrated that people even at HN allow themselves to indulge in conspiracy theories that would be immediately whistle-blowed or reported on. There are thousands of people that work on or with WhatsApp and related products within Meta who would notice, not to mention all the data separation audits that happen.

dcsommer··on How WhatsApp became an unstoppable global cultural force
This is absolutely not true and would immediately trigger lawsuits across the globe. WhatsApp and Meta data separation is extremely strict. Source: I work at WhatsApp and also https://faq.whatsapp.com/1303762270462331

> We need your contacts to provide the service, but don’t share your contacts with Meta.

dcsommer··on Elixir/Erlang Hot Swapping Code (2016)
GP seems to be implying hot swapping, not Erlang, is unreliable. To which, from my experience using it in Erlang, I heartily agree is fraught. Inconsistent state across nodes is much harder to reason about. When you _must_ ensure consistency, hot swapping is reckless, especially as org size and product complexity increases.

Leave hot loading to local/development environments, not production deploys.

Loading configs on the fly can also have some of this risk, but it is much easier to reason about typically.

dcsommer··on RFC 35140: HTTP Do-Not-Stab (2023)
ePD in 2002 mandated cookie banners well before GDPR in 2018. But yes, point taken that well intentioned regulation can be poorly implemented and have negative repercussions.
dcsommer··on Why systemd is a problem for embedded Linux
How many systemd CVEs are memory or thread safety related?
dcsommer··on BazelCon 2024 Recap
I'd love to hear more about the relationship between Buck2 and Bazel such that they share a conference. Sure, they are quite similar systems and both use Starlark DSL, but is there a long term vision of these projects belonging "together" or even merging? Or was Buck2 a one-off guest?
dcsommer··on The TikTok documents: Stripping teens and boosting 'attractive' people
I'll find out in due time when my kids get older, but I think #1 is overblown due to #2. It probably varies by region, but there is so much demand for "back to the roots" where I live, that I don't think this will be as bad socially as you say. There will be other like-minded families, and the bonds between my kids and those families' will be more enriching and meaningful than the average, device-oriented ones.

Some degree of device pragmatism is inevitable of course. But I don't think my kids will need a smartwatch until high school, or a phone till very late HS. In other words, I think there is a balance of these options possible.

Jonathan Haidt gives a lot of hope here, as depressing as "Anxious Generation" usually is.

dcsommer··on Enum class improvements for C++17, C++20 and C++23
I think you are thinking of the concept of "explicitness" not "expressiveness".
dcsommer··on Translating All C to Rust (TRACTOR)
GP was proposing a different situation where the source code is not changing or changing very rarely. If you have a high churn codebase, obviously the maintenance experience will worsen dramatically after machine translation (at least with many current tools), so your experience is not unexpected.
dcsommer··on Thorium: Cross-platform patched Chromium fork
Remote code execution + local privilege escalation to own your device. Just last week on the RCE front: https://thehackernews.com/2024/05/new-chrome-zero-day-vulner...
dcsommer··on JEP Draft: Support HTTP/3 in the HttpClient
Yup. We've finally been able to consolidate the redundant flow/congestion control in the HTTP multiplexing and TCP layers while solving the head-of-line blocking problems. It only took 15 years (2009 was SPDY)!

HTTP has been around since 1991, 33 years ago. We really pushed things faster in the second half of HTTP's life so far.

dcsommer··on Airbnb is banning indoor security cameras
AirBnB should tie the cleaning fee to your rating, perhaps a cleanliness dedicated rating.
dcsommer··on The Xylophone Maze: Screen-free coding for children
I love this idea! I can't wait to try it with my son when he gets a couple months older. By the way, what you have there is a glockenspiel. A xylophone is made with wooden bars, not metal as you have. It's a common mistake!
dcsommer··on New Linux glibc flaw lets attackers get root on major distros
In the presentation there are links to multiple companies observing a consistent 60-70% of high severity security issues being attributed to memory safety issues. These are companies that are organized, well resourced, etc.

Rust eliminates these bugs and it results in fewer security issues in Rust code than C/C++. See https://security.googleblog.com/2022/12/memory-safe-language...

Additionally, even in brilliant soloist projects like curl, Linux, etc., you still get plenty of memory safety CVEs. The best still don't get it right.

> Are there any studies that show excluding memory overrun bugs...

Why exclude memory safety from the argument? That's the whole point -- to fix those significant fraction of vulnerabilities.

dcsommer··on New Linux glibc flaw lets attackers get root on major distros
> you can eliminate these bugs by getting better at writing code.

No, the data doesn't show this. This is the "anger" response to being confronted with the reality of the inherent insecurity of C and C++. https://www.usenix.org/conference/enigma2021/presentation/ga...

dcsommer··on Due to blade damage, Mars Helicopter Ingenuity will not fly again
Mars has weather, unlike the moon. Will the samples really still be there a decade or two from now?
dcsommer··on AI is destabilizing 'the concept of truth itself' in 2024 election
It's not necessarily the case that because AI can destabilize truth, that it can also re-stabilize truth. It's much easier to burn something down (e.g. trust) than build it up. c.f. second law of thermodynamics, etc.
dcsommer··on Lowriders may cruise again in California
Any alternative car culture to "bigger and taller is better" is welcome in my book.
dcsommer··on "Paste this post into ChatGPT 4"
Many parts were. Overall, though, I am glad it exists compared to the before-times.
dcsommer··on Is Objective-C BOOL a boolean type? It depends
Except for the Obj-C related parts of Swift!
dcsommer··on The teen mental illness epidemic is international (2023)
Video games are very different today. There are far more social and gambling features built-in to addict users than in the old mostly-single-player days. I'm not convinced you've disproved video games as being part of the problem.
dcsommer··on The teen mental illness epidemic is international (2023)
There are so many alternative explanations to go through before it "has" to be social media. Already mentioned was time spent outside. For instance, video games are (also) a huge drain on time spent outside.
dcsommer··on NHS to investigate Palantir influencer campaign as possible contract breach
Please refrain from ad hominem and guilt by association.
← PreviousPage 2 of 9Next →