HNHacker News
TopNewBestAskShowJobs

deepblueocean

1,249 karma · joined January 25, 2013

submissionscomments
deepblueocean··on Bing doesn't support SSL
Wow. This has been going on for an hour now. It's such a simple fix, especially since one would assume that they already have a valid cert somewhere (or that Akamai does). Yet they've had an hour of SSL downtime.

Does anyone know if Bing has any SSL-only clients? Like do any of their toolbars or built-in search widgets in Windows use SSL by default?

deepblueocean··on CISPA Passes in the House - Full Roll Call
If your congressperson voted for the bill, you can express your dissatisfaction, which counts for something. This kind of thing is not the sort of issue your congressperson likely understands or even thinks about for very long - they just do what their staff suggest and they don't expect to be called on it when they get back home to their districts. So if you can make it an issue, make it something they think might affect votes, you'll raise the priority and raise the level of discussion a little bit. And that makes it harder for the kind of disinformation that spreads around CISPA to survive.

Congresspeople are currently very afraid of "getting SOPAed" where they try to make some kind of tech policy regulation and then accidentally set off a huge wave of activism.

Keep in mind, just because something passes in the House doesn't mean it's law. There's a long process - right now it's still just a bill (that they voted for on Capitol Hill (sorry)). There's a lot that can be done, and, now, probably will be done to mobilize on this issue. I doubt that it will come to SOPA-level activity (SOPA would have affected the bottom lines of big tech companies. This is "just" about privacy). But there's always room for trying to make things more reasonable.

deepblueocean··on CISPA Passes in the House - Full Roll Call
I found this slightly more readable: http://www.govtrack.us/congress/votes/113-2013/h117

Call your congressperson. They do care what you think, at least a little bit, especially if you take the time to call or write their office thoughtfully.

deepblueocean··on A New HTTP Status Code to Report Legal Obstacles
This reminds me very much of the TCP Evil Bit [1]. That is, it seems like the issue of whether anybody would actually set this is essential to the question of whether or not it would work.

One could even imagine that governments would want people to live in ignorance of the existence of restrictions. It's 100% the Ethan Zuckerman Cute Cat Theory of Internet Censorship [2]. The government would rather that you have all of YouTube except the subversive content, because then you might not notice the restriction and so will learn not to care.

Indeed, from the document:

  "The use of the 451 status code implies neither the
  existence nor non-existence of the resource named in the
  request.  That is to say, it is possible that if the legal
  demands were removed, a request for the resource still
  might not succeed."
That suggests to me that the author is also aware of this problem.

It should be noted that Google has done an amazing job in trying to fix this problem by trying to force whole services to be blocked when that's feasible and by transparently explaining (in the UI itself!) when content is unavailable for legal reasons. Kudos to them.

For that reason, I would say such an effort is worthwhile even if it won't have much impact: it's quite likely that it will help further the norm that when censorship exists it should exist transparently. That's a cause worth fighting for, even if every step is going to be a huge challenge.

[1] http://www.ietf.org/rfc/rfc3514.txt

[2] http://www.ethanzuckerman.com/blog/2008/03/08/the-cute-cat-t...

deepblueocean··on I Tried Hacking Bitcoin and I Failed
His point of view is certainly worth listening to, but Dan should know better than anyone that the fact that even he can't break something is still not an argument for (or even a suggestion of) its security.
deepblueocean··on Tech group representing Google, Yahoo backs CISPA
Nah. It's bad. Here's a simple argument that covers just one part of the bill.

CISPA would give a safe harbor from other privacy rules to companies that share information with the government as long as that information is about "cyber threats". Now, let's say someone breaks into your database server and you're at a company with not-too-skilled IT people. The government shows up and says "hey, what can you tell us about the attack you experienced? PS - we'd be happy to analyze your data for you."

What do your IT people do? They say "screw it, we'll just send in all the logs we have and let the feds figure it out." And so they do that.

What if the law protects the information in those logs? What if the information is sensitive (like health or financial information) and is protected under a special privacy regime like HIPAA? Or what if the information is protected from disclosure by contract (like in a TOS/TOU document)? CISPA says that the disclosure is exempt from whatever sanctions/punishments would happen under those protection regimes because Cyber Threats Are Important (tm).

Disclosure: I am not a lawyer. Even after it's passed into law, only a court can decide exactly what the safe harbor in CISPA means.

deepblueocean··on Tech group representing Google, Yahoo backs CISPA
So who is TechNet? It's not really fair to cherry-pick from their members when writing a story like this. So let's take a look:

http://www.technet.org/leaders/member-companies/

A headline "Tech group representing AT&T, Palantir backs CISPA" isn't good copy. But that could have been the headline. The "Executive Council" (which seems to be the part of the organization that draws the focus on Google and Yahoo) also contains people from Oracle, Microsoft, and VeriSign. And one thing that council doesn't do is sign off on every letter the group sends out (or, probably, every point in the policy platform it espouses).

I doubt without knowing exactly that Google's official position is anti-CISPA and that this group doesn't speak for them because they don't actually control what it says. But I've been surprised in the past.

Perhaps, though, people should read this and think "hey, Google ought to put some pressure on the lobbying groups they participate in not to be stupid/evil/whatever." And perhaps if a few Google executives express that they're upset that their names were used in conjunction with something they don't support, they can rein in groups that want to claim the mantle of "the tech industry".

deepblueocean··on Mt.Gox does not mean "Mount" Gox
I don't like to be a pedant, but what the hell.

Your belief about which is the "correct" pronunciation depends on whether you believe the "correct" etymology is French or Italian. It appears to me that people agree that the word came into English from French earlier, but also that (at least in 'murica) people have settled on the other pronunciation.

It's not that there's a correct pronunciation that got corrupted, as you suggest. There are two legitimate derivations of this word with different pronunciations and one has won out.

By the way, the word in French would be pronounced \ˈfȯt\, which is a common usage in Britain. And it refers not to a fort (which is the Italian etymology for "a strong point") but rather to the part of a sword between the middle and the hilt.

Source: I like to read about usage and etymology. Sadly my dictionary of classical word origins suggests that forte comes from fortis in Latin, which (while ultimately true) doesn't reflect either later usage or pronunciation.

deepblueocean··on Zerocoin: making Bitcoin anonymous
Why? Why not simply set a minimum quantum for transactions in Zerocoin, like the penny or the satoshi? Or why not redeem the Zerocoin for a Bitcoin, which is divisible and which would be free of (traceable) history.
deepblueocean··on As Big Investors Emerge, Bitcoin Gets Ready for its Close-Up
Oh, so that's why the value is crashing... people just wanted to get out once they saw the Winkelvii getting in.

Well that explains everything. I can go home now.

deepblueocean··on Mtgox stops trading for 12 hours
This is a really interesting analysis of the risk of Bitcoin exchange failure, for what it's worth: http://fc13.ifca.ai/proc/1-2.pdf
deepblueocean··on Realtime Bitcoin Stats
It doesn't bother you that your method counts only unique hash values tested? Or that this value is being used on the site to talk about power expenditure (which is clearly related to total hashes per second, not unique hashes)?

You're right that you can compute the N-second average rate easily. But nobody reports the "network hash rate" as such. And since the denominator matters a lot in determining what the number means, pretty much all the numbers you find out in the world are (1) misreported and (2) bogus.

deepblueocean··on How a banner ad for H&R Block appeared on Apple.com without Apple’s OK
One could argue that DNSSEC is a variant of this - put your SSL certificate in a TXT record in your DNSSEC-signed domain and you no longer need a certificate authority system to sign the certs. Now you can self-sign the cert and get it for free!
deepblueocean··on Realtime Bitcoin Stats
I'm aware of that. rwinn, can you tell me if this is what you're doing?

It's in your last sentence that you go wrong. There's a relationship between the number of expected hashes per new block and the difficulty. That tells you something about the hash rate, but not the rate itself. Actually, it tells you something about the number of unique hashes being tried per new block (in expectation). And for some applications, that may, in fact, be what you care about.

Specifically, the appearance of new blocks is, if you like, a random variable with an exponential distribution. You can, in principle, estimate the rate parameter for this distribution using the difficulty and the timestamps in the Bitcoin log, but it's not straightforward. The last time I got into it, I was halfway through building a Bayesian estimator for the rate parameter using the log before I had to give up and move on to real work. I'll do it soon.

deepblueocean··on Bubble or No, This Virtual Currency Is a Lot of Coin in Any Realm
I'm pretty sure the exchange price of Bitcoins is driven by the marginal supply and demand. So I think it's got to be what you call "investors" almost entirely (note that not all people buying in have to be speculators: if lots of people suddenly decided they'd rather have some Bitcoins because they want to use them, that would suffice).

So the question is how are the marginal supply and demand determined? The marginal demand is subject to spikes in interest, media coverage, the Cyprus crisis (I really doubt the latter is meaningful but perhaps it makes people everywhere think they want to move out of bank deposits. People certainly attribute things to it). The marginal supply is based on (1) mining, which happens at a fixed rate and (2) people who wish to exit Bitcoin, which is subject to lots of whims.

Lots of evidence shows that most Bitcoins are hoarded, so it's possible that what we see is just a supply crunch - nobody wants to sell their Bitcoins and some people want to buy. I suppose the natural way to answer that is to go look at historical exchange volume across all the exchanges (or, as a first-cut proxy, just Mt. Gox).

deepblueocean··on Realtime Bitcoin Stats
How do you calculate the hash rate?

I have spent some time trying to understand the various hash rate estimates people come up with. Basically, I've determined that they're all 100% bogus. People like to work from the difficulty using bad/incorrect statistics since that's the most obvious way to get to something in the units of hashes/s, but I can never understand exactly what the process is. I'm genuinely curious to know what people do in practice, since I'm genuinely curious to know the "real" answer.

deepblueocean··on How a banner ad for H&R Block appeared on Apple.com without Apple’s OK
This is probably the best counter-argument to the best counter-argument that gets leveled at the people promoting HTTPS-everywhere. People like to say that HTTPS everywhere would break transparent cacheing by ISPs. After all, HTTP is designed to allow caching proxies to exist inline and still supports dynamic content gracefully (er, somewhat, anyway).

But in fact the same features that make transparent caching easy make this kind of shenanigans easy. There are tons of companies in this space now. Not just people like NebuAd and R66T, but lots of "subscriber messaging systems" like FrontPorch (which I've heard sells messaging data for behavioral advertising) and PerfTech (which has assured me that they do no such thing).

This should be an easy way to push back one of the last "real" arguments against using HTTPS everywhere. There's no excuse not to be running your site on HTTPS all the time - it protects you and your users from all sorts of mischief for a minimal overhead.

deepblueocean··on Are Bitcoins The Future?
I look at it this way: there are two kinds of rules in the Bitcoin system: crypto rules and social rules.

Some are self-executing, by which I mean that they can be enforced "by construction" - if you create an object that doesn't follow the rule, other people will know. Said another way, breaking the rule would also require breaking some crypto.

Some rules, though, are social. For example, why does everyone try to extend the longest branch in the block chain? Sure, the protocol says it's the rule, but why should that mean anything? People don't follow rules because they want to. They follow rules because it's in their enlightened self interest to do so. If you could make money by choosing a different rule, somebody would do that instead. So it must be that these rules get followed because it's in the interest of Bitcoin players to follow them. The natural follow-up question is whether these social/economic rules are stable. That is, why not some other solution? Why not only extend blocks whose (nonce % 0x0d) == 0?

Cryptographers use a very particular notion of security in which they like the security of their schemes to "reduce" to a well-understood assumption. That is, we prefer it you can prove something like "if you can break my system, then you can also solve problem X" where problem X is well-known and widely thought to be very hard. Then either I am forced to believe that your system is secure or that you have found an efficient way to solve problem X. And since solving problem X is unlikely, I should consider your system secure.

As I said, some parts of Bitcoin do reduce in this way to known cryptographic primitives (which in turn reduce to problems we believe are hard). But not all the parts.

deepblueocean··on Bitcoin Plunges By Nearly $30 As Largest Market Suffers Outage
This demonstrates perhaps the largest real threat to the bitcoin ecosystem right now: the exchange markets are heavily concentrated. Confidence in the system is, right now, heavily based on the perception that Bitcoins can be traded readily for something (pizza, drugs, dollars, quatloos...). Anything that alters that perception will, of course, have a big effect on the price.

In fact, exchange risk could lead to something akin to a bank run - the exchanges only keep a small reserve of national currencies and Bitcoins to handle orders and are essentially acting as market makers. But a big swing in the demand for either Bitcoin or real currencies could push the exchanges into a tight spot. If they don't have enough Bitcoin, obviously, the price rises until the demand for Bitcoin subsides. But if they don't have enough (say) dollars, then the price must fall. And there's a natural death spiral: as the price falls, particularly after such a big run up as has happened recently, people might suddenly decide that it's time to get out. But that only increases the demand for (scarce) dollars. And so the value collapses.

Here's the real Bitcoin security question: can someone precipitate this situation? Maybe someone who benefits from a collapse of the Bitcoin price (say a law enforcement agency that wants to affect the Silk Road business or, if you don't like that, then say any entity with a significant short position on Bitcoin exchange markets). This is not a question I've seen previously addressed in Bitcoin literature or even musings on the various Bitcoin forums. It's a security economics question. I'm interested in the answer.

By the way, my current favorite term for such a situation is the "Goldfinger attack" on the theory that while Goldfinger wanted to steal the gold from Ft. Knox (in the novel version), such an adversary wants to invalidate the coins in Mt. Gox.

deepblueocean··on How the Internet Archive is having a great time with Bitcoin
I wonder how much pressure IA feels to convert its donated bitcoin holdings to cash, given the run-up in exchange rates that has happened recently. Does IA prefer to support Bitcoin as if it were, as its proponents suggest, a real currency with sticking power for the long-term future? Or is there more real and permanent good to be had from converting that money to dollars to support the Archive's excellent programs today?

Clearly the latter must trump the former at some price. I think that price may be well below the $/BTC exchange rate today.

deepblueocean··on Bitcoin Hits $1 Billion
This is just wrong - see the Hal Finney attack. Basically, an attacker can pre-mine a block with the double-spent coin in it but not announce it. Once an attacker spends the coin and gets something of value, they can immediately announce their block, pay the coin to themselves instead, and keep the goods.

It's true that it would be hard to get a lot of value this way, but it's still the case that the person accepting the payment must be wary of the possibility and, as you say, be able to reverse the transaction if the coin ends up double-spent.

deepblueocean··on US Treasury Guidance on Virtual Currencies (aka Bitcoins)
tl;dr No. IANAL.

If you mine Bitcoins, you hold them. If you want to exchange them, you can give them to someone in exchange for dollars (in which case the exchange is an MSB and is subject to the rules for money transmitters) or you can give them to someone in exchange for "real or virtual goods or services", in which case you're fine, or you can hold them, in which case they don't care.

On the other hand, if you happen to mine some coins and then set up a lemonade stand in front of your house where you sell those coins to somebody in exchange for real dollars, then you are a money transmitter according to the guidelines.

deepblueocean··on US Treasury Guidance on Virtual Currencies (aka Bitcoins)
As far as my non-lawyer view takes me, that line is simply meant to catch the case where you exchange a de-centralized virtual currency for something (anything) else of value that's meant to substitute for currency in some context (i.e. what if you traded BTC for gold? For certificates that represent gold? For another virtual currency like WoW gold?).

That is, FinCEN is saying that you're still a money transmitter if you accept Bitcoins for anything else the Treasury considers to be equivalent to currency (which means, roughly, it can be readily converted back to currency), but not for goods and services. That way, you can't claim not to be subject to the rules just because you don't exchange Bitcoins for dollars.

Remember, the idea here is to make rules that allow FinCEN to track large flows of capital and generally prevent money laundering. So they're concerned with the situation where I give you bitcoins for gold and then turn around and sell the gold for clean dollars.

deepblueocean··on US Treasury Guidance on Virtual Currencies (aka Bitcoins)
Insofar as such currencies can be converted back and forth to "real" currency, yes, they're covered. I think that's what the document is trying to get at when it discusses "centralized" virtual currencies.
deepblueocean··on Only Apple and Google are skating to where the puck is going
I've had good luck with Chrome Remote Desktop:

https://chrome.google.com/webstore/detail/chrome-remote-desk...

It works from two instances of Chrome, which could be on any platform (not just Chromebooks).

deepblueocean··on What Thomas Edison expected job candidates to know
I wonder what Nikola Tesla asked prospective assistants?
← PreviousPage 2 of 2