HNHacker News
TopNewBestAskShowJobs

deepbreath

55 karma · joined March 21, 2018

submissionscomments
deepbreath··on Xzbot: Notes, honeypot, and exploit demo for the xz backdoor
The knockee PoC should also be straightforward, can use socat + udp-listen + fork with a script that checks that input matches `sha1sum(secret||num)||num` and `num>previously_seen_num`, and if so, adds an iptables rule.

This should prevent against replays. Throw in some rate limits somewhere maybe to not get DDoSed, especially if you let socat `fork`.

deepbreath··on Xzbot: Notes, honeypot, and exploit demo for the xz backdoor
Don't have to do anything too complicated. Here's the knocker code in a short Bash script, produced by GPT4:

~ % gpt4 'write a very short bash script that takes the number stored in ~/.ssh/knock_seq, increments it by 1 and saves it to the file. It then takes the new number and concatenates it with the value stored in the file ~/.ssh/secret. It pipes the resulting string to sha1sum, spitting out binary. It then takes both the resulting sha1sum and the number used and pipes their concatenation to "nc -u $host $(cat ~/.ssh/knocking_port)". be brief'

  knock_seq=$(cat ~/.ssh/knock_seq)
  let knock_seq++
  echo $knock_seq > ~/.ssh/knock_seq
  concat_seq_secret=$(echo -n "${knock_seq}$(cat ~/.ssh/secret)")
  sha1_output=$(echo -n $concat_seq_secret | sha1sum -b | awk '{print $1}')
  final_output="${sha1_output}${knock_seq}"
  host=localhost
  knocking_port=$(cat ~/.ssh/knocking_port)
  echo -n $final_output | nc -u $host $knocking_port
deepbreath··on Xzbot: Notes, honeypot, and exploit demo for the xz backdoor
> At the point an attacker has remote code execution

The attacker doesn't have remote code execution in the xz case unless they can speak to your port 22. Port knocking prevents them from doing so, provided they don't know how to knock.

deepbreath··on Mozilla to put ads in Firefox address bar suggestions
You're right, I guess it depends on what you choose A and B to be. For:

A = OP supports Mozilla making money from address bar ads

B = Mozilla is honest about making money from address bar ads

"B -> A" (OP supports Mozilla if Mozilla acts a certain way) makes sense. "A -> B" sounds confusing in a sentence, but its contrapositive, "!B -> !A", also makes sense.

However, for:

B = Mozilla decides to make money from address bar ads and is honest about reasons

"A -> B" no longer makes sense, since OP can support Mozilla having the address bar ads with an honest justification, but Mozilla can still decide to not have the address bar ads.

deepbreath··on Mozilla to put ads in Firefox address bar suggestions
Except it's not used correctly here. "A iff B" means "A implies B and B implies A".

"I'd be willing to entertain, or even support, this way of them making money iff they spelled out honestly what they're doing and why" implies both of these:

- "If they spelled out honestly what they're doing and why, I'd be willing to entertain [...]"

- "If I'd be willing to entertain [..] then they will honestly spell what they're doing and why".

The second of which doesn't make sense to me, unless I'm missing something? He should have used "only if" rather than "iff" here.

deepbreath··on The Problem of Free Speech in an Age of Disinformation
> I don't even know how people can say this stuff with a straight face.

It's not too difficult to do so, when there are examples of courts banning satirical poems of a foreign leader from being uttered: https://www.bbc.co.uk/news/world-europe-38934027

Would something like this ever happen in the US? Could you provide an example?

deepbreath··on Mozilla VPN
I thought I did? The condescending attitude is unnecessary. Happy to clarify my point if my initial comment was confusing:

Websites such as http://panopticlick.eff.org/ showcase how fingerprinting works. They tell you how many bits of information they can extract from various datapoints they get out of you when visiting their site, such as User-Agent.

Panopticlick does not use your IP address as a datapoint, but actual trackers most likely do. If not your IP directly, then a prefix thereof (such as your /24), to account for ISPs w/ dynamic IP allocation.

If you have a static IP, there's a lot of bits of entropy in it, i.e. it's great for fingerprinting. It's basically sufficient, by itself, to uniquely identify your home. The handful of devices in your home can then likely be distinguished by the User-Agent.

If you're part of your ISP's small dynamic IP pool (e.g. a /24), there's probably still a lot of entropy in there. How many people in your neighborhood are also on Linux and have the same set of fonts installed? Probably just you.

Your VPN's dynamic IP subnets, OTOH, can be a lot larger, and the members of the pool are not geographically close to one another, so there's probably a lot less fingerprinting entropy in your IP in that case.

deepbreath··on Mozilla VPN
Could you point what you believe to be the issues in the thread?
deepbreath··on Mozilla VPN
If nothing else, it significantly reduces the entropy of your IP when websites are fingerprinting you, especially if your ISP assigns you a static IP.

Even if you don't have a static IP, I suspect the entropy of your /24 (IPv4) is also a lot smaller when over VPN.

deepbreath··on UK government to pay up to 80% of wages for employees not working
There are plenty of homeless people in London.
deepbreath··on Dealing with Loneliness
Honestly, your comments are pretty much an r/wowthanksimcured meme.
deepbreath··on Ask HN: Burning Out
> (Hint: go ahead and start interviewing and have semi-serious job leads before this talk)

I think this bit of advice is at odds with OP's statement: "I don’t think I’d come across very well (or as sharp as I usually) in interviews at the moment without a break."

I was quite burned out at my previous job, as well, and decided (against most people's advice) to quit without an offer. I had similar "I'd rather give it a shot at being a bartender than write more code" thoughts. I was unemployed for a few months, but ultimately ended up with a few good offers. Leaving without a backup was definitely the right choice in my case.

deepbreath··on Creeping normality
Makes me think of the gradual increase of identity politics in mainstream media, politics and liberal circles, to the point it's driving me insane. Most people around me seem undisturbed by it though.
deepbreath··on The Linux kernel's inability to gracefully handle low memory pressure
Not thinkpad x1 carbon
deepbreath··on The Linux kernel's inability to gracefully handle low memory pressure
I committed the grave mistake of purchasing a laptop with only 8GB ram and I constantly run out of memory as a result. When it happens, I just repeatedly mash alt+sysrq+f until it kills off some chromium tabs and unfreezes my machine. It essentially behaves like one of those extensions that lets you unload tabs. If needed, you can get the tab back by just reloading the page. The machine slows down to a crawl at 96% usage, and freezes at 97% usage (according to my i3 bar).
deepbreath··on Terminating Service for 8Chan
https://www.telegraph.co.uk/news/2016/04/07/german-comedian-...
deepbreath··on Twitter urges users to change passwords after computer 'glitch'
The server would not be able to verify a changing hash without knowing the password
deepbreath··on Twitter urges users to change passwords after computer 'glitch'
It's unclear to me how your random salt would work. From my understanding, you're suggesting smth like:

register: send (username, user_salt, HMAC(user_salt, pwd))

login: send (username). retrieve user_salt. retrieve a server_salt generated randomly. send HMAC(server_salt, HMAC(user_salt, pwd))

But now your password is effectively just HMAC(user_salt, pwd), and the server has to store it in plaintext to be able to verify. Since plaintext passwords in the db are bad, this solution doesn't sound too attractive, unless you were suggesting something else.

deepbreath··on Twitter urges users to change passwords after computer 'glitch'
But the password is only known to the client?
deepbreath··on Twitter urges users to change passwords after computer 'glitch'
> meaning old hashes wouldn't be accepted and reducing hash "replay" possibilities

How would the server even verify the hash, then?

deepbreath··on De-Googling my phone
I think one of the things I'd really miss is Google Maps. The directions are really good, and the web app is unusably slow
deepbreath··on A coworker stole my spicy food, got sick, and is blaming me (2016)
The last two employees would eat eachother's lunch.

The issue is that the last employee has to have the moral integrity to fire himself.

deepbreath··on Europe’s New Privacy Rules Favor Google and Facebook
So then all he needed to do is write his name in addition to his IP address in the comment?
deepbreath··on After Facebook scrutiny, is Google next?
It's happened before, with Microsoft, too. They've transitioned from an OS where you pay with cash (win7), to a spyware OS where you pay with cash and your data (win10).
deepbreath··on Facebook to change user terms, limiting effect of EU privacy law
> People living in the EU absolutely want control of the gathering of their PII.

I know everyone here wishes this to be true, but what data are you basing this claim on?

deepbreath··on Facebook to change user terms, limiting effect of EU privacy law
> Anonymous comments

Wordpress asks for your name and e-mail to post a comment, doesn't it?

I guess the tuple (ip,name,email,comment_text) is PII?

deepbreath··on U.S. Launches Attacks on Syria
Is there reason to believe the strikes will result in thousands of innocent casualties?

They claim that they're only striking "chemical weapon research facilities". Looks like it's 4am there, so I guess not a lot of people in research facilities (plus they've been forewarned of the potential strikes)

deepbreath··on Google bug bounty for security exploit that influences search results
Yeah, but you might feel differently if instead of $200 it had $10m cash. And instead of accidentally coming across it on the ground, you spend months of your own time just walking the streets looking for such a wallet to return. And also the owner is one of the richest men in the world.
deepbreath··on ThinkPad X1 Carbon 2018 review: The only laptop in a professional’s paradise
Haven't heard of it before, but they look decent. I think the price difference with brand laptops becomes less impressive if you go for the higher specs and also want it shipped internationally (20% UK VAT).

The base weight for their portable 14.1" one is 1.6kg, but switching from i3 to i7, adding more RAM and choosing a bigger SSD would probably bring it closer to 2kg (compared to ~1.2kg on the x1).

I think the x1 does things like soldering the RAM to the motherboard, which makes upgrading hard, but also makes it really thin (1.5cm compared to 2.2cm for the System76 one).

Since the number of possible configurations on a build your own is quite high, I imagine it's more likely that you'll run into issues on getting everything to work on Linux.

deepbreath··on ThinkPad X1 Carbon 2018 review: The only laptop in a professional’s paradise
+1. Also using Debian on a X1 Carbon 5th gen (2017). Everything except the fingerprint reader (which I don't much care for) works perfectly.
Page 1 of 2Next →