HNHacker News
TopNewBestAskShowJobs

derpherpsson

80 karma · joined August 10, 2018

Human Being.
submissionscomments
derpherpsson··on Windows X86-64 System Call Table
A book... That cost money.

Compare that with the man pages of some decent BSD. Or even Linux..

But yes. I have contemplated buying one of those windows internals. I will probably buy that book just because of your comment. It's not that expensive.

derpherpsson··on Windows X86-64 System Call Table
I also ask myself this question. How can anyone use an OS where the creators deliberately hide some of the documentation?

I would love to read up on windows internals, but there are no real resources out there. A few books that at first glance appears to cover it, but then just deals with the application layer and up to point-and-click.

This is why I don't use windows anymore. I don't ever again want a job where I have to debug why old program P stopped working after an update. I prefer to be able to learn stuff.

derpherpsson··on OpenBGPD: The OpenBSD BGP internet routing daemon
It is a delight to have an OpenBSD machine as my central router in my home. OpenBSD is so easy to work with and also comes with that cozy feeling of security. I can rest assured that the devs preferred to drop functionality rather than build insecure half-crappy stuff. That is a positive thing!
derpherpsson··on Samba versus SMB: Adversarial interoperability is judo for network effects
Aaah.. SAMBA :D

I read the samba hacker guide and how they had reverse-engineered the protocols over the years. MS Windows is not even compatible with ITSELF ffs lol ;D

derpherpsson··on The CIA Spied on People Through Their Smart TVs, Leaked Documents Reveal (2017)
This does not go away.

That people treat this as news is for me an indication that people simply don't either read the news, or don't remember them.

I hope people maybe remembers now when they read it the 2nd time.. The US surveillance machine needs to stop.

derpherpsson··on Ask HN: Does anyone still use IRC?
I use it.

It's neat for finding those wonderful little crazy communities that are hiding out in the anonymizing crypto nets (Tor, I2P, LokiNet, ..)

It's the only place left where there are ONLY real terminal junkies and nerds. No normies. I can relax.

derpherpsson··on Ask HN: How to initiate or respond to small talk (not the programming language)?
Okay. By having done away with it I guess I really meant that they are not doing it pointlessly often, when it could just as well be quiet.

Such as at the coffee (fika) break. It might be okay to just be silent. All you are going to talk about is rather obvious in either case.

derpherpsson··on Ask HN: How to initiate or respond to small talk (not the programming language)?
Some northern Scandinavian people and especially the Finns do without it.

I tried having comfortable silences with my coworkers. Some like it, some just go insane. It kind of depends on the person - maybe some people never learn to appreciate the silence.

derpherpsson··on Ask HN: How to initiate or respond to small talk (not the programming language)?
This... Is not right. You can not extrapolate personality traits from answers to silly questions.

That said, I do hope I get to answer some of these questions soon.

derpherpsson··on Termshark – A terminal UI for tshark, inspired by Wireshark
The terminal is Eternal. It has not changed since the Dawn of Time.

It's not retrofitting. If you make it work for the terminal it will always work from now on.

It comes outside the reaches from the graphical designers. Nothing with a graphical design survives more than 10 years.

derpherpsson··on Guantánamo’s Darkest Secret
Somehow, you being surprised by this, actually makes me a bit uneasy.

How can you not know that stuff like this is happening?

derpherpsson··on Unveiling the first-ever image of a black hole [video]
Whenever this type of question comes up, how much science cost, think about the following:

It costs more to do a sciency Hollywood movie about than it costs to actually do the science. Sending an actual probe to the orbit of Mars is in general cheaper than making a sci-fi movie.

So...

derpherpsson··on Programming: Doing it more vs. doing it better
I spent my first 4 years after the university at a company with very little quality control. We had to talk the bosses into having code reviews. When we began having code reviews my older colleagues never complained about anything - everything went through.

That truly was quantity over quality. Oftentimes I had to wade through piece-of-shit code that really made my soul hurt. Really. Bad.

But in hindsight that was good. It's good to have spent 4 years ONLY writing code 8 hours straight 5 days a week.

But I never, ever, want to go back to anything like that.

derpherpsson··on Jerks on the Internet: what my first DDoS taught me
It's fun. Or maybe you are angry. Or maybe you just want to test to break it down. Or maybe you just want the programmers to feel sad, maybe because they were boring
derpherpsson··on We moved our servers to Iceland
The royal we.

Also makes it easier to hire people if you don't have to update any texts ;)

derpherpsson··on We moved our servers to Iceland
I really liked this :)

Thank you for existing.

derpherpsson··on Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
They have had several remote code execution vulnerabilities lately (summer 2018). While they were very quick to patch them they did not notify their customers in any way. There was nothing on their website that said anything about the urgency.

Instead of reusing functionality that exists in the router already (ssh?), the authentication for winbox is something they built themselves. It was in the winbox auth that the main security flaw was. It just looked really bad to me.

The winbox client also downloads and runs any DLL that is sent by the winbox server. The winbox client has a windows certificate so all it's code is trusted. So own the router and you get the admins workstation too.

It just feels like maybe they hired some random guy without much appreciation for security for doing winbox.

The SMB server also had a rce a while ago.

That said, I guess that if you disable winbox and stuff that should not face the internet, you are probably safe?

Too much for me though. I would not feel safe.

derpherpsson··on Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
LOL

I guess there is nothing good.. what is wrong with people :(

derpherpsson··on Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture.

My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy.

Ubiquity was number 2. I refrain from buying from them only because of their glossy UI.

Mikrotik was on that list. Until I saw how horrible their winbox protocol was. And their implementation of SMB.. I must assume there are still plenty of unknown RCEs there.

derpherpsson··on Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
Cisco is crumbling under its own weight.

This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents.

It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunch of well-paid but uninterested people seeking jobs at prestigious companies.

Culture matters. I want my socially maladapt terminal junkies back plz.

derpherpsson··on Ask HN: How are you getting through (and back from) burning out?
No choice. I had to.

Homelessness is not an option for me. I just dug myself out of the hole, even if I was out of energy.

I had a text file on my computer where I wrote down the steps I had to take. Then I followed this todo-file for maybe 6 years. It was organized into sections: Now, next phase, next phase after that, and so on. It got more sketchy the further it is into the future.

I have been following this TODO-list for 6 years now. I am now at a point where I can add whatever I want to it, almost. I kindof succeeded.

derpherpsson··on Ask HN: What kind of information do you look for before learning/using new tech?
How useful is this tech? Some tech is just pointless or part of someone's scammy business.

How Eternal is the knowledge? Math is Eternal in the true sense, while that new webpage framework will be around for maybe just 2-5 years, and is thus not worth learning. (Although I am sometimes happy that people sacrifice their lifes on stuff like that, I would never do it.)

Vendor lock-in? I steer clear from that.

Is it being maintained? (Some things are okay not being maintained though. It depends on the type of tech.)

Surveillance potential. I am somewhat paranoid in my own personal life.

When procuring network-attached tech I usually dig through exploit-db and the CVEs and try to make myself a picture of how their security is being handled. Small companies are difficult to judge from this because they have little recorded history. (So I didn't buy any mikrotik router because of their shenanigan attitude to security, for example.)

Do the creator of the tech try to keep my hands away from digging into the machinery? Like hiding that it is really just a Linux/bsd box underneath? I stay away from that, if possible. (It's not always possible, almost all tech runs on Linux nowadays.)

I can be bribed to ignore any of these things that I usually avoid. For example, I learned MS Windows and some of their tech because I got bribed.

derpherpsson··on Demystifying Radix Trees: How Radix trees made blocking IPs 5000 times faster
I am appalled that the understanding of basic complexity theory is missing in a company like this, and that people apparently think this is worth reading.

This SHOULD NOT be news.

Maybe you guys should revisit your school books.

No, this comment is not "too harsh" or elitistic.

derpherpsson··on Christopher Domas: Hardware Backdoors in X86 CPUs
This is absolutely insane! With all the recent bugs and features that looks like backdoors I have completely lost faith in x86.

We need simple open ISAs (like RISC-V) and a handfull of trusted organizations that inspect the manufacture processes to protect ourselves from this. A bit like how countries and organizations send people to inspect other countries democratic voting processes, or like how IAEA inspect nuclear stockpiles etc.

I call for:

+ Open source.

+ No creeping featurism.

+ Multiple inspection organizations that watch the process from source code to final chip product.

← PreviousPage 2 of 2