HNHacker News
TopNewBestAskShowJobs

dgl

1,262 karma · joined May 24, 2007

https://dgl.cx
submissionscomments
dgl··on A Console-Friendly Pastebin with binary support
I made a similar thing: https://waste.st/waste.1

If you run curl waste.st you also get the “manpage”

The goal was to make it do uploads without a ton of frameworks. The front page is around one request under 20K. It also has a special emoji url: https://[waste bin emoji].st that HN doesn’t support.

dgl··on Speeding up Electron apps by using V8 snapshots in the main process
What's old is new again. Emacs has long done snapshots a bit like this, albeit in a hacky way[1][2]

[1]: https://lwn.net/Articles/673724/ (2016)

[2]: https://lwn.net/Articles/707615/ (2016) and discussion here: https://news.ycombinator.com/item?id=13073566

dgl··on Ircpipe – Netcat for IRC
I wrote something similar that uses Redis pubsub, so you can run the script somewhere to connect and then write simple clients just using Redis: https://github.com/dgl/redis-irc-bot

The neat thing about this is you can then extend it to other protocols. I have a (private) implementation using Apple's Shortcuts so I can also use the same "bots" with Apple Messages.

dgl··on Do low-level optimizations matter? Faster quicksort with cmov (2020)
The most important bit of this is in the conclusion:

  Before we conclude anything, we should remind ourselves of its limitations. The tests run were on completely random data. Truly random data seldom occurs in real life.
Linus famously ranted about CMOV in https://yarchive.net/comp/linux/cmov.html (2007, so potentially more modern architectures are better at some of this) and he says:

  if you KNOW the branch is totally unpredictable, cmov is often good for
  performance. But a compiler almost never knows that.
As usual with optimizations like this you have to benchmark and even then if your sample isn't representative it might not mean much.
dgl··on SREBench Competition
Maybe the AI can work it out?

More seriously usually issues where the observed behaviour is "the system is slow" are harder to root cause than complete outages. It depends partly how good your capacity planning is obviously, but maybe an AI could help with that too.

dgl··on SREBench Competition
Not sure whether there's lots of people trying out commands right now (is it backed by a real k8s cluster?), but some commands are taking over 10 seconds to run. Not really a fair "benchmark" when the system's speed is variable.

I also only got "partially_correct" for some, not sure whether it wanted more detail or just didn't like how I phrased things. Neat though.

                      Success Rate        MTTR (Mean time to Resolution)
  YOU:                50.00 %              1.80 min
  PARITY AI SRE:      70 %                 2 min
At least I'm faster than an AI?
dgl··on Peerfetch – Peer-to-Peer HTTP over WebRTC
> There's something nice about being anonymous behind a communal v4 gateway.

IPv6 lets you do this -- nearly every client will use privacy addressing, so your (default) source address rotates daily. However you can still connect to the machine on its main (non-privacy protected) IPv6 address.

dgl··on The weird and wonderful world of DNS LOC records (2014)
While the example here is broken, http://find.me.uk still works:

  $ dig loc SW1A1AA.find.me.uk
  
  ; <<>> DiG 9.10.6 <<>> loc SW1A1AA.find.me.uk
  ;; global options: +cmd
  ;; Got answer:
  ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 63530
  ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
  
  ;; OPT PSEUDOSECTION:
  ; EDNS: version: 0, flags:; udp: 512
  ;; QUESTION SECTION:
  ;SW1A1AA.find.me.uk.  IN LOC
  
  ;; ANSWER SECTION:
  SW1A1AA.find.me.uk. 21600 IN LOC 51 30 3.637 N 0 8 29.624 W 0.00m 0.00m 0.00m 0.00m
dgl··on VDEv2: Virtual Distributed Ethernet
Mostly historical interest; User Mode Linux (UML) was one of the first more performant options for virtualisation of Linux.

This let you play with a network lab based on UML or other technologies without needing to set up a physical network.

This was before hardware virtualisation that we now take for granted. UML was actually the first technology that Linode used for virtualisation, then Xen came along and was a far better option.

dgl··on MIME, RSS, and Existential Torment
I wonder what compression gains, are you serving the gziped version directly based on Accept-Encoding headers to avoid a decompression and compression? If not it would be possible to just use Store[1] to use the zip as a container format but not a compression format.

[1]: https://pkg.go.dev/archive/zip#Store

dgl··on Waste.st a.k.a. .st – A tiny waste^W pastebin
This is also available at https://[Wastebasket emoji].st but unfortunately hacker news seems to double encode the emoji.
dgl··on Fingerprinting VPNs with Custom Router Firmware [pdf]
I find the premise of the paper strange -- if the router is untrusted it can do many things, not just statistical traffic analysis at a high level (e.g. DNS/HTTP may give away apps downloading a list of VPN endpoints).

In 2024 IPv6 isn't mentioned, even in the future work section. While privacy addressing is often used, the address is usually rotated infrequently in terms of tracking what a device is doing for a few hours, privacy addressing aims to stop tracking over days. A router can easily see the real MAC address in the neighbour table, but right now a client device using a VPN over IPv6 is potentially trackable even beyond the local router, which seems more interesting than their local only threat model.

I wonder if any VPN clients force renewing the IPv6 privacy address, combined with careful firewall rules to avoid leaking the device's other address(es)? I suspect many clients/people just disable IPv6 out of paranoia though.

dgl··on Wikipedia over DNS (2008)
While the serving code still works the code to download Wikipedia dumps and summarise them has bitrotted.

The database is circa 2013, so you’re exploring a nearly 11 year old summary of Wikipedia!

dgl··on Reclaim your focus with ~12 lines of bash
This iTerm2 specific escape sequence[1] has the benefit it works over SSH.

You can however use "osascript" to generate the notification directly, see https://apple.stackexchange.com/questions/57412/how-can-i-tr...

[1]: https://iterm2.com/documentation-escape-codes.html

dgl··on WPA3 Enterprise 192-bit mode at home
Doing multiple PSK / PPSK is not compatible with WPA3 (at least as supported by most APs today*, as WPA3 requires management frame encryption), so you limit to WPA2 only, therefore you're better off just having multiple SSIDs with WPA3 support. (Also that way you can have a "secure" network which is WPA3 Personal only, much easier than using WPA Enterprise and gives a reasonable level of security for home use.)

*: In theory password identifiers (https://www.gabriel.urdhr.fr/2022/06/07/impact-of-the-differ...) could be used with WPA3-SAE, but I don't know how good the support is currently...

dgl··on Sudo without a setuid binary or SSH over a Unix socket
Ping and traceroute really shouldn’t need setuid on Linux anymore.

tracepath uses an option to set the TTL and works without setuid (although options like TCP tracerouting aren’t possible with that, but as mentioned that can use CAP_NET_RAW).

ping can also use a similar API to run fine unprivileged (fairly sure Fedora uses that already to have a non-setuid ping).

dgl··on Sudo without a setuid binary or SSH over a Unix socket
> While good luck doing that on a laptop that is only ever used to establish an SSH session.

[...]

> Set that up about ten months ago now (don't remember exactly). It's working flawlessly. Not a single issue.

So now your laptop hasn't had security updates for 10 months? Things like this are part of the reason I did the research in https://dgl.cx/2023/09/ansi-terminal-security.

It also funny that you've reinvented basically a serial console, but in a modern way, with a second factor. (You could actually just use a physical terminal with S/Key or something.)

> P.S: it's just a proof of concept... But I think that requiring to tap a Yubikey every single time you want to do something as root is something that should be envisaged/discussed more and it was great to read TFA doing it too.

Agreed, https://neilzone.co.uk/2022/11/using-a-yubikey-or-other-secu... is another potential option for this.

dgl··on Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
You're looking for DNS rebinding protection, many DNS servers support it. However there are some cases where things do use private IPs in DNS records outside of the local domain, one example is Plex (e.g. https://support.plex.tv/articles/206225077-how-to-use-secure... suggests turning off DNS rebinding protection) -- although in some cases you can allow particular domains which is a much better way than turning it off entirely.

(See also the sibling comment about microsoft.com being IPv6 only as a result of a particular implementation of DNS rebinding protection: https://news.ycombinator.com/item?id=38704159)

dgl··on Write your own terminal
Note very few terminals implement UTF-8 and C1 controls and in particular xterm (which is kind of the defacto standard) doesn't because of the issues you outline. My opinion is they should just die as a legacy thing. No programs depend on them.
dgl··on SQLite 3.44: Interactive release notes
Depending what NAS you’re using maybe it supports iSCSI? It can be a better option for things where you need to make sure only one system accesses the data at a time.
dgl··on Is the Intel N100 a better option than high-end ARM RK3588 boards at the moment?
The big one with the N100 is it either comes from random sellers on AliExpress, or you get something like the ASRock ITX motherboard with one on. Those motherboards alone cost the same price as an eBay system with an 6500t.

If the goal is to go with something familiar, which is why this thread was even considering the N100, then going with a system from a known supplier might be even better.

The power might not be such an issue -- while the 6500t is a 35w part, it idles quite low, it would really depend on the system it is in; I wonder how different the power draw at idle would be.

dgl··on Is the Intel N100 a better option than high-end ARM RK3588 boards at the moment?
If you’re wanting to save money though something with say an Intel i5-6500T (6th Generation Core) the ‘T’ meaning it’s a low power (throttled) part is worth considering. They are surprisingly close in performance to an N100: https://www.cpu-monkey.com/en/compare_cpu-intel_processor_n1... (although how much to trust those benchmarks I don’t know — it would be good to see benchmarks where all bug mitigations are definitely applied to the older CPU, edit: except neither are hyperthreaded so maybe spectre isn’t such an issue)…

Something like a HP EliteDesk 800 G2 Mini, can be had on eBay for around $80-100 (USD), with probably 8GB RAM and an SSD. So even less than a new thing with an N100 (although in some cases it’s close!)

It uses DDR4 (one of the first generations that did, so means if you want you can go up to 2x32GB SODIMMs). There’s a whole series of these things, servethehome has a “project tiny mini micro” covering many of them.

dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
Actually, I got it wrong, too many vulnerabilities in flight. They did fix it: https://github.com/openbsd/src/commit/375ccafb2eb77de6cf240e...
dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
It does. Try grep -i
dgl··on With Firefox on X11, any page can pastejack you anytime (middle button paste)
See my reply in the thread: https://www.openwall.com/lists/oss-security/2023/10/20/2 — not all terminals get this right.
dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
Cute, I found a similar issue in OpenBSD's tar as mentioned, I didn't share the exploit before but basically a long filename does it.

Something like: https://gist.github.com/dgl/355840320535bf8ef8b70f2e0722bf65

(I reported this one to OpenBSD but they didn't fix it. Much like Busybox, which has been known for years.)

dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
(Author here.)

If there's any takeaway from this, while the worst part is the terminal bugs; I'd like people to be aware that any tool dealing with text (command lines, potentially even websites) should consider sanitizing control characters for defense in depth.

I am amused that for example https://www.osnews.com/story/137552/31m-ansi-terminal-securi... has posted my article with the escape character in the title intact. This means that running:

  curl https://www.osnews.com/story/137552/31m-ansi-terminal-security-in-2023-and-finding-10-cves/
...will turn your screen red because of the embedded "". Obviously this is just harmless fun (would have been more fun to get iTerm2's "]1337;RequestAttention=fireworks", like my curl ip.wtf/moo does, but I couldn't really stick that in the title innocently), but an attacker might be able to find a way to social engineer someone into running "curl" or similar on what looks like a trustworthy site.

edit: Hacker News also doesn't sanitize escape characters, so this very comment will turn your screen red:

  curl 'https://news.ycombinator.com/item?id=37963815'
dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
Sixel isn't state of the art, see https://sw.kovidgoyal.net/kitty/graphics-protocol/
dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
Some terminals can do tricks like this, some terminal authors care about performance, e.g. https://codeberg.org/dnkl/foot/src/branch/master/doc/benchma...

In general you're better off using a terminal that performs better, because extra buffering would be annoying the other way around in the usual throughput/latency tradeoff (you'd press ^C and then it would continue to display what's in its buffer to you, rather than reacting quickly).

What mosh brings is decoupling the rendering across the network. A lot of the poor perceived performance over high-latency links happens because ssh puts your terminal into raw mode, so even if the line is being echoed back, that is going all the way to the remote system and back again.

It's actually possible to fix line editing in ssh, without using something like mosh, see for example https://github.com/hyc/OpenSSH-LINEMODE. It's a shame OpenSSH hasn't merged something like those (now quite old) patches.

dgl··on "<ESC>[31M"? ANSI Terminal security in 2023 and finding 10 CVEs
(Author here.)

I agree the only correct way C1 controls can work is encoded within UTF-8 data, else nothing works.

The context is escaping C0 control characters is simple, you look for a single byte and filter it as you need. C1 controls when not encoded as UTF-8 are also single byte characters and therefore easy to filter out. For multi-byte encodings, you need to correctly decode the encoding, then filter, this has synchronisation problems and is tricky[1] (particularly as a Unix byte stream doesn't tell you it's encoding, although you can assume if someone is trying to display it as text it is probably UTF-8 these days).

I should probably expand on that recommendation more, there's a lot in the paper, but the crux of the issue is C1 controls are a legacy thing and serve no useful purpose anymore and as I've shown there are enough issues just dealing with C0 controls.

If C1 controls are encoded as UTF-8 as is the only way they can work on a modern system, then they take up as many bytes as C0 controls (e.g. CSI is "\e[" or U+009B, which encoded as UTF-8 is 0xC2 0x9B) so they don't even save bytes on the wire.

[1]: see https://www.openwall.com/lists/oss-security/2015/09/20/1 and some replies to that.

← PreviousPage 3 of 7Next →