HNHacker News
TopNewBestAskShowJobs

dobin

295 karma · joined December 5, 2016

submissionscomments
dobin··on Charm – Tools to make the command line glamorous
I wrote a side scrolling beat-em up in the terminal ("telnet exploit.courses"). Charm seems to have identified all the pain points, the Charm backend with KV store and user authentication would be something i'd need to implement multiplayer functionality. Gonna play with this stuff for sure.

Love the website!

dobin··on Swiss army restricts use of messenger apps for military purposes
Only Threema is allowed now.
dobin··on Swiss army restricts use of messenger apps for military purposes
I dont think the army permits transferring confidential information via privately owned phones, or via foreign companies, before. And neither does it now.

Note that we have mandatory military service. Every year thousands of new recruits will perform military service for around half a year. After that, they have to attend three weeks of military service yearly (refresher). This always requires organization; when to arrive in the barracks, equipment to bring, request for leave, corona updates etc. Also coordination at which McDonalds to stop at the freeway.

Same for professional army members. They need to communicate somehow, without using super encrypted email or radios (schtichwort "fill guns", super). Military IT is also as you expect (old and cumbersome).

dobin··on Facebook crisis grows as new whistleblower and leaked documents emerge
Everyone wants to have regulations "where its necessary". This boils down to "rules for thee but not for me". If you work in construction, you want more building site safety. If you are the own who uses his money to construct one building after another, you want to have it cheaper, so less safety. Democracy is the process of finding a nice middle ground.

Nowadays, it seems that common people are mostly convinced by the rich to vote against their own interest.

dobin··on Facebook crisis grows as new whistleblower and leaked documents emerge
Its basically in every country where people vote against their best interest because rich people told them to do so, but it isnt as celebrated as much. I agree that if the government misuses the population in every way possible, that you start to lose trust in it. But how can it be that people think the solution to this is less democracy, more power to companies? It looks like some weird form of masochism.

Every law creates and restricts freedom. Food safety laws restricts the freedom of restaurants: need to clean kitchen, remove all the cockroaches etc., but gives the people the freedom to eat food everywhere without getting sick.

More regulations on FB restricts its freedom to misuse the attention of the population to make more money, but also gives citizens the freedom to consume less fake news.

dobin··on Facebook crisis grows as new whistleblower and leaked documents emerge
Is this a specifically american thing, that regulations are bad? Thats exactly what FB would say. Next you tell me, that "trickle up economics" are bad, and we should try "trickle down"
dobin··on Google, Mozilla Close to Finalizing Sanitizer API for Chrome and Firefox Browse
It doesnt matter where the data is coming from, it matters what it is able to do. As always with security, if the server attempts to protect the client app by emulating its behaviour, it will go wrong (as the server is never able to emulate the client perfectly). This is a problem in most of the magic black security boxes (WAF, IPS, DLP etc.).

The browser knows if a certain piece of data will perform execution or not, as it is the software implementing the functionality. It is the correct app to ask, as it is the one being exploited.

dobin··on Amazon puts its own “brands” first above better-rated products
The problem is that Amazon said that they dont do it (Copy successful products and then manipulate search results so they appear before the others).

The available documents show that its an official Amazon strategy.

dobin··on How to Survive the End of the Universe (2014)
When the stars go out, we can live as virtualized entities in a big computer built around a black hole for a few quadrillion years, by using the hawking radiation as energy source. We have like 200 billion years to collect as much matter in our local supercluster as possible. After the black holes evaporated, maybe can use proton decay.

According to Isaac Arthur (on youtube. I highly recommend it).

dobin··on A Chemical Hunger: Mysteries
If people before 1970 eaten approximately their TDEE (2000 calories?), than a 20% increase in calories eaten means something like 400 calories over TDEE per day - every day, all your life. Of course people get fat like this.
dobin··on A Chemical Hunger: Mysteries
If someone can't eat less calories than he expends, thats usually called addiction (boredom, food as reward etc.), and should be treated accordingly
dobin··on A Chemical Hunger: Mysteries
I've heard something of overuse of antibiotics destroying the gut microbes
dobin··on No one has been murdered in Norway so far this year
There are few legal restrictions to buy a gun here. Fill out a form, send it to the police, they mail you the license, go buy some AK's.

Petty crime yes, mostly bicycle theft, and some mugging

dobin··on No one has been murdered in Norway so far this year
I think there are different reasons:

- Mandatory military service makes people know how to use guns

- People have mandatory health insurance and social security, means there is no need to shoot people for money

- Less racist police, means minorities dont solve problems by themselves with violence

- high minimum wage, so nobody has to starve

- Gun owners do not use guns to defend against burglars, so burglars also dont have to use guns

- Proper handling of drug addiction (including addicts)

- better mental health because of mandatory holidays, parental leaves, and a lot of chocolate

- Prostitution is legal, so no pimping

dobin··on LXD – next generation system container manager release 4.3
I made a GUI too, but dont actively develop it anymore. https://github.com/dobin/lxd-webgui
dobin··on LXD – next generation system container manager release 4.3
LXD is awesome. I use it via REST for exploit.courses to dynamically create containers for users.
dobin··on Docker Bug Allows Root Access to Host Filesystem
In my opinion, VM's are less secure than containers.

VM's provide a large attack surface, while one CAN restrict containers sufficiently. See contained.af. Doesnt mean Docker does this though.

dobin··on A proposal to improve Twitter and perhaps the world
I would like the opposite - hide all uninformative and boring nonsense some people tweet (but not often enough to unfollow), and just get the retweets. These usually have high information and are of relevance (i'm only using twitter for itsec news).
dobin··on Show HN: Momentum – create lists to structure your thoughts and projects
i found https://rockiger.com/en/akiee/, but not web based and seems to be dead.

I'm also interested in self hosted apps.

dobin··on Show HN: Momentum – create lists to structure your thoughts and projects
TBH, i'm also confused, but i didnt invest more than 2 minutes looking at it. The menu changes the location to all sides which is a bit confusing. I also added some drop's, gave it a context, now they are gone?

It seems that the application is trying to help a lot, with video and the help pages etc. Which is good, but also a sign that its not very intuitive.

dobin··on uBlock Origin Maintainer on Chrome vs. Firefox WebExtensions
The claim is correct. The security of IE9+, Edge and Chrome is far superior than Firefox. As Geohot said, writing an exploit for Firefox is similar to a harder CTF challenge (done in an day or two). While IE or Chrome Exploits cost a lot. I can back it up with references, but https://www.zerodium.com/program.html shows a pretty clear picture (Scroll down to Payout Ranges). It will take FF like 3-5 years until they have a sandbox as good as the other Browsers, sadly.
dobin··on OpenBSD Will Get Unique Kernels on Each Reboot
KASLR just requires ONE leaked pointer to calculate base offset of the kernel, and from there is the standard ROPchain technique. The kernel is still one big identical blog, just mapped at a different starting address.

If i understand KARL correctly, they reorder the internal code (and data?) in the kernel. Therefore a single pointer-leak does not expose all the ROP gadgets anymore. More information leak is necessary, or a smaller amount of gadgets. Therefore imho this is a much better protection than KASLR.

dobin··on SSH Check – public SSH server testing tool
Is this based on ssh-audit? https://github.com/arthepsy/ssh-audit
dobin··on The blockchain paradox: Why DLTs may do little to transform the economy
Decentralized trustless databases can also be implemented with Merkle Trees (as it is done with certificate transparency). I dont understand why people choose blockchains instead.
dobin··on WebAssembly: Mozilla Won
I agree. I dont know where Mozilla is spending their money, but they are years behind in regards to security enhancements in comparison with Chrome, Edge, and IE11. Around IE7 nivea. Still waiting for 64 bit Firefox with Sandbox and per-tab-process and CFI.
dobin··on Granary.pro – Beyond Bookmarks and Read-It-Later
I wanted to try it, but it requires a chrome plugin to save websites. Removed my account instantly.
dobin··on Containers vs. Zones vs. Jails vs. VMs
Chroot does not provide security, just a restricted view on the file system. Container can provide pretty ok security, but fail with Kernel Exploits. VMs provide better security, but also fail with VM exploits (which there are quite regularly some).
dobin··on Azure Jupyter Notebooks
Pretty interesting as a tool to learn Python or other things. I'm intrigued.

I'm doing something similar with exploit development learning, but with a javascript based terminal and linux containers, and a markdown writeup (https://exploit.courses for anyone interested). But the close interaction of code and text in Jupyter is much more advanced, and useful :-)

← PreviousPage 3 of 3