HNHacker News
TopNewBestAskShowJobs

dobin

295 karma · joined December 5, 2016

submissionscomments
dobin··on Ideas on modernizing the open-source desktop
Microsoft and Apple as leader dropped the ball. Microsoft's several dozen Windows-related teams dont care about UX (maybe UI). Apple is busy making money and mobile.

It really is currently the time and chance for Linux to finally innovate again.

* Alternatives to tree filesystem UNIX introduced (see WinFS, or how Android/iphone manage it)

* Alterantives to WIMP as discussed, specially for large monitors (37" - like 57")

* Every App should provide a REST API to access its functionality remotely (for AI and data exchange. Think OLE/COM in Windows, but good)

* PLAN9 anyone?

dobin··on Running MicroVMs in Proxmox VE, the Easy Way
Wow thats pretty cool. Even with plan9 images!

I would love to use this in production, but dont know how much it can break things. Proxmox should just implement this in mainline.

dobin··on The Future of SCIP
Or this SCIP https://www.scip.ch/en/
dobin··on Claude Code is suddenly everywhere inside Microsoft
Like Microsoft Defender, which is now Defender Antivirus, or Defender for Endpoint if you have a real license. You will also get Defender for Identity, and maybe Defender for Office 365, which is probably not ASR. And Defender for Cloud, not to be confused with Defender for Cloud Apps.
dobin··on Microsoft please get your tab to autocomplete shit together
Nobody at Microsoft has ever used this with WSL, and doing a "cd /", and getting autocomplete for "$RecycleBin" and other windows paths? It completely breaks bash autocomplete, and every single suggestion is completely wrong, in every single command i type.

I, and probably most uses, just hoped this going away as soon as possible again.

dobin··on Printing Petscii Faster
I also having a side project optimizing draw calls to french Minitel terminal. Instead of letting the generator create their own draw calls, just let them print in a buffer/array.

Drawing the array means finding out what changed, and then create optimized draw sequences: Like using delete-till-end-of-line, vertical cursor moves, or repeat-character-x. Very noticable on 1200/4800 baud.

dobin··on How the “Kim” dump exposed North Korea's credential theft playbook
No tolerance for the intolerant.
dobin··on Show HN: Nash, I made a standalone note with single HTML file
I am also creating a Log viewer in a single HTML file (like Splunk, but a bit smaller). Pure JavaScript with no dependencies makes it runnable and integratable everywhere, which is nice.

https://github.com/dobin/SemiDataSieve

dobin··on Anyone can push updates to the doge.gov website
Its not just this website. Since DOGE, China probably canceled all vacation days for their hackers, as its a free for all. Firing of most so many people including security departments and most likely the (good) femboy furry hackers.

Is the newly created user with name "bigballs" who downloads whole government databases a foreign TA or just DOGE? Who knows. Who cares, certainly not the Government.

The data and access gained currently by China, Russia, NK and SA will continue to be useful until and way after the next war.

dobin··on Show HN: A Better Log Service
Pretty unrelated, but i like how it displays large amount of potentially diverse JSON events. Would need some better filtering and sorting, hiding of keys etc. Products which do this well are Elastic and Splunk, but are too heavy for my taste.
dobin··on Nvidia and its partners built a system to bypass U.S. export restrictions
Its not ideological, its to break out of the physical constraints setup by the US, to gain access to the pacific, and to the rest of asia. Simple geopolitics, just check a map.
dobin··on How Discord stores trillions of messages (2023)
So the TL;DR is: Cassandra and ScyllaDB have bad performance when reading. So they put a cache in front.
dobin··on Total War: Rome II and Creative Assembly – My Statement Ten Years On
> This is an approach that is sometimes taken when planning game projects, that you design your production plan so that as many parts of the game as possible are made in parallel, and then it all gets put together near the end of the development timeline, hopefully with enough time to fix bugs, balance gameplay, and add polish.

I feel like all AAA games are developed this way: Not playable till very late. Thats why they generally suck.

While a normal board meeting style development, i feel completely bamboozled by this approach. Indie games in contrast usually start with an MVP, a Minimum Viable Product, to test the basic concept. Then make the basic game loop fun. Then do the rest of the game like maps, sound, graphics, to support the central idea.

AAA do all the graphics and maps and sound and AI first, somehow merge it together and just hope that it will be a "good" game, that it will be fun. Even if there is internal QA or playtesting, feedback gets consequently ignored.

And people still preorder.

dobin··on More and more German trains are not allowed to enter Switzerland
Maybe you are not aware, but swiss trains dont go back to sleep after they arrive at a destination. They stop for 3-5 minutes, and then continue to their next destination. All day long, from morning till evening. Geneve to St. Gallen with like a dozen stops is pretty long way. Especially when you drive it 6 times a day.

Also generally the length of the tracks dont magically change. It is possible to create a timetable: which train should be where when, and then stick to it.

Note that before the DB, SBB were anoyed with some models of french or italien trains, which broke down regularly, putting too much pressure on the integrated timetable.

dobin··on The accidental tyranny of user interfaces
This, and the other examples, reek of lacking knowledge by the users.

Tall building are expensive. The taller, the more available floor space to rent. The taller, the more elevators you need. More elevators mean less floor space. People need to move between floors.

Buttons outside means that an algorithm can dispatch elevators most efficiently, combining people who want to go to the same floors, or follow up floors. So the throughput of people thru the building is maximized.

Its tyranny of capitalism. Or the tyranny of efficiency.

dobin··on The scarcity of the long term
Many cathedrals took hundreds of years to build. The following around 500 years: Cologne Cathedral, St. Vitus Cathedral and Milan Cathedral. Sagrada Familia was started in 1882, and Gaudi is dead for 98 years. If the emperor demands, it will be built.
dobin··on The KGB, the Computer and Me – The Cuckoo's Egg Story (1990) [video]
I am currently reading "CYBERPUNK: Outlaws and Hackers on the Computer Frontier" and can recommend it if interested in pre/early computer hacking (Phreaking, BBS, VAX/Digital). First third is about Mitnick and friends, second about Pengu and CCC friends.
dobin··on revng translates (i386, x86-64, MIPS, ARM, AArch64, s390x) binaries to LLVM IR
I once had the idea to do malware-similarity analysis. The X86 should first be lifted into a IL, so it gets "normalized" (e.g. register independant). The problem with all lifters is though that even a trivial "add rax, 1" generated a lot of IL code (probably 50-100 lines in LLVM IL), as the lifter had to implement all side effects of the X86 instructions in a fake memory space (i used remill if i remember correctly).

Does this lifter have a similar implementation, or will a "add rax, 1" be lifted to something like "register1 += 1"?

dobin··on Ask HN: What to do with text from old, unarchived, online forums?
Related, I have a lot of IRC logs form 1997-2004. Is there somehow an IRC archive project?
dobin··on HTTP/3 adoption is growing rapidly
Full inspection of user traffic is required to implement:

* Data leakage policy (DLP; insider threat, data exfiltration)

* Malware scanning

* Domain blocking (Gambling, Malware)

* Other detection mechanisms (C2)

* Logging and auditing for forensic investigations

* Hunting generally

I dont see how this breaks security, and of course you also didnt elaborate on why it should be. Assumed TLS MitM is implemented reasonably correctly.

Dont worry tho, zero trust will expose the company laptops again to all the malicious shit out there.

dobin··on μMon: Stupid simple monitoring (2022)
I was also overwhelmed by Grafana and co. In the time required to install it, i coded a simple monitoring alternative DMSR "Does My Shit Run" in python. Each agent has plugins which basically just sends a data structure to the monitoring server, which will display it as yaml. No persistence, history, graphs or similar. uMon looks like a behemoth in comparison.

Github: https://github.com/dobin/dmsr

Live: https://mon.yookiterm.ch

dobin··on Polish railway system hacked, trains forced to stop by attackers
As the gruq discussed in his keynote at HITB-HKT a few days ago, one can make the argument that the "train system" was hacked: Simple mechanisms were used to bring the whole system down.
dobin··on Short session expiration does not help security
"Thank got we set the session timeout to 5 minutes, or we would have been compromised" - no one ever.

I am in the 10-hour session timeout camp (or at least 4h, so you only have to authenticate twice a day). Session timeout checks are same sort of checkbox tests auditors (and pentesters) like, like password policy where you have to change it every 90 days. And about as effective.

What's missing in the article is the difference between soft- and hard session timeout (Soft: Reset upon user activity. Hard: session gets killed after X hours regardless of user activity).

dobin··on We need scientific dissidents
I am perplexed too. Is the word "science" being redefined in the US? Why does it appear that most people discussing here are so... helpless? Needing someone to tell them the truth? Did no one in here ever do any science at all?
dobin··on nic.funet.fi: Serving freely distributable files with FTP since 1990
The only thing i wanted to know is on what a machine it runs.

> It runs on a Linux server with dual 20 core processors, 786GB of memory and 80+TB of NetApp NFS storage.

And they deliver.

dobin··on Strlcpy and strlcat added to glibc 2.38
Imho its pretty simple: Strings in C are 0-terminated char arrays. If the char array is not 0-terminated, its not a string.

strncpy() can make a string into a non-string (depending on size), which is clearly bad.

dobin··on 32“ E Ink screen that displays daily newspapers on your wall (2021)
Cool! And pretty good quality of the video stream. But for a big tv as a real window, needs to be higher resolution
dobin··on 32“ E Ink screen that displays daily newspapers on your wall (2021)
Looks nice, but it's still just more news for the news addicted.

Silly idea dump: How about: A 4k TV in form of a window, which displays a live stream of a 4k camera of various places in nature. Lets say, in the middle of the forest, or a beach in italy. To have a window into another place, for some calm and mindfulness.

dobin··on Open source licenses need to leave the 1980s and evolve to deal with AI
I think open source licenses didnt even arrive in the 2000 to deal with the web.

The original intend was to make the source code available, done by distributing the compiled program. With SAAS companies (FAANG...) can just use open source on the servers, never distribute their program, only the output. Therefore not requiring making their changes available to the public.

dobin··on China state-sponsored cyber actor living off the land to evade detection [pdf]
Every SOC should have simple usecases for these basic lolbins. Such an attack usually lights up the SIEM/SOAR like an xmas tree.
Page 1 of 3Next →