HNHacker News
TopNewBestAskShowJobs

dolfje

146 karma · joined May 20, 2015

submissionscomments
dolfje··on DigitalOcean: New $4 Droplet and updated pricing
I tried to create an account and got the following error message: Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ? + # - . , ; : ~ * @ [ ] { } _ ° § What year is it, that we cannot use &?
dolfje··on 300 Drones Formed a QR Code That Rick Rolled Dallas on April Fools' Day
I'm founder of https://and-lights.eu and it's not that simple of just purchasing. There are mainly three aspects.

First you have the hardware itself, your drones. Best is to create them yourself. As there aren't many of the shelf products and they are mostly coming from China where safety concerns aren't that high valued as US and EU. For example letting them do a return to home, is a nightmare. As they will just fly across your other drones and hit other while doing. We have also incorporated lots of redundancy, so that we have different ways to communicate with the drone. And also a manual override so that you can steer the drone personally into safety.

Next you have the software. That will steer the drones. You have two possibilities for that. Either pre-program all drones with a gps path and send a start signal. Or do it our way and realtime manage the drones (ofcourse with backup path if communcation fails). On the lower level of the software we have our red box that does collision avoidance. So even if you ask the drones to go through each other, that box will stop them before they hit eachother. On top of that we have the real route planning that should produce non-hitting paths. Real-time planning is harder to implement. But it makes sure that you can replace drones if pre-flight checks doesn't let the drone fly. And also makes sure you can adapt the show mid-air. For example to sync up with a live performance.

And then the 'boring' part. Getting a license. We have already created more than 800 pages of certification and safety procedures. Just to get a license. That is because in a lot of countries drones are certified as airplanes. So procedures are also like airplanes. Flying a normal drone is possible, but for drone shows you have to get 3 exceptions certified. Namely flying at night, flying in formation and automatic flying. And by creating your own drone, you also need to homologate and certify your drone.

Hope I gave you a little hint of what is needed ;)

dolfje··on SpaceX recovery attempt not successful: water landing instead of land
Although it didn't land as they wanted, primary mission is still success. Also the booster is in the sea and still transmitting and will be recovered, but only be used for internal spaceX missions. Unfortunately the live spaceX webcast tuned away from the failing booster. But Elon has given his word it was wrong to tune away.

The issue is apparently with the hydraulics system of the grid fins that had a problem. It was nice to see that the gimballing engines recovered the spin before the sea landing.

dolfje··on Now Live: Webinar about GDPR from EITDigital
As the deadline of GDPR is near, you can recheck your knowledge. It is required to enter you email address. But we will only use it once to provide you about one upcoming course about GDPR. The webinar itself is hosted on Zoom.
dolfje··on Elon Musk promises rain-sensing wipers, Tesla pickup truck
?
dolfje··on Show HN: Extract btc information for trustless recovery
pm? nikos@uwsoftware.be
dolfje··on Show HN: Extract btc information for trustless recovery
This is actually a follow up on https://news.ycombinator.com/item?id=15852100. We are creating a service to help everyone who has lost their bitcoin password. Till now our clients had to go through the terminal for extracting information (Thanks pywallet for intermediate solution). But we created a GUI script to aid the extraction. This is also done trustless. So we never have access to the funds. I'm asking hackernews to help and confirm the code (Technically it is working, also the trustless part. But that should be confirmed! As my reputation is zero ATM).
dolfje··on Show HN: Lost BTC wallet password? We might be able to help
We cannot walk away with the mony, because we never have access to the full funds. We let the users send a partial wallet only containing the bits needed to check if we have bruteforced the wallet. But without the actual private keys. So therefor we cannot scam our clients. There is a real registered company behind it. USW bvba. We exists already for 5 year HQ Brussels, mostly in creating software solutions. As we did have the knowledge about Bitcoins, we wanted to help lessen the sad stories of Bitcoins (e.g. we have lost our Bitcoins)
dolfje··on Show HN: Lost BTC wallet password? We might be able to help
Definitely helpfull as other tools. But this recovers the secret key only if you didn't add a password to your wallet. Also we provide a service, because not everybody knows the inner workings of Bitcoin. Luckily we have a lot of these tools for tech savvy people. We also pledge to send Bitcoins to the third party tools that we use while recovering!
dolfje··on Show HN: Lost BTC wallet password? We might be able to help
That part is based on trust. Most clients are happy enough that we have recovered their funds and are also doing their end of the deal. If there are to much clients not doing their end, then we will have to scratch the partial wallet deal. But at the moment we didn't have any client rejecting the fee.
dolfje··on Show HN: Lost BTC wallet password? We might be able to help
In you wallet, not all addresses have budget. But they are still encrypted. So we can check the decryption phase with parts of the wallet that have no coins.
dolfje··on Show HN: Lost BTC wallet password? We might be able to help
You are correct. That is also something I tell the clients before they are providing the passwords. That they should make sure that all their passwords are changed. Even so, never reuse your password for Bitcoins as they are too valuable.
dolfje··on Show HN: Lost BTC wallet password? We might be able to help
Good point, but you never know. Also first pitching to tech savvy people. As we try to reduce the scammy part (not a lot of business really trying to recover the coins for the customer). Thus any advice is welcome ;)
dolfje··on Warning: this website will log you out of the most visited website
Disclaimer, this isn't mine. But I found it while searching and I hadn't thought about it. But most sites don't check if the user actually initiated a logout.
dolfje··on Show HN: BashScanner – Script to list Outdated Software on your server + cronjob
And next to coffee, it now also returns composer modules (top 100 used and still expanding)
dolfje··on Ask HN: How to enter a new market with an SaaS without VC?
Maybe interesting for us, why don't you want to use VC funding / investors? Is it the equity part?
dolfje··on Ask HN: What are the best non-American Linux media/blogs?
http://arstechnica.co.uk/
dolfje··on Oracle’s license agreement as it pertains to reverse engineering
Disclaimer: cross-posted from the original HN Post, but still relevant.

Apart from the legal stuff and a lot off egocentric 'we can do it better', she has one point. There are many companies giving a lot of money for security, manually scrubbing all exploits that come out, create their own patches. While some lack the basic security guidelines. I think this money can be better spend upstream, to create tools so they can test patches for exploits better and create a faster security update release pipeline, so that all downstream and customers can rely on the security releases and that it can be released quicker to everyone. (Controversial: Maybe even adding automatic security updates to the package itself, like wordpress did, so that customer cannot be on a release with exploits)

Though saying to your client that they cannot reverse engineer to look for security problems, is totally not done! What is next? "Exploits will not be fixed, because the users has signed an agreement that they will not hack?"

dolfje··on “Stop reverse engineering our code”
Apart from the legal stuff and a lot off egocentric 'we can do it better', she has one point. There are many companies giving a lot of money for security, manually scrubbing all exploits that come out, create their own patches. While some lack the basic security guidelines. I think this money can be better spend upstream, to create tools so they can test patches for exploits better and create a faster security update release pipeline, so that all downstream and customers can rely on the security releases and that it can be released quicker to everyone. (Controversial: Maybe even adding automatic security updates to the package itself, like wordpress did, so that customer cannot be on a release with exploits)

Though saying to your client that they cannot reverse engineer to look for security problems, is totally not done! What is next? "Exploits will not be fixed, because the users has signed an agreement that they will not hack?"

dolfje··on Show HN: BIND9 Denial of Service Exploit Checker
Yes, that is a problem. 'Hardened' configurations cannot be checked. But there are a lot of non-hardened configuration. Actually there are more that returns there version than not.
dolfje··on A deep look at BIND9 CVE-2015-5477
You can check your server easily without doing the real attack. Because that would result into a denial of service. You just check the version of BIND in the linux terminal: dig @google.com version.bind chaos txt

If that is one of the following (or higher), you are save: 9.10.2-P3, 9.9.7-P2, 9.9.5-3ubuntu0.4, 9.8.1.P1-4ubuntu0.12, 9.9.5-4.3ubuntu0.3, 9.9.5-9ubuntu0.2, 9.9.4-18.el7_1.3, 9.8.2-0.37.rc1.el6_7.2, 9.3.6-25.P1.el5_11.3, 9.7.0-21.P2.el5_11.2, 9.8.4.P1-6+nmu2+deb7u2~bpo60+1, 9.7.3-1~squeeze16, 9.8.4.P1-6+nmu2+deb7u6, 9.9.5-9+deb8u2, 9.9.5-11

Ofcourse everything is easier if automated, so that is exactly what following page does: https://scan.patrolserver.com/bind/CVE-2015-5477

dolfje··on [dead]
Stats of 45min, still 17% are vulnerable for the BIND vulnerability, 5 days after the disclosure.
dolfje··on 32% outdated of the Alexa top 42.500 websites
Small stat: At the moment we are scanning at an average rate of 2000 sites / hour. So average of 0.03s for each site. Making the stats page has definitely helped us to test/increase our performance.
dolfje··on 32% outdated of the Alexa top 42.500 websites
Be aware that this statistics is only about the top 40.000, if you extrapolate the graph, you see 50% outdated software for the top 10 million.

As this takes a lot of resources, do you find it usefull? Or do you think the 40.000 is already representative?

dolfje··on Ask HN: Who is hiring? (August 2015)
PatrolServer - Software Engineer - http://patrolserver.com

Responsibilities: Creating advanced fingerprinting tools to check server software version and exploits

If you are interested please mail info@patrolserver.com

dolfje··on Pro-security? Stay away from these hosters
Glad to see you fixed the issues, I absolutely love it that you acted to fast. You have been removed from the list.
dolfje··on Pro-security? Stay away from these hosters
By using multiple versions of multiple software, you can determine the false positives. There are little servers that deliberately fuzz external in a consistent way of all software found. Mostly they only do PHP or Apache, but forget OpenSSH. If there is a hoster doing it in consistent way and ended on our shame list. Please stand up, you deserve a full new blog post about how it should be done.
dolfje··on Pro-security? Stay away from these hosters
It is definitely not the only measure. There are many more aspects of security. But a hacker only needs to find one gap. So the security is not the average of all aspects, but the minimum. So finding hosters that fail one aspect (outdated software) are already problematic.

That is the reason why security is hard ;)

dolfje··on Pro-security? Stay away from these hosters
It is a strong indication, because we are talking about non-packaged versions. PHP 5.3 is still maintained in Ubuntu, so those hosters aren't on the blame list. Only if PHP 5.3 / 5.2 / 5.1 is used without package manager.
dolfje··on Pro-security? Stay away from these hosters
Because PHP au contrary to Apache returns the full packaged version (so PHP packaged version are easier to check out). Also having e.g. OpenSSH ubuntu version strongly suggest you are using PHP ubuntu version. In that way we could cross out some of the packaged versions.
Page 1 of 2Next →