HNHacker News
TopNewBestAskShowJobs

ecma

246 karma · joined February 7, 2014

submissionscomments
ecma··on Re: What is acceptable for -ffast-math? (2001)
Could use (2001) in the title.

This is a pretty interesting email chain and a fairly good case study for those of us who aim for zealous adherence to standards and rules vs. providing a practical and useful output for users. I know I tend to go zealous by default and often have to remind myself that I'm not just writing software to satisfy my own academic ego.

ecma··on Show HN: Whosfiring
I use mbasic.facebook as my main was of interacting with Facebook. I acknowledge that my choice to disable JavaScript is unusual and will jump through some hoops because of that, but it's not excusable for a website to display /nothing/ pre-script like the OP does.
ecma··on Defending against Rowhammer in the Linux kernel
From the Wikipedia article on memory refresh [0] for DRAM describing distributed refresh techniques:

"For example, the current generation of chips (DDR SDRAM) has a refresh time of 64 ms and 8,192 rows, so the refresh cycle interval is 7.8 μs."

Sounds like your idea is already a thing! That's cool! Unfortunately it seems like the performance-cycle period tradeoff is difficult and Rowhammer is taking advantage of that.

Protecting subsets of memory is an interesting idea but what bits do you choose? What if I could Rowhammer the memory frame behind a COW page belonging to a setuid binary? I feel like it might be an all or nothing kind of thing in this situation. Who knows though, maybe there's merit in specifically protecting kernel owned frames, it's difficult to say for sure.

0 - https://en.m.wikipedia.org/wiki/Memory_refresh

ecma··on Defending against Rowhammer in the Linux kernel
Are you potentially confusing a page fault which results in the page being pulled into main memory with a cache miss which pulls a line from memory into on-CPU memory? My understanding is that the cache miss is managed by the MMU without much kernel involvement and we're relying on non task aware PMU statistics local to a single CPU for the proposed mitigation.

Am I missing some aspect of page mapping/cache management?

ecma··on New paper: “Why most of psychology is statistically unfalsifiable”
Confidence levels in the hypothesis based on results and rigour of the methodology producing those results (implicitly reproducibility) are two different things. I suspect that's why the downvotes.
ecma··on Re: [PATCH 1115/1285] Replace numeric parameter like 0444 with macro
Not in the kernel, you can't :)
ecma··on Re: [PATCH 1115/1285] Replace numeric parameter like 0444 with macro
There are some mixed opinions in the maintainers' replies. Steve Rostadt is NACKing all of his patches (amusingly also spamming everyone in the process) since he likes the octal and others are making the same argument. Other again are suggesting more use of S_IRUGO since the author seems to have broken up a large number of octal macros into naive combinations of the S_* macros without much thought for semantic intention. A hardware maintainer encouraged the use of some ATTR_RW macros which indicates that the author didn't necessarily recognise the preferred tropes for various subsystems.

The backdoor argument (mentioned in an earlier email in the OP thread) is pretty reasonable to raise. The maintainers seems to be fairly on top of things though, acking and nacking as patches come in but this will take a while to process. I suspect very much that these commits will have to be rewritten to include subsystem labels and more accurate summaries by the maintainers if they want to include them. The patch set as an aggregate whole is garbage.

ecma··on [dead]
This is not a novel tool. It is literally just running msfvenom with shikata, and setting up a listener. I'd recommend reading some tutorials on using msfvenom/msfconsole rather than relying on a tool to do what should be trivially understood. If you'd like to dig deeper into what metasploit can help you do, check out the Metasploit Unleashed material published by Offensive Security (a brief venom tutorial is at [0]).

[0] https://www.offensive-security.com/metasploit-unleashed/msfv...

ecma··on Study opens new realms of light-matter interaction
Plasmons are an aggregate oscillation of charge density in a material. In the case of the charged graphene sheet, we get surface plasmons from the oscillations of the charged added to the sheet as mentioned in the article.

Plasmons are kind of cool because they can associate with photons to create polaritons. It's not clear to me without having read the paper if they're proposing that polaritons be induced or if the emissions are being caused by spontaneous plasmons in the graphene.

ecma··on Nightcode 2.0.0 released
I was genuinely hoping for screenshots from films starring Kevin Hart, Ice Cube and The Rock. The IDE is okay too I guess...
ecma··on Supersingular Isogeny Diffie-Hellman: Post-Quantum Curves [pdf]
It'll be a while yet. OpenSSL is still the standard platform for trading research implementations and AFAIK the problem isn't characterised with enough depth to suggest it as a recommended hard problem to base post-quantum cryptographic primitives on. The next few years will be very exciting though!
ecma··on Supersingular Isogeny Diffie-Hellman: Post-Quantum Curves [pdf]
I recently had the privilege of listening to Brian LaMacchia speak on this and other developments in the post-quantum cryptography space at Microsoft research. What they're doing is remarkable and their commitment to the space is impressive. SIDH is an exciting problem and I'm looking forward to reading more work on implementations and cryptanalysis.

Well done to the people at MSR behind this paper!

ecma··on U.S. government worse than all major industries on cyber security
Spending millions on support for an operating system which is well out of life is indicative of poor IT procurement and lifespan management. Business interruption was a valid excuse about 5 years ago, to continue to argue that is a farce.
ecma··on U.S. government worse than all major industries on cyber security
As a exemplary symptom of the toxic IT culture in many aspects of government and defence, the US Navy paid $9M for continued support of Windows XP last year [0]. They definitely aren't the only government agency which is doing this and it's indicative of systemic problems in business support and procurement.

[0] http://money.cnn.com/2015/06/26/technology/microsoft-windows...

ecma··on U.S. government worse than all major industries on cyber security
That doesn't preclude government contracting this kind of work out to professional infosec consultancies. Budgets are usually more complex than a single bucket and the heightened requirement for accountability in government practically guarantees that.
ecma··on GNU/kWindows
Accurate. Technically the Microsoft compatibility later could have been entirely done at the library level by replicating POSIX and adding an ELF linker/loader. There would have been some edge cases around Linux specific source but the GNU core would have been well served by something like that.

The reason the language is all centered around Linux is because what they chose to do was do a Linux syscall compatibility layer. Really it could be called GNU/sLinux/kWindows but nobody is ever going to bother with that mouthful.

Edit: I should add that this doesn't mean I agree with the use of Linux here - I just understand why that's the case. I would much prefer if those involved went to the trouble of explaining what GNU is to those consumers who are interested. Pretty unlikely Microsoft would be leading that given GNU's position on Windows.

ecma··on Hidden latency in the Linux network stack
Good catch. I did mean that mixing in the source would apply to the established table if it's constructed in the same way but doesn't do so already (which would surprise me now that I think about it properly).

I don't think that you'd need a separate table for star bound listeners if the IP is mixed in since you could just hash in 0.0.0.0 but you'd need to check both the real IP and the special value too which is a potentially damaging performance hit. It's probably done with just the destination port for a good reason.

ecma··on Hidden latency in the Linux network stack
I'm not entirely convinced that increasing the size of LHTABLE solves anything. True, it may remove some collisions in the hash table but note that 63925 % 64 = 53. Given that the two slow ports listed seem to be arbitrary and assigned to customers, they're probably just a symptom of the overload on 53/UDP. I'm not suggesting they chose 64, that's unclear, but whatever they chose probably just shifts problem the elsewhere. Increasing it /would/ inherently reduce the frequency of the events though so you can call that a win.

A naïve solution would be to choose a bucket based on the destination port as well as the source port if one is available (e.g. TCP). This might help balance load affecting particular local ports since we can assume the source port for TCP will be random enough. However, it doesn't solve the problem - it'll just hide it. Random spikes in latency for connections to random customers? Sounds undesirable.

A reasonable solution might be to work out a way to map gateway 53/UDP to a diverse set of ports which are bound to rrdns processes on the boxes which currently have 16K IP addresses. For UDP packets, this would be possible by doing on-wire modifications to the transport header and recalculating any checksums. Perhaps that just shifts the burden though.

ecma··on Sphere Packing Solved in Higher Dimensions
MathWorld has a really good article [0] with density numbers from R2 through R8 if you're interested.

[0] http://mathworld.wolfram.com/HyperspherePacking.html

ecma··on Sphere Packing Solved in Higher Dimensions
The paper [0] was linked, the article gave context to the problem and outlined the approach. What more do you want?

[0] http://arxiv.org/abs/1603.04246

ecma··on Do you have the brains for cybersecurity?
"They range in difficulty from simple to knotty and fiendish. We will let you know the answers next week."

It's not a recruitment operation. They're just some fun puzzles which are accessible to laypeople. It shows the fundamentals of cryptanalysis in a way that a casual reader can understand and even have a crack at solving.

Someone mentioned in another comment that Simon Singh's "The Code Book" starts in a similar way and they're dead on. You don't introduce someone to a subject by posing problems based on constructs they don't yet have the tools or context understand. The history of the field informs its current state - cryptography and cryptanalysis have a very rich and fascinating history.

ecma··on bcwallet: A /dev/wallet for Bitcoin
You realize that /dev/ is for devices, not developers, right? The title of the OP is fairly misleading because of that.

Otherwise, an interesting project. I'd be interested to know why you chose Python and if/how you protect against code poisoning on the user's machine.

ecma··on Re: Obama on Fetishizing Our Phones
I didn't think I'd come back but I liked your comment and wanted to rebut.

There is a middle ground and where it lies is directly related to the assessed risk. To support a mechanism is a binary choice but its design is not.

In the San Bernardino example, an unexpected potential adversary (Apple) has emerged. An unexpected vector is being discussed which has nothing to do with the encryption mechanism itself. Perfect cryptography doesn't imply a perfect cryptosystem and it sure doesn't imply perfect privacy.

The balance that needs to be found is around the assistance which is rendered to warranted agencies to enable their access to data. IMO vendor supported key material attacks are not an unreasonable solution but obviously that mechanism can go horribly wrong if the software is leaked and it is not adequately designed. The same can be said for signed updates in general though. This is a hard technical problem but it's not a binary choice where the agency has some magic key they can use wherever they want or they have nothing. If they can be enabled on a case by case basis such that it is cost effective for them to do the rest, that might be enough.

Obviously this is all based on the assumption of a robust local judicial process. However, whatever decision making process occurs needs to take into account global implications. Other commenters here and elsewhere have mentioned what this could mean for agencies in other countries where judicial process may be less robust. Many have commented about a lack of transparency in our own. This is a separate but very closely related concern. There are also considerations for the open source community and how precedent like this might be applied to them. It's a hard problem but it's not binary.

ecma··on Re: Obama on Fetishizing Our Phones
If the San Bernardino case proves anything, it's that encryption is not the whole picture.
ecma··on Re: Obama on Fetishizing Our Phones
This is incredibly naive bordering on puerile. To suggest that POTUS' view on this is without nuance is to miss his point. POTUS went on to cite existing warrant mechanisms and their underlying principle:

"And we agree on that, because we recognize that just like all of our other rights ... that there are going to be some constraints we impose so we are safe, secure and can live in a civilized society."

I'm not suggesting that this means POTUS and the government have the right answers at the moment. Despite that, we can't ignore the important role law enforcement plays in society, the requirements in support of their role, and the complexities surrounding the right to privacy. We need people advocating for the right balance, not just getting each other frustrated.

OP may have worries other than US law enforcement being from another country. This is one of the /many/ complexities in this space.

ecma··on Is India’s Freedom 251, a $4 Smartphone, Too Good to Be True?
Official site:

> http://freedom251.com

Previous thread on the phone before the release event:

> https://news.ycombinator.com/item?id=11123135

ecma··on Maybe: run a command, see what it does to your files without actually doing it
The parent is more similar to doing `sudo find . | grep -- "*-foo.bar" | xargs rm` which I can definitely say I've never done because it's absurd. The consequences of redirecting to a file are usually nil, unlike running rm on the output of a pipeline without at least using -n on the destructive util...
ecma··on Maybe: run a command, see what it does to your files without actually doing it
Why would anyone ever invoke something like this and expect maybe to somehow steal those pipe characters? It's almost meaningless and displays just enough know how that the author should know how a shell works.
ecma··on XINU OS – Xinu Is Not Unix
If you happen to read this, the courses at Purdue which are based around XINU seem to be CS354 and CS503. Some google-fu turns up lecture notes but I'll avoid linking them due to the fact that they don't seem to be openly distributed.

That may or may not be what you were after since the book is probably more detailed at to the point than the course notes would be.

ecma··on XINU OS – Xinu Is Not Unix
More important than the acronym is the effort itself. XINU is a really interesting project and probably the second OS I was introduced to outside of the POSIXy neighbourhood. It differs from a lot of other projects in that its goals (to my understanding) were very different to the usual approach toward providing POSIX compliance or a platform intended to support layering POSIX on top of a base architecture.

I picked up an old copy of the textbook and never read it. Maybe this is the kick I needed to pick up the newer edition and actually check it out in earnest!

← PreviousPage 2 of 4Next →