HNHacker News
TopNewBestAskShowJobs

ehhthing

421 karma · joined February 26, 2022

submissionscomments
ehhthing··on Min: A fast, minimal browser that protects your privacy
First and foremost, electron runs on often outdated versions of chromium which are vulnerable to known 0days.

Electron RPC also makes it really easy to get RCE if you don't implement it properly, and most JavaScript developers don't implement it properly. Electron also does not have anywhere near as much security research into it.

If you want to read more into the current state of electron security research, see https://blog.electrovolt.io/

ehhthing··on Copyright denied because the model’s pose is not unique
I think the ruling is probably much more complicated than the simple statement that it was on pose alone. Whether or not the similarities between the original and derivative work meet the criteria for the Luxembourg equivalent of Fair Use is probably a better discussion.

However either way, I see no reason to think about copyright in such a limited way. I don't think many people believe that copyright is only enforceable if two works are exactly the same. Rather I think they're simply discussing how inspiration and imitation is very common in art.

ehhthing··on Hackers earn $990k for 63 zero-days exploited at Pwn2Own Toronto
Generally, the way that you're paid if you sell to a exploit broker is in installments over time to prevent this kind of business.

I'm not sure about whether it's your intellectual property or not. Can exploits be "intellectual property"? Like sure your specific PoC could be considered intellectual property, but if you were to rewrite it differently (and there is always another way to exploit a vulnerability) then I have no idea whether that would still count or not.

ehhthing··on Copyright denied because the model’s pose is not unique
And clearly the Luxembourg copyright system doesn't work that way? Maybe in Luxembourg, copyright only exists in much more limited situations?

Whether something should or should not be copyrightable in the moral sense is a very different conversation than in the legal sense and I don't really see why we should be restricted into believing that things that commonly require licenses should always be that way.

ehhthing··on Hackers earn $990k for 63 zero-days exploited at Pwn2Own Toronto
I'm active in the CTF crowd, and I think the general feeling is that you only want to burn your lower tier exploits at pwn2own. Usually these will be the exploits for things that are harder to sell to an exploit broker. You probably won't see many top tier vulnerabilities at pwn2own.

Zerodium is definitely a bit too well known to have actual market pricing for vulnerabilities, but their tier graphic is pretty accurate (https://zerodium.com/program.html). Notice how most of the things hacked at pwn2own are at the bottom of this graphic.

Selling to a exploit broker is pretty much always more profitable for higher tier exploits, and usually if you're in this industry and want to make bank you'll just work for a company like dfsec where you get bonuses for finding these kinds of exploits anyway.

ehhthing··on Everything SBF is doing is in singular pursuit of not going to jail
While FTX US did operate in the US, its finances were never nearly as fucked up as FTX (The Behamas company) was, especially with its relationship with Alameda.
ehhthing··on Samsung’s Android app-signing key has leaked, is being used to sign malware
The article is rather misleading. It is almost certain that Samsung used HSMs to sign their APKs, so the key itself could never actually leak unless someone had physical access to the HSMs themselves and managed to somehow delid it and then put it back together without anyone noticing. I'm not too familiar with the documented attacks on delidding HSMs, but I believe that delidding chips causes permanent damage to them in such a way that they will never function properly again.

It's much more likely that an employee's account was compromised and then used to sign malicious APKs, or something similar. Once Samsung realized, they could get the logs of every APK signed with the HSM and then revoke those certificates individually through a software update. Not really sure if they actually did that or not, but either way the key doesn't necessarily need to be replaced.

ehhthing··on EU Regulator: Proposal to force websites to pay telcos puts Internet at risk
They do peer locally, but of course they charge for it. It's all PNI, and quite expensive. For the longest time, Cloudflare routes from Toronto went down to Chicago.
ehhthing··on Show HN: Run unsafe user generated JavaScript in the browser
You can achieve the same thing with iframes using the "sandbox" attribute.
ehhthing··on Google officially launches Equiano subsea cable
The UAE's connectivity isn't actually bad. Latency to most of SEA is quite good (50ms to India, 80ms to Singapore).

But for what I assume to be political reasons latency to Europe is about 20 or 30ms higher then what it could be .

When I was there, I could get sub 100ms latency to France using a Wireguard tunnel to an AWS server in Bahrain, while direct connections were closer to 120-130ms.

Overall though, I found connectivity in the UAE to be absolutely fine by middle eastern standards.

ehhthing··on Prevent DoS by large int-str conversions
I was the one who reported this originally in 2020. Christian said it wasn't a vulnerability because it was intended that people who used standard library functions should validate user input. A day later I get another email saying that a CVE had been assigned, and that it was now suddenly a vulnerability.

I wait a few months, follow up and nothing. Pretty much dropped it for 2 years and now I see that they finally fixed it and never let me know. I asked a few days ago whether I'd be credited in the CVE, still no reply...

Why do I feel as if there are serious communication issues here?

ehhthing··on Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
This all seems a bit silly, and could easily be attributed to a communication issue.

On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected.

Even modzero themselves admitted that the vulnerability is not of great severity so the motivation for the security triage team to put more resources in validating a non-severe bug are probably very low. They likely just tried to run the exploit, and didn't think much of it after it didn't work.

Also if modzero is not participating in a bug bounty program then CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix.

I'm no fan of CrowdStrike (in fact, one of the more memorable moments for me at my previous job was my boss calling them "ClownStrike"), but it seems as if this is just a bit of overzealous entitlement from modzero as well as not enough testing on CrowdStrike's end.

ehhthing··on Tell HN: Google Intercepting SMS
RCS is an open protocol, in fact it was developed with the GSM association https://en.wikipedia.org/wiki/Rich_Communication_Services

You seem to want every single reason to dislike anything Google has ever helped to make, rather than doing actual research into what some of these things are.

ehhthing··on Lessons I wish I had learned before I started teaching differential equations [pdf] (1997)
I just (barely) passed what is known as my university's hardest first year physics course: electricity and magnetism. We didn't use differential equations, but we had the same hand wave "just think about it" relationship with line integrals. The way my professor explained it was "we're engineers, not mathematicians, so we actually know what we're talking about".

What he meant by this is that as engineers, we need to have intuition as to what an integral actually is rather than knowing how to prove things with them. To an extent, this is a good way to go about it. Really it's not at all useful to understand things like delta-epsilon as an engineer because those concepts really have no application. It's much more useful to just gain an intuition as to what you're actually doing when you're taking a line integral, and applying that to, for example, calculating an electric field strength as a result of an object.

Physics teaches physics, not math.

ehhthing··on Show HN: PDFs that are readable by human eyes only
Lesser known fact: this "feature" is actually built into Chrome on MacOS! If you try to print a website as PDF it will completely break it and copy and paste will result in random Unicode characters.
ehhthing··on Amazon bows to UAE pressure to restrict LGBT search results
You seem to have taken this quote out of context. My point is that "a less censored platform is always better", in other words "Google but censored is better than Baidu".
ehhthing··on Amazon bows to UAE pressure to restrict LGBT search results
As a former Chinese citizen, I've always been a bit confused why people get mad at companies operating in the country, censored.

At least in my experience, a censored version of a foreign website is always much better than the stuff developed locally, and there are some political reasons for this I won't go into.

In my opinion, it's pure virtue signalling to argue that "a company compromising morals in a different country is bad", at least in the general case. I would totally rather use a censored version of Google over Baidu.

Arguing that "companies operating in China while censored hurts the Chinese people" is pure nonsense. The only people that care that {some company} is censored in China are distinctly people outside of China.

ehhthing··on Mastercard and visa are the de facto regulators of porn
I mean there are certainly alternatives to Visa and Mastercard. Credit cards aren't the only way to pay for goods and services. PayPal and Crypto being the most common. For personal transfers there's also Wise (which you can do person-to-person instantly), and if you live in some countries there's stuff like Interac E-Transfer for making personal payments. If worse comes to worse there's bank transfers and ACH, which are accessible from virtually any bank.

I see Visa and Mastercard like Facebook, Twitter and Instagram and they seem to have the right to refuse service to anyone they want to.

ehhthing··on Mastercard and visa are the de facto regulators of porn
But that's not the point is it? The point is that Mastercard and Visa are facilitating the transfer of money for illegal transactions. In the same way you can't start a bank to facilitate money laundering, Mastercard and Visa cannot knowingly facilitate the transfer of money for illegal goods.
ehhthing··on Mastercard and visa are the de facto regulators of porn
What, exactly is the alternative? The system might not be perfect or even good, but as far as I can see there is no alternative to this kind of issue. Even if there were a million different credit card companies (and god help us if that ever happens), they would still be bound by the same requirements.
ehhthing··on Arc Browser Company: Chrome and Safari face a new challenger
Thank you for introducing me to a wonderful privacy nightmare.

P2P networks inherently are not private: everyone on the network knows who else is on the network and what they are doing. Thus one bad node could collect data on others' browsing habits and track people quite easily.

ehhthing··on PSA: HelloFresh doesn't delete data when asked, only changes the email address
30 days is not instant.

The only issue here is HelloFresh not properly telling its customers how long it takes for them to actually delete the data.

ehhthing··on Everything with a battery should have an off switch
Can we add pacemakers to this list too? A bad lurch could kill someone...
← PreviousPage 4 of 4