HNHacker News
TopNewBestAskShowJobs

ejr

739 karma · joined March 7, 2013

I like chocolate.

  grepcoco at gmail
  @grepcoco
submissionscomments
ejr··on Mayhem – A hidden threat for *nix web servers
Thank you. That's actually far more constructive advice.
ejr··on Mayhem – A hidden threat for *nix web servers
These are often used on crawlers, bots - not necessarily of the harmful variety - and other automated retrieval, transfer and storage scripts. They're very useful, but highly specialised for those particular tasks and often not needed on traditional web applications. Of course, these are often abused for retrieving malware payloads as well so enable at your own risk.
ejr··on Mayhem – A hidden threat for *nix web servers
The list is limited to a very specific set of functions that PHP is an ill fit to utilise and I have never seen used in a positive context. These are best done with a non-scripted program or perhaps Python.

Of course, no matter the language used, input sanitising is essential.

Edit: Since you've edited your post to add cURL to your criticism, please note I originally replied "These are best done with a non-scripted program or perhaps Python" for exactly this reason.

Much of the criticism of PHP can be leveled against its misuse as much as the language's own shortcomings.

ejr··on Mayhem – A hidden threat for *nix web servers
This is a very well reasoned point. Thank you for writing this.
ejr··on Mayhem – A hidden threat for *nix web servers
While the dropper was written in PHP, it's important to keep in mind that Perl, Python or other language could just as easily have been used. If you're using a shared host that otherwise doesn't allow many configuration changes, you're very limited in what you can do to protect yourself.

If you use PHP, you can add the following to php.ini to mitigate risks like these (mitigate != bulletproof) :

  ; Mayhem dropper uses "system" so let's kill that and other dangerous functions
  disable_functions = system,eval,curl_exec,curl_multi_exec,exec,passthru,shell_exec,show_source
If this breaks your software, your software is badly written.

Allowing write permissions in the script directory is always a dangerous thing. It's best to put the application files outside root and enable execute permissions only on the script directory. If uploading files is allowed, it should be to read/write enabled directories only. Execute permissions should be turned off.

The dropper tries to kill critical processes as mentioned so chrooting services individually is a good idea.

Or you could just use OpenBSD ;-)

ejr··on Hacking Online Polls and Other Ways British Spies Seek to Control the Internet
Well a significant percentage of HN folk certainly, but I doubt this translates well outside this sphere.

I'm more alarmed by the email spoofing. Isn't this the same as manufacturing evidence? Consider: An entity is under surveillance, however the powers that be decide the scope is too limited. What better way to invite scrutiny than ensuring an email from the desired target arrives in the monitored entity's inbox?

ejr··on North Texas citizens organize to monitor police with video cameras
This might be one occasion where throwing technology at the problem may actually be productive. HN has a reputation for using tech as a crutch for social problems, but this is an ideal job for a quadcopter.

In the U.S. the FCC was overruled over bans on commercial use of these so that's another barrier lifted. As an added bonus, it also prevents immediate discovery of the pilot and thereby avert suppression to some degree.

ejr··on U.S. Needs to Weigh Rocket Engine Options, General Says
Thanks! Who knew breaking a large problem into smaller chunks works in rocketry as well ;-)
ejr··on U.S. Needs to Weigh Rocket Engine Options, General Says
Could anyone with knowledge about engines explain why Russians always seem to prefer multi-nozzle designs? Is there some inherent advantage in redundancy, cost or some other factor?
ejr··on Google Noto Fonts
It may not be so infuriating when you consider how important names are to Japanese people. Breaking your name is unacceptable and breaking it because of a technical convenience chosen during development would be deeply offensive on top of being unacceptable.

Until Unicode stops breaking people's names, it will continue to be the one standard for Japanese systems on and offline. Even when(if?) it stops breaking Japanese names, it will take a very, very long time to roll over existing systems and that's precluding unforeseen problems during the conversion.

We should stop before we take the "not following standard" = "broken" ideology. Especially when we consider whom the standard serves best.

Edit: By "it will continue to be the one standard for Japanese" in the 2nd paragraph, I meant ShiftJIS not Unicode. That looked a bit unclear.

ejr··on An FBI Counterterrorism Agent Tracked Me Down Because I Took a Picture of This
He has a Muslim background, I think, and he wasn't the only one to be part of this complaint. Wired has a write up about this as well http://www.wired.com/2014/07/five-sue-gov-over-targeting/
ejr··on An FBI Counterterrorism Agent Tracked Me Down Because I Took a Picture of This
There's a great disconnect between actual security needs and the security theatre demanded of those who must engage in guard duties. Those in charge must view the empowerment of security guards to determine actual threats as somehow inviting disaster when in fact, it may reduce the significant bureaucracy and paperwork these "centralised evaluation" procedures may impose.
ejr··on Lincoln Penny on the Curiosity Rover
Lacking immediate political or economic drivers, I'd say this is realistic. Neil deGrasse Tyson has a better explanation of why this is the case https://www.youtube.com/watch?v=ErZq2ZQQTrs (starting at 7:45 or so)
ejr··on SQLite: Small, Fast, Reliable – Choose any three
That's awesome! Thanks!
ejr··on SQLite: Small, Fast, Reliable – Choose any three
This is a delightful discovery. I wonder there exists a used book anthropology of sorts for these tidbits.
ejr··on This maze looks familiar
We seem to have killed the site.

https://webcache.googleusercontent.com/search?q=cache:krazyd...

ejr··on Anon – Tweet about anonymous Wikipedia edits from particular IP address ranges
Bringing work home has not been a popular option in these spheres as far as I know, so the staff may become excluded. The officials themselves may be doing the edits if that's the case.
ejr··on App parking system shuts down in San Francisco
There's a significant difference between those two scenarios. You'll find Americans are far more willing to intercede if speech was at stake here.

The right to speech and free expression is protected in the U.S. (for the most part) whereas the right to affordable parking is an arguable point. The primary issue San Francisco had in this whole episode is that they didn't come up with it first. This was all about revenue.

ejr··on Making sure software stays insecure [pdf]
There are times when the wheel at hand is an ill fit or perhaps there genuinely is a better way to do things Ex: Libressl. And so the wheel needs reinvention.

Reinvention of the wheel, reimplementation of a paradigm or some other repetition in a slightly different or totally different way isn't necessarily a bad thing as long as the underlying concepts are well understood and it is executed with competence. I still believe malicious tampering is unnecessary when carelessness - or tiredness - on the part of the developer will do just as well.

ejr··on Ask HN: Why are so few links posted as https?
It wasn't that long ago and I don't think it was compromised. At least I hope not. It may have been a new plugin, but I'm fairly certain it was "Nowhere".

I'll have to look into HTTPS Everywhere. Thanks for the recommendation.

ejr··on Ask HN: Why are so few links posted as https?
Resource efficiency has a lot to do with that, I think. Crawling sites twice will add not only to the burden of the bots but the sites too. Admins may disapprove of this.

I wonder if users can be motivated to do the checking themselves when they post the link.

ejr··on Ask HN: Why are so few links posted as https?
Good point. I borrowed a computer that had "HTTP Nowhere" installed on Firefox, but that seemed to break a lot of things to the point I had to turn it off. That may explain why browsers still default to http.
ejr··on Data.sparkfun.com: A place to push your data
Is this the same Nedb? https://github.com/louischatriot/nedb/

Looks like a pretty nice project.

ejr··on Every person with a Wikipedia article in a frequency graph by birth year
That's part of it:

  "When exact birth year was not tagged, the 
  individual was prorated over the appropriate time period."
Which makes sense as you still get a relatively accurate portrait of the scheme. I wonder how large a roll the loss of records have played in erasing a large chunk of our history.
ejr··on Mod Notebooks’ Launch
That's a good idea. A friend of mine created a little wooden stand and holder for his phone on his desk. Once he's done with a piece, he puts the phone in the holder, swings it around and takes a picture on a delay so he has time to hold the pages down. I believe he also has markings on the desk so he can position his papers/books correctly.

Of course, this might be way more trouble than most people are willing to go through.

ejr··on Mod Notebooks’ Launch
What happens if the book is lost in transit? Isn't that worse than "forget them forever when I leave it in a dusty box somewhere"?
ejr··on Retirement of Prof. Andy Tanenbaum
Humour works best when it's true ;)

It amazes me that the majority of computer related books I've read are really not fit for human consumption. It's really refreshing to see that he understood this and made his work and lectures - I've seen a few on YouTube - as engaging and entertaining as possible while still being clear and concise.

Code is for computers, but in the end, programming is for humans.

ejr··on Ask HN: Why would you disable JavaScript?
It kills a lot of autoplay videos, popups -- the "in page" variety -- and other dark patterns I see on a lot of sites. The only regret I have is that ads get disabled too so if it's a place I really enjoy a lot and they have a means to donate, I give them something.

Besides this, it also gets rid of a lot of ad tracking without having to install any plugins specifically to block it. I'm a big fan of using existing features, both in software and hardware, to their fullest before extending them.

But the biggest reason is my computer is a bit slow too and I don't want to spend hundreds more just to consume text; something that hasn't changed since the dawn of the web and something I've been doing for years. It's wasteful to pollute my closet and a landfill in the future with e-waste because single-page apps and fancy transitions don't work properly.

← PreviousPage 6 of 6