HNHacker News
TopNewBestAskShowJobs

enzanki_ars

687 karma · joined February 1, 2016

[ my public key: https://keybase.io/enzanki_ars; my proof: https://keybase.io/enzanki_ars/sigs/YUkdF9keCmpzagkCBf2_BapvMhycMty-8hv66GSNt_8 ]
submissionscomments
enzanki_ars··on I built an app to backup Live Photos from iPhone to external hard drives
This is a real feature of iPhones since the iPhone 15 Pro model. https://support.apple.com/en-in/109041
enzanki_ars··on Apple and Goldman Sachs deceived Apple Card customers, regulators say
Washington Post article has a paywall for two paragraphs that don't give much details. Here's the official Consumer Financial Protection Bureau report: https://www.consumerfinance.gov/about-us/newsroom/cfpb-order...
enzanki_ars··on Nintendo is suing the creators of Switch emulator Yuzu
https://archive.is/LvxxW
enzanki_ars··on I chose the ThinkPad Z13 Gen1 as my Linux laptop
The OEM kernel is available in the repo too, though requires that the kernel in the ISO works enough for your hardware to get to that point. More info about that OEM kernel is available at https://wiki.ubuntu.com/Kernel/OEMKernel, and worth looking into when you have really new hardware and running slightly older OS releases.
enzanki_ars··on The FCC responds to my ATSC 3 encryption complaint – they want to hear from you
It would only stop pirates for a whopping 24 hours at best. If there is a will, there is a way to bypass video DRM. It has to be decrypted at some point to appear on a display, and that's the place where it's possible to bypass any DRM without much issue. HDCP is useless [1][2][3], and unless Roku is failing to implement it right, my basic HDMI splitter from Micro Center is more than enough to strip it and feed info HDMI signal into a raspberry pi for ambient light effects. And in order for people to actually use ATSC 3.0 encrypted streams with an overwhelming majority of TVs on the market in use, folks will have to have some form of HDMI box that does the decryption anyway...

[1]: https://en.wikipedia.org/wiki/High-bandwidth_Digital_Content...

[2}: https://en.wikipedia.org/wiki/High-bandwidth_Digital_Content...

[3]: https://en.wikipedia.org/wiki/High-bandwidth_Digital_Content...

enzanki_ars··on NVD Damage Continued
The problem is the CVE score do work in most cases. A lot of organizations still prioritize updates based on their CVE score, and don't bother with updating unless it meets a certain threshold. If it doesn't meet that threshold, then they wait until their monthly patching cycle, or don't even bother updating ever at all.

Until that culture is fixed/adjusted, having a scoring mechanism that is easy enough for manager/executive type people to easily understand risk without any technical knowledge is important. Way easier to argue for an emergency patch/downtime that could cost money when there is a big scary 9 associated with it. And so if the scoring is off and not accurately representing risk, let's work to improve those scores, rather than getting rid of them.

Plus, there is a reason environmental scores exist in the CVSS mechanizm, as it allows for folks to adjust the CVE number to better fit their environment and specifications. I'd personally rather see more CVEs appear and be tracked quickly for easier referencing and discussing, with a slightly adjusted formula to better reflect severity.

enzanki_ars··on [dead]
This is not the official OBS project page, which is at obsproject.com instead. The URL for the release announcement can be found at https://github.com/obsproject/obs-studio/releases/tag/28.0.1 instead (which includes the 28.0.0 changelog.) There is also a more blog like post at https://obsproject.com/startup/obs-studio-28-release which can be seen inside the application before updating.

The nature of the url being "projectobs" instead of "obsproject" is concerning, and while there appears to be no download links hosted on the site, just redirects to GitHub's downloads, this looks concerningly like one of those SEO spam pages. Further research shows that it likely isn't the case at the moment, just a means to slap ads onto the official wiki docs: https://github.com/obsproject/obs-studio/issues/2565. Still concerning none-the-less.

enzanki_ars··on Contrasting Intel AMX and Apple AMX
Seems to be related to https://news.ycombinator.com/item?id=32722510
enzanki_ars··on Denuvo Launches Nintendo Switch Emulator Protection
There is still a large amount of friction in keeping a game though. These types of DRMs can cause the game to be unplayable years later. Like when Alder Lake came out and a bunch of games with Denuvo DRM broke [1]. Because of all of this recent attention on it, I wouldn't be shocked if it resulted in less sales and higher rates of emulation. Probably not enough to cause a dent in sales to disincentive addition of DRM though sadly.

[1]: https://arstechnica.com/gaming/2021/11/faulty-drm-breaks-doz...

enzanki_ars··on The GNU Name System
Cloudflare also outlines the following reason in the linked blog post:

> "The reason this matters so much is that the maximum size of an unsigned UDP packet is typically 512 octets. DNSSEC requires support for at least 1220 octets long messages over UDP, but above that limit, the client may need to upgrade to DNS over TCP. A good practice is to keep enough headroom in order to keep response sizes below fragmentation threshold during zone signing key rollover periods."

enzanki_ars··on Using a "proper" camera as a webcam
I was able to do this on my Rebel T7i by switching to manual focus, and then selecting the "info" button a couple of times to remove the overlay. There might have been some other changes I made, like turning off the grid overlay, but I think just the first two changes were enough though.
enzanki_ars··on Amazon says browser extension Honey is a security risk, now that PayPal owns it
Article from Jan 9, 2020. Not sure if there is any context to it resurfacing now...
enzanki_ars··on Multiple vulnerabilities found in Snap-confine function on Linux systems
In terms of that Adobe Acrobat Reader snap, how am I supposed to trust that the container is a maintained, trustworthy, and official version of the application? That looks to me sketchy to use as to my knowledge Acrobat Reader hasn't be released on Linux in over 9 years, and shouldn't be used/trusted given the large number of potential vulnerabilities...

This is the reason I don't trust snaps, as I have 0 way of auditing it. I know that there is a "verified" mechanism in snapcraft, but not all apps that are "official" or "trusted" have that tag, such as MusicBrainz Picard, published by the MusicBrainz team, so the only way I know they support it is going back to the official website, which also offers a more conventional PPA that is also easier to audit and trust given the GPG key processes in place there, which _should_ be a bit more trustworthy.

enzanki_ars··on Include diagrams in your Markdown files with Mermaid
ASCIIFlow is less accessible than Mermaid though for folks that use screen readers. Mermaid can be read as is from the source, or be transformed into a readable format for screen readers, but ASCIIFlow has no such mechanism to translate it into a format that can be accessible.
enzanki_ars··on Working around expired root certificates
In terms of the topic in this thread, it's not the customers responsibility to deal with expired root certificates. That said, I understand that there is a large issue with devices that drop support way too soon, even though the hardware is good. But the solution is not the weaken the security, but instead to force better standards for how hardware is maintained, and ensuring that there is a long lifetime where either the manufacture supports the device, or the device is completely unlocked and allowed for easy community sourced modifications and updates. That sort of critical information should be secure, because taking an example from elsewhere in this thread, I'd rather be confident I was reading the exact page as intended from the government source regarding how to apply for unemployment benefits and not have to worry that malware in the router is modifying the information on the page to steal information and use it to redirect those unemployment benefits.

And this theoretical attack on home routers is not out of the question at all. How many unmaintained unpatched IoT devices have been abused with malware/botnets. The clock is ticking on mass exploitation of home routers being attacked and it's firmware replaced with one injecting/stealing information from insecure webpages. If the devices can't be updated, we should make sure there are _safe_ alternatives to accessing the information, rather than hoping that no actor is doing things they should not.

I can list so many scenarios with critical information and attacks that could be made if the webpage was not HTTPS with proper certificates. Including school districts in the United States being force to block inappropriate content in order to receive federal funding, and those firewalls abusing non-http content to decide what to block, and school districts abusing that capability to block anything and everything they want. How about a student trying to understand more about LGBTQ+ individuals and the school district inspecting and censoring the exact content inside the pages to remove words like "lesbian" or "gay" because the school considers them "questionable." Or a school blocking articles pertaining to hacking. I have seen that exact last scenario in fact, where certain articles posted here were blocked in my highschool years ago because they were considered hacking and that was apparently not appropriate to view in school. These are real scenarios and not hypotheticals.

For more info on some other various types of fun attacks, see https://www.troyhunt.com/heres-why-your-static-website-needs...

enzanki_ars··on Working around expired root certificates
ISP MITM is not low risk, and has been already done by Comcast at the very least in the US to inject warnings about bandwidth caps [0]. And with the horrible security of home routers, ISP provided or not, MITM attacks are highly likely on home connections sourced from botnets and malware attacks on routers.

[0]: https://rietta.com/blog/comcast-insecure-injection/

enzanki_ars··on A $795M analogy: Locast, broadcast copyright, and the fall of big antenna
Edit: Not a lawyer, and what follows is intended to be more of outlining my understanding and trying to ask clarification on what I'm clearly missing. Sorry if it sounds a bit defensive. Just a very strange lawsuit, specifically in how the service was forced to shutdown instead of being allowed to continue to operate.

Isn't that a valid use of the non-profit status? That as long as the funding from donations was going towards that expansion only, it can still be considered a non-profit? Looking at the quick Wikipedia definition, that seems to be the case, if you consider Locast's mission is to provide retransmission of OTA broadcasts to all people in the US.

> "A second misconception is that nonprofit organizations may not make a profit. Although the goal of nonprofits isn't specifically to maximize profits, they still have to operate as a fiscally responsible business. They must manage their income (both grants and donations and income from services) and expenses so as to remain a fiscally viable entity. Nonprofits have the responsibility of focusing on being professional, financially responsible, replacing self-interest and profit motive with mission motive." [1]

PBS is also a non-profit, but PBS does something similar in that certain content is locked behind their "PBS Passport" subscription. If this ruling that requiring donations view without interruption, then PBS is also violating non-profit status based on your statement regarding "Locast chose not to operate like a non-profit." But Locast attempted to resolve that and remove the interruptions entirely, but was still required to completely shutdown and was given 0 chance to adjust... My understanding about hte reasoning for shutting down is that using collected funds, via any means, expansion across the US isn't allowed for some questionable reason under the section of the law Locast was using.

[1]: https://en.wikipedia.org/wiki/Nonprofit_organization#Managem...

enzanki_ars··on A $795M analogy: Locast, broadcast copyright, and the fall of big antenna
What infuriates me the most about this ruling is that long term effects of it. Locast did what they did and inserted ads every 15 minutes because they knew nobody would not contribute to hosting costs without some reason. Had they made it so it was interruption at the start only, _maybe_ it could have held up better in court. And I agree on that front. Remove the donate video from showing every 15 minutes, and only show it at the start. Encourage funding through better on screen messages and make it more clear that it's voluntary.

But the big part of the ruling was that it wasn't just how they requested funding, but the why. The ruling argued that collecting funds to expand more throughout the US was not valid for their non-profit status for some reason that made no sense. And as a result, it appears that a replacement will never exist, because the cost of pulling all of these channels with careful and specific antenna placement in a city, the hardware to pull all of those channels in real time, re-encoding the feed from MPEG2 to HLS/MP4 for the web, potentially making different qualities to account for network conditions (can't remember if the M3U8 playlists from Locast did that or not), and the networking costs of transmitting video are expensive.

And the lawsuit was stupid too. US TV channels are crammed to the max with advertisements, so much so that it feels more like an ad delivery mechanism than an entertainment delivery system. Locast could have been advantageous as they would have actual data of who is watching what when and where. Ad companies love that data, and with traditional OTA feeds, they don't have that. Instead, all of these OTA companies actively refuse offering the ability to watch their streams online for free. Other than local news content, everything else is locked behind a paywall of having an active cable subscription. Why should I, as a consumer, pay $100 a month to watch this same OTA content, just so I can watch it online, especially for a medium so jam packed with ads?

I live in the edge of Columbus, Ohio in an apartment. I'm still within 10 miles of the transmitters for the big 6 stations (the local affiliates of ABC, NBC, CBS, FOX, CW, and PBS collectively only use 4 transmitters.). My apartment is luckily facing sort of line of site to most of those transmitters. But even then, I still have bad signal issues with those channels, and in some cases leading to an unwatchable recording. The signal was bad enough that my recording of the 2020 Tokyo Olympic Opening Ceremonies was bared by loss of 2 to 5 seconds of video and audio every 2 minutes. My only alternative was to play $65 to $100 a month to cable or cordcutting subscription to watch that broadcast online. And out of spite for continuing to shutdown any free way to watch their OTA content online, I will _never_ pay. Our laws regarding OTA broadcasts and how people can use and view them need to change ASAP, otherwise what is the point of having them if is not accessible to all.

enzanki_ars··on Locast’s free TV service shuts down after losing copyright ruling
I have one, but I still use Locast because I'm in an apartment. I don't have line of sight at all, and I have a lot of issues with signal quality. And I live 3 miles away from my local NBC station, and the only window I can point my antenna has a bit of line of sight, thought it is at about 70 degrees. Yet my recording of the Olympic Opening Ceremonies had severe compression artifacts due to missed parts of the signal every 2 minutes. Locast or paying nearly $70+ for cable is the only way I could watch over the air broadcasts, and I'm not going to pay $70 for cable to watch ad filled content that's 80% reruns and barely any of the sports content I want to watch.
enzanki_ars··on Don't Talk to Corp Dev (2015)
Like others have said, I agree that stating that TLS does not garuntee security. But, plain unencrypted HTTP does mean insecure.

For a good discussion into why _all_ websites should use HTTPS, and the many different ways that not having the connection secured is actively harmful and why should not be done in the modern era.

https://www.troyhunt.com/heres-why-your-static-website-needs...

Not having your site as HTTPS puts all of your website visitors at risk. Even US ISPs like that of Comcast use these very same practices to inject warnings into insecure web traffic[0], some of which look more like advertisements than warnings. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant. And when you have the power to inject anything without notice, you can do anything and everything with the website experience. You can attempt to force a download, present scam pages that look like antivirus warnings or software updates, one of the easiest ways to have users fall for malware.

We should _never_ expect regular non-technical users to have all of their threat models in mind, nor should they be expected to understand all of these differences. Website owners should be expected to protect all of their visitors as best as possible and one of the easiest ways to start is by protecting their website with modern HTTPS encryption. Otherwise, it would be like a chef leaving the bones in a salmon before serving to a customer. You could do leave them in, but a customer might not know they are there and you have left a choking hazard.

[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...

enzanki_ars··on Don't Talk to Corp Dev (2015)
For a good discussion into why _all_ websites should use HTTPS, I'd highly recommend this article.

https://www.troyhunt.com/heres-why-your-static-website-needs...

Not having your site as HTTPS puts all of your readers at risk. Even US ISPs like that of Comcast use this very same practice to inject warnings into insecure web traffic[0]. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant.

[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...

enzanki_ars··on Apple to Ban Apps That Reward Users for Enabling App Tracking
You say that, but they also have set a precedent of doing that before with the Fortnite and plenty of other apps trying to subvert their arguably harsh In-App Purchase rules. I agree though, they try to ban the MLB, NFL, or other video apps with blackout rules based on geolocation, there could be a lot of people doing exactly what you suggest. Now, all of the apps could get rid of their app experience and go to a webapp only experience and circumvent the rules that way.
enzanki_ars··on Apple to Ban Apps That Reward Users for Enabling App Tracking
I wonder if there is an added benefit to this policy in terms of required geolocation for access. As in, will Apple prevent apps from requiring geolocation for access to content such as the MLB, NFL, or other apps that will only show content specific to your market area.

> "[...] and you can't withhold functionality or content or make your app unusable until people allow you to track them."

Per that reading, it would seem like the MLB and NFL apps would be banned from requiring location access before the live streams are playable, which could finally progress some of these insanely stupid TV blackout rules once and for all... Though, unless Apple will also apply this to IP based geofencing, there would still be a long way to go before TV blackout rules are gone from streaming services....

enzanki_ars··on Dominion Voting Systems Sues Rudy Giuliani
In Ohio, we used the same Dominion voting systems with the same process:

Poll worker validates proper ID, get ballot code for your precinct, walk to voting system, poll worker enters the precinct, voter validates info on screen, voter votes on the touch screen, system prints out choices, walk to scanner system, vote gets scanned, scanner stores those ballots in it's tray in case need for audit.

enzanki_ars··on Ubiquiti Networks Breach
They have an official thread/announcement on their community forum: https://community.ui.com/questions/Account-Notification/9646...
enzanki_ars··on Ubiquiti Networks Breach
They have an official thread/announcement on their community forum: https://community.ui.com/questions/Account-Notification/9646...
enzanki_ars··on Carmack on Apple successfully migrating from 68k to PPC to x86 to ARM
The tweet also links to another tweet [0], which links to a GitHub file [1] with the story referenced in the title.

[0]: https://twitter.com/brockgs/status/1330711644977053696

[1]: https://raw.githubusercontent.com/ESWAT/john-carmack-plan-ar...

enzanki_ars··on Acoustic Kitty
If you have never seen Tom Scott's Citation Needed, I highly recommend the comical take on this article.

https://www.youtube.com/watch?v=gcRJr9xQSAE

enzanki_ars··on Search Engine for Free Music Ranked by Usage of Youtubers
I think the reason why the GP stated that is because the site requires you to provide an email and states it as a demo. I would love to look at a site like this, but I agree that there seems to be no good reason to provide an email address to see the results for a website like this.
enzanki_ars··on Georgia School Reopening Photo Even Worse Than It Appears
The worst part too is the fact that the students posting those photos have been suspended with potential for expulsion.

https://www.buzzfeednews.com/article/laurenstrapagiel/north-...

Page 1 of 7Next →