HNHacker News
TopNewBestAskShowJobs

erglkjahlkh

164 karma · joined October 24, 2014

submissionscomments
erglkjahlkh··on Panama Papers: Mossack Fonseca leak reveals elite's tax havens
Well, it is actually pretty interesting how the information has been managed in case. The press wants their own piece after they lost the previous major leaks completely. It's actually pretty relevant discussion about the future of an industry that has been in slow decline for the last decades. In case someone interprets that as sarcasm or sensationalism that is probably an attitude problem, or perhaps an issue with low media interpretation skills.

I have found Hackernews as one of the islands that really acts still like penguins. Strong engineering culture, and just like penguins people just love guarding their rocks and throwing poo at others, just in certain style that is very typical to technical communities. Sarcasm should be the last of issues when compared to that.

erglkjahlkh··on Panama Papers: Mossack Fonseca leak reveals elite's tax havens
That kind of makes sense. The internet sleuths would analyze it in minutes further than the reporters ever could. They like their jobs so they insist on keeping that data to themselves.

Edit: Ahh, hackernews, the tumblr sister site where inconvenient truth means downvotes :D

erglkjahlkh··on CVE-2015-8126: Multiple buffer overflows in libpng
Buffer overflows are basically about memory corruption. They can lead to crashes, remote code execution, if run in privileged code to privilege escalation, etc.

Most modern operating systems have buffer overflow protection technologies such as ASLR. I tried recently exploiting a few guaranteed buffer overflows for fun, and it's getting irritatingly hard at least on Linux. Non-executable stack, *alloc functions have sanity checks, -fstack-protector provided canaries, ... It's possible to get past all that, but it takes a bit work.

I would be freaked if I was running some older operating system, and someone vendored a poorly compiled version of libpng. Windows applications are probably the scariest here, especially when run on older Windows servers...

erglkjahlkh··on Gnuspeech
AFAIK there are a few that produce such results that they can not be distinguished from a real person. None of the really good ones are open source, and the best ones I have heard of are not even for sale.

The best implementations make an advantage in markets so they are well guarded. We do not know about the best implementations, because we did not notice a thing. For example some phone operators have replaced their customer services with TTS / STT solutions. Because people tend to lock up when they realize they are talking with a computer, they have had to make those systems sound very natural.

I know a few are pretty crappy ones, but a few are plain spooky. Customers that tend to joke and flirt with the computer, hoping for an emotional response, probably are most likely to notice them.

Then there's the case where the US intelligence services demonstrated their capabilities to a politician (senator/congressman) by recording him, and producing a voice clip of him saying something like "death to america" so well that no one could distinguish the speaker. It also seemingly passed further voice analysis. Google it up, pretty interesting read.

erglkjahlkh··on OpenBSD's tame gets a path list parameter
Tame is forming up pretty nicely.

The logic here is that most of the time files of certain type are usually in logical locations, whereas with SELinux the logic is that types are intrinsic properties of objects, and saved as metadata their metadata. The difference is that with the latter moving the object does not change the properties (the context comes along), while the first one might lose the properties in case something made moving outside the intended envelope possible.

The approach taken by Tame is technically easier to implement without shooting yourself in the foot, and featured also in Grsecurity fame's RBAC implementation. Jolly good.

The thing just is, the approach taken by SELinux with the external security daemon can and has been extended beyond files. Tracking the information by its properties when it moves from files to database, web servers, etc, is a powerful (but extremely hard for implementors) feature. Also, administratively the security classifications of documents are properties of documents, not the storage containers they are found from.

erglkjahlkh··on Who's doing this to my internet?
Taking a look at Alexa, the trend for Reddit has been and still after the "Pao debacle" is upwards. They are constantly getting new users, probably much more than what they lost. So from the viewpoint of the management all is well. These new users are also probably more susceptible to their monetizing efforts.

The fact that Reddit has in the last 6 months lost most of their high quality content creators does not seem to concern them.

erglkjahlkh··on Forthcoming OpenSSL releases
3) Does anyone have any reference to this?
erglkjahlkh··on Show HN: Claimsman – tool for auditing users' file access
Since the days of Orange Book in 80's three rules have been golden in IT security: authorize, audit all information usage, and never let uncontrollably the information out of the secure domain. Implementing properly access management, watching users, and limiting the tools works still nowadays when implemented correctly.

The leaks of the past a few years each one of the previous failed. The users had baffling access to the information, there were oversights in auditing, and it was somewhat easy to move the information mass out of the secured domain. Leaking was downright easy, and getting caught was not certain.

I took recently a look at different products meant for file access auditing, to solve the part "audit all information usage" in cases where the information systems can not be adapted (COTS). There seems to be a surprisingly large amount of products with different feature sets and value propositions. Some of which have pretty steep prices and highly evolved features.

I got the inspiration to develop my own very simple tool, just for learning new skills and for the heck of it. A few hours of wading through MSDN, nerve wrecking C/C++ programming, tuning and it's ready. Quality is a bit so-so (there might be at least memory leaks, although I attempted to catch them) and I had no accurate specifications, but here it is...

With this application all file accesses (creation of low level handles) cause an event that is logged at centralized log management system. I did not implement hashing the files or gathering them, because it probably has a direct impact on the performance of a desktop, but it would be trivial to add as a feature.

After the information is in the centralized log management system, it is relatively easy to generate for instance weekly report of all the file accesses of users. In AD environments one could fetch information about managers, push the data through a good PDF template, and email the reports. As outcome the managers would get weekly reports of what their underlings have accessed.

When the awareness of the previous would spread, that would raise the bar to even attempt anything in the higher security environments. The impact on the overall security in the long rould would be more significant than the actual technical feature. The information security tools work best when they have a psychological impact. Absurd but true. It's not always the best to crank some technical bolt all the way.

On the other hand, some privacy should be guaranteed to the users by limiting the tool. At least in lower security environments this might come across, because employees probably nowadays have limited rights to use employer's computers for their own matters, for instance accessing banking services while on lunch break.

I would appreciate comments, code review, bug and feature reports, etc!

erglkjahlkh··on Why firewalls won’t matter in a few years
I have tried preaching similar message while I have worked for a C4I unit. I found it extremely hard to get anyone understand what the actual point was, and even after that I got mostly "but we're all COTS now" with a shrug.

The previous, while working with netsec, stands practially for abandoning the sound principles and going for superficial compliance models. There is no real security architecture in place for most systems, there are not trusted paths of handling information, and the assurance level is at rock bottom. The result is scary, when you take it into the context of your adversaries being hostile, active, and very well funded (typically state sponsored).

Actually I considered elaborating the previous with examples from real life, but then I realized that stuff might be classified, so... Meh.

erglkjahlkh··on Grooveshark Shuts Down
Spotify is very bad for music discovery.

It has no random feature, the channels they offer are either hand crafted or based on popularity. The music selection excludes many smaller, and indie, labels. The search functionalities are very limited (the metadata is too low quality).

I wanted to love Spotify, and I really gave it a try. I just couldn't keep using it, all it did for me was to make me angry. In the end it's mostly good for listening to what the major labels think you should listen.

erglkjahlkh··on OpenBSD 5.7 Released
Probably not anything new from Asus. I just recently purchased one, and it's pure UEFI. The newest models have begun removing the options to enable "legacy mode", so you can't run legacy operating systems anymore.

This will probably become more and more common, and after the next couple years it will be extremely hard to find any good laptop that would run openBSD.

erglkjahlkh··on IBM to Microsoft to Apple
What is that company that seems to appear at around '05 and grow to close 10% size?
erglkjahlkh··on Mailman 3.0 to modernize mailing lists
I am not sure about modernizing. I am all for developing core applications like mailman, but I fail to see great value in this piece of execution.

Post voting is bad for fact oriented discussions, popularity is a poor indicator for the value of a post. The user interface is cramped, and hides too much of valuable information I would expect to see instantly. Also, the looks are from previous decade (looks like sf.net clone to me) and not very aesthetic.

Sure, this might be a step forward nevertheless, but it is a really small one.

erglkjahlkh··on Compilers in OpenBSD (2013)
Also LTS means "95% of the developers left for the newer version because on open source projects no one can be forced to work on legacy applications like in business world".

Good luck with that. I tried to go on with the Ubuntu's LTS once, and the logic definitely doesn't work. Bugs, even major ones, just pile up faster than the remaining couple developers can fix, and it's was too painful of an experience to repeat. Ubuntu LTS has shelf life of 6-12 months unless if you start paying. Which is unfortunate.

erglkjahlkh··on Germanwings plane crash: Co-pilot 'wanted to destroy plane'
It dislikes terrain alright. There's a master alarm and audible "pull up!" warning... If they ever release the complete tape the last minute or so will be very, very grim.
erglkjahlkh··on Germanwings plane crash: Co-pilot 'wanted to destroy plane'
Been there done that. The entourage I was in (30 people going to enjoy the woods) was once stopped in airport for carrying knives. Hell yeah we did, everyone did, the longest one was 40 cm long and all were carried visibly.

We just told the guards to sod off as we had our own private transport plane we were waiting for. Who on earth would hijack their own plane? Especially as there were 30 armed people on board?

That's the safest way to travel!

erglkjahlkh··on The Little “Fighter” That Couldn’t: Moral Hazard and the F-35
I am not sure it was so disaster. The main problems from operational point of view for F-22 are operational costs (maintenance), and that it's heavy and flies like a slug. The latter is due design actually so the real problem is price.

They did not want to compromise the stealth and they wanted the plane to match the two-plane doctrine US forces have used since 2nd world war. Basically you got your agile and light fighters that clear the skies, and then you got the heavy planes with superior firepower that mop up the rest. So yeah, that's what they got.

F-35 attempts to be made from cheaper parts and with cheaper costs, and lighter. That means a lot of pea counting, and using simply worse parts. No wonder that program has had problems.

Operationally, F-35 is barely stealthy, and it doesn't fight that well. I'd rather sit in the cockpit of F-22 at this point.

erglkjahlkh··on Break-In at Y-12 – the vulnerability of America’s nuclear-weapons sites
Easily twice? 1 minute of Googling found already this, suggesting the true number would be mere fraction of that:

http://www3.cancer.gov/intra/dce-old/pdfs/ciabp.pdf

If someone knows better sources, please do post!

erglkjahlkh··on Study and Interactive Visualization of Toxicity in Reddit Communities
Well put.

"Hatred (or hate) is a deep and emotional extreme dislike. It can be directed against individuals, groups, entities, objects, or ideas. Hatred is often associated with feelings of anger, disgust and a disposition towards hostility."

-- Wikipedia (Hatred)

It is alright until you get to the three last words. Disposition towards hostility. Things tend to go downhill from there, especially with large groups of people. People get dragged into all kinds of spats, some see no problem with doxxing, spreading outright lies, continuous flow of ad hominem and other logic errors, ... The a few actually good people tend to leave quietly as time passes, and what is left is toxic wasteland of bigotry.

erglkjahlkh··on UEFI boot: how does that actually work, then?
The problem with secure boot is that most want to choose what parties to trust for managing the security of the boot chain. Microsoft is not on the list of many, and many large corporations and such would want to certify the sources themselves with more granularity. Whether this is a perceived or a real problem, I can not say, but until it is corrected this will slow the adoption of these new features.
erglkjahlkh··on Google Chromium drops support for Linux 3.16 and earlier
Well put. Although someone makes a LTS distribution, it really does not mean 3rd parties would be compelled or required to support that steadily aging platform.

When you combine the fact that not even Ubuntu developers really support the LTS (9/10 of the developers flock to the newest release, and the bug reports towards LTS get generally ignored - the LTS tagged bug queues are graveyards), I can not see the whole point of making LTS version available in the first place.

That being said, 7 months is a bit small window of support for a specific platform component. I would understand not supporting 1-2 years old kernel/glibc/whatever, but 7 months is really not enough.

erglkjahlkh··on Show HN: InstantCryptor – AES256 Encryption for Dropbox and Google Drive
I wish it were just interns... Example follows.

The Finnish security company F-Secure revealed a secure cloud service, called Younited (https://www.younited.com/). It did not catch on. The active user amounts stayed at near zero level so it was sold to a company called Synchronoss.

F-Secure initially hoped that their good reputation, and the fact that the servers are located in countries without draconian spying legislation would be enough. They seriously hoped to make a star product out of their secure cloud service.

Well, secure against whom? Simply installing the applications and completing registration process revealed instantly that the service is insecure. Yes, in compliance sense "everything is encrypted", but the keys are clearly held server side. The customer has absolutely no control over the key management and storage, meaning they are at F-Secure's mercy, and F-Secure can technically open everything for authorities.

Now the actually interesting part of the story: The problem isn't the implementation. The problem isn't that they marketed it as secure. The important alpha users on this product area are way too savvy, and stayed away. As per the standard innovation diffusion model, they did not drag other users in. Not marketing the service as secure would have yielded better results!

It's funny how even serious software security companies screw things up. Even when they are attempting for a strategic new product positioning, and even when at near clear blue sea situation.

erglkjahlkh··on Email Regex that works 99.99%
The dot isn't mandatory either... There are also local (for example company internal) email services.
erglkjahlkh··on A Crypto Trick That Makes Software Harder to Reverse-Engineer
Also, does the scheme unencrypt the code to be run into what memory segment? What does this technique mean for current memory protection methods?

We do have nowadays non-executable stack, and heap by default. In fact, only the marked read only segments can contain runnable code, unless if you use specific workarounds. What happens if the code you are protecting and running is more complex, requiring calls where you would usually use position independence and stuff like ASLR to full extend? Do you lose these the benefits or those features, or is there necessary information leak (take a look at plt for instance)?

To add to this that in the end of the day if you can access both the data and the key it is just highly complex obfuscation, I am hardly impressed.

erglkjahlkh··on Things to Love About Reddit’s First Transparency Report
Also, they are not mentioning the cases where the SJW subreddits have terrorized the moderators and admins to delete complete subreddits. It's like if those incidents never existed.
erglkjahlkh··on Results of the python 2.x and 3.x use survey, 2014 edition
Unfortunately this was my first thought as well. Although wxwidgets works on several platforms, it manages to look and feel alien on almost every. If you care about usability, I believe your application should be consistent with the rest on the target platform(s). Wxwidgets based applications are simply failures especially on Windows.

QT fares significantly better on the usability. Java's look and feel system works as well. You could also separate the V properly, and for instance use WinAPI wrapper on Windows platform. Just please, please let wxwidgets die already :(

erglkjahlkh··on Rooftop solar is now cheaper than the grid in 42 American cities
In the country where I live no one does solar. The reason is that it doesn't get heavy subsidies, and the utilities have dropped their prices to discourage competitors from entering the market. We also screwed up the feed-in tariff system. So, you can drive around local cities for hours and not see one single panel.

That might actually be good in the long run. Part of the actual cost is the maintenance, and installation. Most of the solar power fanatics fail to count all the costs in their calculation. With a large scale utility those things are all in.

erglkjahlkh··on Gnome Wayland porting – the endgame
As long as it supports root windowless mode, whatever works is fine for me. Also, it must work out of the box on most common distributions, without requiring extra software installation. Configuration is fine though, not even X11 forwarding is enabled on many platforms by default.

I have sadly seen nothing of value in Wayland that would be worth losing X11 over SSH forwarding. I really need some similar feature, and I am not aware of anything usable being available with Mir or Wayland. VNC doesn't cut it unless it can export single windows.

I am well aware that X11 tunneling is an aged piece of technology that is in serious need of facelift, but the new alternative to X11 should match the functionality. Before that happens, I will keep uninstalling Wayland and Mir, because the critical requirements (for me and my environments) have not been met.

erglkjahlkh··on Show HN: The Silicon C++14 Web Framework
Where are the benchmarks? Seriously, I'd expect this thing to fly.
erglkjahlkh··on Conception – An experimental modern IDE written in Go
This indeed is commendable. There are more possibilities than what he has touched so far.

He could add automatically reloading live code, and link the testing suite... You see a bug, correct it, and the test suite runs continuously at the spots where the code is compilable, giving feedback per code fragment.

Page 1 of 2Next →