HNHacker News
TopNewBestAskShowJobs

euank

566 karma · joined October 28, 2013

hn@euank.com
submissionscomments
euank··on The SSL Co-operative: A Member-Controlled Certification Authority
You both have to prove that you own the ability to create dns (with blogspot sorta) and the actual content. The CA provider both lists the record name and value.

You do have a good point though. I'm sure there are some services right now that allow decent control of a chosen subdomain's dns, but don't mean for you to be able to create ssl certs valid for all other subdomains too. Perhaps there should be a blacklist of sites like "blogspot". Perhaps there should be a way for a domain to indicate that wildcard certs cannot be automatically created for it without passing other conditions.

euank··on The SSL Co-operative: A Member-Controlled Certification Authority
Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain they suggest within a wildcard range, that makes it almost certain I can create every subdomain.
euank··on Dear Google, it's not me. It's definitely you.
It didn't affect the large majority, as I said.

Youtube and Google+ have merged (in case you didn't miss the large outrage over that). It was after Google softened its enforcement a bit, and the enforcement was never good.

I also have multiple google accounts and had no troubles, but we're just anecdotes, we're not everyone. The few cases where it did happen were well publicized: http://gizmodo.com/5830463/if-you-use-a-fake-name-on-google%...

The fact that Google+ and Youtube accounts have been merged is common knowledge at this point.

Sure, the people probably did click "Update my details", but you can't expect regular users to read everything and google's actions sorta "sets you up for failure" in terms of identity.

Your argument that "I had no trouble so it's okay" is a bad one because it's an anecdote.

Your "evidence" that they help you manage multiple accounts is a good point. What I really meant is "Google has tried to prevent you from having false identities". Multiple accounts supports e.g. having a company Google Apps account and a personal account, or having a school account and personal, etc. Places where you have one identity and switch between multiple accounts.

euank··on Dear Google, it's not me. It's definitely you.
I like google, but your point that "different account for youtube and gmail, Google is perfectly happy with you doing exactly that" is false.

It might be true in the general case, but Google did make a significant effort to require real names on Google+ (and by extension youtube / gmail). It didn't affect the large majority, but you can find some people it did affect. Google cared in some cases.

euank··on NodeBB: Node.js-based forum software
Right now, nodejs shines anywhere you need websockets and I personally want to see the modern web move to websockets. It allows for much more cool interactions than the server being unable to get data to the client without the client either clicking on something or constantly polling. On a bb software, having the "this thread has unread posts" indicator update without a page reload would be great, and websockets make that easy.
euank··on NodeBB: Node.js-based forum software
"modern web" doesn't have to be node based, but just about any web app is a suitable use case for node.

The exceptions are web-apps that require heavy backend computation (javascript/node sucks at that), but even then you could use node + a work queue that's handled by a more appropriate language.

Nodejs has arguably the best websocket implementation of any language and has mature drivers for pretty much every database backend. It has various templating frameworks etc.

A BB just needs a database at the backend and a way to get that data out to a browser. In that regard, nodejs is more suited than many other languages.

I don't really get your comment since it seems to imply that writing it in nodejs comes at some cost and you need to justify that cost by saying you expect a lot of traffic. I've seen this attitude before when someone writes something in assembly.. "Oh, you're hand-optimizing your program's assembly? Unless you really need that performance I wouldn't think it's worth it to use assembly". The thing is, nodejs doesn't have all that many problems. Sure, there's the massive number of warts of javascript, but people have learned to write readable and less-buggy code in the javascript ecosystem at this point (promises, jslint, etc).

So to repeat my answer to your question: no it doesn't have to be nodejs to be "modern web", but I do think nodejs is appropriate for this use case.

euank··on Show HN: GitHub-based DNS Hosting
I don't see a way to add txt records, which are important for many things. Nor do I see srv records or others.

The documentation also doesn't make it clear because it links TinyDNS format, but says you're using a simplified version without mentioning any real details.

Are there any plans to support / document these other record types?

euank··on Webkit.js
You could, but it would change scope a little. Right now, it's reasonable to expect that information will not be leaked to external servers, but user interactions can be faked.

On an information only webpage (no user interactions) there's no need to have the X-Frame-Options to remain secure. If there's a way to access the data in that frame suddenly, that changes the necessity of that header.

euank··on Webkit.js
That's not a solution for the general problem of getPixel + iframes though.

Here, I'll give a simple example. Let's say there's a site that uses cookies to track logins. For example, hacker news. Now, hacker news does have the X-Frame-Option Deny, but let's assume it doesn't.

So to figure out my hacker news username, all you have to do now is create an iframe with hacker news, and then getPixel on the area of the frame that contains usernames, run some trivial OCR, and done.

Now, this issue is even more serious in other instances. For example, google talk widgets are embedded by iframes I believe.

In both these cases, a fresh rendering would still have the inappropriate material due to cookies. If cookies aren't sent, e.g. you do a fresh render in a private tab, it would still have security concerns for anything that displays different, sometimes private, content based on ip address.

For an example of that, you could render "private.internal.company.localsite" in an iframe and if a visitor from that company visited, even a cookie-less load would probably show private data due to the internal site relying on ip/nat controls.

euank··on On Mining
I find your claims that "worry comes in when a 51% minor is a bad actor" and "safe in GHash's hands" to be conflicting.

All it takes is one bad actor at GHash, as supposedly happened with the gambling incident, and suddenly you've got a problem again.

Just because GHash is successful now does not mean they won't change. Let's imagine a future where CEX.io decides to ditch GHash. GHash no longer has any form of profit (0-fee pool) and thus has no incentive to remain honest.

Satoshi's logic, that a large minor would have a selfish interest to be honest, actually completely falls down when it comes to mining pools. Mining pools have massive power, and yet (in this case) get 0 profit. GHash could easily have nothing invested in bitcoin while still having control of a large gashing power.

Now on to the other things you said. "Would Bill Gates ... for a penny?" is a terrible analogy. For one, this isn't a penny. 51% attacks could allow GHash to steal millions and extort further. They would also allow someone with a vendetta against bitcoin do do real damage... And the risk isn't nearly as severe as jumping in a volcano. A more relevant analogy might be "Would a company commit tax fraud on the order of a million dollars and risk being caught" (yes many have) or "would an executive steal from the company he works at and, when they notice, cut and run."

Your theoretical for what happens on a 51% attack is also silly. There would be signs of some attacks (like consistent double spending on high-confirmation things), but other attacks like extortion-for-inclusion could be silent for as long as the victims don't speak up. Furthermore, people wouldn't leave overnight.. not that many did when GHash performed attacks the last time. In addition, people are highly unlikely to change. Things won't drop off over night. They weren't DDOSed last time. Your entire speculation is optimistically assuming there won't be significant doubt and inertia... and betting against human lazyness is rarely a good idea.

Finally, you assume GHash is left with nearly worthless bitcoins. Well, sort of. The extortion could lead to them being paid in anything. If the entire company decided to do an attack they'd obviously sell all bitcoins first so any new bitcoins gained through any attack would be pure profit (and wouldn't be worthless for at least several hours until someone notices and news spreads). Furthermore, each employee of GHash that is capable of causing such an attack to occur might not have any bitcoins, even if GHash does.

I think that your defense of GHash is flawed, especially considering they've behaved badly in the past. and your arguments in general aren't strong.

I see it as fully plausible that if they maintain 51% hashing power for an extended period of time, a bad employee might modify their code for their own profit and then GHash will plead ignorance when it's discovered and carry on. I also see it as fully plausible that if GHash decides to close shop at over 51% they'll choose to go out with a bang and do what thievery and damage they can on the way out.

I fully agree with the article that this is a problem.

euank··on Abstract software patents struck down by Supreme Court
There are no ramifications for the USPTO.

In addition, approving a patent takes almost no work while not approving one takes significantly longer and can have more bouts of back and forth.

The USPTO right now operates on a very loose definition of 'patentability' simply because it is more convenient to do so and the course will sort it out eventually anyways.. and there's absolutely no downside for them other than their own conscious.

euank··on The K8 Javascript Shell
I wholeheartedly agree, especially with the "unable to read a line" comment the author has.

Perhaps he has never seen the "Lazy" nodejs library which lets you simply do new Lazy(fs.createReadStream("data.txt").lines.forEach(handleLine));

The claim that "other programming languages have ways to read lines" is sort of true in that many do, but they don't do it significantly more efficiently than implementing it as above.

Nodejs certainly is minimalistic if you look at the core modules, but the minimalism does not get in the way of accomplishing the goals the author describes; rather it simply leaves them up to userland to implement (which they have been many times).

euank··on NAS Distribution Shootout: FreeNAS vs. NAS4Free
It appears to not support ZFS.

That's basically a no-go for me by itself.

euank··on Chinese government reveals Microsoft’s secret list of Android-killer patents
I understand that logic and have heard it before.

However, it has a fundamental problem. Patents do not protect abstract ideas; they protect concrete inventions. I cannot patent "a means of traveling backwards in time" because that is an idea. As far as we know it's also impossible. You can't get a patent on "A surface that has zero friction" unless you also create that surface and explain how to do so. The idea that any physicist who is "skilled in the art" could figure out how to create such a surface from the laws of physics (which it surely must follow) is silly.

On the other hand, software patents are exactly like that. I can patent "A method whereby clicking a button solves P=NP" and simply claim that the solution is produced somehow. I have to give no example implementation or even very specific details. This is highly at odds with other industries.

I do understand the legality of it, but it's still significantly different than other fields and leads to inane results.

euank··on Chinese government reveals Microsoft’s secret list of Android-killer patents
This is one of the reasons software patents are dumb imo; they don't actually share sufficient details to implement the idea any more easily.

In other fields, such as mechanical engineering, patents are required to describe an invention in enough detail that a person "skilled in the art" could reproduce it.

In the field of software, the patent merely has to describe the invention (software) well enough that it can be identified, not written. To match other fields, where it's common to require essentially full bluprints, it would make sense to require working source code (if only a reference implementation) for any software patent.

As is, the patenter "gifts" the public with the knowledge of an idea which is rarely in itself useful; the source code could at least be potentially useful.

euank··on Using BitTorrent Sync to live-edit or deploy websites
I've never used Teamcity, but it looks nice. I do agree chef/puppet can be overkill when you can just do custom AMIs. Definitely make sure you're using proper version control... Honestly, you don't give enough information for a proper opinion, but it'd probably be more informative to just do what you think is best and see how it works out. Ultimately the best workflow is the one that works (even when things go wrong).
euank··on Using BitTorrent Sync to live-edit or deploy websites
This is a bad idea for several reasons.

The first issue is security. Loads of text editors create temporary files (.swp, .php~, etc) in the same directory as the file you're editing. These can render as text instead of going through php, thus revealing things like database secrets and such. Now, this problem won't always occur and can be configured around.

However, perhaps the bigger problem is that this is simply a bad workflow when a better one exists. For "live editing", run a local webserver. Don't expose your playing around to the world, potentially breaking your site for others. Heck, if it's a static site, just run "python -m SimpleHTTPServer" if you like. Second, for deploying, you should have a better process than "sync this directory". Specifically, you should have git hooks that handle deployment if you want don't-think-about-it instant deployment. Preferably you have CI that deploys after it passes a few tests. Using git also has other benefits like letting you have commit messages, easy rollbacks, different branches (which you can auto-deploy to test / dev / etc).

Basically, the problem with using Dropbox or BTSync to edit websites is that you rarely want to throw partial changes to the world, and file sync programs like to sync as often as possible. It's a cool idea, but those sync programs simply don't replace proper version control and CI.

I'd even prefer rsync if you're not using version control simply so you can control when it syncs and setup complex excludes / shell scripts to run around it. You could easily have a script that runs a minimizer and then rsyncs the output while having rsync exclude any potentially accidental files. You can't do that nearly as easily with the workflow the author is talking about.

euank··on Towelroot by geohot to root Galaxy S5 with one click
Why do you even need to root a Nexus 4? It just lets you unlock / root it out of the box with no more effort than plugging in a usb cable and installing fastboot/adb.
euank··on 42.zip (2004)
Your answer is wrong. He says "Just given the raw zipped data and no size metadata".

The page calculates it using exactly that size metadata he excluded.

The question, as I see it, is if that size metadata (the 4.3 gigs at the bottom) can be determined from the zip file without unzipping a rather lot of data.

It would be interesting if someone who knew the exact details of the zip format could comment.

euank··on Only Apple
>the people at Apple genuinely want ... to enhance people's lives

I believe that too. However, I think that's generally true. You could replace Apple by Google or Microsoft there.

People on a whole are generally good (or at least I believe so).

If what you meant to say was "Apple cares about people and wouldn't let profit motives let them make questionable decisions, like including ads or adding DRM to software " then carry on.

If you indeed said what you meant to in your second sentence, then I think it was essentially meaningless since it's so generally true.

euank··on Show HN: A browser-based IRC client built on Node.js – first Node project
Other browser-based irc clients written in nodejs:

KiwiIRC - Probably the most used of them. https://github.com/prawnsalad/KiwiIRC

Subway - I've been following this one for a bit because it look promising. It's nice. https://github.com/thedjpetersen/subway

nirc - This one is pretty simple and I'd say a little less polished than yours, but still does a lot of things right. https://github.com/cjstewart88/nirc

If anyone knows of others, I'm interested.

I'd also like to plug glowing-bear (https://glowing-bear.github.io/glowing-bear/) since it's a rather cool project. It's an entirely static html5 frontend to weechat.

euank··on Netflix responds to Verizon
Here's an archive.org link: https://archive.org/details/netflix-response-to-verizon-dema...

Direct link (not sure if this is the best direct link you can get from them): https://ia902509.us.archive.org/21/items/netflix-response-to...

euank··on 64-Bit Chrome for Windows
What would be great is if Google supported other 64-bit browsers on windows. Mozilla doesn't really officially support it, but they've provided 64-bit nightly builds for quite a while now. For example, the current nighly 64-bit can be found here: https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/late...

Flash, Java, Silverlight, and so on all have 64-bit variants which work, but there's just no way to get the Google Talk and Hangouts plugin to work on those builds of Firefox.

Seeing the title gave me a bit of hope until I thought "No, of course, Google just bundles the plugin anyways... not like they'll publish a download link for a 64-bit build". I wouldn't even care if you had to click through several "Other system / Select custom download" links, if only it were available at all.

I feel like we have a chicken-egg problem. Firefox isn't offering 64-bit prominently because plugins have terrible support for it, and plugins don't support it because it doesn't exist yet... But, unlike Firefox, plugins can offer 64-bit compatible versions without angering a large number of users. Really, the ball should be in their court, Google included, to provide the options.

euank··on M64.pl – how I learned that the default settings are not production settings
Assuming you're referring to the font of the blog's text...

Firefox: Right click, inspect element, click the "fonts" tab on the right.

Chrome: Right click, inspect elmeent, look at "Computed" styles on the right, find Rendered Fonts.

Ironically, the answer is he's not using a font. It uses Times New Roman on my Chrome and DejaVu Serif on my firefox because those are my default system fonts, not because he specified them. If you look at the source of the webpage, you'll see he has zero stylesheet links, all his styles are inline in <style> blocks... So searching font in that one source page is sufficient to find he only styles code blocks, the rest is default.

If you're referring to some other font, I have no clue, sorry!

euank··on M64.pl – how I learned that the default settings are not production settings
For anyone wondering how to properly troubleshoot in this manner without breaking things:

Run 'sudo su www -s /bin/bash'. using '-s /bin/bash' will override the usual nologin shell, and running 'su' as root will mean a passwordless account can be su'd too.

This will allow you to try accessing files and directories as if you had the user 'www's privileges without having to make the 'www' account regularly usable.

You should never set a real shell or password for any accounts that a real user will not be using.

euank··on PythonJS now faster than CPython
Javascript (6) has those in the form of Proxies [0]... Coming soon! I think that they cover the set of features you indicate anyways.

However, you can already hack them in and there are multiple js projects that let you compile ES6 down to ES5, proxies included.

As other commenters noted, python is not "more dynamic" than javascript. You can easily transform python code that does unusual metaprogramming stuff to javascript code that does similar metaprogramming stuff but looks significantly different; basically all languages that support runtime-eval will let you imitate all other metaprogramming features in a somewhat verbose fashion.

[0]: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...

euank··on The Last Line Effect
I think that's a function of text editor or workflow often.

A vim user that makes heavy use of recording and/or search-replace will be able to do large copy-paste-edits very quickly.

In fact, I think this might be another potential source of error. Depending on how the recording is done, or how an edit is scripted, it's very likely that the first and last lines are the two special cases. The first line, however, will be given the most scrutiny. This leaves another potential source of "last-line" errors; the use of editor features that make such a line the exception.

euank··on The security hole I found on Amazon.com
I find it ironic that the wikipedia page on clickjacking [0] lists exactly this exploit as the example, and yet noone has reported it or fixed it in all this time.

[0]: https://en.wikipedia.org/wiki/Clickjacking#Examples

Edit: This example was added to the wiki page in December 2009. Relevant link: https://en.wikipedia.org/w/index.php?title=Clickjacking&oldi...

euank··on Flickr is removing Facebook and Google sign-in
Well, if you don't mind Google, Google+ lets you handle images pretty well. I would have said picassa before, but that was merged into G+ (and some features were lost I think).
euank··on The URL shortener situation is out of control
This still doesn't stop all use-cases.

Click count statistics, time-clicked, and geo-information can all be gotten without any cookies. Some sites use url shorteners just to see clickthrough statistics, which can always be determined with no cookies etc.

← PreviousPage 2 of 5Next →