HNHacker News
TopNewBestAskShowJobs

euank

566 karma · joined October 28, 2013

hn@euank.com
submissionscomments
euank··on Malcolm Gladwell ‘Surprised’ to Become an Amazon Bargaining Chip
Amazon did issue a statement: http://www.amazon.com/forum/kindle/?cdForum=Fx1D7SY3BVSESG&c...

"When we negotiate with suppliers, we are doing so on behalf of customers. Negotiating for acceptable terms is an essential business practice that is critical to keeping service and value high for customers in the medium and long term." is the relevant quote for how it's not killing customer experience.

The short term customer experience is indeed impacted, but in the long run, I'd rather have more reasonably priced ebooks.

Of course, this is Amazon so they're not going to just say "yup, we're doing this out of greed, screw the customer". It's up to you if you believe what they did say or not.

euank··on Who or What Broke My Kids?
He is talking about the same problem that is discussed in Lockhart's Lament [0]. If you've never read this piece of writing, I encourage you to do so now as it presents our math education system in a wonderful and critical light. I can't speak as elegantly as Lockhart, so I won't damage the piece by summarizing it or discussing it in the post; rather, I'll leave you to read it and draw your own opinions.

[0]: http://www.maa.org/external_archive/devlin/LockhartsLament.p...

euank··on Scribd and Quora considered harmful
Dropbox is a bad option if you intend to share it with too many people; pdfs are often large enough you'll get the "This account is generating too much traffic! Try back later" pretty quickly. Dropbox is great for sharing with the family or a small email list, but not for linking to the general internet.
euank··on LoopBack, a new Node.js framework by StrongLoop
Yeah, the HEAD or GET should return a 404 on not existence; however, the HEAD also won't return data which is the point. GET implies that you have need of the returned data (presumably all the properties of that person). GET is for "it exists AND I want to know about it". HEAD really is more appropriate here.
euank··on Show HN: WordPass – password generator giving over 90 bits of entropy
That he has it or can get it, yes. Even if he doesn't have it, there are a few dictionaries (/usr/share/dict/words on various popular distros would be a good start) he could try and only guess the probable options in both of them.

Furthermore, it's possible he could figure out which dictionary you were using by another means. If a site that stored your password in plaintext was compromised, that would give him 4,5,whatever words in your dictionary, and using a similar attack on this flawed prng as discussed above, he could narrow down the possible positions of those words, thereby figuring what dictionary is most probable.

The assumption that the attacker can get your word list in this sort of password scheme is actually implicit in how the entropy is calculated; it's calculated assuming the attacker is stringing together words from the same known source in the same general format.

euank··on One reason I dread Google doc shares
I haven't used it in a long time, but I did use it at one point.

It's just not as good security and privacy-wise. Using proxies on/off on one profile, as it encourages, results in any tracking cookies seeing both IPs having the same tracking data, and thus your proxy has lost some of its privacy.

I also run entirely different extensions when I'm going for privacy vs fun browsing vs banking etc etc.

If you just want proxies to get around some region restriction and don't really care about the privacy or security aspects, then FoxyProxy might be fine.

euank··on One reason I dread Google doc shares
The firefox instances have completely different processes, settings, etc. Everything. Chrome, unless I'm mistaken, does not go that far.

For example, one of my main uses of multiple-profiles is that I have a different profile for every proxy I use. I can launch a firefox profile that's proxied side-by-side with my usual firefox (aside, the firefox proxy settings are exposed via the UI, unlike chrome).

Chrome, I'd have to run "google-chrome-stable --proxy-server=$proxy" and then, again unless I'm mistaken, all accounts will use that proxy server. That, by itself, is a deal breaker.

I'm not familiar enough with chrome's settings and so on to say what does and doesn't leak; I could be completely wrong on all of this, but I suspect I'm correct.

Edit: On looking more, Chrome's does look more complete than I thought. The proxy bit still is a dealbreaker for me (well, and I'm adverse to logging into a google account), but I retract much of what I said.

euank··on One reason I dread Google doc shares
You can easily use a firefox profile per account rather than a browser per account and end up in roughly the same boat.

Just start firefox with "firefox -P" to create a new profile, and run "firefox --no-remote -P" on a new instance of firefox and choose that profile to run it side-by-side with your first, but with no data overlapping.

euank··on One reason I dread Google doc shares
Firefox has an even more powerful version of this.

If you start firefox with the "-P" flag you can choose to create a new profile. You can also pass it an argument (e.g. firefox -P default) to choose one.

In this case, the profiles are completely disparate; there is zero overlap. In this case, you simply have to login to one google account per window and paste into the correct window (still not ideal).

To run multiple profiles at once, launch all profiles after the first one with "firefox --no-remote -P <profile-name>". Clicking links will open them with the firefox that was launched without "--no-remote".

euank··on Show HN: WordPass – password generator giving over 90 bits of entropy
We need to just get away from remembering passwords. Something like Mozilla Persona would have been great, but since it didn't catch on we already have KeePass (and for mac/linux, keepassx2 alpha works quite well).

These cutesy little passwords might be fairly strong and easy to remember, but it hardly matters because having to remember them results in reuse and an upper bound on the possible entropy. The human mind has more important things to do than remembering thousands of bits of entropy (spread among all your passwords, you should have at least that much)... we made computers to remember this sort of stuff for us.

If these passwords aren't meant to be remembered, but put in keepass, then there's no point in not just upping the entropy by randomizing at the character granularity.

KeePass makes it much easier; you have it generate you 300 bits of entropy passwords (or whatever you feel is enough), and then you can focus all your security efforts on that one database file. Having a "single point of failure/password" doesn't have to be bad because it lets you guard more closely against that single point.

euank··on Show HN: WordPass – password generator giving over 90 bits of entropy
To expound on the other response.

A PRNG is only as random as its seed / starting state. Let's say it gets this state from the current time, in milliseconds.

Now, let's assume the attacker knows, based on your "Time joined" statistic for some account, a roughly 2 minute period of when you generated your password (it's very common for a website to show time joined in the granularity of a second through an api; passwords are rarely generated more than a minute beforehand if you use a generator + keepass). 2 minutes is 3,600,000 milliseconds... or in other words, they can seed the RNG with all 3.6 million "time-in-milliseconds" and run the program and see the output. They now only have to guess 3.6 million possible passwords, not, say, 1e20 (assuming a dictionary of 10k words). That's a massive speedup on the order of 1e14.

I hope that all made sense... the basic idea is just if the attacker can make any sort of estimate about the state of the PRNG, he can just test passwords generated from states like that, not all possible passwords.

You'll notice, of course, that this vulnerability relies on the other party being able to discern some information about the state. This doesn't have to be from guessing the seed directly (as was the case in the example above). It can also happen by observing multiple outputs and guessing at what seed could produce them both, or noticing a bias.

The last one, the chance for a bias, is quite possibly what you're asking about. "How could a weakness in the randomness be a problem at all in this case?". A weakness in randomness means that some combinations of words will show up more often than others, by definition. It makes the password weaker because the attacker can discover this bias and then guess more probable passwords first.

euank··on CEO writes tech hiring blog post, everyone winces…
I've got a possibly naive question about DropletPay.

I was under the impression that Apple essentially took 30% of all money that flows through an app. Is there an exception for payment / ecommerce apps? Is there a special agreement in place? Is this app a "timebomb" that just hasn't been noticed by apple yet?

It's possible that the "30% of all money" is a bit of misinformation; I can't find where Apple's app policies are enumerated.

I'd be interested in knowing and I have no doubt someone here has a good idea.

euank··on Did You Say “Intellectual Property”? It's a Seductive Mirage
I find your assertion that basement hackers never "invent" silly. Heck, Google/Pagerank started in a garage, as the saying goes. The demo you link is amazing and I'm not sure anyone has topped that in or out of a company since, but using that as proof that only companies and governments can invent is fallacious.

Many other statements you make are downright false or silly. For example, you say "the GUIs are copies of Windows or Mac" and yet I've never seen a powerful tiling window manager on those two OSs ... certainly not before I used them on Linux. There might be similarity between some WMs and others, but there are dozens that are fairly novel.

The "Basement / Garage hacker that changes the world" you say is a myth; and yet Google and Apple both have undeniably changed the world despite originating with basement hackers.

Furthermore, the industry has moved to open source where it's easier for a basement hacker to do something big. At the time that video was made, you would have to create practically everything from the ground up. There was no free code to build on. Anyone might have had an idea expressed in that video, but he or she would have had great difficulty implementing it in a basement due to lack of resources to make the whole stack.

Nowadays, if I have an idea, there's a good chance many components of it are already done in the open source sphere, and I can "stand on the shoulders of giants" and implement my idea with minimal work. The ability to create slow and steady progress and have such diverse bases on which to build, I think, makes the basement hacker far more possible. The jump from idea to working product is now much shorter in the software world than ever before.

Next, you say "basement hackers can innovate ... but it certainly doesn't invent". I honestly don't see the difference you're drawing between innovation and invention. innovate is the verb that creates inventions, the noun. I'm just not seeing what you're trying to do by creating that false dichotomy.

I also think you have the intent of "IP" a bit wrong. Patents are supposed to grant limited monopolies to people who have innovated. IP also covers trademarks and copyright which each have nothing to do with "innovative work" paying. By using IP there, you just fell into the trap of the article you're commenting on (I recommend reading it).

Furthermore, you say patents are meant to reward innovative work. That's simply false. Innovative work rewards itself. If you invent something truly innovative, you'll make money selling it. If patents were only meant to reward, they would have no requirement of disclosing sufficient details to reproduce the invention. What patents are meant to do is help the economy and industry as much as possible. A patent requires an inventor to disclose his invention and gives him a limited monopoly. The disclosure is meant to allow others to use his idea to create further inventions. The monopoly is to encourage people to disclose ideas at all, not merely hoard them as trade secrets.

"Invention is also hard for startups because there is little to no way to monetize it." ... The whole point of a useful invention is that it solves a problem in a novel way. Surely people with that problem will want to pay for the solution that didn't exist before?

euank··on The Truth on OpenGL Driver Quality
It's not a hack in that it's held together by tape, precarious, or any such thing; it's a hack because it's going around the back of SDL to do the graphics, even though SDL is supposed to do all the graphics for you.

Perhaps my wording was poor. It's more of a hack than in SDL2, where all the SDL functions support hardware rendering with no need to touch OpenGL directly ever.

The general point still stands that you can write performant software rendering in SDL1.

euank··on The Truth on OpenGL Driver Quality
To expound on this comment: SDL1 defaults to fully software rendered output. You can hack in opengl hardware rendering, but it's fairly common for SDL1 games and such to be fully software rendered and run fine.

SDL2 in general is hardware rendered.

SDL1 is a good counter-example to "software rendering isn't quick enough anymore". You can make perfectly performant 2d games with sdl1's software rendering... 3d, not so much.

euank··on Oracle continue to circumvent EXPORT_SYMBOL_GPL()
You will doubtlessly get many opinions on this.

It's worth keeping in mind that the "dev time" is a function of existing libraries, internal and external. At any fairly large company (e.g. Google) that has many existing internal libraries in some language (java), the dev time will be massive to switch. By this logic, the dev time is too costly for absolutely any language you pick other than the one being used. There is little exception to this.

For a programmer or programmers with no legacy cruft, I'd argue that dev time is more a function of the programmer's familiarity with a language than the language itself. Perhaps there are a few exceptions to that, but in general I don't think that a language should be described as "too" anything. Java might be memory inefficient, but does that mean it's usage "too high"? Clearly not for some people as it's still used frequently.

euank··on Google Maps Has Forsaken Us
My issue with Chrome's UI is that it is inflexible. I agree that the content area is important; as such, my firefox displays much more content (while also displaying more useful icons IMO).

In Chrome, you take what Google gives you and you better like it. I'll admit, it's not a bad default.

Firefox, however, allows addons to fundamentally alter the appearance of the webbrowser. I can add stylish themes that do all sorts of awesome things. I can use vimperator with "set gui=nonavigation" and reclaim even more space for content.

This fundamental difference is the reason I think Chrome's UI is bad. Firefox, you can customize the gui to be good for any definition of good. Chrome's only works if your definition of good aligns with Google's.

Also, for an example of when Chrome's UI fails, simply try and half-screen it on a 1080p screen with 30+ tabs open. All the tab favicons vanish. There's no way to search for an existing open tab (akin to firefox's % Location Bar Search character[0]).

If you'd like, I could show you my firefox and chrome running side by side with firefox having dozen's of more pixels of content-viewing area. Even if you don't like my setup, the fact that I can change it at all makes it an obvious win for me.

[0]: http://kb.mozillazine.org/Location_Bar_search#Location_Bar_s...

euank··on Royalty statements of a Grammy-nominated artist
views != plays anyways. Some viewers probably played Gangnam Style dozens of times. It's possible those 15,000 plays came from only 1000 people listening to it 15 times each, thus being comparable to only 1000 youtube views.

Basically, it's an apples-oranges comparison in more ways than just youtube ad revenue != royalties. The metric is different as well.

Of course, your basic point that 15,000 is big number, which should probably be worth much more than 5 bucks, still stands.

euank··on Bit.ly compromised – More Details
Why not just ignore the bcrypt portion? "Intuitively" it seems to me like you could just un-concatonate the two strings and guess at them separately, working on whichever you know to be easier.
euank··on Amazon granted patent for taking photos against a white background
Patent law requires something to be "non-obvious". It cannot be a single step away from a previous patent. This patent would count as prior art for such an obvious change, and as such the patent you describe would not be valid or granted.

Non-obvious is supposed to be a broad term, but in reality a patent examiner will just search through prior patents for prior art. In this case, if you really did copy everything else word for word, he or she would very quickly find the existing patent and deny you.

euank··on Tech firms write to U.S. FCC to oppose 'net neutrality' plan
On the contrary, I'm glad they aren't throwing money at this.

Throwing money at things sets a precedent; if they let things run as they are now, it's quite possible that the bill will fail (like SOPA did) due to public outrage, not due to money.

The fact that politics is powered by money in the US is terrible, and the more exceptions there are to that, the better. I think this can set another precedent.

I think the big tech companies should only toss money in if the current efforts fail, as a matter of efficiency, morality, and precedent.

euank··on Two Equals Four (2011)
Fyi, "3/3 = 1" is true as well, which you seem to be indicating is not the case. 3/3 does not approach 1; it is exactly 1. In fact, the idea of "approaches" cannot happen with just rational numbers. You need a limit in order for the word "approaches" to be correct. I think you need to read up on math terminology a little (and just math in general) if you want to try and discuss this... though there's no point discussing this because that implies there's more than one side.

In the case of .99.., that could be expressed using a limit and thus you could say it approaches 1, though it's much more accurate to say that it equals 1.

euank··on [dead]
codedicks is an obvious parody. In fact, it only has two pages, no real content. Just try to click "Sign Up" or "Log In". You can't. The videos and education don't exist.
euank··on Samsung to jury: You can't copy iPhone features that aren't in the iPhone
Not at all. Samsung's argument is not that the patent can't be litigated because it's not in use (in fact they state the opposite). They're merely claiming that they couldn't have "copied the feature" from the iPhone, as apple claims, if the feature never existed in the iPhone. It's a counter to Apple's statements, not a legal precedent.
euank··on Firefox and Flux: A New, Beautiful Browser is Coming
I run my own firefox sync server, and have since it was introduced. It's working fine for the current version of sync. There's a rather helpful guide for setting it up and there were a handful of alternative server implementations which have unfortunately fallen by the wayside.

https://docs.services.mozilla.com/howtos/run-sync.html

euank··on Ruby Security Have You Not
It appears that you failed to read the data correctly. He says that 66% of the Gemfiles examined contained any vulnerability and 13% of them contained a 5+ issue.

That doesn't even mean an exploit btw. Some of those gems might be in the Gemfile but never actually used (deprecated but not removed, hence not updated), or the vulnerable component might never be used. The gem might only be used on internal data, not user-manipulateable data.

Furthermore, you can't extrapolate 13% of the examined gemfiles containing such an issue to all gemfiles, which you did.

The fact that it's reported certainly doesn't mean it will be fixed in all downstreams (what this article refers to). Do you read every CVE? Every single one? Didn't think so. Most gems are relatively unpopular and any issues in them won't be widely publicized. Sure, Rails issues are shouted far and wide, but most of the rest are easy to miss.

Hell, some CVEs don't even get fixed in the gem itself, let alone all the consumers of that gem; the gem just remains vulnerable because there's no maintainer or the maintainer insists that it's "not an issue".

Please don't make such misinformed comments without even reading the article with sufficient attention to detail to get the statistic right.

euank··on Am I evil, or is killing patents just plain fun?
The problem with "patenting an algorithm" is that it's "not allowed" by the rules of patents. You cannot patent laws of nature, like math (not that that stopped everyone [0]). Algorithms are purely mathematical constructs. The idea that someone "owns" something just because they discovered it, not invented it, is scary.

Of course, I'll give you that algorithms sort of feels like a gray area. Even though they're pure math, they also sometimes feel like inventions to me.

[0]: http://www.amazon.com/Math-You-Cant-Use-Copyright/dp/0815749...

euank··on Heartbleed disclosure timeline: who knew what and when
Amazon Web Services was explicitly listed in the group of companies at the bottom that did not get notification.
euank··on The Operating System That Can Protect You Even if You Get Hacked
No, I had no clue that was the case! That's pretty reassuring to know. It still doesn't change that my confidence in the Hyperviser has been shaken a little, but I trust this more knowing that, and I do think the premise of Qubes is great and relatively secure - if not certainly perfect.
euank··on The Operating System That Can Protect You Even if You Get Hacked
I don't see how that follows or relates; chrome's sandboxes are definitely not VMs... VMs are in general better understood and far better isolated.

Can you expound on that comment?

← PreviousPage 3 of 5Next →