HNHacker News
TopNewBestAskShowJobs

evan_a_a

161 karma · joined February 7, 2025

submissionscomments
evan_a_a··on Building a certificate authority for the whole Internet
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.

https://cabforum.org/working-groups/server/baseline-requirem...

evan_a_a··on U.S. State Department pauses immigrant visa applications
A green card is permanent residency, not a visa process.
evan_a_a··on The University as We Know It Is Finished
>>Professors should teach about AI, include how to prompt efficiently and how to critically scrutinize the output

>100% agree, as with any important technology. But this is just a small curriculum change, just one more topic to cover in the lecture, and maybe a class.

Critically scrutinizing LLM output is just critical thinking skills, something universities should already teach.

evan_a_a··on Universal health coverage could save $1T and 114k lives a year: study
Healthcare worker shortages are a problem in the US and other developed countries with universal systems. The type of system doesn't really influence the waiting time.
evan_a_a··on Flock impersonates journalist in order to cancel his hotel reservations
That comes with a contract between the hotel and the block holder.
evan_a_a··on Flock impersonates journalist in order to cancel his hotel reservations
If the journalist really did make a reservation under the room block for the event, and then was denied attendance to the event, it would seem fairly normal for the reservation to be canceled by the block holder.

Really, if the journalist wanted to cover the event without being noticed he could've done so undercover.

evan_a_a··on Illinois just told every operating system to start reporting your kid's age
Encryption does not ensure data integrity, sigh...
evan_a_a··on What happens if an entire class of workers loses faith in their careers
Translator jobs aren't really getting wiped out according to the stats (in the US). Growth is still projected at 2% in the next 10 years.

They also have this to say about AI:

>Computer tools, including artificial intelligence (AI), are making the work of translators and localization specialists more efficient. However, many of these jobs cannot be entirely automated because computers cannot yet produce work comparable to what human translators do in most cases.

https://www.bls.gov/ooh/media-and-communication/interpreters...

evan_a_a··on US strikes $1.2B deal to pay German firm to halt offshore wind projects
They've been in a stop work since April 2025 so that buildup is likely all gone or already reallocated.

https://www.reuters.com/sustainability/climate-energy/rwe-ha...

evan_a_a··on US strikes $1.2B deal to pay German firm to halt offshore wind projects
They'll certainly continue wind projects, just not likely in the US and not with this money.
evan_a_a··on US strikes $1.2B deal to pay German firm to halt offshore wind projects
>RWE said that it will now reinvest the sum into conventional gas projects, including $900m (£669m) in a liquefied natural gas (LNG) export terminal project in Louisiana.
evan_a_a··on How to think about software quality (2022)
If the design is so inflexible that a single requirement shift destroys it, then it wasn't a good design.
evan_a_a··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
This is contingent on the sealing policy including PCRs that would change as a result of booting a different operating system, like PCR 11, which, when booting a UKI, contains those measurements. Only sealing against PCR 7 would allow this attack, since the default platform secure boot policy would not need to change.
evan_a_a··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
The keys can be indirectly sealed against specific system and software configurations such that this attack is not possible. Additionally, as you noted, using custom secure boot keys would prevent the attacker from booting an arbitrary OS.
evan_a_a··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
The disk encryption key(s) isn't typically stored in the TPM, it is sealed by the TPM. A sealed key can only be unsealed if the TPM is in the same state as it was sealed against (simplifying some things here). With the proper selection of Platform Configuration Registers (PCRs), this can prevent the key from being unsealed if the system has not securely booted (sealed against PCR 7). In more complicated configurations, it is also possible to seal the key against a particular phase of boot such that it can't be unsealed once userspace is reached.

In your scenario, yes it is bad if the attacker gets root on your computer, but sealing the key with the TPM means they can't retrieve the key itself. Where the TPM helps is preventing the attacker from establishing low level (kernel, bootloader, or firmware) persistence, since modifications of these components would change the TPM PCR measurements and result in a boot failure.

If the attacker is local and they reset the UEFI, the TPM PCRs are now different and as before, the disk encryption keys will not unseal.

It is also generally recommended to use a pin with TPM, which further complicates this scenario for the attacker because the TPM enforces rate limiting. As the other commenter mentioned, the physical access scenario is commonly a stolen laptop situation, where the attacker would not be in communication with the victim and probably wouldn't return the laptop.

evan_a_a··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
Far better to just use the raw tools and manage it yourself ala arch wiki:

https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR...

evan_a_a··on GrapheneOS protections against data extraction from locked devices
Border searches are special case in US law where the 4th amednment protections aren't as strong. See the EFF page about it for more:

https://www.eff.org/issues/border-searches

evan_a_a··on So Reddit has decided that plain HTML is unsafe
According to stats on a relatively small local sub I mod, most people interact with Reddit through the mobile app these days. All of the web interfaces make up a small percentage of visits, and old.reddit is even smaller.
evan_a_a··on Interstitial risk: when two secure systems make one vulnerable one
The author is describing a practice that is already well known: Systems engineering. Applied well, systems engineering helps prevent many of these issues from happening in the first place. Unfortunately, outside of heavily regulated industries or critical systems (like aerospace, as mentioned), systems engineering practices are rarely applied with the proper level of discipline.
evan_a_a··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
>We very much fear at $work that there are vulnerabilities in the Tailscale product awaiting discovery

Spoiler alert: This applies to all software. This is why security preaches defense in depth.

evan_a_a··on Sandia National Labs SA3000 8085 CPU
Modern process nodes with smaller feature sizes are likely to fare far worse under radiation than the nodes of 25 years ago.

Additionally, total dose is only one part of the equation. Single Event Effects (SEE) also must be mitigated.

You can read NASA JPL's ASIC design guidance for a brief intro.

https://parts.jpl.nasa.gov/asic/Sect.3.4.html#A0

evan_a_a··on Sandia National Labs SA3000 8085 CPU
Yes, the Xilinx space grade devices are engineered and qualified for radiation tolerance. These are FPGA socs and share no heritage with AMD desktop and server processors.
evan_a_a··on Spain's Solar Is So Cheap Investors Are Looking for an Exit
This is an economic problem due to the poor level of interconnection between the Iberian Peninsula and the rest of Europe. It is also something that is actively being worked on. With better interconnection, renewable power could be more readily exported to the rest of Europe during peak generation, rather than ending up in the situation described currently where renwable generation is forced offline.

https://energy.ec.europa.eu/topics/infrastructure/high-level...

https://www.ree.es/en/ecological-transition/electricity-inte...

evan_a_a··on Sandia National Labs SA3000 8085 CPU
To my knowledge neither AMD nor Intel ship any processors that are rad hard or rad tolerant. For aerospace applications this is a very specific type of device which requires specific engineering work to achieve. You don't just get rad tolerant design through standard error correction and you definitely don't get rad hard without designing for it.
evan_a_a··on Credit cards are vulnerable to brute force kind attacks
I am a bit confused about your situation. Did you have a stolen card used to make a purchase at ebay that was not under your account? Or did you make a purchase at ebay and have an issue with the product you received?
evan_a_a··on Credit cards are vulnerable to brute force kind attacks
>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that.

>I got the money back via chargeback in short time.

So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, the banking system cares about fraud loss. And they are exceptionally good at finding the fraud. Making changes to the card payment system is extremely difficult, due to the vast scale of the systems, so without a very good justification that a particular change will move the needle on fraud rates, the banks will opt to not make the changes.

evan_a_a··on How Mark Klein told the EFF about Room 641A [book excerpt]
She has not yet left her role, and they haven't named a successor.

>The search committee hopes to hire someone next spring, with Cohn planning to remain at EFF for a transition period through early summer

https://www.eff.org/press/releases/executive-director-cindy-...

evan_a_a··on HERMES.md in commit messages causes requests to route to extra usage billing
place this alongside the classic "mcdonalds is a real estate investment firm"
evan_a_a··on How Mark Klein told the EFF about Room 641A [book excerpt]
Aka the Executive Director of the EFF.
evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
>Even that ignores the fact that major corporations are frequently attacked by state actors, so really the minimum standard for protection against expected threats should include those as well, but I will leave that aside for now since the overwhelming sentiment is that protection against state actors is so utterly hopeless it is not even worth mentioning.

It always has been, it's just now the state actors are more and more active (and visibly so).

Page 1 of 2Next →