HNHacker News
TopNewBestAskShowJobs

f-

1,101 karma · joined October 6, 2010

submissionscomments
f-··on Doomsday Prep for the Super-Rich
The last time this story made rounds on HN, quite a few readers were ripping into the people described in the article, and it sure feels good to do so, but... I don't know about you, but if I had more money than I conceivably ever needed, I sure would contemplate having a helicopter on standby and a luxury compound in some scenic part of the world. You know, just for fun, just in case.

In fact, I suspect that once you're in that particular wealth bracket, it's no longer about people who have contingency plans versus the ones who don't. I'm pretty sure that almost every Fortune 100 CEO has private security parked in front of their house and a plan to get out quickly something bad were to happen. There are many security consulting companies that cater exclusively to this segment - and they are doing very well. It's just that most of the CEOs won't talk about it to The New Yorker - partly because of opsec concerns, but partly because such revelations would make it even easier for us to vilify them.

And before we assume that their plans are lopsided and irrational, I think it's worth keeping in mind that the article is written to be entertaining. The author wants to tell us about the stuff that is out of ordinary and out of reach of mere mortals. That doesn't mean that the people featured in the article don't also have a fire extinguisher and some tarp and nails in their garage. Heck, perhaps 95% of their prepping goes toward more pedestrian risks? Perhaps they practice defensive driving and situational awareness? Perhaps they go camping or hiking every other week? Perhaps they take EMT courses and participate in community preparedness drills? Who knows... that stuff is boring. ICBM silos and helicopters are fun.

We should also remember that unlike many many of the stars of "Doomsday Preppers" who seemed inexplicably frightened by the prospect of social unrest in the US, the ultra-rich may actually have something to worry about. When angry masses take it to the streets, it's not the cookie-cutter, mixed income, urban sprawl neighborhoods that are going to be set ablaze. We had quite a few big revolutions, and it's usually the heads of the variously defined aristocracy that roll. It's not ancient history, too.

Lastly... one viewpoint presented in the article is that it's somehow immoral for the CEOs to worry about self-preservation instead of trying to give back to the community. I think that's a non-sequitur - is it also immoral for them to buy a fire extinguisher or install sprinklers before making the world a better place? - but more importantly, the two goals are not mutually exclusive.

PS. Disclaimer - I'm the author of http://lcamtuf.coredump.cx/prep/, so I might be not entirely impartial.

f-··on COP21: Arnold Schwarzenegger: 'Go part-time vegetarian to protect the planet'
The "top ten" list you linked to includes accidents (such as poisonings and falls), suicide, and influenza.

I do not mean to be a jerk and I am no meat apologist - but is meat consumption playing a direct, notable role in at least two out of these three?

f-··on I lost my OpenBSD full-disk encryption password
Off-topic, but my personal work sometimes ends up on the front page, and I'm always amazed how much reposting there is on HN - probably more than on Reddit and similar sites. Say, here's my stuff:

https://news.ycombinator.com/from?site=lcamtuf.blogspot.com

https://news.ycombinator.com/from?site=coredump.cx

The process seems quite random; sometimes, the same link is submitted four times and lingers at score 1, and then some random dude's fifth attempt goes to #1. May be an interesting thing to graph (and get a #1 story on HN out of =).

f-··on Google's login page accepts a vulnerable GET parameter
One important consideration here is that the phishing attack as described here could be pulled off even if the targeted site did not support redirects - and in general, it would be exploitable without any identifiable fault on the part of the "vulnerable" web app.

This property is an artifact of how browsers work, and it's not something that's likely to change soon. Basically, if you visit evil.com, evil.com can always load accounts.some-trusted-domain.com in a new window, give you enough time to examine the address bar and confirm that it's legit - and then sneakily navigate that window to a phishy location that looks the same as our legit login prompt, but is controlled by the attacker.

(The evil site can also detect certain events, such as navigation, and deliver the payload only at that point.)

For my whimsical demo for Chrome and Firefox (dating back to 2011!), see: http://lcamtuf.coredump.cx/switch/

(Disclaimer: I kinda wrote a book about this stuff. Also, I work for Google.)

f-··on This JPEG is also a webpage
Author here. Rookie mistake! It's actually a golden-mantled ground squirrel.

https://en.wikipedia.org/wiki/Golden-mantled_ground_squirrel

A chipmunk would have a stripe going across the eye.

(Today, you learned your first squirrel fact!)

f-··on Image-diff – Create an image differential between two images
Not sure I follow - especially if it already depends on IM, how is it different from 'convert -compose difference' or a similar operator?

http://www.imagemagick.org/Usage/compose/#difference

f-··on Online tracking: A 1-million-site measurement and analysis
Although the emphasis on the actual abuse of newly-introduced APIs is much needed, it is probably important to note that they are not uniquely suited for fingerprinting, and that the existence of these properties is not necessarily a product of the ignorance of browser developers or standards bodies. For most part, these design decisions were made simply because the underlying features were badly needed to provide an attractive development platform - and introducing them did not make the existing browser fingerprinting potential substantially worse.

Conversely, going after that small set of APIs and ripping them out or slapping permission prompts in front of them is unlikely to meaningfully improve your privacy when visiting adversarial websites.

Few years back, we put together a less publicized paper that explored the fingerprintable "attack surface" of modern browsers:

https://www.chromium.org/Home/chromium-security/client-ident...

Overall, the picture is incredibly nuanced, and purely technical solutions to fingerprinting probably require breaking quite a few core properties of the web.

f-··on Doomsday planning for less crazy folk
> Assault with a hand is much less likely to end in serious injury than assault with a weapon.

Really? I'd take pepper spray over fists. I'm talking specifically about non-lethal choices, especially for people who do not stand a chance in a fist fight.

Most of Europe does allow pepper spray, stun guns, and similar tools, and they really don't see more violence than the UK. In fact, violent crime in the UK is fairly high in comparison with many EU states.

f-··on Doomsday planning for less crazy folk
I think this is pretty similar to the rest of the western world, and certainly to the legal frameworks in much of the US. The interpretation is probably very different, though. So is the legality of carrying weapons in anticipation of an assault...
f-··on Doomsday planning for less crazy folk
Interesting. Lethal weapons are banned in much of the world, but based on my reading of it, the UK seems to be pretty radical when it comes to non-lethal tools, compared to most of Europe. Looks like pepper spray, stun guns, or really anything else is not legal to carry.

Legal self-defense tools apparently include bright flashlights / strobes (I kid you not) and personal alarms.

It's actually a pretty extreme doctrine, no? The UK does not enjoy a particularly low rate of assault or rape, compared to most other western countries. If unarmed self-defense is the only thing you can try, this would seem to put smaller-framed women, the elderly, and less physically fit people at a distinct disadvantage. Weird.

f-··on Doomsday planning for less crazy folk
The guide doesn't go into specific instructions on how to find flood maps and doesn't do a risk analysis on everything (although it provides numbers for many of the more common risks) chiefly because (a) it's difficult to provide answers that are universally applicable no matter where you are; and (b) I sort of trust the reader to be able to search / ask around; (c) it's already 60 pages of text.

The other thing I sort of learned is that when you spam people with links to hundreds of external resources, you actually lower the odds that they will stay focused and read any of them.

But yeah, maybe a catalog of links to ready.gov and the like may be useful at some point. I actually had several, but I think I lost them in subsequent edits.

For the chemical tanker bit, see section 3.7, which talks about doing a risk analysis before wasting time on such stuff; and in general, most of part I, which tries over and over again to drive across the point that there are some things you really need to worry about, and that they don't involve gas masks and night vision goggles.

f-··on Doomsday planning for less crazy folk
Sure, and I'm using "space zombies" humorously, to broadly refer to all sorts of apocalyptic / TEOTWAWKI scenarios that many hardcore preppers are preoccupied with.

Most prepper guides devote a lot of time to societal collapse, complete self-sufficiency, urban combat, and wilderness survival topics, while dedicating much less attention to more pragmatic risks that one can prepare for without making profound lifestyle changes or buying a farm.

f-··on Doomsday planning for less crazy folk
The subsequent paragraphs address that, I think. It does not have to be this way, but the reality is that most people spend as much as they earn. You know, anecdotally, I talked to people in the Bay Area who claim that they couldn't really save any money even if they wanted to, because they were only making $120k a year. But I don't think it's a US-only phenomenon; it certainly happens in Europe, too.

I suspect it comes down to a belief that a raise entitles you to a better life, right now: so you go out and buy more expensive groceries, get a nicer car, etc. I was actually raised in a fairly poor family and it's a habit I picked up very early on; took me a fair amount of work to overcome this.

f-··on Doomsday planning for less crazy folk
Hm, I sort of suspect that you skipped much of the first part of the guide, which talks about identifying the relevant risks, including - say - studying flood maps, identifying nearby industries, walking around the home to spot fire hazards, etc? And talks a lot about not obsessing about unlikely issues, when your greatest worries may be your own financial security or a house fire. It specifically instructs people to map out plausible risks and write response plans before they buy a single thing listed in part II.

The whole purpose of part II is to go over some cost-effective purchases iff you have a robust basis to prioritize a particular threat and a rough idea of how you want to solve it. So yeah, for example, the mention of respirators has to be interpreted in that context; very few people can meaningfully benefit from a respirator.

There are also mentions of being able to board up windows in locations prone to severe weather, etc. I would really like to address your concerns and improve the doc, but as it is, I'm sort of struggling to pinpoint the nature of the complaint :-(

f-··on Doomsday planning for less crazy folk
I honestly don't know; it's interesting that in Europe, the same culture - certainly present in the nineteenth century - has atrophied very quickly after WWII.

I'm not sure how to explain that; urbanization? The expansion of the welfare state? Faith in the EU as the promise of enduring peace and prosperity? It happened in most of the Soviet Bloc countries, too, so perhaps the welfare state aspect is key.

In the US, my first guess is that it might have been kept alive, even in suburban and urban communities, because of the exposure to the Cold War paranoia, school drills, and so on. "The Russkies" and the specter of the nuclear apocalypse left an ominous mark on the American psyche.

But you are right, the desire to capitalize on the phenomenon might have played a role, too. On the flip side, Europe is not a very different market; the buyers are a bit more smug and you can't sell guns, but that's about it - so why aren't we seeing more of the "new" prepper culture cropping up on the other side of the pond?

f-··on Doomsday planning for less crazy folk
Yup. In fact, the guide talks about home fires as one of the most significant dangers (right after going insolvent or getting hurt); and cites the 72 hour figure. It also highlights that some of the prepper ideas, such as stockpiling gasoline, actually make you less safe.
f-··on Doomsday planning for less crazy folk
Oh, I don't think that trying to prepare for historically plausible contingencies is crazy - quite the opposite - but it's definitely easy to approach it in a haphazard, disorganized, or wasteful way.

The Bay Area culture definitely has a distinct aura of invincibility to it, though; we have many young folks, including immigrants with no familial safety nets and a messy legal status, living paycheck to paycheck while working in a very volatile industry on exorbitant salaries. And all that next door to an active seismic fault =)

Elsewhere, especially in rural America, the prepper culture seems a lot stronger, perhaps owing to the echoes of the Cold War. It always shocked me that the movement is virtually non-existent in Europe (where I grew up); if you look at their history, they certainly have more to worry about.

f-··on Doomsday planning for less crazy folk
The page talks about it a bit, but in an attempt to differentiate itself from the usual, mildly paranoid "prepper" content, it does its best not to get hung up on more outlandish scenarios, such as fighting off zombies and surviving for months without water and food.

I basically tried to approach it from the perspective of threat modeling / risk management for real life; and by that metric, incidents such as losing a job are far more likely than a zombie apocalypse. I have seen far too many people in the Silicon Valley discover that the hard way :-(

f-··on On Journeys
(Author of the blog post here.)

As a matter of fact, I did, many years ago. Ultimately, I didn't go for it, but it was more a matter of circumstance than conviction. I think I would have been happy there.

The US is hardly the violent crime dystopia that some Europeans make it out to be (the overall crime stats don't really stand out compared to the rest of OECD), so this was never a compelling argument; healthcare, more so - although thankfully, the US is now getting a bit smarter about that, too.

f-··on On Journeys
(Author of the blog post here.)

While I don't want to debate my mindset or the motivations for the original blog post, I do want draw the attention to the closing comments at the bottom of the article :-)

In essence, I very much acknowledge that the Poland I left 15 years ago was not the same country it is today, and that it has changed in profound ways. Ultimately, the post is not an attempt to contrast the modern-day Poland and the modern-day United States; it is a personal story of getting out of the 90s Poland and finding happiness elsewhere.

Cheers!

f-··on On Journeys
(Author here :-)

It's difficult to argue about the merit of subjective experiences, but I think that two things are worth emphasizing.

First of all, my experiences are colored by growing up in relative poverty in the 80s and 90s; I explicitly acknowledge that the Poland I left behind many years ago is not the Poland of today. I think that you are painting a rather rosy picture by implying purchasing power parity between Poland and the US - but I don't think I would be unhappy still living there.

Secondly, the appeal to some sort of a patriotic duty to stay in your country of birth is an interesting conversation that I had with several folks before. In essence, my take on this is that the allegiance you have to your children is much stronger than that to your ancestors and the historical circumstances of the place where you were born. It's a complex topic, but I think there are many equally defensible views.

Finally, as for your comment about "not considering criticism" - I think you may be reading too much into this sentence; some of the social critiques of the US that are prevalent in Europe are quite valid; many others are based on smug oversimplifications. The only thing I'm saying in the quoted sentence is that I wanted to find out for myself =)

Anyway, we won't have a very meaningful discussion on HN, but if you'd like to chat, please do drop me a mail :-) I think our views are probably more aligned than it may seem.

f-··on OpenSSL Security Advisory
Yep, the two PKCS bugs were from afl-fuzz.
f-··on What afl-fuzz is bad at
(afl-fuzz author here)

The basic idea for AFL is that it's supposed to be reliably better than dumb fuzzers without requiring you to think too much about the problem space, fuzzing settings, grammar definitions, harness design, etc.

Anything that makes it retain these properties while improving results is probably worth pursuing. Conversely, anything that sounds cool but ultimately doesn't meet that criteria is probably a better fit for other tools.

f-··on Finding bugs in SQLite, the easy way
Many of the horribly vulnerable parsers are generated with Bison / Flex, so it's not exactly a robust solution. Plus, especially for binary formats (images, videos, etc), it's hand-written or bust.
f-··on Finding bugs in SQLite, the easy way
As others have said, parsers for complex formats (be it text-based or binary) are exceptionally hard. There are some classes of C/C++ software where the choice of a language doesn't have such a striking effect. For parsers, the effect is hard to ignore.

But parsers are also the kind of stuff you almost always end up writing in C/C++, and there are semi-compelling reasons for doing so - chiefly, performance and flexibility. You can disagree and make your pitch for Ocaml or JavaScript or whatever, but really, if we had clearly superior choices, we wouldn't be dealing with this problem today (or it would be a much more limited phenomenon). There are some interesting contenders, but the revolution won't happen tomorrow, no matter how much we talk about it on HN.

Perhaps a more fitting conclusion is that if you are parsing untrusted documents, our brains are too puny to get it right, and the parser really needs to live in a low-overhead sandbox. Mechanisms such as seccomp-bpf offer a really convenient and high-performance way to pull it off.

f-··on How Heartbleed could've been found
Hey all,

I'm the author of AFL. I think this is pretty cool, but also would like to ask you all to hold on to your hats =) Here's the short response I posted to the oss-security mailing list:

http://www.openwall.com/lists/oss-security/2015/04/07/8

f-··on An overhyped GHOST
There is no inherent correlation between the severity of the find and the PR budget available to the discoverer.

On top of this, some types of security claims attract considerably greater attention than others for reasons unrelated to their actual impact or merit. If you mention privacy, Internet of Things, malware, and rooting in a single sentence, you will get headlines out of it, no matter how bogus the underlying claims may be.

You need a reliable way of finding about the vulnerabilities that affect you even if they are discovered by a teenager in Romania and a PR agency is not involved.

f-··on Looking Back at Three Months of afl-fuzz
Also SELECT c.* FROM (a,b) AS c;
f-··on HSTS Super Cookies
We also have a pretty comprehensive discussion of this and many other vectors in:

http://www.chromium.org/Home/chromium-security/client-identi...

f-··on Nobody expects CDATA sections in XML
afl-fuzz can be parallelized fairly easily. The exchanged data amounts to newly-discovered, interesting inputs that then seed the subsequent fuzzing work.
← PreviousPage 2 of 4Next →