HNHacker News
TopNewBestAskShowJobs

f-

1,101 karma · joined October 6, 2010

submissionscomments
f-··on No-till no-herbicide farming system in trial since 1981
Well, potato is one of the higher-calorie crops, and one pound contains around 350 calories. If you produce 3,120 lbs a year, that gives you about a million calories.

Now, let's assume a family of three - an average person needs around 2,000 kcal a day. That's 2,000 * 365 * 3, or around 2,200,000 kcal a year. So, you come quite a bit short. And that's on a good year; you're gonna have bad years, too.

Also a function of climate and soil. In the 19th century, settlers in the plains - Nebraska, Wyoming, etc - often couldn't make it work on 640 acres granted by the government. In contrast, there are eastern states where 20 acres would be more than enough.

(Farming in the West is now much more viable thanks to deep wells and mechanical irrigation, but that's a capital-intensive and resource-intensive approach that works best at a scale.)

f-··on $100M in bounties paid via HackerOne to ethical hackers
If you do that, you're merely trading one grievance for another: "evil company marked my bug as duplicate to avoid paying" for "evil company claimed to have gotten duplicate reports to weasel out of paying the full amount". More people upset, although individually, maybe to a lesser extent.

The core issue is not the reward division algorithm, it's the inherent lack of visibility. One solution here would be to just open all reports after a while, but this creates problems of its own. One is that it gives ammo to people engaging in dishonest or clueless PR. Another is that some researchers don't actually want visibility, because their employers have murky rules around such engagements, or because they have some far-off disclosure timeline in mind (as a part of a presentation at a conference, or whatnot).

f-··on Learning to See in the Dark (2018)
As a photographer, the comparison to "raw" results without color balance or noise removal seems somewhat deceptive. The effects visible in the video seem easy to quickly replicate with existing techniques, such as the "surface blur" filter that averages out pixel values in areas with similar color.

This happens at the expense of detail in low-contrast areas, producing a plastic-like appearance of human skin and hair, and making low-contrast text unintelligible, which is why it's generally not done by default.

f-··on American fuzzy lop – a security-oriented fuzzer
One of my design goals for AFL was to make it very simple to use - because there's plenty of fuzzers that work OK when you dial in 50 knobs just right, but fail spectacularly otherwise - basically ensuring that nobody but the author can really use the tool to its full capacity.

While AFL++ is cool, it sort of ditches that philosophy, giving you a lot of options to tweak, but not necessarily a whole lot of hope that you're going to tweak them the right way. So, that's one gotcha to keep in mind.

f-··on American fuzzy lop – a security-oriented fuzzer
(Author here)

The funniest part is that this ugly hack kept working across platforms for many years; whereas when somebody else implemented a "proper" integration with the clang / llvm API, their solution proved to be extremely fragile. The API wasn't stable between compiler versions, and because it wasn't really used much, it had all kinds of bugs, including being outright unusable at times.

Also, most distros packaged clang in a way that made it impossible to compile the plugin, because of missing or mismatched headers, missing companions tools, etc. So you had to download and rebuild the whole compiler, which took hours (and that's if you didn't get stuck in a dependency hell).

So yeah, this was very much a lesson in "worse is better".

f-··on Awesome-ld-preload: List of resources related to LD_PRELOAD
Does objective reality exist, my friend?
f-··on Awesome-ld-preload: List of resources related to LD_PRELOAD
Disappointed that my LD_PRELOAD exploit - still unpatched after 20 years! - did not make the list:

http://lcamtuf.coredump.cx/soft/ld-expl

f-··on Art's sale value? Zero. The tax bill? $29M
You can refuse to accept an inheritance. It goes to whoever is next in line. If everybody refuses, the state gets to keep it.
f-··on Is it still ok to have kids in face of climate change?
"The Population Bomb" was a pretty fashionable scientific prediction back in the 1960s which had a significant following in the academic and policymaker circles at the time.

It extrapolated from data about population growth, farmland capacity, etc, to reach the irrefutable conclusion that there is going to be mass starvation and famine in the 1970s. It led to calls for China-style population controls, to articles about whether it's ethical to have children, etc.

What happened instead is that population growth has slowed down quite a bit without government intervention, and that we've gotten a lot more efficient at growing food.

This does not prove anything when it comes to climate change, but is an interesting anecdote.

f-··on German police ask for help in identifying a bomber's MAC address
I'm no expert, but "blackmailing a bomber" does not sound like a particularly solid business plan...
f-··on A file that’s both an acceptable HTML page and a JPEG (2012)
Hey - I'm the author of that page. Your comment is a common misconception, but the animal pictured is actually a golden-mantled ground squirrel. You can tell because the stripe doesn't extend to the eye. Thank you for subscribing to squirrel facts!
f-··on Using some good old obsolete HTML to create JavaScript-free animations
Yeah - you can actually implement surprisingly complex motion by nesting <marquee> tags with different directions, speeds, etc.

I posted this long time ago: http://lcamtuf.coredump.cx/marquee.html

f-··on The Population Bomb Has Been Defused
Not long ago, a significant proportion of the scientific establishment - along with a number of celebrities and policymakers - believed that the "population bomb" is an inevitable, imminent, and apocalyptic threat. There was talk of "point of no return", calls for worldwide China-style fertility restrictions, and so forth.

Instead, what happened over the past several decades is not just a drop in birth rates, but also dramatic improvements in our ability to grow cheap food at a scale (something that the article doesn't really talk about).

So it is a very interesting take to claim that the population bomb has been "defused" - since this implies it wasn't an episode of pathological science flirting with mysticism (with frequent allusions to the pristine "natural" order contrasted with the evils of Man), but just some sound science that turned out to be a bit off.

(Please don't read into this as a critique of any contemporary scientific debates; that's not my point, but I think we should be more willing to recognize our past mistakes.)

f-··on Progressing from Tech to Leadership
Change jobs, probably? A toxic environment like this will not make you happy, and you can't easily fire your boss. The good news is that if you're working in IT, you probably have the luxury of being able to go somewhere else with relative ease.

On that topic, I'm a huge believer in a degree of financial independence, a rainy-day fund [1]. When you don't have to worry about having money for next month's rent, it really changes your outlook on things and makes it easier to make decisions that are just or right for you, without stressing over every possible misstep. And it's pretty easy to build such a fund [2].

[1] https://www.thebillfold.com/2016/01/a-story-of-a-fuck-off-fu...

[2] http://lcamtuf.coredump.cx/prep/#3.1

f-··on Progressing from Tech to Leadership
[Author here]

I don't there's a single answer. The "right" path is usually some combination of soft and hard skills, persistence, and dumb luck. Skill and persistence come into play because to a large extent, you are the master of your destiny, corporate or otherwise: you can settle for what's expected of you in a role, or you can go above and beyond, trying to find and fix pressing problems that others didn't even know they have, trying to help others grow, persuading other groups to give you the tools you need, and balancing it all with the reality of the business... Rinse and repeat enough times and you will probably be noticed for good judgment and the ability to get stuff done.

Now, dumb luck comes into play because to some extent, it's also a matter of being at the right stage of your career at the right time and in the right place. In some companies, especially smaller ones, there might be no way to become a manager or a director until somebody retires or is forced out. And if you miss that window, it might be several years until another opportunity to advance presents itself.

As with any other role, there are also many "wrong" paths, depending on the culture of the company; favoritism, cronyism, political horse-trading, bamboozling people, and so forth. But realistically, such things are less common than most people think. It's just easier to be cynical about others than to acknowledge our own personality flaws. We all have some, they weigh us all down; we just need to find a way to work around them and hope for the best.

f-··on The Tangled Web: A Guide to Securing Modern Web Applications (2011)
I'm not working on one right now and have not talked to the publisher about it. So not in the next couple of months. In the longer haul - maybe probably?
f-··on The Tangled Web: A Guide to Securing Modern Web Applications (2011)
The $100k+ price tag of top-level domains is prohibitive enough to discourage abuse and to allow them to individually review applications and reject anything even remotely problematic or questionable. In other words, life goes on at this point.

If they ever decide to relax the rules, it may become a bigger deal.

f-··on The Tangled Web: A Guide to Securing Modern Web Applications (2011)
(I'm the author of the book in question.)

I think it happened quite a bit earlier (perhaps 2005 -> 2010), at least when you look at some of the "prime" web properties. Gmail or Google Docs in 2010 were already pretty close to what we have today. Hard to believe, but XMLHttpRequest actually dates back to 1999! JSON isn't much younger.

I don't think the models of web development have changed dramatically since the publication of TTW. There are some other, more incremental changes that aren't reflected in the current edition - there are two examples in my other comment here (Service Workers, parser harmonization, etc) - but by and large, the content should be still largely relevant.

f-··on The Tangled Web: A Guide to Securing Modern Web Applications (2011)
(I'm the author of the book.)

Some things have changed for the better. For example, there's been a push to harmonize the behavior of some of the core parsers and APIs. Say, we now have less variability in how HTML is handled across different browsers.

On the flip side, there are also several new APIs and JS features that have some scary security implications. Service Workers come to mind.

The near-complete demise of Java and Flash are the two other major changes since 2011.

Either way, the book should still give you a very robust understanding of the fundamentals (and a mental framework to evaluate the dangers of some of the new stuff).

f-··on Alert About Missile Bound for Hawaii Was Sent in Error, Officials Say
Because it's almost certainly true? I'm not trying to invent some sinister conspiracy, but most people on HN and otherwise acquired an exaggerated perception of the effects of nuclear war after being exposed to pop-cultural portrayals of it - chiefly in the movies.

Some of these portrayals were exaggerated simply because it resulted in a better story, but some were almost certainly colored by anti-war and anti-proliferation sentiments predominant among the cultural elites of that time. This wasn't coordinated or meant to advance some sinister agenda, but for better or worse, it skewed our understanding of what we can do in the unlikely case that any ICBMs actually fly.

An argument can be made that another factor was the government's desire to discourage the Soviets from ever trying to attack us, but I'm unconvinced - their generals, politicians, and nuclear scientists sure had a more realistic understanding of what would happen. Besides, the anti-nuclear and anti-war sentiments hurt the government in many other ways (nuclear power generation, nuclear weapons testing, Vietnam...).

Now, I'm not particularly angry at that, and I sure loved Dr. Strangelove.

f-··on Alert About Missile Bound for Hawaii Was Sent in Error, Officials Say
I'm not trying to establish the origin of this narrative; but most people on HN were almost certainly exposed it through pop cultural portrayals of the nuclear apocalypse.

In some cases, these were inaccurate simply because it resulted in a better movie or a novel; but in many other cases, they were probably informed by anti-war or anti-proliferation sentiments. I don't think this deserves any special ire, TBH; it's just our reality. I loved Dr. Strangelove, but it sure affected public perception in a particular way.

f-··on Alert About Missile Bound for Hawaii Was Sent in Error, Officials Say
So I posted something along these lines in another, now-duped thread... but I know that many folks were caught completely off guard and started wondering what they would have done in case of a real threat. Many just cracked Twitter jokes about dying in a blaze of glory.

For folks who want to understand the actual dangers and survivability of an ICBM strike, I strongly suggest a book from the 1960s written by one of the folks involved in the US nuclear program during the Cold War:

http://www.madisoncountyema.com/nwss.pdf

It cuts through many of the Hollywood-perpetuated myths - the certain and painful death in case of a nuclear strike, or the 10,000-year radioactive wasteland that's going to be left behind.

For example, it discusses why the oft-ridiculed duck-and-cover strategy is actually surprisingly effective. The primary threat from an air burst is very conventional - a shockwave and an intense burst of thermal radiation. Shelter - any shelter - greatly improves your survival odds.

The fallout from air bursts is comparatively modest (i.e., tends to be far lower than from an event such as Chernobyl) and while lethal, it decays very rapidly - dropping to reasonably safe levels in a matter of days, not centuries. Staying sheltered for 2-10 days greatly improves your odds, and the thickness of material between you and any surfaces that gather dust (roofs, ground) matters more than anything else. Here's a handy chart:

http://static3.businessinsider.com/image/58cc34b9112f7043268...

In other words, having enough food and water in your home to weather out a nasty stowstorm also makes you well-prepared for the nuclear apocalypse. Mattresses and bulky furniture provide decent shielding when all other options fail.

The long-term effect of fallout tend to be exaggerated, too; water from streams, deep lakes, or wells should be safe or get safe very quickly. Removing a layer of topsoil allows relatively safe crops to be grown. Mild radiation sickness, at the levels where people start experiencing vomiting and hair loss, is actually pretty survivable and has a relatively modest impact on your odds of developing cancer later in life.

(Plus, keep in mind that more than 2,000 nuclear tests have been conducted so far, including around 900 in Nevada alone; while they had some statistically observable negative effects, they have not turned the world into a nuclear wasteland.)

Of course, don't get me wrong - even a single nuclear strike would be awful, and a large-scale confrontation would mean untold damages and loss of life. But the important point is that a lot of people would survive and would be able to do well in the aftermath - more so if we teach them about some common-sense preparedness steps.

The main reason why our understanding of the nuclear risk is so lopsided is because for decades, many nuclear disarmament activists (including many prominent screenwriters, celebrities, and pundits) had a vested interested in portraying the already-awful outcomes of a potential nuclear war as far less survivable and far more hopeless than in reality; the mockery of duck-and-cover, the "barren wasteland" imagery in the movies, and the largely-discredited scientific theories like the "nuclear winter"... all helped to advance (otherwise noble) goals, but at the expense of teaching people that there's nothing they can do save themselves.

Plus, of course, after Cold War, we have fewer reasons to worry. It's hard to top the Cuban Missile Crisis. There's plenty of politicized hyperbole around nuclear tensions right now, but the reality is that a large-scale strike on the US is a lot less likely than throughout a good part of the 20th century.

PS. I have a short summary of NWSS and some other points about this topic (and other, more mundane but plausible hazards) in my "Doomsday Prepping for Less Crazy Folk" - http://lcamtuf.coredump.cx/prep/

f-··on Alert About Missile Bound for Hawaii Was Sent in Error, Officials Say
That is actually reasonably well-established - check out this:

http://static3.businessinsider.com/image/58cc34b9112f7043268...

Not common knowledge, though, in part because nuclear hazards have been painted in an exaggerated light by Hollywood (basically, no point in trying to survive, because everybody is going to die and what's going to be left is a 1,000-year lethal nuclear wasteland), and in part because we stopped worrying after the end of the Cold War.

Despite the goofy title, this is a remarkably good book from the 1960s, citing some actual science, that helps grasp the actual dangers and the survivability of nuclear attacks or accidents:

http://www.madisoncountyema.com/nwss.pdf

PS. For folks interested in less apocalyptic emergency preparedness tasks, I maintain a handy guide:

http://lcamtuf.coredump.cx/prep/

f-··on Concise Electronics for Geeks (2010)
But wait, there's more! I also make tables [1] and doomsday predictions [2].

[1] http://lcamtuf.coredump.cx/table/

[2] http://lcamtuf.coredump.cx/prep/

f-··on Doomsday planning for less crazy folk
As others have said, you're not gonna be drinking it every day...

Stuff like BPA is not acutely toxic. There are some concerns about long-term ("subchronic") exposures spanning a decade or more, and even there, there is basically no clear evidence of adverse effects on humans.

Besides, BPA and its ilk are a concern chiefly with a variety of fancier, transparent plastics. Food-grade HDPE and polypropylene jugs are of relatively little concern. They are just not particularly pretty, so they don't sell.

Steel and glass are two other options, although many steel bottles are lined with epoxy or other coatings. Plus, in a car accident, I'd rather have a soft HDPE jug flying around...

f-··on Doomsday planning for less crazy folk
[Author here]

The mindset is actually a large component of this guide, and it intentionally delays any discussion of "prepper gear" until it gets through a long laundry list of lifestyle tips and discussing the need to plan ahead, figure out what is likely, what can go wrong, what the decisions points may be, etc. In contrast to most other prepping docs, weapons are literally the last thing discussed, and only in a perfunctory way.

That said, I think that your view of emergency preparedness is far more narrow than what I aimed for in the guide. A significant focus of the doc is dealing with small-scale but common adversities, such as recessions / unemployment, house fires, backed-up sewage, and other "boring" but life-altering contingencies. Basically, the stuff that almost everybody will need to face at some point in their lives.

I'd wager that for 90%+ of the events that a typical person in the US is likely to experience, heading into the woods to forage on berries and hunt wildebeest is not the way to go.

f-··on Doomsday planning for less crazy folk
[Author here]

> [...natural disasters...] Pretty much always in the sames typical places though...

Most people live in "typical places" without realizing it, though. I mean, you know when you're in the tornado valley, but tornado / hurricane risk is relatively high for basically the entire eastern half of the US. And wildfire risk is very significant for the entire western half. Add to this earthquakes, etc, and it turns out that most people live in a place that is likely to experience a major regional disaster every couple decades or so.

Still, the guide is not really about that; or rather, it covers natural disasters to some extent, but it puts a lot more emphasis on personal preparedness - being able to cope with another run-of-the-mill recession, a house fire, and other likely occurrences of this sort. More general preparedness is almost a side effect of that.

> [...economic crises and armed conflicts...] Ditto. See: countries with a perpetual history of dictators and authoritarianism (although westerners and capitalism/socialism typically receive the blame in popular depictions)

Well... Greece, Iceland, etc?

f-··on Pulling JPEGs out of thin air (2014)
It's very common when fuzzing. That's why you normally want to place memory limits on the target process, to avoid bringing the system down. AFL does that automatically, most other fuzzers have a config option.
f-··on OSS-Fuzz: Five months later, and rewarding projects
I had pretty good results fuzzing SQLite back in the day:

https://lcamtuf.blogspot.com/2015/04/finding-bugs-in-sqlite-...

I think they eventually incorporated AFL into their continuous testing and squashed several dozen bugs. OSS Fuzz scales it up, but yup - the bottom line is that you might think you have 100% test coverage, but you really still need to fuzz =)

f-··on Everything Is Broken (2014)
I hate to be negative, but I've been working in the security industry for several decades now and... the article reads to me like a collection of condescending platitudes that attribute malicious intent or extreme incompetence to just about any person other than the author. Jumping back and forth between Snowden, PDF attachments, and C memory safety does not help.

The online world is not particularly horrible; we overwhelmingly use it by choice, not out of necessity, and the benefits far outstrip the risks. Sure, it's also far from being great, and the genuine difficulty of designing complex systems in a secure way plays a role in this (heck, between all the interested parties, we can't even really define what "secure" means in practical terms). But it's not because everybody else is dumb.

While I generally hate analogies like this, I think there are quite a few parallels between the online world and the physical realm, where we seldom settle on absolute security. You have a $10 door lock that can be opened with a paperclip, protecting probably in excess of $5,000 in electronics within your home. In that realm, we are far better accustomed to the trade-offs, in part because we have more intuitive data about what can go wrong. We also take a more dim view of a burglar than of a hacker, which makes us assign the blame a bit differently.

In any case, with online security in particular, there some paths forward, including fairly plausible incremental strategies (better UX in the browsers and operating systems, better developer guidance, better mitigations, a culture of fuzzing and other security testing as a part of QA, etc). There are also some ambitious revolutionary dreams ("New everything! In Rust!") that may actually pan out if enough people get behind them. But I'm not sure what this article is hoping to achieve.

Page 1 of 4Next →