HNHacker News
TopNewBestAskShowJobs

fiberoptick

198 karma · joined June 30, 2010

submissionscomments
fiberoptick··on Yale employee admits she stole $40M in electronics from the university
The perfect example for how bloated, inefficient, and wasteful the bureaucracies of higher education can become.

How did $40m of fraudulent spending go unchecked for literally years? It seems to be that even at the largest private sector organizations this kind of malfeasance would have been caught much sooner.

fiberoptick··on Emulating AirTags to upload arbitrary data via Apple's FindMy network
This could have been an immensely powerful covert communications channel for field operators of military and intelligence services
fiberoptick··on Ubuntu 21.04
Well, at companies that actually care about 100% rollout of "corporate, invasive crapware" on computers that _they own_ and that are used to process _company data_ and access _company resources_, the alternative is usually just to ban Linux workstations altogether.

I see this as a strict improvement for adoption of Linux workstations in the corporate world

fiberoptick··on Apache Mesos to be moved to Attic
End of an era...

Are there any viable alternatives to Kubernetes and Nomad?

fiberoptick··on Licensing changes to Elasticsearch and Kibana
I wonder where this leaves the AWS-sponsored Open Distro for Elasticsearch? (https://opendistro.github.io/for-elasticsearch/)

Seems to me that they have no choice but to hard fork off of the last Apache-licensed release of Elasticsearch et al

fiberoptick··on Licensing changes to Elasticsearch and Kibana
Copyright law is the basis for the legal enforcement of software licenses. License violations usually get pursued under copyright law
fiberoptick··on An update to storage policies across your Google Account
There are state laws that require financial institutions to do this actually. Their hands are tied here. It's called "escheatment".

https://www.sec.gov/fast-answers/answersescheathtm.html

fiberoptick··on Robinhood Accounts Looted, No Customer Support
> does not directly answer to any legislative, judicial, or executive authority.

This is patently false. The Securities and Exchange Commission accredits and oversees all national SROs.

fiberoptick··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
Should be corrected to "Vendor-Locks", as well.
fiberoptick··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
Does this defend against any additional attack surface that wasn't already defended by the UEFI Secure Boot standard?
fiberoptick··on Partying like it’s 1999 – Initial public offerings are back in Silicon Valley
Your comment is technically correct, but misleading.

In fact California specifically does not tax ex-residents for income arising from the disposition of stock acquired with ISOs, which is usually the way pre-IPO employees acquire shares. This is true even if the ISOs were granted for work performed in California.

fiberoptick··on QUIC – Will It Replace TCP/IP?
Bad, in my view. (Although I am not a lawyer, and would definitely appreciate input from one here!)

Hardware offload of a network protocol is an extremely generic concept and this patent seems to describe that concept (without any kind of novel mechanism or implementation details).

fiberoptick··on QUIC – Will It Replace TCP/IP?
And emerging QUIC acceleration technology is likely to be stifled by intellectual property laws.

Intel has already filed (in 2019) for a European patent that seems to claim inventorship of the generic concept of hardware offloading (as it applies to QUIC)

https://data.epo.org/publication-server/pdf-document?pn=3541...

fiberoptick··on Slack account takeovers using HTTP Request Smuggling
I noticed that throughout this thread you have been making this assertion. Could you share any data or citations to support this?

Would you feel any differently about the value of this bug if it affected, e.g. Google or Facebook?

fiberoptick··on Slack account takeovers using HTTP Request Smuggling
Wow, an ATO exploit that only received a $6,500 bounty? This signals to grey-/black-hat researchers that their research efforts or Slack bug disclosures are best directed elsewhere..
fiberoptick··on Oracle VP: Data would be safer if most OSS distributed databases didn't exist
The FOSS community would be a lot safer if Oracle didn't exist.
fiberoptick··on UniFi routers will send performance data back to Ubiquiti automatically
Are there any decent alternatives to Unifi APs or home switches and routers?

Willing to pay a modest premium, even.

fiberoptick··on Show HN: Nebula – a distributed graph database written in C++
There's a subtle difference between AGPL and the Commons Clause licenses.

AGPL requires network-accessible code to be disclosed & licensed under an AGPL-compatible license.

The Commons Clause license outright prohibits SaaS-style offerings of the licensed code.

A lot of startups licensing their code under AGPL might still have AWS et al. eat their lunch, becuase all Amazon needs to do to remain compliant is to publish any modifications made to the AGPL-ed code.

fiberoptick··on RunJS
The third demo screenshot [1], which contains a toy implementation of AES in CBC mode, is a great example of why cryptography is hard to get right. Implementation is best left to cryptographers.

AES-CBC requires a random IV to be used as a nonce on a per-message basis, otherwise the entire scheme breaks. The toy example given on this website uses the deprecated Node.js createCipher [2] API which does not take such an IV. In fact, the docs and runtime even warn that using CBC mode with the createCipher API is dangerous!

As the code is currently written, an attacker observing multiple encrypted messages under the same key could probably decrypt all messages!

[1] https://projects.lukehaas.me/runjs/images/runjs3.png

[2] https://nodejs.org/api/crypto.html#crypto_crypto_createciphe...

fiberoptick··on CIA Director John Brennan emails
Why did they publish his SF-86? This seems like a very irresponsible invasion of Brennan's personal privacy; nothing in there could possibly be of legitimate public interest.
fiberoptick··on Bonsai: Bulletproof contracts, simple e-signing, escrow for freelancers
Describing a contract as "bulletproof" and drafted by "top attorneys" is likely considered puffery [1] under the law, and should be fine in my opinion.

[1] https://en.wikipedia.org/wiki/Puffery

fiberoptick··on Netflix to Shut Down Last Datacenter
I've never understood why so many companies are comfortable giving Amazon such leverage over their business infrastructure.

Could someone explain why this is a good move in spite of the risk that Amazon could jack their prices up in the future?

fiberoptick··on Fired
It's highly dependent by the state in which you work. Github is in California, an "at-will" state [1], which basically means that you can get fired for any reason, including no reason at all. The only exceptions to this rule are if you were fired as a result of discrimination of a certain protected characteristic such as your age, gender, race, etc.

[1] http://www.business.ca.gov/StartaBusiness/AdministeringEmplo...

fiberoptick··on Target hackers stole encrypted bank PINs, according to source [video]
Why were they storing the PINs?