HNHacker News
TopNewBestAskShowJobs

graylights

331 karma · joined December 14, 2011

submissionscomments
graylights··on Bitcrypt broken
Depends if you have java plugin enabled
graylights··on Bitcrypt broken
Static signatures are increasingly pointless as malware is rebuilt often.

Heuristics don't work against ransomware because they act like a well behaved program. Search for files, open file, overwrite file. All could be done as non-privileged user.

Ransomware is truly scary but the proper advice is: 1. Don't run untrusted software 2. Proper backups (e.g. not just a mirror) 3. Proper permissions on network drives that are mapped. Ransomware is devastating to small offices.

graylights··on The Man Who Built Catan
I'd argue that Catan is much less complex monopoly. Just that most people learn monopoly at a very young age so they never notice the complexity. Monopoly's rules are 6 pages of pure text. Catan's rules are 4 pages with some illustration.

I don't understand at all why monopoly is the universal board game that every kid learns. It's a horrible game that drags on for hours. Even though I don't particular care for Catan it'd make a much better universal board game.

graylights··on New Linux userland rootkit with anti-debugging, new backdoors and pcap hiding
It's an LD_PRELOAD so it's likely either: 1. a environmental variable for the user, in which case you just need to clear their rc files. 2. In /etc for all users. In which case you'll just have to remove the file. To get around hiding you can use debugfs point to block device (/dev/sda1?). Navigate to find the offending file and mv it.

As someone else points out, all statically linked binaries are immune to this technique since they don't load preloads.

Another warning is don't muck around with /etc/ld.so.preload unless you know what you're doing. It's possible to get in a state that everything you executes segfaults.

graylights··on Important Kickstarter Security Notice
That is quite a leap to assume root access. A user mode database should have write access only to partitions that are mounted noexec. That would make getting root privileges quite hard even on a vulnerable kernel.

Also with proper hardening you can prevent the kernel from being modified even by root. Things like FreeBSD securelevel that once enabled blocks writing to kernel memory and raw disk devices.

graylights··on Important Kickstarter Security Notice
Tripwire is just file integrity. It can help to detect the installation of a backdoor. But that doesn't help at all if the backdoor is just memory resident (or installs at kernel level). It also doesn't help if the attacker breaks in, grabs your data and leaves for good.

File integrity is also a pain in the ass. You have to keep a database of good file hashes and it can't be stored on the server (or the attacker modifies the known good hashes). Generally you also should not even have the file integrity software on the live server filesystem.

Similarly Network IDS has the flaw that you must have well defined profiles of "normal behavior" so it can identify abnormal behavior. The other option is signature-based but that would only detect known exploits.

graylights··on Google will block local extensions in Chrome 33 for Windows
The problem with this is crapware vendors existed before extensions were available. They were dirty hack modifications to the programs. They would introduce all sorts of bugs and since they modified the actual software they were a pain to uninstall.

If your cabin in the woods is getting broken into, you won't secure it by putting a lock on the front door. You'll just get robbed and have a broken window.

The real problem is users accepting and running installers that install crapware. You effectively give it permission to do anything it wants.

graylights··on Scientists Say Their Giant Laser Has Produced Nuclear Fusion
An abundance of energy would result in new technologies, engineering and infrastructure to use it.

Water shortages could be addressed with large scale desalination. Shipping/transportation would become real cheap without significant fuel costs. Food issues could be addressed by commercial hydroponics.

graylights··on Maryland Lawmakers Push to Cut Water, Electricity to Spy Agency Headquarters
I agree completely with your last point. I accept basic utilities are granted a monopoly, but with that comes common access.

Maryland also doesn't want the NSA to leave since federal money is a huge part of the state economy. Also denying state contractors from providing support could cause massive disruptions. I imagine a lot of basic services at government facilities overlap (custodians, food services).

Unfortunately the states don't really have any legitimate tools to punish the federal agencies. I suppose since the NSA is under the DOD they could rollback state benefits to military but that'd be very unpopular. They could also go NJ style and close down roads outside their headquarters.

graylights··on ReactOS 0.3.16 released
I disagree, the future of windows is why ReactOS is important. For the same reason DosBox is important, to run legacy apps.

10 years from now, how are you going to run those XP apps that aren't compatible with even windows 7, let alone three more cycles of ugprades.

graylights··on Why “just use Adblock” should never be a professional answer
I don't consider trackers "well behaved". My reasons for adblock: 1. Security. I don't mind static image ads because the security implications are minor. But running third party code without accountability is scary. (1) 2. Performance. Loading images from a dozen different domains means many dns resolutions. 3. Privacy. This is just creepy, networks watching every page I go to.

There is nothing in advertising that requires all of that. I'm perfectly fine with static locally hosted ads. But the whole industry is based around something else. I continue to use adblock plus despite their "Acceptable Ads" program because I consider it reasonable in requirements.(2) I think there's a lot more room for compromise in allowing ads but no extension makes it easy to address my concerns.

Citations: 1. https://help.yahoo.com/kb/SLN22569.html?impressions=true 2. https://adblockplus.org/en/acceptable-ads

graylights··on Evolution of words frequencies in porn
So I did gay vs lesbian and I was confused why there was a big spike in 2010 for gay that has since dropped off. Is this an anomaly in their sampling?

Also Obama's numbers have really dropped compared to Bush: http://porngram.sexualitics.org/?q=bush%2Cobama

graylights··on How Netflix Reverse Engineered Hollywood
You're right that audience data is going to be full of the obvious. But it's also good for watching trends, before they go bust. A number of genres (e.g. superheroes) have cycles of growing, being massively popular, then dying off for a couple decades.

If you're in the business of making content, you want to join the trend early and get out before everyone realizes it's a fad. A truly great movie can buck trends, or even change them, but there are few truly great movies. Or you could just ignore this all and make the perennial favorites, generic romance or action movies.

graylights··on Searching the Internet for evidence of time travelers
Doesn't relativity say there is no such thing as fixed coordinates? That it all depends on frame of reference.
graylights··on Searching the Internet for evidence of time travelers
It's been 60 years since nuclear power was invented, so in 10 years it'll be available for mass market? I'd also like my watch form plane.

What if it's so energy intensive that a future dyson sphere can only power it once a year. It doesn't matter how cheap the machine is, if the resources are expensive.

graylights··on I fought my ISP's bad behavior and won
DNScrypt only protects from your host to your nameserver. Your nameserver can still be poisoned as it queries other nameservers.

dnssec protects mostly from poisoning between nameservers. It does little to protect between a host and their namserver.

But in reality dnssec is not a solution, it's a problem. It will never be adopted in a meaningful way without major overhaul in spec.

graylights··on Computer-driven cars will convulse the automotive industry
The notion of "control" is silly, you will still be the captain of the car, just not the driver. What if the wetware system kills 100 times as many people, should you still be able arbitrarily override the automated driver?

I already accept a lot of places that I should let machines handle a task for me. I drive an automatic transmission rather then shift myself. I have traction control that overrides my foot to give me better control of the car. I fly in planes that are mostly flown by autopilot.

Assisted driving will only be a short stopgap. It will be quickly gotten rid of because of cost to maintain two systems and because the ugliness of a "drivers seat". Interiors will look nothing like they do now. There will be no drive-shaft (fully electric) so no big bump or center console in middle of car. No steering column, no mirrors and a completely different arrangement of seats then now.

In other words a fully automated car looks nothing like an assisted driving car. I doubt people are going to want to pay more and sit in less comfortable cabin, just for the opportunity to override the computer driver.

graylights··on A universal income is not such a silly idea
I think the costs of administration would exceed the payments. We're fine with bureaucratic jobs now because we need employment numbers, but those jobs aren't producing anything real. Look at the VA, it employs half as many people as the Army, just to manage benefits. What your proposing would, like the VA, require filings, delays, rejections, appeals and a whole lot of heartache. Simplifying things is the key selling point. You reduce pointless jobs that produce nothing and get rid of red tape in the process.

I just don't think adding bureaucracy is the solution. If I want someone to go to school I don't manage it on the individual, you'll spend half your money on administration. I spend it by subsidizing tuition.

Some people will drink themselves to death, but they already do that in our current system. How does that matter? The only difference I see is they'll have a lot more free time. Maybe they'll waste it, maybe they'll improve themselves.

graylights··on A universal income is not such a silly idea
But that's exactly the point of universal income. You don't pay them for idleness, you pay them regardless. You just don't pay them enough for their desires, just their needs.

All those things you want cost money to verify and adds massive administration costs. Another point of universal income is it's cheap to administrate.

If you want to "pay" people for taking college, just subsidize it.

graylights··on Amazon AppStream
The truth is I/O is much slower then networking. Many LCD displays do image processing which results in it being several frames behind the one the GPU is currently pushing out. So between your desktop and your monitor could be 70ms of latency. On top of that there's the delay in input devices.

If streamers could maintain 30ms of network latency then it's just a minor difference from the system baseline.

If the streamers are smart they could colocate with the game servers. Then that 30ms of network latency is there regardless, home system or streaming system. It effectively adds no lag for streaming.

John Carmack made a comment that he could send a packet to europe faster then he could send a pixel to a screen: http://superuser.com/questions/419070/transatlantic-ping-fas...

graylights··on The Driverless Car Revolution Should Not Begin with Cars
Driverless trucks is a real opportunity that could save a lot of money in shipping.

But it could be exploited. If a person walks out in front of a truck, the automated truck better stop. Which an unguarded truck would become easy to rob with little risk. A flat tire would mean the truck calls in for help and is stranded defenseless on the side of the road. That said a fair amount of loss could probably be absorbed with the savings.

I expect long haul truck drivers instead to turn into truck captains. They're present but not for the driving. The truck can drive through the night while they sleep. The captain will handle weigh-ins, emergencies and other road tasks.

graylights··on New FAA Guidelines Permit More Device Use
The reason for banning electronic devices during take-off and landing is because of EM interference, not because of distraction. If you want to ban distractions you need to ban books, sudoku, and noisy kids too, the electronic bit is immaterial.

Also people are already free to use devices during loading and unloading. Your complaint is that people don't have common courtesy, but that can't be regulated by FAA (and isn't currently)

graylights··on Free email address validation API for web forms
"3. Mail Exchanger existence checks

Again, due to the robustness principle, just because a host does not define MX records does not mean they can’t accept mail. Mail servers will often fall-back to A records to try and deliver mail. That’s why we go one step further than just a DNS query, we ping the Mail Exchanger to make sure that it actually exists."

Plenty of boxes don't respond to pings (icmp). Can I assume you're doing a tcp scan on mail ports?

graylights··on Free email address validation API for web forms
Not a valid email address since example.com doesn't have a valid mx record. It's a reserved domain.
graylights··on Free email address validation API for web forms
They're only valid if you can own that email address and The only one that looks valid there is the last n@ai, since apparently ai actually has an mx record.

The first two are legal by rfc but not allowed by the individual providers. The third is not legit by rfc 2606 because example.com is a reserved domain.

If it was just a RFC validation then it should validate all of those (except maybe example.com). But they go beyond that: "Furthermore, the validator is ESP specific, so we can go way beyond valid syntax checks, bring in specific requirement for Gmail vs. Yahoo vs. Hotmail."

graylights··on Final Term - Terminal Emulator
Have you tried setting Quick-Edit for your command line? The right-click copy/paste works well enough (though not nearly as good as a linux terminal). But the highlighting is still garbage.
graylights··on Final Term - Terminal Emulator
Terminal emulators should be expected to deal with a lot of untrusted data, such as when you ssh to another machine. With all the context parsing in this, there is a large attack surface. I hope thought has been put into how to handle this.
graylights··on Understanding the linux filesystem (/etc, /var, /bin, /opt etc.)
Computer literacy doesn't care about linguistic literacy. Every profession has their jargon.

Passwd = "password" /usr = "slash user"

If someone doesn't understand you, then you explain and move on. But the industry has based around this jargon and removing/redefining it just creates separate standards.

graylights··on Understanding the linux filesystem (/etc, /var, /bin, /opt etc.)
I've historically been of opinion that #!/bin/name is preferred. Then I hit a workplace with network mappings and mixed architecture servers. It makes me appreciate linux's default mapping because when you start going off on your own it becomes nasty.

Some machines only have python 2.4 and others 2.7. So /usr/local/python is not a good answer for python scripts in /project/x/bin (network mapped). Worse someone puts gnu coreutils in /project/x/bin, but for sparc architectures, so PATH becomes touchy if you're on a x86 server.

I've resorted to having my bashrc build my path by scanning uname for architecture/platform and conditionally adding path entries to these network folders.

All organization scripts on network drives now have caveats "This only works on linux x86 servers" or "This only works on server X". Not because it can't work elsewhere, but because the PATH and #! management problems when the dependencies are installed at different places on different servers.

Blegh </rant>

graylights··on Terms of Service; Didn't Read
I like it. I'm more interested in the site then the extension though.

Things I'd like to see: 1. Highlight sites that have changed terms recently. 2. The discussion links should show how active the discussion pages are

← PreviousPage 3 of 4Next →