HNHacker News
TopNewBestAskShowJobs

greyface-

7,278 karma · joined December 7, 2017

Look at all the order around you,
submissionscomments
greyface-··on Tesla takes on $30B in credit as it approaches unprofitability
Unless you have an "insurable interest" in their life, probably not. In SF, this is governed by California Insurance Code § 10110. https://law.justia.com/codes/california/code-ins/division-2/...
greyface-··on Owed a billion dollars in Nvidia stock
> but consider the alternative where anyone could sue anyone after any period of time

What's the problem with this alternative, exactly? Some crimes already have no statute of limitations, and this hasn't caused the sky to fall.

greyface-··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
> critical examination; that is what law enforcement's job is

Critical examination is the judiciary's job, not the police's. Jordan v. City of New London established that police departments can and do deny employment to prospective officers who possess excessive cognitive ability.

greyface-··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
Information wants to be free(d).
greyface-··on Wall Street is growing skeptical of the data center boom
Any data center that is in the business of selling tokens rather than space, cooling, power, and connectivity is going to be in trouble eventually.
greyface-··on RSA-896
P2TR outputs have a script that always starts with OP_1. That script may or may not commit to a tapscript.
greyface-··on RSA-896
Of course there's a script; every bitcoin tx output has a script. These challenges use the standard P2PKH script, i.e.:

  scriptPubKey: OP_DUP OP_HASH160 <pubKeyHash> OP_EQUALVERIFY OP_CHECKSIG
  scriptSig: <sig> <pubKey>
https://en.bitcoin.it/wiki/Script
greyface-··on List of references on Sony websites to players "owning" their digital games
> taking away people's rights as [...] workers

I was recently reviewing a collective bargaining agreement (after being approached by a campaign to add my job category to an existing union at my employer), and was surprised to find that it forced arbitration for all employee disputes, with no opt out. It's not just employers that use binding arbitration to take away workers' rights.

greyface-··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
It appears this commit actually introduced the bug the attacker exploited by adding additional flexibility for cache key confusion via scriptPubKey. https://twitter.com/mononautical/status/2096928595432374706

The mechanism reminds me of this classic AWS request signature forgery bug from 2008: https://news.ycombinator.com/item?id=401876

greyface-··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
Further on-chain communications:

https://mempool.space/tx/91271efcbb5ab29abfc38ae635f0644e3ba... "Please contact security@blockstream.com"

https://mempool.space/tx/bd81219691eb1e22475c5985d847fa888c3... from Blockstream, unknown PGP message

https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798... from attackers, "sending most back to bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr, is that ok"

https://mempool.space/tx/8a444eed65c4584f138e08ee138f61490ef... from Blockstream, PGP-signed "Yes, thank you."

https://mempool.space/tx/83825b2135dd0abac12c9dfe17f29ab81b3... from attackers, "Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix. The detail is as follows (encrypted using https://blockstream.com/pgp.txt)." with unknown PGP-encrypted payload

As of writing, no response from Blockstream, and funds are still controlled by the attackers.

greyface-··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
While moving the funds, the attackers left an OP_RETURN message with the text "we are whitehats. contact us on chain" https://mempool.space/tx/c103de95817b43f2df635ec6f35ff126ca2...
greyface-··on Shutting down our public encrypted DNS
IIRC, Google addressed the incident you're referring to by adding E2E encryption to sensitive inter-DC RPC sessions, rather than by fully encrypting inter-DC traffic at the link level. It would be nice to be able to reasonably expect carrier/ISP backbones to be secure against this threat, but in our actual reality this seems like fantastical thinking.
greyface-··on Shutting down our public encrypted DNS
Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?
greyface-··on Shutting down our public encrypted DNS
Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.
greyface-··on An open DNS recursive service for free security and high privacy
Sending every single query to a centralized third party is hard to square with "high privacy". I prefer to run my own local recursive resolver.
greyface-··on .name Termination
> This isn’t how things are done these days

The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635

Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.

greyface-··on LLMs and self-referentiality
This one thinks LLMs should be trained and RLHF'd into illeists, as an experiment.
greyface-··on California lawmakers unanimously pass Linux exemption from age-verification law
> I'm not clear if you're doubting the correctness of what I said in my previous comment.

I don't dispute any of the factual or legal claims you've made. I even agree that a FOSS license is probably the best choice if the author's goal is to protect the user from the scenario where they turn evil and renege on their gift of code to the public.

In situations where I'm the author, this isn't always my goal. You know that Bernstein isn't going to go after his users, and I know that I'm not going to go after mine. Most users aren't going to be concerned about this possibility, either. Those who are concerned about it are likely to be for-profit corporations or their lawyers, and I'm not losing any sleep over making them nervous or losing them as users. I don't care to over-formalize things by invoking or even acknowledging IP law in my act of publication.

Each author's motives and goals are going to vary. It's not reasonable to enforce that "maximize assurances provided to user" is always at the top of the list for everyone.

greyface-··on Discontinuation of third level domain registrations for the .name TLD [pdf]
There are 22,000 third-level registrants currently. https://www.icann.org/en/system/files/files/reconsideration-...

(via https://www.icann.org/resources/pages/reconsideration-26-2-s...)

greyface-··on California lawmakers unanimously pass Linux exemption from age-verification law
> Like what?

djb's software is the canonical example here: qmail, djbdns, etc. Widely used; distributed without explicit license until 2007, and placed in the public domain thereafter. No legal disputes ever arose from this.

greyface-··on California lawmakers unanimously pass Linux exemption from age-verification law
This is exactly what GP was talking about: entrenching a preference for one style of licensing over another. We all know what set of licenses the FOSS zealots would prefer for us to release code under, and those who release license-free or public domain software anyway typically do it with full knowledge of such arguments.
greyface-··on California lawmakers unanimously pass Linux exemption from age-verification law
https://www.pdos.org/ Public Domain Operating System
greyface-··on California lawmakers unanimously pass Linux exemption from age-verification law
It only applies to software distributed under a license. Public domain software isn't distributed under a license. It's in the public domain; no license is needed.
greyface-··on California lawmakers unanimously pass Linux exemption from age-verification law
The bill exempts:

> a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software

which at least doesn't choose specific winners and losers among licenses. It does disfavor license-free and public domain software, which isn't great.

greyface-··on IPFS Maintainers Winding Down
IPFS doesn't fetch or store content that the user has not explicitly requested. If your application allows strangers to request arbitrary IPFS objects, this might be a concern. Otherwise, no, simply running a node doesn't expose you to this risk.
greyface-··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
The general public was authorized to enter the facilities 24/7. The exterior doors were unlocked and it was considered an "open campus". The access controls you see today have only existed since COVID. Whether he was a student at the time also means "precisely nothing".
greyface-··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
Both Aaron and "those hackers" were MIT community members.
greyface-··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
> trespassed into a room

A room with an unlocked and unmarked door, off of a hallway that was open to the general public. An INCREDIBLY tame act compared to other unprosecuted trespasses normalized and celebrated at https://hacks.mit.edu/.

> rotated his MAC address

Not a crime; in fact now a widespread and default practice for consumer Wi-Fi/Bluetooth devices.

greyface-··on How to compromise your system with a job interview
Their upstream transit providers do, surely.
greyface-··on Find Chicago Parking Cops
One man's "disruption of police work" is another's protected First Amendment activity. https://www.reuters.com/article/world/us/top-new-hampshire-c...
Page 1 of 34Next →