HNHacker News
TopNewBestAskShowJobs

grlass

529 karma · joined July 17, 2017

submissionscomments
grlass··on Tell HN: SMS-based two-factor authentication is not secure
I don't have a source to hand, but I've heard from other post-mortems that in SIM-jacking attack the carrier has been socially engineered into not bothering with the pin, ongoing court cases RE negligence perhaps on-going.
grlass··on USB-C is about to go from 100W to 240W, enough to power beefier laptops
Yeah, it's a bit of tragedy.

Resistor style stripes on cables would be fun, a stripe for each feature such as bandwidth, power, etc; perhaps already suggested (and ignored). Though complement for ports would be trickier.

Embossing symbols in the style of thunderbolt might be the way to go, even if the standard is not fully adopted.

grlass··on USB-C is about to go from 100W to 240W, enough to power beefier laptops
I wonder if the the committee have looked at integrating colour or some other indicator into the standard so that cable/port capabilities are clear visually.

Though ofc the design challenge is for users to feel comfortable that putting red into blue won't break anything, it just might not give the expected features.

grlass··on UK Rail services to come under unified state control
The ScotRail brand was operated by the private company Abellio, who lost the contract due to long term failure to meet its requirements of reliability etc - was in trouble before the impact of the pandemic.
grlass··on Irish health service hit by cyber attack
Theft was happening anyway via malware, it's just fewer of the costs were being borne directly. And as data collection increases, those indirect costs are getting higher.

Now the organisation has more at to lose at first pass, rather than just data subjects.

grlass··on Irish health service hit by cyber attack
true, though arguably it's a good thing. In the sense that it moves more of the costs of malware to the organisations that are meant to be securing the data. Previously, these costs were more borne by customers/clients/etc, and thus not taken as seriously - abstract costs and externalities.

Putting a clear number of the cost of poor cybersecurity should push more organisations to actually do something about it.

grlass··on An analysis of Bitcoin's throughput bottlenecks
It may be arbitrary, but increasing blocksize to mitigate network congestion is not a good solution, since any cap you set it to will also be arbitrary, and harm decentralisation (block propagation time, node operation costs, etc).

And given how valuable it is to have data in a semi-permanent near-immutable distributed ledger, that block space would be filled up pretty quickly, solving nothing.

Keeping the limit however has inspired a number of novel innovations to use the space more efficiently, including segwit (effectively increasing blocks to 4MB), and taproot.

In short, block size increases are an "easy solution" that don't really solve much.

grlass··on $7.5B In Stolen Bitcoin from 2016 Bitfinex Hack has just been moved
iirc, a number of wallets allow you to specify which unspent TX outputs you use.

So if you got tainted coin sent to your address, you could avoid using that UTXO in future TXs.

That might protect you from some scrutiny.

grlass··on Richard Stallman FSF support/remove letter signature counts
Is this Sybil attack resistant?
grlass··on RMS Support Letter
why?
grlass··on The Unreasonable Ecological Cost of CryptoArt
Indeed, targetting a specific industry seems like too focussed and approach that won't actually solve much.

Especially when you have e.g. the aluminium smelting industry that uses around 10x more energy*. Arguably more useful, but the externalities of using unclean energy for that process, and all other unclean energy consuming industries, should still be priced in.

If cryptocurrency miners want to use that energy, they can knock themselves out, but they should at least be strongly economically incentivised to do it in a CO2-minimizing way.

* (15,000 kWh per tonne) * (63.2 million tonnes annually) = around 948 TWh sources: - https://aluminiumleader.com/production/how_aluminium_is_prod... - https://agmetalminer.com/2015/11/24/power-costs-the-producti...

grlass··on Some Schools Are Blocking Replit to Prevent Kids from Coding
not listed, and presumably to encourage them to stop blocking sites like Repl.it
grlass··on Ask HN: How are virtual desktops useful to you?
I have 10 virtual desktops, accessible with the keyboard shortcut Super+[0-9].

I essentially use it as a faster alternative to tab switching, by grouping types of applications in different desktops.

- My main text editor can always be reached with Super+1. - Most of my browser windows are at are Super+2 (tab switching between multiple windows) - Super+3 is has my terminal sessions - Super+4 has my dashboards and things like Jupyter notebooks - Super+5, Super+6 don't get used that much - Super+7 is for media - cmus, Spotify, etc - Super+8 is for Zotero and papers I am reading, as well as ebooks and such - Super+9 is for my email client - Super+0 is for my social apps, such as those stored in a Rambox-like, Element, cwtch, Signal, and others.

I haven't bothered with any automatic grouping, and I can easily send a given window to a given desktop with Super+Shift+[0-9].

This isn't as deep as what some power users do. But it saves me a lot of keystrokes, and helps me feel organised.

grlass··on Signal's Server repo hasn't been updated since April 2020
Take your point, though given it's all E2E, the server logic doesn't need to be that complicated, or changed with new features, since every new feature can be implemented as a message. Server just needs message queues and routing?

I'm aware they're looking at backup features and such, wondering if they'd be part of the server, or a different system.

I'd expect some improvements to performance and such, esp. as they grow, so good catch on the 10 month wait, but it's an orange flag rather than red flag to me.

grlass··on Bitfinex and Tether required to end all trading activity with New Yorkers
Also note Kraken, withdrawals are as fast as a wire transfer (so a few days): https://www.kraken.com/en-us/prices/usdt-tether-usd-price-ch...

What I'm not sure is how that market connects to Tether's bank accounts increasing or decreasing in holdings. This is all third-party exchanges, presumably with other customers as the counterparty.

grlass··on The Lost History of Socialism’s DIY Computer
PoC||GTFO article on this also good: https://archive.org/stream/pocorgtfo09#page/n39/mode/1up
grlass··on A German man is keeping $60M in Bitcoin from police
If he doesn't have a copy of the file, then even if the cops can't access it, semantically they could be said to have seized them?
grlass··on Creating a Signal account
worth looking that the cwtch.im alpha chat app, that attempts to mitigate the metadata problem with TOR, and having untrusted servers that host group chats.

Similar philosophy to Signal of trying to really get usability right (looking at you, Element). Though still early in alpha development, wouldn't trust current alpha builds to be reliable.

grlass··on Creating a Signal account
Short-medium term you have the advantage that the Signal codebases are open source, thus much easier to audit.

There have been a number of independent security audits over the years, which are easy to find. WhatsApp code was never open, even pre-Facebook.

grlass··on The embedded YouTube player told me what you were watching
You misunderstand: it's ageist to suggest that parents and grandparents are by definition not likely to be technical enough to use mitigations like containers and such.

Which it is.

grlass··on The Internet Is Starting to Turn on MLMs - TikTok first major platform to ban
Yeah, acronym overload is very strong here, MLM is Men Loving Men, thus the title is pretty funny on first reading.
grlass··on Apple iCloud account and sign in outage affecting some users for over 24 hours
If we're talking server class, then the average experience for me is a lot easier than what setting up that particular device was.

From the perspective of an individual, whether or not your experience is representative of most people's experience of a similar thing only has moderate relevance. Most people find serial killers to be normal, or even charming. This is of little comfort to victims.

grlass··on Apple iCloud account and sign in outage affecting some users for over 24 hours
Indeed, purpose was illustrative hyperbole - I am used to frustration. Consumer devices come with less expectation of frustration, a justified expectation setting up Android devices, games consoles, Chromecast-type things, etc.
grlass··on Apple iCloud account and sign in outage affecting some users for over 24 hours
Am not an Apple user, was tasked with setting up a new Apple ID for a parent's iPad today. Took an hour, one of the most unpleasant computing experiences I've had in recent memory, and I deal with embedded Linux systems.

14 OTPs sent to their mobile number, frequently being dumped back to the login screen. Maybe this was the reason, but damn this has discouraged me from ever going into their walled garden.

grlass··on Mozilla takes action to protect users in Kazakhstan
Worth looking at what the response to Mozilla's DNS-over-HTTPS system in the UK has been. Disabling it by default is a good way to avoid conflict, but means that the feature effectively doesn't exist for the vast majority of users.

https://www.zdnet.com/article/mozilla-no-plans-to-enable-dns...

grlass··on Demon Core
The authority on the subject: https://youtu.be/lJXwRdbbQ50
← PreviousPage 3 of 3