HNHacker News
TopNewBestAskShowJobs

half-kh-hacker

1,194 karma · joined June 3, 2017

she/her. videogame cheat developer
submissionscomments
half-kh-hacker··on Cname / DNS based third party tracking
If you get allocated a /32, you have 95 bits of addresses to play with. You could use a different IP every millisecond and not have problems.
half-kh-hacker··on How I cut GTA Online loading times by 70%
Game cheat dev here: Just to provide some context, the GTA Online client is woefully horrible at doing client-side validation on the packets it receives from other peers. (there isn't an authoritative server)

This means that anyone in your session can send you a weirdly-formed packet to crash your game. Most cheats have protections against this by just doing Rockstar's job and adding better validation around packet interpretation routines.

Using "cheats just to protect [your]selves" actually makes a lot of sense.

half-kh-hacker··on Python 3's F-Strings: An Improved String Formatting Syntax
Not f-strings, but I am partial to something like:

    _("Hello, {name}").format(name=name)
half-kh-hacker··on How Prosody developers spent 2020
I think XMPP is a really good contender in the non-centralized personal-and-public messaging space. It doesn't look like an insurmountable effort from one person to support the XEPs required to create a competent chat application, unlike my impression of Matrix.

I think a nice, lean-but-glossy desktop client (we already have Conversations on mobile) would be really good for the platform. It's a lot easier to fight network effects if the end-user-experience is tangibly better (and you can do a LOT better than the current incumbents that are Slack and Discord.)

half-kh-hacker··on Radicle: A peer-to-peer alternative to GitHub
If your main repo lives on GitHub, your (primary) issue tracking is tied to GitHub.
half-kh-hacker··on Zero-Days in Desktop Web Browsers
Surely that xkcd applies more to privilege escalation vulnerabilities, not plain RCE?
half-kh-hacker··on New youtube-dl release: v2020.11.01.1
> "token" parameter not in video info for unknown reason

This is seemingly fixed in commit 6d4733ce - " [youtube] Fix JS player URL extraction" at 2020-10-31 23:52 GMT.

half-kh-hacker··on Python 3.9
> This is equally true in Java. Types are erased at runtime. They don't exist in the bytecode.

I work with bytecode on a daily basis (I develop a commercial Java obfuscator) and this is untrue. You may be thinking of generic type parameter erasure, but even then special interface methods are generated by the compiler so that no lowering to java/lang/Object happens too soon.

In non-generic code, the types remain and are strongly enforced. Methods have descriptors that restrict parameters to certain types (you can get a VerifyError upon loading the class if you've generated code with a type confusion), there is a 'checkcast' instruction to ensure that a stack values is a certain type, and a ClassCastException is thrown if a cast is impossible.

half-kh-hacker··on A request to a YouTube video downloads the title 14 times and displays it twice
There definitely needs to be a way to turn off the localization.
half-kh-hacker··on When you browse Instagram and find Tony Abbott's passport number
I love Alex's stuff.
half-kh-hacker··on Why Johnny Won't Upgrade
You might be able to hit the OK/Confirm button to switch faster.
half-kh-hacker··on Kotlin 1.4
What's wrong with:

    data class Point(val x: Int, val y: Int)

    // Later on...

    if (p is Point) {
        let (x, y) = p
        // x and y are of type Int
    }
That Kotlin has, already, now?
half-kh-hacker··on Court dismisses Genius lawsuit over lyrics-scraping by Google
1.608 megametres :^)
half-kh-hacker··on Passbolt: Self hostable, open source, password manager for teams
bitwarden_rs solves this.
half-kh-hacker··on The U.S. can now set its own rates for mail from China and other countries
I'm not American so I'm probably just used to other systems, but does a public service need to be profitable?

Think of it like a "cost centre" in a business, does the utility outweigh the price?

half-kh-hacker··on FF Sandbox Escape
My one run-in with this has been that Firefox and Chromium both use libwebrtc, which is managed by the Chromium project as far as I can tell.
half-kh-hacker··on Prologue: Full-Stack Web Framework Written in Nim
I'm curious: Is there anything you're using for parsing in Nim?
half-kh-hacker··on 5G is perfectly fine
> I don't imagine the network as a whole will upgrade to 5g-only.

5G only is fine, as it encompasses more modes of operation than just the millimetre-wave model.

half-kh-hacker··on Sol – a sunny little virtual machine (2012)
(2012)

Having written a few toy VMs in the past (and some in production!), there are always avenues to "make it weird."

Sol's yield/end instruction pair looks super abusable if you want to write somethiing obfuscated.

My favourite alteration has always been to not have any control flow instructions in the provided ISA, but allow the programmer direct write access to the program counter register, or force them to write self modifying code.

After all, programming is fun.

half-kh-hacker··on Deno Is a Browser for Code

    const status = await Deno.permissions.revoke({ name: "run" });
    assert(status.state !== "granted")

    import * from "https://shady-site.com/this-file-cannot-run-processes.ts"
half-kh-hacker··on I bought netflix.soy
I own 인스타그램.닷컴, and (actually!) use it to share photos with my Korean friends.

But, uhh, I would certainly not decline if Facebook were to try to purchase it to make it reroute to Instagram.

half-kh-hacker··on Deno 1.0
Both the network and disk access permissions are granular, which means you can allow-write only to your logs folder, and allow net access only to your DB's address.
half-kh-hacker··on Show HN: Silk, a simple systems programming language
Anecdote: Kotlin uses val/var, but IntelliJ (the de-facto standard editor for Kotlin) will underline all mutable variables.
half-kh-hacker··on Show HN: Pxy – A Go server that proxies websocket livestreams to RTMP servers
While WebM usually contains VP8 or VP9, it isn't impossible to throw an h264 stream in there
half-kh-hacker··on Google Fonts Analytics
I would hazard a guess that more Linux users are blocking the ad networks that StatCounter utilizes to collect their data than Linux users that block requests to fonts.google.com.
half-kh-hacker··on Ask HN: How to tell if my Linux server has been infected by a mouse
Actually, this 'auto-install Razer bloatware' behaviour is a feature of Windows itself.

The mouse merely presents itself as being from a certain manufacturer, and Windows asks the user if it should fetch the drivers (and any other bundled crapware Razer wants to load on there).

There is no installer payload inside the mouse.

half-kh-hacker··on Circumventing the JVM's Bytecode Verifier
To be fair, this is three-and-a-bit years of experience in this area, so it's not like I've learned this in my eight weeks of lectures...
half-kh-hacker··on Circumventing the JVM's Bytecode Verifier
I would love to do something like that to HotSpot but with W^X being a thing I don't think it'd be easy with these Unsafe tricks. I'd probably have to do some JNI hackery...
half-kh-hacker··on yGuard – An open-source Java obfuscation tool
yGuard seems to focus mainly on removing dead code and emitting small names, so this looks like size optimization.
half-kh-hacker··on yGuard – An open-source Java obfuscation tool
A little, but you can balance the obfuscation's complexity so that the HotSpot JIT is able to inline the transform.

Of course, this comes with a trade-off that custom deobfuscation transformers will also be able to inline these, but that's theoretically possible for every transform, anyway, since you can try some symbolic execution until you get the string values back out.

← PreviousPage 3 of 6Next →