HNHacker News
TopNewBestAskShowJobs

harporoeder

6,669 karma · joined August 17, 2018

Website: https://harporoeder.com

Twitter: https://twitter.com/harporoeder

GitHub: https://github.com/harporoeder/

submissionscomments
harporoeder··on Flock Wants a Closely Surveilled World with No Exit
There is not generally an expectation of privacy in public. Things in public can be recorded without consent. Filming a car on a street and giving that video to the government is not the same as me giving private information to a third party, and then them giving it to the government such as Carpenter v United states covers.

Edit: Note that this is not an endorsement, rather stating that recent supreme court cases may not be applicable.

harporoeder··on FreeBSD Capsicum vs. Linux Seccomp Process Sandboxing
A default container seccomp profile will let you do quite a few things but you can use a different profile some json and limit to just a few system calls if you want such as doing IO on open FDs without the ability to open them. I think the runtime opens the FDs before the child process starts and are inherited.
harporoeder··on FreeBSD Capsicum vs. Linux Seccomp Process Sandboxing
This is essentially what containers are. Bubblewrap / Docker / Podman. I think the primary issue is very few applications on Desktop systems are actually designed with sandboxing in mind unlike say something on a phone.
harporoeder··on OpenMANET Wi-Fi HaLow open-source project for Raspberry Pi–based MANET radios
The killer application in this case is ATAK.

https://en.wikipedia.org/wiki/Android_Team_Awareness_Kit

harporoeder··on Wayland Apps in WireGuard Docker Containers
I have had pretty good success with steam inside docker. Things like playing counter strike have been pretty seamless. It's cool to see others doing the same. I'm waiting for wayland isolation stuff to actually be integrated into everything (security contexts etc). Even with all this isolation passing in an X socket totally breaks any security guarantees against anything actually malicious. For other apps I can do the dummy X server trick (nxagent etc), however for gaming that is really not an option with the performance requirements.
harporoeder··on Types as Interfaces
With dependent types you still end up having to do dynamic checking of invariants for a substantial portion of real world code to construct the value with the properties you want. Anything coming from disk or network or a database etc. In practice I feel that it is far easier to just do manual dynamic checking with the constructor hidden from other modules such as `constructEmail :: string -> Email' which uses normal value level code, a common Haskell pattern. Obviously a little less flexible for the common dependent type examples of such as appending two vectors of a specific length.
harporoeder··on Zooming User Interface (ZUI)
While I'm not sure I would claim it is practical, playing around with eaglemode is fun. It is available in the AUR among other places

1. https://eaglemode.sourceforge.net/screenshots.html 2. https://aur.archlinux.org/packages/eaglemode

harporoeder··on Kernel Hardening: Protect Linux user accounts against brute force attacks
There are lots of ways to protect your system from a browser exploit via containers, another user, a vm, etc as brought up by other people responding. However protecting a browser from other applications is basically impossible unless you also sandbox everything else you are doing. Even if you run a browser in a VM some other process run as your user could just automate clicking the UI to do whatever. If you go qubes style and isolate everything from everything then it is fine.
harporoeder··on The hunt for the missing data type
Even with direct mutual references between some node type this can be represented in a lazy functional language such as Haskell pretty easily without mutation.
harporoeder··on Tell me your most exotic selfhosted solution
Interesting. I had no idea CBRS existed. Can you provide any more information about the base station and what your experience was like?
harporoeder··on SpaceX launches first phone service satellites
Line of site transmissions can go massively further than with even minor obstacles. While a different frequency amature radio operators easily contact the ISS on $30 5 watt handheld radios. If I recall Iridium phones are only a couple watts.
harporoeder··on OpenBSD Workstation Hardening
Obviously OpenBSD has some limited mechanisms for managing RAM usage and open file descriptors, just like every other system.
harporoeder··on OpenBSD Workstation Hardening
Wayland does not stop a process from manipulating the home directory, doing various things on the network, using a ton of memory, recording what other processes exist etc. Once you add all that stuff you start to get something that looks a lot like containers.
harporoeder··on OpenBSD Workstation Hardening
A malicious program is going to have a difficult time adding something to your ~/.profile script if it cannot access your home directory. Although I don't doubt that many flatpak programs have too lenient default permissions, and the various XOrg lack of isolation issues are unfortunate somewhat remedied in wayland.
harporoeder··on OpenBSD Workstation Hardening
eBPF is used for substantially more than observability.
harporoeder··on OpenBSD Workstation Hardening
It is hard to call OpenBSD an OS focused on security. Beyond pledge their primary focus seems to be "just implement everything correctly and don't run malware". If some utility has an implementation error or you do accidentally run something malicious you are hosed. Compare this to Linux with the extensive use of containerization and things like eBPF for dynamic security measures, or portals as part as flatpak for dynamic application permissions.
harporoeder··on Blueprint health protocol
I wish blueprint was more public and open about the methodology and data. Johnson is doing so many interventions and it would be interesting to have public data for them beyond a periodic aggregate snapshot on the blueprint websites which basically amounts to a marketing page. In comparison someone like Michael Lustgarten (1) publishes nearly everything, documents what intervention they are about to do, do it, and then publish the results.

https://michaellustgarten.com/

harporoeder··on Chinese villagers capture video of falling Long March rocket booster [video]
I'm not sure what large tax bill you are referring to assuming you have been correctly filing? Googling it looks like there is a flat fee of $2,350. There is an exit tax if you have a net worth above 2 million, or a high income, and this appears to be a capital gains tax on assets.
harporoeder··on Learn Modern C++
I feel that modern c++ is a game of how many times you can fit `const` in a single declaration. I usually have at least three for the simplest of functions.
harporoeder··on Obsidian 1.5 Desktop (Public)
For an opensource alternative to Obsidian checkout Logseq (1). I spent a while thinking obsidian was opensource out of my own ignorance and was disappointed when I learned it was not. I mistook the extensive github presence for the actual product being open.

1: https://logseq.com/

harporoeder··on How to Escape a Container
All of these escapes rely on some obvious explicit reduction of the isolation guarantees. If you know how to escape a simple docker container invoked with default parameters such as `docker run --rm -it ubuntu /bin/bash` I'm sure many people would be interested.
harporoeder··on Earlyoom – Early OOM Daemon for Linux
I would prefer a process on my desktop be killed rather than my system become unusable to the point of requiring a hard reset of the machine as is common on Linux systems during low memory scenarios.
harporoeder··on TSA introducing self-service screening technology in Las Vegas
This is well before TSA but plane hijacking used to be common occurrence: "Between 1968 and 1972, more than 130 American airplanes were hijacked. Sometimes there was more than one hijacking on the same day. "

https://www.vox.com/2016/3/29/11326472/hijacking-airplanes-e... https://en.wikipedia.org/wiki/List_of_aircraft_hijackings#19...

harporoeder··on Polycentric is an Open-source distributed social network
The privacy policy is just for servers FUTO runs. We can't host content that is illegal in our jurisdiction for example. It is similar to refusing to seed certain torrents. Servers run by other parties, or in other jurisdiction will likely have different policies. Your identity is always yours, and whoever is willing to host it can.
harporoeder··on RISE: Accelerate the development of open source software for RISC-V
There is a risc-v laptop available using the Alibaba Xuantie chips:

1. https://www.alibaba.com/product-detail/DC-ROMA-RISCV-Laptop-... 2. https://www.tomshardware.com/news/risc-v-laptop-world-first

harporoeder··on Storage on Vercel
Backblaze is $0.01/GB egress and $0.005/GB/Month storage.
harporoeder··on Globally Distributed Elixir over Tailscale
Nebula implemented UDP(?) Relay support (1) last year although it is marked experimental.

1. https://github.com/slackhq/nebula/pull/678

harporoeder··on Nuclear explosion impact on humans indoors (2022)
This is not without controversy (1), and as I understand the expected cause is not from the nuclear explosions but the fires caused by the bombs such as standard forest fires.

1. https://en.wikipedia.org/wiki/Nuclear_winter#Criticism_and_d...

harporoeder··on Jack Ma cedes control of Ant Group
https://archive.is/uuDDb
harporoeder··on NY Sabotages Right to Repair Bill [video]
Shameless plug, the organization Louis (and I) work for, FUTO, is hosting a fellowship program sponsoring people to work on open-source software for three months for $20k-$80k and free housing in Austin. Applications are due Jan 1st!

https://futo.org/fellows

Page 1 of 2Next →