HNHacker News
TopNewBestAskShowJobs

herendin

963 karma · joined April 25, 2014

u
submissionscomments
herendin··on U.S. Supreme Court expands gun rights, strikes down New York law
Irrelevant. If only edge cases support the analogy, then the analogy is a poor one, as I said.
herendin··on U.S. Supreme Court expands gun rights, strikes down New York law
>It's not a practical solution, full stop. See how mass quantities of drugs are smuggled around the world

Not a good analogy. People want guns because other people have guns. But people do not want drugs because other people have drugs

herendin··on Mega says it can’t decrypt your files. New POC exploit shows otherwise
>tampered logins need not show up as failures.

Thanks for clarifying it. Yes, the writing about it is surprisingly unclear. Even on the original paper and the dedicated website for this bug, there's a frustrating lack of clarity about what they mean by "login" and how much the user is in the loop of this attack, which could be an important gating factor making it unlikely to ever have been a practical exploit

herendin··on MEGA: Malleable Encryption Goes Awry
The point is this exploit, according to the researchers, required massive and unusual manual intervention by the user, so it's very different from the other exploit you mentioned that involves millions of auth attempts

From the link I just posted, written by the researchers:

'Nevertheless, on the clients that we analyzed, all attacks would have required a substantial number of manual login attempts (i.e., the user entering the password). Since clients usually cache the credentials, users often stay logged in, minimizing the number of logins performed and thereby increasing the difficulty of the attacks.'

herendin··on MEGA: Malleable Encryption Goes Awry
Put simply: this attack required the user to enter the password 512 times[0]

[0] https://mega-awry.io/#questions

herendin··on MEGA: Malleable Encryption Goes Awry
These are apparently login attempts visible to the user.

To conceal them might be possible in some cases, but requires tampering suspiciously with public source client-side apps

herendin··on Mega says it can’t decrypt your files. New POC exploit shows otherwise
It appears the attack is based on a failed login leaking information, and that 512 failed logins would be enough for Mega itself to crack the key.

But, to be a practical attack, the client software would first have to be modified to conceal the suspiciously big number of bogus failed logins from the end user (if I understood clearly)

herendin··on On the angst of American journalists (2019)
>The trouble with journalism is that there's too much punditry and too little reporting.

That seems more like a symptom than a disease. Punditry is cheap, good journalism is very expensive.

herendin··on Bankers Are Driving the Wheat Price Explosion, Not the War in Ukraine
I don't know, but there are several earlier links from the site at HN, with lots of upvotes and comments

https://news.ycombinator.com/from?site=novaramedia.com

herendin··on Think of a Number. How Do Math Magicians Know What It Is?
Probably easier if you imagine it with a much smaller range of numbers, like 1-9, or even 1-3
herendin··on Details emerge of Air France B777 landing incident
In the 777 it's a direct mechanical linkage between the controls, with a torque-driven breakout which temporarily severs the link if there's too much difference in the two pilots' inputs

That still leaves the question of how to interpret opposing inputs for the physical control surfaces, though

herendin··on A man bought a cruise ship on Craigslist
Well here's your own comment, which is clearly seeking possible intention, and identifies individuals who may be responsible:

>I couldn't help being curious whether Willson, his partner, or the reporter is responsible.

I just say that this phenomenon you noticed may be accidental, and there may be no intention by any of the individuals you named in that statement, or by any other party.

Sorry, but I can't explain this situation to you any more simply than that.

herendin··on A man bought a cruise ship on Craigslist
No, I'm suggesting you're seeing intention where it possibly doesn't exist

Am I defending the reporter? Or complaining that they did a bad job by leaving that obvious question of the partner unanswered? Neither, I hope.

herendin··on A man bought a cruise ship on Craigslist
There's a photo of them in the gallery. It's likely the reporter didn't have time to talk to her, or she was unavailable or unwilling. You're probably overestimating the time and effort dedicated to writing this article. It appears to be mostly or entirely sourced from one short interview with Wilson and photos from him
herendin··on Dropbox Backup
The page effectively forces tracking cookies, because the option to decline them doesn't work
herendin··on Insider Trading at Coinbase
> I guess you could have that opinion if you wanted.

Yes, and that opinion of mine, WITHOUT USEFUL EVIDENCE, is worthless. It's no benefit to this community

That's exactly my point, this mode of discussion is totally unproductive. It's spam. It's just tribal ranting.

Sorry to hear you're in hospital. Hope you're feeling better soon

herendin··on Insider Trading at Coinbase
OK then, I assert that Beacon Studios is a company to be avoided because the management is incompetent.

My evidence is that the founder is a hothead who wastes his time leaping into online flame wars with little understanding and no evidence.

Can't you understand that this mode of discussion is totally unproductive?

herendin··on Insider Trading at Coinbase
"That which can be asserted without evidence, can be dismissed without evidence." (Christopher Hitchens)

You made the assertion, you claim to have evidence: the onus is on you to provide that evidence, otherwise how can anyone possibly challenge it?

herendin··on What is money, anyway?
>It gets even funnier when Crypto Bros start proselytizing about blockchains.

What is a "Crypto Bro"?

herendin··on How to Get Hired at Coinbase
A soft recruitment ad which instantly spams mobile users to download the app, and by using a deceptive pop-up as well, is a big blunder
herendin··on Ask HN: How can scam callers fake a mobile phone number?
Isn't it already possible for a phone to display the STIR/SHAKEN Caller ID verification status of each incoming call now?

This would be useful in the interim as this system rolls out, and would also encourage adoption by mobile carriers

herendin··on Apache Log4j bug: China’s industry ministry pulls support from Alibaba Cloud
Chinese surnames pronounced 'Mu' are similarly common to 'Xi'.

There is a Mu variant of Covid[0]

[0] https://en.wikipedia.org/wiki/SARS-CoV-2_Mu_variant

herendin··on Writer Liu Cixin on How His Visions of the Future Collide with Reality
The source of that quote, which adds a little explanation of his reasoning and thought process: https://www.newyorker.com/magazine/2019/06/24/liu-cixins-war...
herendin··on Central Bank Digital Currency – US Senate Testimony of Dr. Neha Narula [pdf]
I can think of at least two potential downsides

Fear of losing control in future. For example Ethereum presently seems to be quite secure based on the potential reward of an attack vs the assets that might be deployed to attack Ethereum. But if a Fed-backed stablecoin relies on Ethereum, then a very expensive attack on Ethereum could become more attractive to an adversary. And how about the risk of an accidental coding error by Ethereum developers in a future update?

Fear of lending legitimacy to other cryptocurrencies and tokens. Their values would explode if the Fed issued an ERC-20 token on the Ethereum blockchain

herendin··on Zip – How not to design a file format
The author makes good points about the poor documentation and vagueness of details of the current Zip format. That is something worth criticizing.

But I think criticizing the 30-year-old 'design' is pointless. So this is a good article with a bad title.

What is much more helpful is suggesting, in detail, how Zip might be extended to remain backwards compatible while moving forward to adopt a more sensible future format. (Though 30 years later, some guy is going to write an article saying how terrible that new design is).

herendin··on PayPal launches crypto checkout service
>ThIs iS AdOptIoN gUyS

Please don't do this juvenile crap here. If you have an argument to make, then make that argument.

herendin··on PayPal launches crypto checkout service
Every address, not every 'wallet' - it's a big difference
herendin··on The Downside to Life in a Supertall Tower: Leaks, Creaks, Breaks
Compare property price to land price. Then consider that apartments need windows, so building footprint is limited
herendin··on A Simple Model of Grabby Aliens
If you mean 17th century trading companies, their sailing ships had one way journey times of six months to one year to practically anywhere in the world. So it's an interesting example, but interstellar distances are usually many times longer: 5 (light) years or 10 years or much more.

I guess that the reason globe-spanning empires and trading companies appeared from about 1600 on was in fact because sailing ships had reduced the travel time enough to allow a cohesive network with some centralized control. Previously, with slower communications, they tended to lose control of the extremities and devolve to looser associations (because the lag was excessive, on the scale of a human life)

herendin··on A Simple Model of Grabby Aliens
From a human perspective, it's difficult to imagine a civilization that could remain cohesive when its territory is thousands of light-years wide, and therefore separated by time as well as space. Every significant journey is a trip into the future
← PreviousPage 2 of 4Next →