HNHacker News
TopNewBestAskShowJobs

hf

454 karma · joined January 25, 2014

hfuchs.net
submissionscomments
hf··on Xkcd: Heartbleed Explanation
That's precisely the point that riles our tinfoil-hated friends: Heartbeat should be a simple matter of hi-ho's ad infinitum (ie: no or constant-space parameters).

This is, of course, glossing over the fact that TLS over a TCP link doesn't actually need a heartbeat. TLS/UDP does, granted. Ever heard of DTLS?

hf··on TLS Lite
Having found no mention of TLS Lite in the last few discussions[0], I thought this TLS lib with just under 10.000 LoC (roughly 1/30 of OpenSSL's) deserves a bit of spotlight.

Written by Trevor Perris of "Moxie Marlinspike and Trevor Perrin's TACK."-fame. Summary from the page:

    TLS Lite is an open source python library that
    implements SSL and TLS. TLS Lite supports RSA
    and SRP ciphersuites.  [It] is pure python,
    however it can use other libraries for faster
    crypto operations.
Direct link to the Github-page: https://github.com/trevp/tlslite

Now onwards with the arguments ("side-channel attacks?")!

[0] It has actually never been on HN, if Algolia is to be trusted.

hf··on Free Programming Books
A fine, curated list.

As with most meta-topical lists, there is virtually no profit in browsing through it. Time may be wasted a-plenty, though.

Bring a question about technology X with you, go straight to section X and then consult with the search engine of your choice (or a hacker friend, idealy) which book to actually read.

Hint: some of those have wikipedia-pages, like https://en.wikipedia.org/wiki/Higher-Order_Perl and others hide the books behind an email signup front (one is a strong signal for quality, the other, perhaps, not so much).

hf··on Free Programming Books
As with all things: necessity dictates, curiosity nudges.

If you come without baggage (project idea, interest in FP, what-have-you), you'll need to come back later.

hf··on The Heartbleed Bug
Thanks!
hf··on OpenSSL is written by monkeys (2009)
I am a bit reluctant to repeat myself, but I can't see any mentioning of the sheer volume of code. It's more than 300.000 lines of code in the .c files of the official tarball.

My experience with code grown beyond >10⁵ LoC is that it forces you to monkey-patch around any bugs (or even features for that matter). Surely there's a Potterson's Law or something that describes the situation.

In short: it's not the monkeys (quality), it's the volume of code.

(Of course now we're getting in a chicken-egg situation.)

hf··on The Heartbleed Bug
Thanks! So how does this work: Say I have this project and I want it audited -- would you (or the company/person that you had in mind) give me an estimate like "I'd need 3 weeks for 25, 5 weeks for 50 or 10 weeks for 95% coverage" or do you simply analyse away for a week (or whatever time I'm willing to pay you) and try to find something?
hf··on The Heartbleed Bug
Over 300.000 LoC:

    ~/tmp/openssl-1.0.1g $ find . -name "*.c" | xargs wc -l  | tail -n1
      349834 total
This is too much by at least one order of magnitude. What's the going price for a crypto-level code review (I'm not even saying audit) these days?

Is all this code necessary for state-of-the art encryption or isn't it rather backwards compatibility baggage? If the latter: how much could be gained by splitting the project into '-current' and '-not'?

hf··on Linux 3.14 out
Also, we're possibly one step nearer to Plan9's portable /bin concept (where each user overlays her binaries with those provided by the system).
hf··on Linux 3.14 out
This should've been in my never-ending history:

  $ tex -v | head -n1 | awk '{print $2}'
  3.1415926
but it wasn't (I distinctly remember using this line to prove a point a few months ago).
hf··on Show HN: manpages-tldr – short manpages with examples
Yes, as in that case

* the survival of OP's labour is more likely; and

* one might use something like `eg`[0] to directly jump to the 'Examples' section.

[0] I gave a possible implementation below (https://news.ycombinator.com/item?id=7167835).

hf··on Show HN: manpages-tldr – short manpages with examples
Elsewhere[0] I mentioned a shell alias called `eg` that jumps to the 'Examples' section in traditional man-pages.

I made great use of it with the excellently structured yet rather verbose git man-pages.

Anyways, here's the alias:

    alias eg='man --pager='\''less -p "^[A-Z]* ?EXAMPLES"'\'''
Try it out:

    eg git pull
(With older shells you might have to say `eg git-pull`).

Now as concerns the fine project submitted here, I'd suggest to try getting as much of those tldr's into actual man-pages. This will at least make the long-term survival of OP's labour more probable.

[0] https://news.ycombinator.com/item?id=7167815

hf··on Bro pages: like man pages, but with examples only
I humbly submit an implementation of `eg`. It solves the technical problem discussed here for a selection of programms (notably git!):

    alias eg='man --pager='\''less -p "^[A-Z]* ?EXAMPLES"'\'''
This obviously depends on the quality of the man-pages.

Witness: `eg git pull` (with a recent enough Bash, `eg git-pull` otherwise), `eg awk`, `eg cat` or even `eg man`.

Ironically, the curl man-page doesn't have a separate Examples section; the authors prefer to intersperse those throughout the text.

The name was coined here by imdsm[0] -- I had been using `examples` previously.

[0] https://news.ycombinator.com/item?id=7121505

← PreviousPage 3 of 3