HNHacker News
TopNewBestAskShowJobs

hrbrmstr

91 karma · joined June 4, 2010

[ my public key: https://keybase.io/hrbrmstr; my proof: https://keybase.io/hrbrmstr/sigs/B4ep-4X35yfgJTMR8QrOZi275cFEnB4u30BaHBFsSjU ]
submissionscomments
hrbrmstr··on macOS 27: ifconfig command no longer prints hardware MAC address
it works fine in system bash for me
hrbrmstr··on I build it a domain security scanner
What in the name of $DEITY is that map projection?
hrbrmstr··on Ask HN: Why is my web server being attacked?
These "noise storms" are becoming more common than in previous years and are generally tied to global "major" events.

This: https://observablehq.com/@greynoise/noise-storms has some explanation but I'd be glad to elaborate more if needed.

hrbrmstr··on Ask HN: How to do literal web searches after Google destroyed the “ ” feature?
100% ^^this^^
hrbrmstr··on 𝕏 monthly users reach new high in 2023
Well, when you force users to login at least 1/month to keep their handle/account, you're 100% going to get an inorganic and non-truthful MAU metric, especially if you define that "A" to be <=20 seconds.
hrbrmstr··on Men are dropping out of the labor force because upset about their social status
I realize the study was unable to or just did not perform “follow-ups” with the individuals they are positing “no longer work”. But, what exactly are these malcontents doing instead, then?

Living with parents? (Why would a parent enable this juvenile behavior)?

Relying on their spouse's income to survive (and, if so, is there any real harm/issue with this)?

Going “off the books” and just being part of the underground economy (in which case, this 'not working' posit is partly a falsehood).

Even woefully entitled dudes have to eat, no?

hrbrmstr··on Why can't we download data from screen time feature on Apple devices?
It's accessible: https://rud.is/b/2019/10/28/spelunking-macos-screentime-app-...
hrbrmstr··on Ask HN: Why do I see so much crazy inline styling on websites these days?
That particular page appears to have been created with "Unbounce" (https://preview.unbounce.com/) (the "lp-*" strings give that away). If you look for said "lp-" strings on the web there are more than a few pages using them. Unbounce is primarily designed for creating HTML email that won't break and won't get auto-rejected and it's likely easier for the builder program to stick in hardcoded values in-tag than to rely on complex CSS, especially with the varied capabilities of mail clients.
hrbrmstr··on Apache HTTP Server Remote Code Execution CVE-2002-0392
I'm not sure why this particular CVE is [re-]surfacing now, but the January 1, 2019 Rapid7 Sonar HTTP port 80 scan found ~5,000 vulnerable servers and the list of vulnerable versions is larger than what's on the CheckPoint page: https://www.cvedetails.com/cve/CVE-2002-0392/?q=CVE-2002-039...
hrbrmstr··on Ask HN: Is GWT/Google Web Toolkit still being used today?
According to https://trends.builtwith.com/framework/Google-Web-Toolkit ~43K sites use it.
hrbrmstr··on Ask HN: Google repeatedly thinks I'm a robot
Yep. If you move around in google faster than "normal" humans it's flagging that behaviour more lately. I suspect some malicious (i.e. made by content thieves) web scraping instrumentation frameworks have added more natural human behaviours to their capabilities but still operate at a higher-than-"normal human" rate and those of us who are highly adept at legitimately utilizing google now fit into that new classifier slot. It's been super annoying.
hrbrmstr··on Ask HN: InfoSec questionnaire – what to do when customer wants one completed?
Properly constructed information security questionnaires enable a business partner to conduct a high-level, non-intrusive assessment of your organization. You have a right to be concerned about the sensitivity of the data, but if you distrust your business partner that much, then don't do business with them. Your org is not a special snowflake and this is a very common practice by organizations of all shapes and sizes with organizations of all shapes and sizes. They are not the be-all/end-all of information sources (orgs regularly fib on these forms) and you do have a similar right to ask the inquisitors how they will protect your form data (that will also partoy show them you at least give lip-service to data security). It's also far more likely that your organization is going to get pwnd via phishing that is completely unrelated to the potential loss of confidentiality of this document. I say that as someone who has formally studied cybersecurity breaches for years.

Also, as cyberinsurance increasingly becomes "a thing", you're going to see this questionnaire situation increase in frequency. Your org should consider creating a pre-composed (and regularly updated) SSAE 16 (https://en.wikipedia.org/wiki/SSAE_16) to avoid having to fill out unique assessment questionnaires for every request that comes in. It'll save you time and — unless you "go N/A crazy" on the SSAE 16 — should be accepted by any firm worth doing business with.

hrbrmstr··on Luna, the visual way to create software
Congrats to the team for launching something in 2018 on macOS without it being signed! Great way to encourage good security & safety practices for data folks on macOS! Signing is super hard, too. Totally not baked in to any workflows.
hrbrmstr··on Curiosity – Find cool GitHub projects as a feed
how many times are you going to submit this?
hrbrmstr··on Beer and Concurrent HTTP Pipelines
Rather than emoticon-ing away your responsibility in a potential site DoS, perhaps read up on responsible crawling - https://webarchive.jira.com/wiki/display/Heritrix/Responsibl... + http://blog.mischel.com/2011/12/20/writing-a-web-crawler-pol... . You had no need for either unlimited or even 50 parallel crawl tasks. And, if your intent is anything but personal use, you shld prbly (re)read https://www.brewtoad.com/legal since you just got their attention in a pretty big way.
hrbrmstr··on Bureau of Labor Statistics Public Data API
Indeed. Pretty quick work with RCurl & RJSONIO… https://gist.github.com/hrbrmstr/6566865
hrbrmstr··on ping `curl whatismyip.akamai.com`
From the methods outlined in the thread so far, I think I'd pick Akamai after a quick test of each of them. (results in the following are based on the 'real' value returned in a 'time' command

  Google 'ping' "baseline" from my ISP
     20 packets transmitted, 20 packets received, 0.0% packet loss
     round-trip min/avg/max/stddev = 19.858/23.823/31.484/2.593 ms

  #/SITE/METHOD
  #1: myip.opendns.com (dig)
  #2: whatismyip.akamai.com (curl)
  #3: ifconfig.me (curl)
  #4: ip.nux.ro (curl)
  #5: icanhazip.com (curl)

  RESULTS

  #1      #2      #3      #4      #5
  0.051   0.144   3.45    0.24    0.333   
  0.05    0.143   7.229   0.237   0.106   
  0.053   0.147   1.986   0.246   0.103   
  0.047   0.143   7.065   0.246   0.109   
  0.045   0.145   2.15    0.257   0.102   
  0.046   0.141   4.301   0.273   0.113   
  0.05    0.141   2.763   0.242   0.103   
  0.048   0.144   3.685   0.251   0.114   
  0.045   0.149   15.312  0.256   0.195   
  0.047   0.148   5.091   0.244   0.118   
  0.044   0.144   2.637   0.248   0.133   
  5.038   0.142   1.535   0.247   0.109   
  0.049   0.143   7.065   0.238   0.115   
  0.044   0.146   4.098   0.241   0.106   
  0.05    0.145   1.665   0.248   0.216   
  0.05    0.142   1.365   0.261   0.108   
  0.051   0.143   2.509   0.256   0.159   
  0.046   0.17    5.323   0.245   0.109   
  0.044   0.141   83.252  0.246   0.117   
  0.05    0.145   1.435   0.242   0.119

  0.048   0.144   3.685   0.246   0.113 MEDIAN
  0.310   0.145   8.551   0.248   0.135 AVERAGE
  1.144   0.006   18.377  0.008   0.057 STDEV
hrbrmstr··on Data protection
For #1, I would suggest that your application/API will be the weaker link in the security/privacy chain. While it's possible that you could have Heroku or EC2 admins do "bad things" or have "unruly neighbors", it's far more likely you'll introduce flaws via insecure coding practices or by using insecure libraries. If you rely on solid data encryption (at rest and in transit) practices and make the effort to secure credentials properly, you should be fine in either setup. I'd make the dedicated VPS vs "cloud" setup based upon need for scalability/etc vs security. You should be able to secure a "cloud" config to your needs.

For #2 – since it seems you're in more a 'privacy' realm than a 'compliance' realm, it may be worth the time to peruse the White House's framework – http://www.whitehouse.gov/sites/default/files/privacy-final.... – from this past Feb (which has links/refs/comparisons-across privacy standards) and then the CSA's Cloud Controls Matrix : https://cloudsecurityalliance.org/research/ccm/ : or the whole CSA GRC stack : https://cloudsecurityalliance.org/research/grc-stack/ : which should help you assess which provider/service is right.

The prescriptive controls in PCI can help you design your data access & handling strategy, but you have to remember that PCI is highly focused on protecting a sixteen digit number and you'll need to determine what your critical data components are from a privacy perspective to effectively map against PCI or other control frameworks.

hrbrmstr··on 21 Things You’ll Learn From Blogging for 10 Years
It's a shame "crafting proper headlines/titles" was not one of them.
hrbrmstr··on The real source of Apple device IDs leaked by Anonymous last week
Make sure to read the actual details from David Schuetz's – @DarthNull – blog post (the dude who did the digging):

http://intrepidusgroup.com/insight/2012/09/tracking-udid-src...

hrbrmstr··on What UPS knows
As others have pointed out, they use an identify verification service. In most cases, any org that uses such a service doesn't even see the data the form is asking for (i.e. it's just a pass thru, much like CC# forms in IFRAMEs).

Granted, it is scary what is aggregated about you and stored in some giant data warehouse somewhere (prbly not protected very well). But I'd rather an org use a third-party such as this vs begin to aggregate similar data on their own.

However, think about what else UPS knows about you (without this data). They have your name, address, phone and know precisely (for all things they handle) how often you receive shipments from where, how much they weigh and potentially other data (depending on whether they've done any scanning or if there is any hazardous or perishable labeling on it). If they've ever tried to deliver and needed a sig and you weren't there, they have a record of when you're not home as well.

I wonder if they (or FedEx, et al) have a policy whereby you can request all the data they have stored on you like this…

hrbrmstr··on Growl, meet Bark.
Annnnnddd… Bark is totally unnecessary now: http://growl.posterous.com/developers-growl-20-sdk-released
hrbrmstr··on Growl, meet Bark.
I think it is indeed "just" a stop-gap but is also more of an alternative for folks who want to keep with the non-gate-kept ecosystem. The concept of Bark is cool, but I'm not keen on running code that injects at the level it does without it being open source and something I can inspect/build on my own.
hrbrmstr··on Growl, meet Bark.
It does code injection and is different primarily in that all Growl notifications show up as "Hiss" notifications in ML NC vs being unique sections that you an select and go to the app context with.
hrbrmstr··on EmailOracle (YC W10) Tracks Your Emails and Confirms They've Been Opened
I've worked and consulted in over 15 very large enterprises. While it may not constitute a survey of the entire Fortune 500+, I've come into contact with enough business & IT professionals to know that is is - in fact - not a well-received feature. It's used by either underperforming folks as a CYA measure or other folks who have side-swiped by self-serving individuals.

There is no legitimate use or business-case for a read-receipt service, especially ones that use the same techniques as malware writers.

I fully support your third-party "who responded to me?" reporting & reminder tool, as I can see that being incredibly useful - especially to those who are not adept at scripting and/or using mailer APIs.

hrbrmstr··on Dropbox never deletes cache files
er...not true.

take a look at (start from the last post): http://www.rudis.net/category/topic/dbcc

that was a problem a while ago. they've cleaned up their client quite a bit.

hrbrmstr··on Ask HN: Teaching programming to a 10 year old, and I'm kind of lost
I'm with dpcan on this one. I started my current 10yo on Scratch at 8 and have been giving him incremental "challenges". The immediate feedback for even his first "program" was enough to keep him hooked. He regularly keeps making new games and often pushing the system to its limits (Scratch has many annoying limitations if you're a seasoned programmer or even a kid who has figured out that something like an array - he wouldn't use that word, tho - would be useful).

He started 5th grade last week and one of his classes is a programming class which uses MicroWorlds - http://www.microworlds.com/ - as the learning platform. I grabbed the demo and may shell out the $100 for the home version, just so he can do stuff here in it as well. It's not a horrible system, but it's definitely rough around the edges.

I fully expect to have him starting in Python by 6th grade, tho.