HNHacker News
TopNewBestAskShowJobs

invokestatic

1,106 karma · joined December 16, 2014

Brendan Heinonen heinonen.co
submissionscomments
invokestatic··on Supreme Court Overturns Roe vs. Wade
It's actually written in the Constitution that we as Americans enjoy many rights that aren't explicitly written in the text. It's in the 9th amendment and 14th amendment due process clause.

The 14th, to me, encompasses everything that it means to be American: self-autonomy. The right to marry outside our race, the right to choose our sexual partner, the right to birth control are established in the due process clause.

invokestatic··on SF Conservancy now accepting copyright assignment for any GPL software
> following their failures to force through the GPLv3 such as the EFF

Surely you mean GNU and not EFF.

invokestatic··on I accidentally loaned all my money to the US government
The treasury does not create money. The treasury deposits its money at the Federal Reserve Bank of New York.
invokestatic··on Testing my system code in /usr/ without modifying /usr/
I believe this was to mitigate certain PHP code execution and file upload exploits. It used to be fairly commonplace that file upload code was buggy, allowing you to upload arbitrary files into the web root. So people would upload “PHP shells”, which are backdoor scripts, somewhere on the web root and then navigate to that URL to execute the shell.

I think this technique still remains common to escalate getting admin on a WordPress blog to taking over the host.

invokestatic··on Lenovo Forums stores plaintext password as a cookie
Nothing stops a hacker from siphoning all the credentials from a login page either. Servers have to handle plaintext passwords regularly.
invokestatic··on FORCEDENTRY: Sandbox Escape
As explained in the introduction, this escape used only logic bugs. So rust would still be affected
invokestatic··on Spring Core on JDK9 is vulnerable to remote code execution
I am still deeply skeptical that this exploit really exists, or if it does, it is extremely exaggerated. I can’t really articulate the reasons why. Part of it is the fact that a lot of the people reporting on it self-admit that they are unfamiliar with Java and Spring. One “PoC” repo I’ve seen is just simple API misuse. API misuse is a CVE in the application that does the misusing, NOT the library that is misused (in this case spring).

Something else is that very soon after there was a /hint/ of a log4j exploit, we saw rapid and evolving exploitation in the wild. We have nothing like that happening now, since this news first broke, what, 12 hours ago?

Then there’s also the suspicion where I feel the LunaSec people, one of the first groups to report on this, are desperately trying to re-catch the fire they caught when they first reported log4j. I’m sure that was amazing for marketing their company. Problem is, I think reporting on this before there is really indication of a real issue reduces the credibility of them as competent security researchers.

Of course, I may come back to eat my words.

invokestatic··on Legal Concepts for Founders
Depends on the /state/ as well.
invokestatic··on Unikraft is a fast, secure and open-source Unikernel Development Kit
I went with OSv (another unikernel) for a previous pet project and, while I really loved the concept, I found the tooling to be immature. This project’s tooling and documentation does looks better so I look forward to trying it out.

One thing I find missing with these unikernels though is IPSec support and Firewalls. I’d love to throw a unikernel image on DigitalOcean and have a secure software-defined IPSec tunnel.

invokestatic··on Undocumented x86 instructions to read/ write microcode
Your last point is why I don't really see the hype over RISC-V from an end-user perspective. Companies manufacturing RISC-V processors are free to add whatever private extensions (or backdoors) they want. And unlike software, you can't easily reverse engineer it to discover them.
invokestatic··on Reclaiming the lost art of Linux server administration
I used to reach for shell scripts to configure servers, then Puppet, then Salt, and then finally to Ansible. Configuring servers declaratively is such a massive improvement over shell scripts. The fact that Ansible is agentless is also very nice and works very well for when you only have a handful of servers.

Only thing I dislike is YML, which I think is yucky!

invokestatic··on Pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)
I’ve really come to the conclusion that OS users are merely policy barriers and not security barriers (or at least, not strong barriers). This seems to be the position of Microsoft as well, given their stance on UAC and privilege escalation exploits in general.

I think it’s akin to real-life locks. Keeps good guys out, but not a determined attacker.

invokestatic··on Yuzu: Nintendo Switch Emulator
Uses C# for its scripting API, but crucially the engine itself is written in C++.
invokestatic··on Covid-19 vaccines and treatments: we must have raw data, now
I have no qualms with releasing a subset of the data that is properly and irreversibly anonymized. But you have to keep in mind that by introducing “randomness” into the dataset, you limit it’s usefulness to check to make sure the statistics match up with the study’s official topline results.

Furthermore, the FDA submission dataset is essentially a database with dozens of tables each with often hundreds of columns. It’s a LOT of data, with exponential complexity to make sure all the right fields are redacted. There’s also the point that pharma companies are under no obligation to release this data. It’s generally considered proprietary. That said, due to the substantial amount of government funding provided to the development of the vaccine, I think we should be entitled to this information.

invokestatic··on Covid-19 vaccines and treatments: we must have raw data, now
Under the safe-harbor deidentification guide you posted, all dates must be removed except for the year. If this was done on a clinical trial dataset, the data would be useless. Specifically for the COVID vaccine trial, the “statistic” used is the number of days between when the patient enters the study and when they get COVID. This is called TTE or time-to-event and underpins the entire study design. You need the exact date the patient entered the study AND contracted COVID to calculate the TTE value. Without this information, you have no chance of validating the results of the study.
invokestatic··on Covid-19 vaccines and treatments: we must have raw data, now
I’m a software consultant for Pharma companies and have worked on projects that used the same kind of study design as the Pfizer COVID vaccine (Kaplan-Meier).

“Raw data” is submitted to the FDA in the CDISC format. This format contains a lot of pretty sensitive medical information, including which diseases a patient has, their medical history, what drugs they take, etc. This is supposed to be anonymized, but if the public were to be able to get this info, I strongly believe there is enough information to re-identify patients. And it’s not as simple as just removing the sensitive medical data because the primary or secondary analyses may be dependent on them.

invokestatic··on Clever uses of pass, the Unix password manager
The term “ransomware” is never used to describe malware that steals passwords, thats the point of confusion.
invokestatic··on Clever uses of pass, the Unix password manager
This is still susceptible to ransomware. Ransomware will simply encrypt over each file with its own key, regardless of if the file is already encrypted or not.
invokestatic··on Mold 1.0: the first stable and production-ready release of the high-speed linker
Why Affero? Are there cloud linker tools? Or simply because it is one of the most restrictive open source licenses?
invokestatic··on Fedora 36 Planning to Run Wayland by Default with Nvidia's Proprietary Driver
I’ve been “daily driving” F35 with Wayland on Nvidia for the last couple weeks and it’s been an… OK experience. The only real show stopper for me now is that GNOME night light doesn’t work (Nvidia issue) and screen sharing in some select applications. I’ve worked around the former by setting the color temperature on the monitor itself.

Another big deal is there’s no hardware video decode support in Firefox. I don’t have integrated graphics, so I rely on Nvidia’s VDPAU implementation that doesn’t work on Wayland. This really stinks!

I’m really on the fence about it and I keep thinking of switching back to Xorg.

invokestatic··on Should Windows Transition to Linux?
One of the things that the Windows kernel does just better than Linux is providing a stable kABI. The argument against that is “just upstream/open source your driver”. Well that’s not always possible. I think this is honestly holding back hardware support in Linux. The ideologically driven FOSS folks can choose to only run open-source drivers, while those just wanting to get stuff done (like me) will happily run proprietary drivers. I understand this does undermine the purpose of the GPL so it will never happen.
invokestatic··on Courts block two Biden administration Covid vaccine mandates
Lopez overturned Filburn for the most part.

> Doesn't it need to be framed as the government having the right to apply a medical treatment to me against my will?

This will be tested in litigation in cases like OP, but remember, these vaccine mandates are NOT the government forcing you to accept medical treatment. These mandates have been coercing private employers to require vaccination as a condition of employment. This indirection muddies the water and I can't speculate as to what the courts will ultimately decide on.

invokestatic··on Courts block two Biden administration Covid vaccine mandates
It's interesting you bring up both commerce clause and abortion as I'm currently taking a constitutional law class covering both issues. The commerce clause did wildly expand through the 20th century, but I just want to point out that US v Lopez substantially cut back Congress' Commerce power. It laid out clear restrictions to what and when Congress has the power to regulate interstate commerce. Further cases like NFIB v Sebelius (Obamacare) also cut down on commerce power.

The difference I see with abortion is that the SCOTUS held in Roe v Wade that women have an affirmative right to an abortion under substantive due process of the 14th amendment. If the government coerced healthcare providers to stop providing abortions, this would be a direct infringement on a right protected by the constitution. Conversely, there is no constitutional right to /not/ get a vaccine. Of course, the demographics of the court has changed, so it's very possible the SC will rule that not getting vaccinated is also a constitutional right conferred by substantive due process.

invokestatic··on Courts block two Biden administration Covid vaccine mandates
I think it’s actually reasonable for an agency (CMS) to decide eligibility criteria for receiving federal Medicare and Medicaid dollars. This was authority granted to the agency by Congress. Requiring employees to be vaccinated as a condition to accepting Medicare seems pretty reasonable to me. Just as I would hope hospitals need to meet basic care standards to be eligible as well.

Congress often delegates their power to other agencies. It’s an important regulatory function that allows agencies to adapt to a changing world even in a gridlocked legislature.

invokestatic··on Ask HN: What browser extensions are a must-have in 2021?
resistFingerprinting has kind of a nasty side effect of making every website think you are in UTC. I put up with it, but I’m sure others may find it annoying.
invokestatic··on WSL2 can now mount Linux ext4 disks directly
I am often happy to give up full control in exchange for convenience. WSL2 works fantastic for very quickly getting a Linux box up and is pre-configured for interoperability with Windows. Sometimes I don’t want to mess around getting these types of tools up myself.
invokestatic··on Windows 11 upgrade tool that bypasses Microsoft´s requirements
I actually completely agree after upgrading. Very trivial differences over 10. At least it forced me to upgrade from MBR to GPT and UEFI boot.
invokestatic··on An interview with Mark Zuckerberg about the Metaverse
I’m not really seeing the WireGuard aspect of this. Sounds like TLS would be fine.
invokestatic··on Container security best practices: Ultimate guide
Virtualization-backed container technologies are a definite security improvement over traditional containers (including Hyper-V), but most of the measures in this article are still important. Remember, security-in-depth. Virtualization mainly protects against zero-day kernel exploits, limiting the "blast radius" to a single container. You still need to monitor dependencies, isolation, signing, scanning, and have a vulnerability management program, among other things.
invokestatic··on Windows Package Manager 1.1
Windows has a manifest system for shared libraries that allow multiple versions of a library to coexist side-by-side. My hope is that this alleviates problems.
← PreviousPage 2 of 7Next →