HNHacker News
TopNewBestAskShowJobs

iueotnmunto

99 karma · joined June 2, 2022

submissionscomments
iueotnmunto··on YouTube is letting people being scammed
So youtube can throw their hands up in the air and say 'its legally ambiguous, therefore we'll take their money' and that's okay?
iueotnmunto··on YouTube is letting people being scammed
If YouTube cannot police or moderate their own platform, then that's a problem they created for themselves.

'Sorry, moderating this content is something we cannot manage' is not an acceptable response, they are a trillion dollar company with access to tools which can be run at scale. Scam prevention is a cost center, which is presumably why they don't care, and that attitude needs regulation (as they'll never change on their own).

> Some people need to learn the hard lesson and we need to stop bailing them out.

I think the same can be said for large tech companies.

iueotnmunto··on Linux guide for power users (2022)
> Where can this be reported or an existing requested be upvoted? This irks me too no end.

You can't. From what I've seen GTK / Gnome devs are incredibly unaccommodating to functionality that they don't agree with. https://bugzilla.gnome.org/show_bug.cgi?id=754302

The patch I'm using:

https://pastebin.com/cdkH8uXg

https://pastebin.com/Ek1tTcsm - this is 'file-chooser__typeahead.patch' which I sourced from a github somewhere

iueotnmunto··on Linux guide for power users (2022)
It's not actually that complicated, iirc, I have an ansible script to trigger the build based on a 2-line patch.

The maintainers proposed a similar patch to Gnome/GTK as a hidden option in dconf, but iirc their dev team took the opinionated 'our way or the highway' approach, as they've done on many other occasions.

iueotnmunto··on Linux guide for power users (2022)
Debian 12.1 out of the box, I'm sure there's a workaround, but I had to google 'How do I shutdown my computer.

s/ipconfig/ifconfig/

> Overall, from the one of your reply, I have the impression that you might be happier switching to a less opinionated distro like Void Linux or Gentoo. Something as curated as Ubuntu isn't a good fit for you.

I agree, but I work in infosec. Nobody ever got fired for running Ubuntu, particularly when there's at least some auditing of source before they push out deb packages. I know there are minimal case studies, but one day someone will get malware into a distro, I'd like to reduce the risk that it happens to the distro I'm running.

I also moved away from Gentoo ~ 10 years after systemd was mainstream, at that point it was basically impossible to get Bluetooth Audio working without pulseaudio, which seemed impossible to run without Systemd. I fully understand that Systemd is probably better in a lot of use cases and I really don't care what's running under the hood, provided it doesn't get in my way.

Edit: And the reason I hate whatever is responsible for the 'ip' command is that it's virtually impossible to google specifically for that command (y'know, because 'ip' was a protocol not a command, convoluting things unnecessarily)...

iueotnmunto··on Linux guide for power users (2022)
My recent gripe is that I've used Linux for more than half my life and I'm well into my 30's. I feel like my ability to navigate a system has gone _backwards_, Debian no longer accepts 'init 0' as a command, ipconfig isn't a command anymore, systemd changed the whole subsystem from underneath me, ubuntu/snap decided not only to litter+bloat my filesystem with needless duplicates but also that not only would I prefer Firefox be a snap package (which broke my workflow), but that it would require me to go well out of my way to solve that, Gnome decided that I wanted a touchscreen layout (I custom compile gtk+ to remove the 'search on type' behavior in file>open dialogs, most major packages seem to default to nouveau which while a great movement seems to totally break critical path regularly.

How the hell have we gotten to a point where Linux closely reflects the instability of the Windows ecosystem. I'm not afraid of change, but I feel like the large majority of changes that are made cause me problems to the point where I now fear upgrading my distro to latest.

iueotnmunto··on CS:GO: From Zero to 0-Day
If the VM operates under the same privileges than a host, all this does is prevent automated attacks - a savvy attacker can still access the disk image of the guest, in some cases, it might actually be more vulnerable (as disk image access is implicitly a privesc in the context of the VM).
iueotnmunto··on Remote Code Execution as a Service
More if you're running `provision --vm-name "$UserSuppliedData"` or similar. I don't know how you've built your wrapping tool, so I can't comment on how likely it would be, but I've seen such breakages IRL (I break things for a living ;) )
iueotnmunto··on Remote Code Execution as a Service
While container breakouts do happen, they're pretty rare. I'd be more concerned about any potential injection vectors in the go code, which could lead to a cloud breach if you're not careful ;)
iueotnmunto··on The teen mental illness epidemic began around 2012
> Things only started getting better when I started seeing a therapist and worked on my issues over the second half of my high school experience.

I'm curious, would you mind sharing how a therapist helped you? I'm in a similar (but not the same) space mentally, and put everything down to environmental issues (high pressure job, etc) and disregard the thought that a therapist could help with this (unless they had a time machine, etc).

iueotnmunto··on OpenSSH Pre-Auth Double Free – Writeup and Proof-of-Concept
quit spending your time talking about it and write a replacement then?
iueotnmunto··on Tell HN: Google Cloud lets anyone add you to a project without your permission
TIL google had support tickets, I thought they largely didn't communicate with their client base
iueotnmunto··on Signal Introduces Stories
I've always thought creating a shared key which rotates as soon as a single individual is added or removed is smart. There are security implications related to whose decryption key leaked, not sure if that's a legitimate threat model for almost any scenario though.
iueotnmunto··on Ring0VBA – Getting Ring0 Using a Word Document
Macros use ZoneInfo NTFS hidden properties to determine the source of the document (local, trusted, internet, etc). I'm unsure of the default for local, but internet downloaded macros are prompt by default.

Group policy can be used to explicitly deny or globally permit. I believe there's also the ability to cryptographically sign macros if required.

iueotnmunto··on Browser password managers – flawed security, by design
If filesystem access is a legitimate concern, you have bigger problems. Even if passwords were secured by FIDO or similar, session tokens are not.

If you compromise a computer, you can compromise web sessions. There is no mitigation for this. Shame on the author for attempting to create panic when far more productive security can be achieved elsewhere.

iueotnmunto··on Some Assembly Required: An approachable introduction to assembly
Check out Ben Eaters youtube channels https://www.youtube.com/channel/UCS0N5baNlQWJCUrhCEo8WlA - He builds similar, and offers a kit for sale at (from what I can tell) a reasonable price, so you can also DIY.
iueotnmunto··on Hertzbleed Attack
An awesome attack vector and kudos to the authors. I do wish it had never been discovered for environmental reasons though :(
iueotnmunto··on uBlacklist – Block specific sites from appearing in Google search results
I really like this solution, but FYI it blocks suffixes, adding gram.com blocks instagram.com, facebookgram.com, etc.
iueotnmunto··on Angular v14 is now available
I fully understand not changing for that reason and don't think anyone would think less of a justifiably difficult situation.

But at the same time, what you described is probably indicative of deeper issues which should be considered technical debt, not because of political correctness but because there may be other inflexibility which inhibit productivity in the future.

iueotnmunto··on Commercial-Emacs
Agreed, it indicates it fixes some systemic issues present in emacs, but doesn't fully articulate what those issues are.
iueotnmunto··on Show HN: Svelvet – A component library for building interactive flow diagrams
I'm talking specifically about electron.
iueotnmunto··on Angular v14 is now available
It takes a few minutes to switch. Maybe a bit more to rebind all CI scripts etc in a project as large as react. There are some things that I don't fully get (slavery was never big in my country).

It takes a few minutes of effort to not be an asshole (real or perceived), so I just do it rather than thinking to much about whether or not the wider population should be offended or not.

iueotnmunto··on Show HN: Svelvet – A component library for building interactive flow diagrams
I keep hearing this, but I've never figured out why it might be the case, and particularly with Electron over Chrome/FF?

Surely if react/svelte etc are built well they're relatively low processor / compute? When manipulating canvas / images / rich-whatever, I assume graphic accelerated functions would work substantially better than alternatives.