HNHacker News
TopNewBestAskShowJobs

jamoes

556 karma · joined March 29, 2012

submissionscomments
jamoes··on Technical report on DNC hack [pdf]
A file with the following text would activate the rule:

    <?php 
    ='base'.(16*4).'_de'.'code'
    (str_replace(
    .substr(md5(strrev(
    gzinflate
    _COOKIE _COOKIE
    isset isset isset
    (additional text, such that the total filesize is between 20kb and 22kb)
Basically, in the filesize must be between 20bk and 22kb, all of the defined strings must be found, and the cookie and isset strings must occur exactly 2 and 3 times respectively.
jamoes··on Disseminating the New Kilogram: An International ‘Dry Run’
At first I thought, "Oh, these sound effects are kinda cool, to give the video a flair for the dramatic." There's not going to be any noise inside of the vacuum, but the initial sound effects were probably the noises that the contraption would make if it had air to propagate the sound waves.

But, as the video went on, the sounds effects just go more and more ridiculous. An alarm sound as the object is sent down a tube?! And the coup de grace was the lawn mower sound effect at the very end as the object was wheeled away.

jamoes··on No Evidence of Aloe Vera Found in the Aloe Vera at Wal-Mart, CVS
"The Jungle" is a work of fiction, in case you weren't aware: https://en.wikipedia.org/wiki/The_Jungle
jamoes··on Exposing high-end poker cheating devices
The cheating device in this article also required a marked deck. So as long as the house isn't in on it, this cheating method wouldn't work in casinos.

The article did mention that some anonymous sources claim to be using these devices in Vegas casinos, so I wonder of there are some corrupt dealers in cahoots with the cheaters.

jamoes··on Not OK, Google
What I'd like to see is some good open source software that can compete with Google Assistant, Siri, and Alexa. It looks like there are some promising projects, but nothing turn-key yet. I'd like to be able to simply apt-get a package, and have voice recognition on my box.
jamoes··on Bitcoin 'creator' backs out of Satoshi coin move 'proof'
He could still have access to his PGP private key, which would be a strong data point. It could be possible that someone stole this key though, so this alone wouldn't completely prove his identity.

If he had the foresight to know he might want to prove his identity at some point in the future, he could have embedded the hash of a message into an early block (using the public keys of coinbase transactions). The message could say something like "Satoshi Nakamoto is <real name>. <salt>". In order to prove his identity, he'd just have to reveal the contents of the message (he'd have the make the salt something he could memorize so that it wouldn't be at risk of being destroyed by a fire). Ideally he'd encode this message hash in multiple early blocks (using a different salt in each message, so that the hash is different each time).

I think anything like the "knowledge of the content of private emails" is flawed. Satoshi's email account was hacked, so most of his "private" emails are no longer private (supposedly he didn't use PGP for most of his private correspondence).

jamoes··on Gavin Andresen's commit access to Bitcoin revoked, hacking suspected
With bitcoin, the election cycle is always happening. Every single block miners decide which rules they want to enforce, and which proposals they want to signal support for. You want to support 2 MB blocks? Run Bitcoin Classic, or point your mining software toward a pool that supports it. You want to support segwit? Run Core 0.12.1. Ultimately, the market decides what becomes of bitcoin, not some unaccountable, unelected bureaucrat.

Also, with bitcoin, all interaction is completely voluntary. There are no legal tender laws or taxation propping up the value of the currency.

> So, in this case, I welcome the failure.

I wouldn't hold your breath. Bitcoin has been through many incidents that are far worse than this, and it's only come out stronger for it.

jamoes··on Zcash, an untraceable Bitcoin alternative, launches in alpha
> but the private currency speculators would usually have a pretty good guess as to the solvency of the issuers

With bitcoin and other Nakamoto-consensus based crypto-currencies, the "solvency of the issuer" is irrelevant, because these currencies aren't debt based.

jamoes··on Obama Signs CISA Bill into Law
Net neutrality, as it's currently being implemented, grants the FCC significant amounts of regulatory power over private companies. This regulatory power has the potential to be abused. So, Rand Paul being against it is consistent with his general philosophy of less government intervention.
jamoes··on A Decade-Old Gag Order, Lifted
> I truly don't understand why nothing is done about that. Why doesn't anyone lose their job over this, let alone go to jail?

My suspicion is that the FBI and various three-letter-agencies have dirt on most of the elected representatives. The mass surveillance apparatus is the perfect tool for collecting blackmail material on current and future leaders.

jamoes··on Ways to start eating insects
In terms of sustainability, I agree with Rob Rhinehart [1] that single-cell protein (e.g. from algae) is the best path forward. It doesn't have the gross factor that insects have, and once the process is perfected, it should be one of the most efficient ways to produce protein.

https://www.reddit.com/r/soylent/comments/3afdfp/i_am_rob_am...

jamoes··on Firefox Now Offers a More Private Browsing Experience
Not to my knowledge. That's why I use the CanvasBlocker extension [1], which prevents websites from abusing canvas tags to fingerprint me.

I'd like to see a comprehensive effort to prevent fingerprinting without having to resort to simply blocking the canvas element altogether.

[1] https://addons.mozilla.org/en-US/firefox/addon/canvasblocker...

jamoes··on What a City Would Look Like If It Were Designed for Only Bikes
> EDIT: Sorry, I know it's off-topic, but there's no other place to post it (that I know of).

Yeah, as annoying as it is to see hostile comments, it's also kind of annoying to see meta comments. I understand that meta comments are important for making the site better, but it distracts from the discussion on the articles themselves.

Perhaps a good solution would be to have a separate "meta" comments section for each posting. This would be similar to how wikipedia has a separate "discuss" section for each article. This would be a useful place to put comments like yours and mine, and moderators could even move comments over to the meta discussion to keep the main comment section on-topic. It would also be a good place to post title-change requests, and other moderation requests.

This would lower the prevalence of off-topic meta discussion, while also providing an appropriate venue for discussing important topics that make the site better in the long run.

jamoes··on Bitcoin XT 0.11A
The #1 story was removed by the moderators. It was an article by Mike Hearn about why he's moving forward with the Bitcoin XT hard fork. [1]

The justification for the removal is that Bitcoin XT is an altcoin, and altcoin discussion is not allowed. [2]

[1] https://www.reddit.com/r/Bitcoin/comments/3h424p/why_is_bitc...

[2] https://www.reddit.com/r/Bitcoin/comments/3h424p/why_is_bitc...

jamoes··on Ross Ulbricht Sentenced to Life in Prison
He was charged with murder-for-hire in a separate jurisdiction, and he hasn't faced trial for those charges yet. Today he was sentenced to life in prison for a number of victimless crimes.
jamoes··on Android Pay is coming
And Google Wallet was just a re-launch of Google Checkout.

I guess it's worth the risk of continual failure, because if they eventually do get a foot in the door it's incredibly lucrative. Taking a percentage of every payment someone makes is a pretty good incentive.

jamoes··on 'Silicon Valley Is Coming' Warns JP Morgan CEO
Do you think people would really accept the banning of certain pieces of code as legitimate?

The US government already lost the battle on "export grade" encryption, and I believe they'd lose any attempts to ban other code as well.

jamoes··on Dear FCC: Thanks for Listening to Team Internet
> The "decision" made at 10AM was to adopt the rules that have been under public comment for months. If you haven't seen them yet, it's your own fault.

From what I've read, the 322 page document wasn't released as of 3 days ago [1]. I'm not sure about the claim that it still hasn't been released, but regardless - the rules weren't really available for public review before the vote.

[1] http://dailycaller.com/2015/02/23/republican-fcc-commissione...

jamoes··on Uber Expectations as We Grow
> waiting in the cold for possible 5-10 whole minute

Isn't this largely solved by the GPS mapping of your ride from within the Uber app? You can easily see exactly where the driver is, and step outside right as the driver is pulling up, regardless of how long the total wait is.

jamoes··on Don't Talk to Corp Dev
> Can someone piece this together?

I think he means this:

If you're talking to someone [from another company] from corp dev, [they want to acquire you], whether you realize it yet or not.

jamoes··on Secure Secure Shell
Thanks for the info! I was hoping it was more secure than a simple USB flash drive. This seems like a really good way to improve key security.
jamoes··on Secure Secure Shell
It looks like he's found a way to avoid using the broken symlinks hack. The blog has been updated and now advises how to make changes to the sshd_config file to disable old authentication methods.
jamoes··on Secure Secure Shell
Does using the Yubikey in this manner protect your keys even if your machine has malware on it? I read through this tutorial [1], and they say you need read/write access to the device, so it seems to me like malware could access your keys while the smartcard is plugged in. If this is the case, I'm not sure how this setup is any more secure than simply keeping your keys on a USB flash drive and plugging it in whenever you need to use ssh.

[1] https://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO

jamoes··on ChangeTip must die
This is exactly what Flattr is all about (they're still around).

Flattr has to deal with credit card fraud though, and all the issues surrounding it. This means they need to spend a non-insignificant portion of their operational budget dealing with risk analysis for all of the payouts they make. And, as their userbase grows, the cost of dealing with fraud also grows. It also means they have to ask their users tons of invasive questions.

Changetip, on the other hand, can accept deposits and make withdrawals with 100% confidence that they will not need to eat the cost at some point in the next 6 months. The downside is dealing with the security cost of storing their stash of bitcoins - but this is a fixed cost that doesn't grow as their userbase scales.

jamoes··on Quantum Attack on Public-Key Algorithm
> It would also be the absolute end of Bitcoin and derivatives, at least as far as I know.

Not really, because bitcoin only relies on the signature aspect of PKC. So, bitcoin could move over to Lamport signatures, which are not affected by quantum computing.

Lamport signatures are larger than ECDSA signatures, so blockchain bloat would be an issue. But presumably by then hard drives and all other computing specs would have increased substantially.

Here's an interesting article by Vitalik Buterin which explains how the transition could take place: http://bitcoinmagazine.com/6021/bitcoin-is-not-quantum-safe-...

jamoes··on Quantum Attack on Public-Key Algorithm
Lattice-based public key schemes are designed to be quantum resistant. So this is a troubling development, because it might indicate that other lattice-based public key schemes are vulnerable to similar attacks. It might be very difficult or even impossible to create quantum-proof public key schemes.

Fortunately, though, a quantum-proof signature scheme (meaning no encryption or decryption, just signing) has already been developed: Lamport Signatures. These rely on the security if hash algorithms (such as SHA256), which are not weakened by the existence of quantum computing.

jamoes··on Baron is a Bitcoin payment processor that anyone can deploy
Based on the fact that it has a "Bitcoind RPC port" option, I think it is safe to say that it just relies on a running Bitcoin Core node.

That means it does not support deterministic keys. Users will need to be careful to back up their wallet.dat file on a periodic basis.

jamoes··on How My Employer Put the “FML” in FMLA
> Cool, let's just bank on the generosity of companies.

Or, how about you think about this when finding a job, and weigh the pros and cons of various employers' benefits and policies. We don't always need top-down guidance from bureaucrats in D.C. to solve societal problems.

jamoes··on Bill Gates: Bitcoin Is 'Better Than Currency'
Proof-of-stake isn't being adopted because it simply doesn't solve the Byzayntine General's problem [1].

[1] http://download.wpsoftware.net/bitcoin/pos.pdf

jamoes··on Drug Market ‘Agora’ Replaces the Silk Road as King of the Dark Net
Yeah, Tor as a whole, and Hidden Services specifically are very vulnerable to traffic analysis attacks.

I'd love to see a project with a real focus on anonymous publishing of content. Tor's original goal was anonymous retrieval of content, with anonymous publishing just added on as a secondary goal.

In order to make anonymous publishing robust against traffic analysis, it may be necessary to sacrifice the "real-time" goal that Tor has.

← PreviousPage 2 of 5Next →