HNHacker News
TopNewBestAskShowJobs

jinseokim

224 karma · joined February 7, 2021

submissionscomments
jinseokim··on MIT asks arXiv to withdraw preprint of paper on AI and scientific discovery
That's what happens when a paper is withdrawn [1], and MIT requested to withdraw the paper [2]. This news title saying that they requested to take down the paper is subtly incorrect.

[1]: https://info.arxiv.org/help/withdraw.html#:~:text=Previous%2...

[2]: https://economics.mit.edu/news/assuring-accurate-research-re...

jinseokim··on Twitch will now let streamers simultaneously stream on any service they want
> Streamers will have to make sure the quality of their stream on Twitch is “no less than the experience on other platforms or services.”

Note that Twitch limits stream quality in certain country. For example, in South Korea, content is transcoded to 720p or lower. [1]

[1] https://www.thegamer.com/twitch-korea-limiting-stream-qualit...

jinseokim··on IPinside: Korea’s Mandatory Spyware
Some softwares: Yes. People with Mac are advised/forced to use Windows. For instance, Uwayapply, a college admission application service, doesn't support macOS.

Or: they provide .pkg file to install similar program.

Most of them want sudo. They use root permission for various purpose, but the most impressive one for me was registering their CA certificate on Firefox root store, to support WebSocket over TLS to localhost on Firefox.

jinseokim··on IPinside: Korea’s Mandatory Spyware
Well... SSL was unsafe then.

The problem came from U.S. cryptography export regulation which makes exportable cryptographic algorithm feasible to crack. Bundled Internet Explorer didn't support good algorithms on SSL.

So, South Korea government wanted to add another security layer. They wanted to state "good to go" algorithm (just like FIPS did), so they built and recommended the encryption algorithm, SEED. And it required ActiveX, because 128 bits cryptography on JavaScript was infeasible then.

The real problem of South Korea is, the slowness of deprecation.

They deprecated ActiveX (and created NPAPI or WebSocket on localhost) in 2014. After Microsoft deprecated Windows XP, they established "Windows XP Task Forse" to respond security issues with Windows XP computers on government agencies. Yeah, this was fairly late, considering MS declared the Windows XP deprecation schedule in 2007.

IE/ActiveX/Java Applet/etc algorithms aren't still completely deprecated in Korea. NEIS, a giantic service used by every K-12 school to record and manage education-related information, still uses the technology based on Internet Explorer by using IE compatibility mode of MS Edge. Repeat, EVERY K-12 school teacher and staff uses this service, with IE compatibility mode.

I want South Korea to adapt new technology and deprecate old one more in due course. I mean, they should accept TLS provides decent end-to-end encrpytion, and they should recognize Triple DES is deemed unsafe algorithm.

jinseokim··on IPinside: Korea’s Mandatory Spyware
Disclaimer: I'm Korean.

A LOT of Korean citizens cared and got angry with this issue. So governments, agencies, and. yeah, "security companies", finally decided/declared to deprecate ActiveX-fu softwares and follow Web Standard.

We didn't expect WebSocket on localhost.

jinseokim··on IvorySQL: Open-source Oracle-compatible PostgreSQL
A Korean company Tmax sells Tibero, the Oracle-compatible DBMS (proprietary). AFAIK, it's quite so much "compatible" (it even has same typos with Oracle DB), and they're not sued by Oracle.
jinseokim··on AirDrop is now limited to 10 minutes
Note: AirDrop is unsafe for broadcasting message anonymously. It will also broadcast your hashed phone number and email[1], which can be reversed by rainbow table.

[1]: https://privatedrop.github.io/

jinseokim··on Researchers quietly cracked Zeppelin ransomware keys
Where would be the sanest choice if I need some CPU computational resources (say, 10k CPU-hours)? Researchers simply used DigitalOcean (under their generous resource grants), but I believe there would be another better way for computing if I can't get such donation...
jinseokim··on Microblog.pub – A self-hosted, single-user, ActivityPub powered microblog
I feel like Python 3.10 is large dependency -- almost no one would use it unless required.
jinseokim··on Stable Diffusion PR optimizes VRAM, generate 576x1280 images with 6 GB VRAM
I just reminded "clean room design" technique: https://en.m.wikipedia.org/wiki/Clean_room_design
jinseokim··on Earn-IT threatens encryption and therefore user freedom
Look Russia and see what happens. They are actively monitoring and censoring 140M citizens. Fortunately Russians are using Signal/Telegram[1] to avoid those censorship.

This is not a tradeoff between just privacy and child safety. This is the matter of freedom and democracy.

[1]: I would say Telegram is available option for privacy but Telegram has pretty much possibility to be attacked than Signal...

jinseokim··on How to set up a blog with Hugo and Cloudflare, and why you should
Happy with Cloudflare Pages but its build takes too long. 2 minutes for "initializing build environment", and <5 seconds for actual build...
jinseokim··on Elsevier embeds a hash in the PDF metadata that is unique for each download
Be aware that deleting metadata is never enough: There are too many ways to hide some fingerprints on the PDF document.
jinseokim··on Nine-year-old kids are launching DDoS attacks against schools
Technology evolved, and we faced a change: Now it's easy to commit a crime through the internet!

We teach kids "you should not steal" but not "you should not launch DDoS." I think the latter should be equally educated.

jinseokim··on CyberChef – The Cyber Swiss Army Knife
Interesting point: They just use Gmail.[1]

[1]: https://github.com/gchq/CyberChef/commit/c423de545fd0d27aabe...

jinseokim··on What NPM should do to stop a new colors attack
Whole npm ecosystem is so fragile.

Remember event-stream[1]? Did we learned something from that? Yes, we might. So was it improved? Never. People are still installing 'new' colors package and wondering why its texts are broken.

What if he uploaded malicious code rather than just just gibberish? What if he uploaded on only npm and not on GitHub? Would we even notice that?

[1]: https://github.com/dominictarr/event-stream/issues/116

jinseokim··on Show HN: I made a free, ad-free and open source tool for sharing private notes
First of all, this is a cool idea. I always love to see something private and encrypted. But I found some concerns and ideas about your project (and I think you may can fix these):

0. This has XSS vulnerability. If attacker writes down this memo: <script>do_the_evil_things()</script> and passes to people, they might be unknowingly attacked(get tracked by attacker their IP/Browser fingerprint, mine cryptocurrencies for attacker, etc...)

1. This basically works under server-side encryption. When user type their text in the website, it is encrypted with the secret key on your config file and saved on the database. This is only effective when attacker only succeeds to crack the database. Also, you can read the text. I know you won't, but you know, cryptographers don't trust anyone. If you want to mitigate this, you might want to learn about end-to-end encryption. In short: the hash of the private link is the secret key. The browser randomly generate the key and encrypt/decrypt the text. The server only receives/saves the ciphertext.

2. AES-256-CBC is unsafe because it provides confidentiallity and not authenticity.[1] This means the attacker who can only crack the database can edit the ciphertext to pseudo-arbitrary plaintext under certain circumstance without knowing of the key. Also under another circumstance, attacker can use 'Padding oracle attack' to recover the ciphertext. it seems your service is not in this case: Laravel's encryption is AES-256-CBC + MAC, which mitigates this problem. So this is safe, but next time, if you write some crypto-related things without Laravel, you'd better use some high-level library such as libsodium or sjcl.

3. This service uses CloudFlare. Using CloudFlare might be safe on small project because they have rock solid WAF to prevent general attacks. But it may be unsafe for a whistleblower from NSA: when it matters with state-sponsered attackers or law enforcements, CloudFlare can be attacked/warranted. Then it becomes another attack vector.

Again, your service and idea are cool. But you should remember that this area is full of land mines, dragons, and dinosaurs with laser guns.

Welcome to privacy/crypto world!

[1]: https://arxumpathsecurity.com/blog/2019/10/16/cbc-mode-is-ma...

jinseokim··on But What's Up with That ¥?
Korean Windows also shows ₩(Korean Won) symbol instead of \.
jinseokim··on Half a million South Korean workers walk off jobs in general strike
No: It was scheduled before the release of Squid Game[1].

[1]: (korean) https://m.hani.co.kr/arti/society/labor/1008768.html#cb

jinseokim··on Chernobyl’s Blown Up Reactor 4 Just Woke Up
No Loginwall frontend:

https://scribe.rip/chernobyls-blown-up-reactor-4-just-woke-u...

jinseokim··on Using xyz TLD domain as a primary email address
Avoid it. Apache's SpameAssassin flags several TLDs including .xyz as 'suspicious' nTLD[1].

[1]: https://github.com/apache/spamassassin/blob/trunk/rulesrc/sa...

jinseokim··on Compiling C Programs Into “Mov” Instructions (And Only “Mov” Instructions)
Past discussions:

https://news.ycombinator.com/item?id=6309631 https://news.ycombinator.com/item?id=9751312 https://news.ycombinator.com/item?id=12372242

jinseokim··on Strange domain names that developers bought
Recently I purchased 'jinseo.kim'.

It's formatted like <first name>.<last name>. I love it.

jinseokim··on South Korea: The only middle power of its kind
I live in SK, so I have a lot of things to talk about the birthrate.

The reason why the birth rate strangely low, is quite interwoven. TL;DR: People (think they) are not capable enough to raise a child.

First: Real estate prices is skyrocketing. This bizarre phenomenon began in the 2000s. The 17th administration completely reversed the situation, which became another problem, and the 18th administration made real estate prices to soar again. The 19th (present) administration tried to control real estate prices with complicated regulation, but it never worked so far.

Second: An educational craze. 386(1960s) and X(1970s) generations believe that children should go to the prestige university to survive in this harsh world. So they let their children go to 'hagwon'[1], something like cram school but really competitive. E.g. (a) Almost students in SK go to hagwon. (b) Some 6th~9th grade students study 10AM~10PM everyday in hagwon during the vacation, to pass an enterance exam specialized high school(10th~12th grade). (c) Some kindergartens promotes themselves as "English Kindergarten"; where every teacher and student speaks English. The problem is -- because of these craze, a lot of childless family concern that they can't afford expenses for hagwon($300~400/mo in average. In the case of the above-mentioned entrance exam, It goes more than $1000/mo) so their child won't be happy because they'll fall behind when they grow up.

Third: Saving for retirement. Because of these problem, rearing child in Korea costs an arm and a leg. In the past, education was not overheated like this, and Korean-specific mindset forced family to give birth. However, starting with military administration's birth control policy, people changed their mindset, and now a significant number of people are more interested in saving for retirement than give birth.

[1]: https://en.wikipedia.org/wiki/Hagwon

jinseokim··on Show HN: Static.wiki – read-only Wikipedia using a 43GB SQLite file
It seems to be 403 happens.

Quick test: https://s3.us-east-2.wasabisys.com/static.wiki/en.db

jinseokim··on Only Google is really allowed to crawl the web
This has been submitted to HN quite a few times.

https://news.ycombinator.com/item?id=25426662 (Most comments; 11 comments)

https://news.ycombinator.com/item?id=25417067 (3 comments)

https://news.ycombinator.com/item?id=25546867 (Most recent; 89 days ago)

https://news.ycombinator.com/item?id=25543859

https://news.ycombinator.com/item?id=25424852

jinseokim··on Draw an iceberg and see how it would float in water
You may want to revert the (tedious) patch about intersections. Here is a simple workaround:

> turf.unkinkPolygon=(x)=>x;

Press F12, click 'Console', copy-paste the above one and press Enter.

jinseokim··on Notion is experiencing a DNS issue
As I recall, This is third down-related issue of Notion in 2021.

Notion advertises itself as 'All-in-one Workspace'... But I don't want to leave everything to unstable 'All-in-one Workspace'.

jinseokim··on Supercookie: Browser Fingerprinting via Favicon
On Firefox Focus Android 8.12.0, the demo gets stuck in an infinite loop.