HNHacker News
TopNewBestAskShowJobs

kaeso

848 karma · joined January 23, 2011

submissionscomments
kaeso··on Ratzilla
I think this may lack a bit of context, so I'll try to fill in.

This is a demo that was just showcased live by the author as part of their talk at FOSDEM'25: https://fosdem.org/2025/schedule/event/fosdem-2025-5496-brin...

The talk was centered on Ratatui (a TUI library in Rust, https://ratatui.rs/) now targeting terminals and web browsers with a shared approach. Video recording of the talk should appear online soon.

kaeso··on DWARF-Based Stack Walking Using eBPF
Nice post @javierhonduco, really interesting read!

As you mention that you are looking into loosening the minimum kernel requirements, what is currently the primitive(s) that is dictating the minimum required version? And how do you plan to sidestep that?

kaeso··on How Google got to rolling Linux releases for Desktops
In a funny twist of events, the author of the grandparent comment above yours was indeed building that OS (Container Linux) at CoreOS :)
kaeso··on Log4j: Between a rock and a hard place
> So we were already potentially vulnerable to the DOS [...]

> the security org at the big tech company I worked at and reported this to

I'm confused about these two statements, because I did not find any recent CVEs for log4j in the DoS category, nor related to format lookup (other than CVE-2021-44228 of course).

Perhaps I misread it, but are you basically saying that (after you reported the issue to them internally) the security team at your previous company could not successfully report a DoS vulnerability in the default configuration of a widely used (by them, at least) Apache library and make sure a CVE got assigned to track it?

If so, it would be interesting to know where the CVE/vuln-reporting chain broke, possibly to reduce the blast radius for similar future cases.

Hypothetically speaking, a CVE in March for a DoS in a problematic design/feature could have resulted in flipping the default setting earlier. Instead of chasing live RCE in the wild in December.

kaeso··on Fedora CoreOS Out of Preview
> have disappeared like locksmith

Locksmith[0] implementation is tightly coupled to the specific update daemon, so it can't be directly re-used outside of Container Linux or without update-engine[1].

Its logic has been ported over to Zincati[2], which performs reboot management on top of rpm-ostree[3].

[0] https://github.com/coreos/locksmith

[1] https://github.com/coreos/update_engine

[2] https://github.com/coreos/zincati

[3] https://github.com/coreos/rpm-ostree

kaeso··on Inside Rust's Async Transform
> Is there any benefit to making this [compute_pi_digits()] function awaitable?

If you introduce suspension points in that (e.g. every 100 computed digits), then you can co-schedule other tasks (e.g. a similar `compute_phi_digits`) or handle graceful cancellation (e.g. if a deadline is exceeded, or its parent task aborted in the meanwhile).

kaeso··on Introducing TAuth: Why OAuth 2.0 is bad for banking APIs and how we're fixing it
Kind of. Starting from 49, the <keygen> feature needs to be whitelisted per web-site. Client certificates are not anymore imported automatically, only downloaded (user action needed to load into the keystore).
kaeso··on LLVM 3.8 Release Notes
> It seems like rust bundles it's own version of llvm. Are patches from the rust community making it in slowly? Or are there some fundamental differences?

https://github.com/rust-lang/llvm/commits/rust-llvm-2016-02-...

The delta is minimal, and mostly consists in bugfixes and optimizations. All changes are typically forwarded upstream. Since long time, rustc can be built without using the embedded LLVM, and several distributions (eg. Debian) do that.

kaeso··on Attack on DNS root servers
Reality check: ~30% of active AS worldwide don't drop spoofed packets originating from their networks.

http://spoofer.cmand.org/summary.php

kaeso··on OpenSSL Security Advisory
This seems to be a common opinion recently, see https://tools.ietf.org/html/draft-thomson-postel-was-wrong-0...
kaeso··on Ask HN: Who is hiring? (April 2015)
Rocket-Internet SE - https://www.rocket-internet.com - Berlin, Germany (VISA) - Security team

# About the job #

Rocket-Internet's security team is seeking talented and motivated security professionals to help us in protecting our key information assets.

We currently have two open positions:

* Security Engineer - https://goo.gl/pdCRkM

* IT Security / Penetration Tester - https://goo.gl/pGYSvR

If interested (and for questions/doubts), please drop me an e-mail at luca DOT bruno AT rocket-internet DOT de

# About Rocket-Internet #

Rocket is the largest Internet platform outside of China and the United States. We identify and build proven Internet business models and transfer them to new, underserved or untapped markets where we seek to scale them into market leading online companies. We are focused on online business models that satisfy basic consumer needs across three sectors: e-commerce, marketplaces and financial technology. Our company was founded in 2007 and now has more than 25,000 employees across its network of companies, which operate in more than 100 countries on five continents.

We currently several open engineering positions, not only in Berlin: https://www.rocket-internet.com/join-us/engineering

kaeso··on Snowden Documents Indicate NSA Has Breached Deutsche Telekom
While everybody is mostly focused on Deutsche Telecom and Stellar, I'm more concerned about the long list of big-profile red-filled dots ('SIGINT collection points from AS') in the dox and slides:

* AS1299 (TeliaSonera)

* AS3549 (Level3/GBLX)

* AS6762 (TelecomItalia/Sparkle)

* AS3320 (DeutscheTelekom)

* AS1273 (CW Cable and Wireless)

* AS702 (Verizon/UUNET)

This list covers most of the uplink/transit/tier-1 providers, serving most of EU operators (TATA and TINET being the biggest absents here).

kaeso··on [dead]
"Z3 integrates a modern DPLL-based SAT solver, a core theory solver that handles equalities and uninterpreted functions, satellite solvers (for arithmetic, arrays, etc.), and an E-matching abstract machine (for quantifiers)"

From http://research.microsoft.com/en-us/um/redmond/projects/z3/z...

kaeso··on Depixelizing Pixel Art
A C++ LGPL implementation of this has been as been developed as part of last year Inkscape GSoC and is available as a standalone library: https://launchpad.net/libdepixelize

It will be released in the next Inkscape major version, expected soon :)

kaeso··on Announcing The Matasano/Square CTF
I would have loved it to be some old ARM ISA to use it as a testcase for Avatar[0]. On the same topic, FIE paper may be an interesting reading for msp430 lovers[1] (but it needs source for symbolic execution, so doesn't directly apply here).

[0] http://www.s3.eurecom.fr/tools/avatar/

[1] https://www.usenix.org/conference/usenixsecurity13/technical...

kaeso··on X32 ABI
An experimental Debian X32 port is currently being built[0], already covering about 79% of the whole packages archive[1].

[0] http://www.debian-ports.org/

[1] http://buildd.debian-ports.org/stats/x32.txt

kaeso··on New Rust runtime turned on. What next?
As a sidenote, libuv is not using libev anymore

https://github.com/joyent/libuv/issues/485

kaeso··on Systemd is not portable and what this means for our ports
The OpenRC port effort is currently ongoing and been sponsored by this year GSoC: http://wiki.debian.org/SummerOfCode2013/StudentApplications/...
kaeso··on Netcat – The swiss army knife of networking
I couldn't really survive without socat: http://www.dest-unreach.org/socat/doc/socat.html#EXAMPLES
kaeso··on The DDoS that almost broke the Internet
Most of the IXP around the globe have public statistics and graphs, so you can check by yourself the impact around the globe.

Here is a nice collection for the interested readers: https://www.euro-ix.net/resources-list-of-ixps

kaeso··on Why doesn't `kill -9` always work?
> ps Haxwwo pid,command | grep "rpciod" | grep -v grep

pgrep(1) is there for a reason.

kaeso··on Why mobile apps suck when you're mobile (TCP over 3G)
As an historical note, most of these concerns are the same expressed in RFC 3481 (category: BCP). You'll note from there that some of the issues are still open even if almost a decade has passed.