HNHacker News
TopNewBestAskShowJobs

kbuck

1,020 karma · joined December 5, 2011

submissionscomments
kbuck··on What to know about the stock market (2007)
The orders are partially filled (either on the buy or sell side).

What this means is that the shares eligible to transact do so immediately, and the remaining shares sit on the order book and wait for someone to be willing to trade at that price.

There is a specific option that you can set (usually called "all or none") that will prohibit partially filling an order and only allow it to execute in entirety.

kbuck··on Virtual machines with KVM on Pixel 6 and Android 13 DP1
For more background on the technical details, I found this presentation describing how KVM works with Arm EL2: https://events.static.linuxfound.org/sites/events/files/slid... (pdf)
kbuck··on Virtual machines with KVM on Pixel 6 and Android 13 DP1
It's in a VM, so it will only have (easy) access to its own virtual disk, not anything from Android.

Check out Samsung's "DeX" feature[1], though -- it's pretty much exactly what you're describing.

[1]: https://www.samsung.com/us/explore/dex/

kbuck··on Apple will charge 27% commission for alternative payment systems in Netherlands
There is no 3rd-party toolchain that you can use for a complete iOS (or even MacOS) build. Even if you cross-compile the majority of your code, you will need to transfer the binaries to a Mac for code signing. Everywhere I've worked that has produced Mac builds has had at least a small cluster of Mac machines to perform code signing. (But usually at this point, you just give up and perform the entire build on the Mac cluster.)
kbuck··on Nine-year-old kids are launching DDoS attacks against schools
A DDoS attack is not a security exploit. DDoS attacks overload internet connections to knock websites and users offline. There is nothing particularly technically exotic about them (most people are launching them with a cheap "booter" account that consists of a webpage with a "target" entry field and a "start attack" button).

The only "solution" for DDoS attacks is to buy a dedicated DDoS protection service or upgrade your bandwidth to the point that the strength of the attack cannot saturate it. This is very expensive and isn't where schools should be spending their money.

kbuck··on Tell HN: Salary data is for sale
Just to add on: an online unfreeze is instant, and all of the major agencies also let you unfreeze for a specified date range (even down to 1 day, I think -- although I usually do 2 or 3 days to cover a second pull if something goes wrong with whatever I'm applying for).

As a side note, if you use the online instant unfreeze, note that at least one of them (I can't remember which) handles timezones extremely poorly, and if the "start" date of your unfreeze has passed in their home timezone, they'll reject the unfreeze with an extremely vague error. You can resubmit using "tomorrow's" date and it will work fine (and be unfrozen immediately).

kbuck··on Ask HN: Those making $500/month on side projects in 2021 – Show and tell
Just a heads-up, a small typo on your FAQ page:

> ServerBaitThief.com retains ownership of the wallet contents at all times.

(wrong domain name)

kbuck··on Ask HN: How were video games from the 90s so efficient?
You can check out some demoscene demos [0], which usually do this (albeit to save executable size instead of just to run fast). These days you don't even have to run them yourself; most have YouTube recordings.

[0]: https://www.pouet.net/prodlist.php?platform%5B%5D=Windows&pa...

kbuck··on AWS's Egregious Egress
I've assumed this was well-known... AWS has never been a good deal on the billing side. You're paying a huge premium for API access and the strength of the AWS brand.

I was a bit confused as to why Cloudflare was blogging about it until halfway through the article, when The Bandwidth Alliance came in. Makes sense now: they just want to shame Amazon into offering free egress bandwidth to Cloudflare. This is basically a hit piece.

Also, another aside: for hosting providers (AWS included), ingress bandwidth is typically free because it's also basically free for the provider. Outbound dominates so much that the inbound traffic is a rounding error if it's billed by their transit providers at all. But I agree that the high egress prices are a vendor lock-in strategy.

kbuck··on Variable Length Arrays are problematic
Something that bothered me: The author mentions that the worst case of VLA usage is an exploitable vulnerability, then goes on to call malloc with n * size, where n is controlled by the user. This should either be bounds checked or calloc should be used instead, since the "fix" presented may also introduce an exploitable vulnerability.
kbuck··on Password Managers
I'm a little disappointed in the conclusion because there are more secure password managers out there that still offer the same level of convenience as the browser built-in password manager. Yes, if you use a password manager that's implemented entirely as a browser extension, you may as well use the browser's built-in password management features. However, if you're an advanced user and are comfortable using a separate password management application, there are options out there that don't force you to choose between a difficult-to-use app and the convenience of something in-browser.

For example, exploiting a browser-based password manager likely means escaping the sandbox that contains web pages and accessing the shadow DOM. But this is still a larger surface area than 1Password, where the password selection menu (on Windows at least...) is actually rendered by an entirely separate process on the system. (I.e., clicking the icons that the extension displays triggers the 1Password desktop application to display UI at the cursor's current position. Picking a password from this UI will transmit it to the browser extension for filling. The password is only present in the browser's memory once you've interacted with the desktop application's UI.)

As always, do your research. Don't get suckered into paying a subscription fee for a browser extension that offers the same functionality your browser has built-in. But realize that there are other options out there that may actually be worth investing in.

Disclaimer: I've been a happy 1Password customer for a few years now.

kbuck··on Ask HN: Can we collaborate on a IP Address or Regex blacklist?
DroneBL administrator here! DroneBL does list many classes of abusive IPs, although most of our listings originate from IRC (as opposed to, say, Project Honeypot, which sources them from web spam). That said, though, it's apparently very popular to abuse IRC with open proxies, "free" VPNs, and many other sources of rotatable IPs, most of which overlap with what website administrators deal with. I am aware of a few sites that use DroneBL to measurably reduce abuse.

Note, however, that you may find our listing coverage lacking for web-only issues, such as WordPress pingback spammers, forum spammers (not using a proxy or VPN), etc. Especially in comparison to something like Project Honeypot.

A layered defense is the best defense. Firewalling, application hardening, rate-limits, hellbans, risk-scoring, etc., especially in combination with a blacklist, can significantly frustrate and discourage attackers and spammers. No single measure (other than extensive manual moderation queues) will prevent abuse entirely, but the more roadblocks you put up, the more likely the abuser is to give up.

kbuck··on Bitcoin surpasses $50K as major companies jump into crypto
I think there are a couple issues with this idea: firstly, they'd be accepting the Bitcoin, so they wouldn't need any on hand to process the purchases. Secondly, if China wants to prevent or restrict the sale of a physical good, especially one as large as a car, it's far easier to stop it from being imported (or manufactured) than to stop people from paying for it.
kbuck··on The life and death of email read tracking
Ironically, the Firefox version of this extension requests permissions to inspect all domains, not just Gmail -- indicating that the extension itself may be performing tracking.

I can't tell offhand whether the Chrome version does the same.

kbuck··on Ask HN: Captcha Alternatives?
If you're seeing connections from random residential IPs, they're probably using a reverse-proxy service like Luminati or 911.re. IP blocklists won't catch these. These proxies originate from (basically) compromised computers -- people who install "free" browser extensions and the like: https://www.trendmicro.com/vinfo/hk-en/security/news/cybercr...

With a troll this persistent (and willing to spend money on it), your best bet is definitely shadow bans and moderation queues.

kbuck··on Targeted MitM attacks using information leakage in SSH clients [pdf]
Windows 10 comes with OpenSSH installed by default now -- start up PowerShell and run `ssh`. Includes all the trimmings, even a `ssh-agent`.

Of course, if you don't like the rendering/look/customization of the default PowerShell window, you can also grab Windows Terminal: https://www.microsoft.com/en-us/p/windows-terminal/9n0dx20hk...

kbuck··on FCC will require phone carriers to authenticate calls by June 2021 [pdf]
Regarding robocalls from political campaigns: I removed my phone number from my voter registration, because honestly I don't want any calls or texts from campaigns. I left my email address in case they want to spam that. I recommend doing the same (although at least with Gmail I find that several of the political emails end up in the spam folder...)
kbuck··on SSD Storage: 2018 in review
At the SSD level, the drives are actually doing block management, not file management. You still need a filesystem to store metadata, manage the layout of the data, etc.

An example of something that a SSD's controller does that the operating system/filesystem doesn't have to worry about is managing bad blocks. If the SSD detects a bad block, it will replace it with a working block and update the data used by its flash translation layer to move the blocks around. This is completely opaque to the operating system; as far as it knows its underlying storage works exactly the same (until there are so many bad blocks that the drive can't keep up this convenient deception).

An example of something a filesystem does that the SSD doesn't provide is storing operating system-specific file metadata, such as permissions, creation times, multiple data streams, directory layouts, etc. SSDs deal only in blocks of data, not arbitrarily-sized units, nor metadata.

The reason that this behavior isn't more tightly-integrated is because some of the details of managing the underlying flash blocks tend to be specific to type of flash, or even different models of flash. For example, the article mentions QLC flash becoming mainstream - we're finally getting to this point because previously, QLC was so difficult to manage that your filesystem had to be aware that it was writing to QLC flash to use it effectively. There are a few filesystems designed for direct flash management like yaffs[0], but this isn't quite as efficient as a SSD's dedicated processor and software stack.

[0]: https://yaffs.net/

kbuck··on VPN Extensions are not for privacy
I deal with a lot of abuse originating from "VPN" browser extensions. I've spent a lot of time looking at how they operate.

A surprising number of these are implemented as open HTTPS proxies. You don't even need the extension installed to use the proxy, nor any kind of authentication. The extension just fetches a list of proxies that the company has configured and picks one.

The free ones are rather questionable. For example, Hola makes your computer part of an expensive VPN service (sold under a different name) aimed at bypassing IP bans[0]. On some the free tier is made so inconvenient that you will almost have to subscribe to the paid tier if you're using it legitimately (but it's usually usable if you just want to get around some ban).

There used to be some ad-supported VPN providers, which would ironically trade away all of the privacy you'd normally otherwise get by using a VPN, making them only useful for ban/block evasion. These have mostly died out now that ads == tracking is common knowledge[1], but I'm still very suspicious of "free" providers that offer generous access without payment. It's difficult to prove that logs aren't collected, and they could just as easily be collecting and selling user logs.

If you're in the market for a VPN, pick a reputable provider that has no free tier (you should make sure that you are the customer and not the product), and ideally one that also provides actual VPN servers and not just a browser extension that connects to proxies. Another good option is to set one up yourself using a cheap VPS.

[0]: http://adios-hola.org/

[1]: https://blog.cyberghostvpn.com/en/ending-free-version-cyberg...

kbuck··on Intel Optane DC Persistent Memory Operating Modes Explained
Since the module has both RAM and Optane storage on it, and only the Optane storage is non-volatile, all memory writes would have to be written to the Optane storage instead of the RAM before they could be treated as complete. This would probably be significantly slower and would somewhat restrict how cleverly the device could manage the RAM/Optane resources. (For example, with the current architecture, if a memory region is being repeatedly rewritten, it can just keep it on the RAM and not touch the backing Optane storage.)

It's also unlikely that this feature would be deemed useful given that they already provide the App Direct interface; for a server (which appears to be the intended market), if you've removed power from the memory, you're probably intentionally rebooting the server and would prefer that it reboot cleanly rather than have the random contents of the previous boot in memory.

kbuck··on Firefox: The Effect of Ad Blocking on User Engagement with the Web [pdf]
Google actually had/has an interesting micropayment-esque solution to this that neatly solves almost all of the problems with micropayments. It's called "Google Contributor"[0].

Here's how it used to work: You'd pay Google Contributor $5-$15 per month. When visiting a page with ads, Google Contributor would bid for the ad spot on your behalf and show a non-ad when it won. This has the benefit of paying each site what they're "worth" based upon the bids for the ad space, so it entirely sidesteps the problem of valuation. Additionally, there's an easy out for people who can't afford it as well - view the ads.

Unfortunately, all good things must come to an end... I only learned about Contributor right before it was reworked. After the rework, it now only works with a list of sites that have opted-in, and the list is disappointingly short[1]. It basically seems dead now.

[0]: https://contributor.google.com/v/beta [1]: https://support.google.com/contributor/answer/7324995

kbuck··on Ask HN: Best alternative to Gmail?
To be fair here, two of these are obvious user error.

In the Etherium case, he deleted the email and wanted to get it back 2 full years later. The only way he would have recovered from this would have been to take meticulous backups (and test them regularly). I would expect any 3rd party provider to honor my wish to delete data, especially 2 years down the line (and, in fact, they are probably legally required to do so).

In the "lost in the Google void" situation, the user set up 2fa but lost all access to their 2nd factors. I don't see any reasonable recourse to this, as any "solution" Google implements would undermine the entire purpose of 2fa.

The remaining two are obvious issues with Google's service. The "gender pronoun" one is a bit odd because gender pronouns don't seem to have anything to do with the account closure (there's speculation that he was mass-reported to exploit their abuse response systems).

kbuck··on YouTube and Netflix ‘Throttled’ by Carriers
MetroPCS is T-Mobile under different branding. T-Mobile is fairly open about their throttling practices (you have to purchase their "ONE Plus" plan to have un-throttled video), but MetroPCS puts it in their rather long "Network Disclosure"[0]: "All current MetroPCS plans include video optimization features that are always enabled, which, when connected to the cellular network, deliver a DVD quality (typically 480p) video experience at up to 1.5 Mbps with minimal buffering while streaming ("Data Maximizer"). Customers may, for an additional charge, add on a native resolution video feature, disabling optimization for their device. Some qualifying video providers may choose to self-optimize their video content or opt-out of the Data Maximizer program."

[0]: https://www.metropcs.com/terms-conditions/network-disclosure...

kbuck··on Stripe Issuing – An API for creating physical and virtual cards
A few banks provide a system like this. I'm aware of at least Bank of America and Citi.

Bank of America calls it "ShopSafe"; you can generate a number for one-time or recurring payment with an associated limit and expiration date.

Citi calls it Virtual Account Numbers. Theirs don't have a limit by default (but you can create one that does).

Unfortunately, both systems use archaic Flash applets to generate and manage the numbers... I hate the Citi one in particular because it has sound effects when you press buttons.

kbuck··on How Much Money Do You Save by Cooking at Home?
I think this analysis is a little flawed. I can understand their argument against factoring in opportunity cost as this will vary widely from person-to-person (and is pretty easy to consider on your own), but they also don't factor in waste or cost of the tools necessary to prepare food.

For example, the article mentions that they used the cost for only 1/2 of an onion if the recipe called for only 1/2 an onion, but what happens to the other 1/2? Depending on how often you cook at home, how often you go out of your way to use existing ingredients, and how much time you spend meal-planning, you'll either manage to use the rest of the onion (which is pretty easy for something as common as onions), or it will go to waste. Personally, since I'm typically just cooking for 1, most of these end up going to waste unless I want to be eating the same thing for several days in a row.

This analysis would be more useful and interesting if it came with multiple "waste factors" for the remaining ingredients, from "completely used" (which is what this article assumes) to "completely wasted". It'd also be more useful if it factored in the amortized cost of maintaining a kitchen that's stocked well-enough with tools and spices to regularly prepare a variety of recipes.

For me personally, the difference in cost is much closer than this article. I will typically use all of the "main" ingredient, but additional (yet expensive) ingredients, such as spices, cheeses, etc. often go bad before I have a chance to use them again. I've also spent a significant amount of money acquiring the kitchenware required to cook at home. I typically don't eat extravagantly when I eat out; most meals are ~$15-$17 (incl. tax and tip). For some meals, I buy pre-made food at the grocery store (e.g. salads, wraps) that also come MUCH closer, if not cheaper, than preparing it at home would cost me if waste is included. Some of these can be very close to restaurant quality.

kbuck··on ACME v2 and Wildcard Certificate Support is Live
Thanks for this; I've been searching for something similar for a while now. I'll look forward to trying it!
kbuck··on Self-driving car on Moscow streets after snowfall [video]
In California (and most places I've lived), this is actually legal. To complete the turn, you first enter the intersection while the light is green, then wait for traffic to clear. If it only clears after the light turns red, you're still in the right - because only when you fully entered the intersection (on the green light) is considered. See here: https://patch.com/california/sanbruno/ask-a-cop-should-i-pul...

Of course, this only allows one car (or maybe two, if the intersection is particularly large) per light cycle, which isn't much. People who enter the intersection on the yellow or red light (tailing the person who was in the intersection waiting to turn left) are turning illegally.

kbuck··on Why TLS 1.3 isn't in browsers yet
Flash requires you to install a socket policy daemon[1] that typically listens on port 843 (which is why the MITM test requires that port 843 be open). When you request a raw socket, Flash first connects to port 843 and requests the policy file, which will tell it whether it's allowed to use raw sockets with that server.

I've set one of these up before, and I'm not really a fan.

[1]: http://www.adobe.com/devnet/flashplayer/articles/socket_poli...

kbuck··on Over the Air: Exploiting Broadcom’s Wi-Fi Stack
This is the important bit:

> However, much more interestingly, we see that the implementation for [vendor-specific] command #4 seems relevant to our current pursuit. First, it does not require the existence of a TDLS connection in order to be processed!

kbuck··on Carbon monoxide poisoning from 3D laser printer may have killed Berkeley couple
On Android, the Google Keyboard has both symbols on the same screen[1], and it's difficult to visually differentiate them. When you see this particular typo, it's probably someone using the Google Keyboard on Android.

[1]: https://www.reddit.com/r/Android/comments/56hwfd/psa_is_diff...

← PreviousPage 2 of 6Next →