HNHacker News
TopNewBestAskShowJobs

korethr

2,932 karma · joined April 10, 2013

submissionscomments
korethr··on NHTSA tells automakers not to comply with Massachusetts right-to-repair law
If I am understanding the article correctly, NHTSA asserts that to open up telematics to 3rd parties would allow remote attacks on multiple vehicles' safety-critical systems simultaneously. This implies telematics has remote control on those safety critical systems.

This raises a question for me: Why the actual fuck are safety-critical systems able to receive commands from anywhere other than the driver's controls or diagnostic port? Perhaps I am old-scool, naive, ignorant, etc, but given what "safety-critical" means, that strikes me as egregiously unacceptable.

I can sympathize with the idea of convenient remote diagnostic and repair, but in my opinion, this is a case where the saftey risk not just to the driver and passengers, but anyone else nearby, outweighs the convenience of logging into Ford's/BMW/Honda's website, click button, car works again.

korethr··on I may be the only evil (bit) user on the internet (2015)
My guess is that since the packet is officially reserved and should not be set, a common firewall or other security appliance considers said packets to be malformed and drops them as a default behavior.
korethr··on Chrome users beware: Manifest v3 is deceitful and threatening
In the article, Firefox is cited as intending to adopt MV3 for compatibility reasons. If they indeed do so, I'm not sure how much relief running Firefox will offer from the more evil aspects of MV3.
korethr··on The Surprising Secret of Synchronization [video]
The concept this video covers proably will not come to a surprise to some here. However, I didn't take any of the classes in college that would introduced this concept to me. Thus, in a failure to recognize that auto-play had been turned back on, again, I was one of today's lucky 10,000. Hopefully, some of you are as well.

1. https://xkcd.com/1053/

korethr··on The nation’s last uranium mill plans to import Estonia’s radioactive waste
I will not disagree with the premise that our current and future energy needs require diversification into more nuclear generation, and that nuclear requires uranium. I will however, reject the notion that such necessarily means that what is happening at the mill and surrounding land is acceptable or can't be done any better.

My objections with the situation described in the article are twofold.

First, the mill is not a designed as a long-term waste storage facility and is being treated as such. My understanding from the article is that the mill was originally designed and intended to be there for 15 years, then reclaimed. But it's still in operation. The holding cells for tailings were designed for the original planned life of the mill, and are still in use. Generally, I like it when things are useful for a long time. But from the OP, the mill and its temporary waste storage is running well past its design lifetime, and more waste continues to be added to the site, allowing it to be treated as long-term radioactive waste disposal by loophole. That's not acceptable. I don't disagree with long-term radioactive waste storage. I do disagree with it being stored long term in a place not properly designed for it and where a containment failure, however small, endangers the health and safety of surrounding communities or otherwise general usefulness of the land. The article describes how the groundwater in the area has been acidifying. The locals worry that such is because of contamination caused by the mill's waste. The mill claims that such is a natural process that just happens sometimes. Regardless of who is (more) correct, those holding cells were designed when the groundwater (and thus soil) were far less acidic, and are being operated decades after their intended design lifetime. The water in the cells is measuring with a pH as low as 1. You can't tell me that's not creating a needless contamination risk.

Second, the age of the mill and thus their processes. As a millennial, I read "Built in the 1980s" and reflexively think "Oh, of course that's modern," because it's something that happened in my lifetime. But it's not; that's 30-40 years ago. I would be in no way surprised that the wastes produced by this mill are as dangerous as they are because of the process they use. From the description in the article, and on the NRC website[1][2] it sounds like this mill is using a conventional process (crush, leach out the uranium with sulfuric acid). Have there genuinely been no improvements in the conventional process over 30-40 years that improve its extractive efficiency, resulting in less radioactive tailings? Or improving the solvent recovery so the tailings don't acidify the soil and ground water so much over the long term? Or in extracting the other heavy metals, (lead, molybdenum, selenium), further reducing the the hazard of the tailings, and possibly providing a useful feedstock for other industrial processes? I find that unlikely, and would be disappointed if that were the case. Even if it doesn't make sense to retrofit such improvements to this mill (more capex on something already past its original design life, etc), the economic need for nuclear capability doesn't mean that this mill must remain. Is is genuinely so impossible to build a newer, better one?

1. https://www.nrc.gov/materials/uranium-recovery/extraction-me...

2. https://www.nrc.gov/materials/uranium-recovery/extraction-me...

korethr··on LANtenna attack reveals Ethernet cable traffic contents
This feels like one of those obvious-in-hindsight things. Of course an unshielded conductor would radiate RF correlating with the signal it carries, and if you could pick up the radiated RF, and knew the modulation scheme and how do decode it, you could see what was on the wire.

I do find myself wondering some things though.

Ethernet cables are 4 differential pairs. As I understand, the whole idea of these twisted pairs carrying a differential signal is that any RF the cable picked up from the environment would be common-mode, and get cancelled out receiver side, allowing the transmitted signal to arrive unspoiled. So, in theory, one would have a hard time injecting spurious transmissions into an Ethernet cable via RF.

Is this supposed to work in reverse, where the common-mode rejection of a differential pair would prevent RF from leaking out of the cable? Or is this one of those theory vs. practice things, where in theory, it shouldn't, but in practice, being a not-ideal twisted differential pair (e.g. twist rate is wrong for frequency of interest, untwisted section, conductors of slightly different lengths, etc) allows some RF emission to leak out, uncancelled. And in the case of a cheap cable, something claiming to be Cat 6A in actuality might never have passed spec for Cat 5, and thus leaks way more RF than it should, because the quality and balance of the twist was half-assed?

Or am I badly misunderstanding how this works because I haven't started studying for an amateur radio license yet?

korethr··on Facebook Dangerous Individuals and Organizations List (Reproduced Snapshot)
Indeed I have. I have edited my post to reflect that.
korethr··on Facebook Dangerous Individuals and Organizations List (Reproduced Snapshot)
That's probably deliberate. An intentional name collision seems a good way to run a front.
korethr··on Facebook Dangerous Individuals and Organizations List (Reproduced Snapshot)
Huh. There's a lot bands in the "Hate" section. Looking up the various names I'm finding various death metal and black metal bands. I can't help but wonder how many of those bands on are on that list because someone at Facebook took heavy metal imagery and lyrical themes too seriously and literally.

More Edit: Turns out I picked a bad example. I missed reference to a name collision with an actual National Socialist band using the original name. The original edit is below.

Edit: Figured I should support my thesis with an example.

Let us take the band Sturmtruppen, from the Hate section of the linked article. From Encyclopaedia Metallum[1][2], they are a Black/Death metal band with themes of war and genocide. Per and interview referenced on their Encyclopedia Metallum page, their choice of those themes is not to glorify them, but to have something evil sounding enough to fit the style of music.

I am not saying that all the listed bands don't belong there. I know that actual neo nazi bands that take their imagery and themes seriously are a real thing that exist. But I do suspect at least some bands are on that list because of imagery and lyrical themes alone.

1. https://www.metal-archives.com/bands/Sturmtruppen/12143

2. https://www.metal-archives.com/bands/Truppensturm/98034

korethr··on The ultimate SMD marking codes database
Man, I wish I would have known about this a few weeks ago when I was working on repairing a water damaged controller board from an electric smoker. Fortunately, the damaged components were not the mysterious SOT-23 devices labeled only "S3", but just a couple shorted-out diodes. Without this page, it would have been quite frustrating trying to source a new "S3" were it blown out, as I wouldn't have been able to measure polarity or hFE to narrow down a short list of candidates.
korethr··on Facebook-owned sites were down
At 21:44 UTC, facebook.com resolves for me.
korethr··on Facebook-owned sites were down
I mean, when I last worked in a NOC, we used to call ourselves "NOC monkeys", so yeah. IF you're in the NOC, you're a NOC monkey, if you're on the floor, you're a floor monkey. And so on.
korethr··on Facebook-owned sites were down
Yes, but Facebook is not a small company. Could PagerDuty realistically handle the scale of notifications that would be required for Facebook's operations?
korethr··on Facebook-owned sites were down
Link to such claims here: https://news.ycombinator.com/item?id=28750894

I have no doubt that the publicly published post-mortem report (if there even is one) will be heavily redacted in comparison to the internal-only version. But I very much want to see said hypothetical report anyway. This kind of infrastructural stuff fascinates me. And I would hope there would be some lessons in said report that even small time operators such as myself would do well to heed.

korethr··on Ambient Chaos
Okay this is fun.

Some thoughts:

* The volume ramps up a bit too quickly. In trying to blend hese, I don't think I've taken a single one above 10. Finer gradations in volume, if possible, would be great.

* It would be great to set some of the sounds to happen randomly or intermittently pop or fade in and out, and possibly at different intensities. E.g. if you're chilling in a coffee shop that's playing lo-fi beats while it's raining outside, there probably not going to be a constant wind, but occasional gusts, some stronger than others.

korethr··on A Battery Spot Welder Made from an Old Microwave and Excessive Mahogany [video]
In the end of the video he lists off the number of things he did that were fancier than necessary. One of them was the use of an Arduino for the pulse duration and switching. I found myself reflexively commenting, "It's called a 555 timer." I'm confident that the same function could be more minimally implemented with a 555 timer and maybe a couple other supporting chips. But he's probably getting more consistent control of pulse duration and it was probably easier for him to implement as well.
korethr··on A Battery Spot Welder Made from an Old Microwave and Excessive Mahogany [video]
What is the cause of the excess heat transfer? Is it mainly an excess pulse duration? I notice that the project in the OP was being pulsed on the order of 100s of ms, long enough to get a visible glow. Or is the excess heat caused by the fact that the OP runs at constant current for the entire duration of the pulse, where a capacitive discharge design is going to have the current falling off during the pulse? Or is it a blend of both?
korethr··on Nuclear War Survival Skills (1987)
If you read the linked book, it covers this point. Yes, the tech exists to build bombs with multi-megaton yields and has existed for decades However, those super-big explosions are actually less tactically and strategically useful. More useful are smaller explosions that can be placed with more precision, and the tech needed to hit with precision has only improved over time. It is more likely that deployed weapons would have yields measured in kilotons. While bigger than Nagasaki, probably still closer to Nagasaki than Tsar Bomba
korethr··on How to properly load a dishwasher (2020)
> Fancypants non-stainless steel knives do exist and will rust. > I don't really get why anyone likes them though.

The non-stainless alloys will have an easier time taking and keeping a very sharp edge. This makes them more useful, and for longer. Not only does a very sharp edge make the knife easier and faster to work with, is safer to use than a not-so-sharp knife.

korethr··on No Starttls
The situation with SMPTS and port 465 is a fun one. By my understanding, at present, implicit TLS for submission isn't standard. Now, a lot of mail server operators listen on port 465 for SMTPS anyway, because very breifly, that was the standard port for such. But there are other operators who are stickler for the letter of the standard, and when asked to support SMTPS on port 465, respond with "That's not standard. STARTTLS on 587 is. Use STARTTLS." I will confess to having been one of those operators in the past. Reflecting, I suspect that was at least partly because in insisting on strict standard compliance, I cut down on the amount of spam I had to deal with (you would be amazed at the sheer volume of poorly coded bots that imediately throw a LOGIN or MESSAGE FROM at you upon establishing a connection, not even bothering to forge a HELO or EHLO).

I totally support RFC 8314's attempt to standardize existing practice, and get port 465 officialy recognized. https://datatracker.ietf.org/doc/html/rfc8314 Once done, what is "standard" will no longer be an excuse. Though, updating out-of-support middleboxen will probably still take a while.

korethr··on My phone case, the hidden state of an RNN
For a second, I was hoping the image on the phone case was an adversarial one, intended to jam up facial-recognition other surveillance-related AI. No, nothing so extravagent, just a visualization of internal state.

'Tis still nifty.

korethr··on AWS adds an extra 5.5M IPv4 addresses
That's an interesting idea. I don't know if the FTC has the authority to do so under the current powers given to it by Congress, and I don't know if I'd like the precedent of them trying without Congress so delegating that power. I'd be totally willing to discuss Congress delegating them said authority.
korethr··on AWS adds an extra 5.5M IPv4 addresses
What's the cutoff for larger networks where the price starts to go down? Would say, a /16 count? Or does that effect kick in as low as, say, a /20?
korethr··on AWS adds an extra 5.5M IPv4 addresses
Years ago, when I perhaps more naively believed in the benevolence of Google, and that wisdom of the Elder True Nerds who worked there would lead us to The Future, I might have applauded them throwing their weight around doing something like that. Possibly with a condescending paternalistic attitude like, "dragging the unwashed masses kicking and screaming into the the future they're too stupid to realize just yet that this will be better for them."

I am no longer so young and naive. Now, there is no doubt in my mind that such a move by Google or the other tech giants would not be made out of benevolence, but because by doing so, somehow, would net them yet greater control over the flow of information across the world. Whether out of an authoritarian desire architect society the right way this time, or chasing their profit margin as far down the asymptote as they can measure, the resultant 1st through Nth order effects would probably be the same for the rest of us.

korethr··on AWS adds an extra 5.5M IPv4 addresses
low whistle I imagine they paid a pretty penny for those /12s.

A thought comes to me: If IPv6 adoption continues to drag along, and AWS/Azure/GCP continue to expand their IP blocks like this, how quickly are we in danger of the cloud providers effectively being the Internet?

korethr··on The World’s Biggest Tire Graveyard in Kuwait Is on Fire
A small request from those of us more prone to breathing issues than average. Please stop setting large fires like this. The smoke crosses continents and oceans, and many of us miss being able to go outside with starting to cough after an half-hour.
korethr··on SAML Is Insecure by Design
What options for addressing the SSO problem would you recommend over SAML if one had the option? OIDC? Kerberos?
korethr··on Catalytic converter thefts in California
The number of police officers in an area is only part of it. Said officers must also be permitted by the policies they operate under to take effective actions that stop or deter the thefts. You could have enough officers and vehicles to have a patrol unit every other block at all hours of the day, but if department policy is such that doing anything other than witnessing the theft and taking a report afterward results in getting fired, odds are, the cops aren't going to be stopping many thefts.
korethr··on How to summon and sell your soul to Satan and other devils
The passage about following the contracts to the letter and thus being able to get out of those contracts with a bit of cleverness reminds me of a similar principle in stores about faeries -- that faeries will follow their bargains with mortals to the letter. In faerie stories, this is what makes deals with faeries so risky, especially with the more malevolent ones; you never know just how your words will be twisted against your intentions and desires.

I wonder how much of the to-the-letter aspect of demonic contracts borrows from the older European folk stories of faeries, or whether it is the opposite -- the to-the-letter aspect of deals with faeries being a medieval Christian projection upon those stories.

korethr··on Don’t Wanna Pay Ransom Gangs? Test Your Backups
This is a post written by a person who's been at this a while, and has spent at least a portion of that time as Cassandra.
Page 1 of 21Next →