HNHacker News
TopNewBestAskShowJobs

lambdaone

1,713 karma · joined October 28, 2021

submissionscomments
lambdaone··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
Again, there are safe ways of doing this. For example, Wuffs exists: https://github.com/google/wuffs

At the very least, big money security software companies should be parsing untrusted content with some kind of rigorouly safe approach, not just squirting it through a big pile of C/C++.

And don't get me started on the whole concept of undefined behavior in those languages. To quote I. I. Rabi, "Who ordered that?"

lambdaone··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
Memory-safe lanuages (for goodness' sake, even the crap I write in Python qualifies!) are the very minimum that is needed; not to use them for anything critical is simply crazy. Yes, do all the other things, but at least put out the blazing fire in your basement while you are implementing your fire-safety strategy.
lambdaone··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
I didn't know that. So that makes this two strikes?
lambdaone··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
It's the equivalent of not writing about Boeing until the day a 737 MAX crashes right in front of your newpaper offices.
lambdaone··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
You're making the mistake of assuming that the people running those companies care about anything other than their job security, and buying in solutions is the best way to have a ready-made scapegoat when things go wrong. The mantra "no-one ever got sacked for buying IBM" still holds, you can just substitute "Oracle", or "Microsoft", or now - apparently - "Crowdstrike".
lambdaone··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
This has been an open secret for decades. Just a handful of major OS and browser vendors, constantly shipping patches to their systems and most software having such vast software supply chains that it's effectively impossible to audit anything, let alone truly certify anything as safe, and "security" software just expands the attack surface.

Everyone in the industry knows this.

Interesting to see the NYT just catching up.

lambdaone··on Ask HN: Can anyone from Crowdstrike explain the back story?
That's all fine, until one day Crowdstrike is the threat.
lambdaone··on Ask HN: Can anyone from Crowdstrike explain the back story?
I think it would take Crowdstrike doing five, six of these in a row before they tanked. Look at Boeing; two planes full of passengers died for quite scandalous reasons, followed up by a whole bunch of other engineering scandals, and while the value of Boeing shares took a 50% hit, the company's still in business, and people are still buying planes from them.
lambdaone··on Ask HN: Can anyone from Crowdstrike explain the back story?
For me, the word "smart" is a red flag. It generally means "unnecessary feature that's designed to screw you".
lambdaone··on Ask HN: Can anyone from Crowdstrike explain the back story?
I'd be surprised if they were toast. Big companies can fuck up with impunity - just look at Boeing. They can take a bit of an insurance hit, chalk it up to the cost of doing business, and pass the cost back to their customers in the long run.
lambdaone··on It's not just CrowdStrike – the cyber sector is vulnerable
Most software in indeed trash. There's neither the budget nor the will to fix it. The existence of "security" software is a symptom of systemic sickness, not the underlying disease.
lambdaone··on It's not just CrowdStrike – the cyber sector is vulnerable
It is certainly possible to write bug-free code, in terms of meeting a formal specification of behavior, and guaranteeing no behavior outside that specification. It requires formal methods, and it's much more expensive than ordinary software development.

Creating exploit-free code is another matter - you have to be able to craft exploit-free specifications, and there's no real understanding what that might even mean. But bug-free software would be a start.

lambdaone··on "No way to prevent this" say users of only language where this regularly happens
There certainly are systematic solutions to at least _some_ of the real problems, based on formal methods, of which Rust's checkers are a simple example, and it's an inexcusable moral failure that they are not used more widely.

Reliable software is expensive to develop; more expensive than we are willing to admit. You can either take the expense at development time by increasing development cost, or you can shift it until later and externalise the cost by making the end-user and society at large suck it up in terms of unreliability and occasional disaster.

We are at the stage the Victorians were with exploding boilers, or people in early Medieval times were with collapsing cathedrals. They fixed their problems, and so can we.

lambdaone··on What If We Stopped Pretending? (2019)
It's a counsel of despair. I stopped reading when I read the words "As a non-scientist, I do my own kind of modelling."
lambdaone··on Chinese AI stirs panic at European geoscience society
Given what existing models can do right now, that moment might come sooner than you think.
lambdaone··on I Received an AI Email
It is, indeed, just a tool like any other. And just like any other tool, like a gun or a knife or a pepper spray, having one does not give you the right to use it on other people.

Your right to swing your fist stops at my nose.

lambdaone··on How I overcame my addiction to sugar
The parent poster is right in that pure fructose is probably worse for you than an equivalent amount of pure sucrose. But the way that fructose is delivered to your body by digesting fruit - slowly, and in conjuction with other materials, in a way that we have evolved to tolerate - is entirely different from eating the pure chemical.
lambdaone··on Make Something With Your Hands (Even if It’s Hideous)
My job, like I imagine the jobs of most people here, involves mostly abstract symbol manipulation, with the occasional meeting. When I'm not working, I do physical things; climbing, hiking, and making and fixing things with my hands. I derive deep satisfaction from all of them.

Sure, I might take three months to make something I could have bought for $1000, but price is not the point. The thing I made is a unique reflection of my own self, and the experience of making it has value that no money could ever buy.

lambdaone··on A violent gang's ruthless crypto-stealing home invasion spree
XKCD saw this coming a long way off: https://xkcd.com/538/

See also https://github.com/jlopp/physical-bitcoin-attacks/blob/maste... , with examples dating all the way back to 2014.

lambdaone··on Entrust Certificate Distrust
I've always thought that company names like "Entrust" are hostages to fortune, daring the Fates to intervene. In this case the Fates are the browser vendors.

There's now also the problem of competing with a free alternative that increasingly almost everyone knows about.

lambdaone··on Will we ever get fusion power?
If you read to the end (or indeed just scroll down to the last few paragraphs) the answer is "almost certainly yes, but only if we have the will (and budget) to do so".

What puts fusion development in peril is the rapid improvement of known renewable technologies, and the likelihood that 100% renewables is possible in the near future using only those technologies at lower cost.

lambdaone··on Will we ever get fusion power?
Well, solar concentrators can in (traditional physics-based) theory increase solar cell efficiency substantially: https://iopscience.iop.org/article/10.1088/0022-3727/13/5/01... . Whether that's cost-effective is a different matter.

But that's not got anything to do with Brilliant Light's claims, which so far do not stand up to scrutiny.

lambdaone··on Will we ever get fusion power?
Their lack of progress in producing power from their system suggests otherwise. Meanwhile the standard quantum mechanical model of matter goes on making correct, testable predictions. Including in fusion experiments.
lambdaone··on Will we ever get fusion power?
There's absolutely no reason to believe that fusion power is impossible. It being very, very difficult and very, very expensive to reach a practical system is the problem.

But you're right about better alternatives. Right now that alterative is a combination of solar, wind, hydro and storage, with perhaps a bit of more exotic systems (wave power? solar towers?) in the mix.

lambdaone··on Will we ever get fusion power?
That's certainly a hard limit for a cell with a single P-N junction. However, with a bit of ingenuity, we can do much better than that; see https://en.wikipedia.org/wiki/Shockley%E2%80%93Queisser_limi...
lambdaone··on Microsoft CEO of AI Your online content is 'freeware' fodder for training models
Fascinating watching Microsoft morphing from intellectual property absolutism to this. "What's mine is mine, what's yours is also mine."
lambdaone··on Why American tech companies need to help build AI weaponry
It's not a foregone conclusion. We have managed to ban chemical weapons. laser blinding weapons and biological weapons on a global scale. If there was sufficient will to do so, we could do this for autonomous weapons as well.

The argument that "bad people will do X", so we must do X to them first, is a race to the bottom.

This article is, however, very revealing about what Palantir wants to happen, without ever mentioning the profit motive.

lambdaone··on Waymo One is now open to everyone in San Francisco
Remember that the passenger cars are not the only thing that can scale; if you can automate the mapping and data preparation part of the process sufficiently, you may even be able to reduce it to mostly a matter of driving a few sensor cars around for a few weeks; maybe even cars that are adapted versions of your normal taxi vehicles, but with a human driver behind the wheel while you are mapping.

I would imagine that while Waymo's mapping efforts have been very human effort-intensive so far, they will be looking at developing this automatic map-making capability as a high priority for rolling out new cities. Scaling the rate of expansion is then mostly a matter of throwing hardware and compute at the problem.

lambdaone··on More Memory Safety for Let's Encrypt: Deploying ntpd-rs
NTP is a ubiquitous network service that runs directly exposed to the Internet, and that seems to me like a good thing to harden. Making NTP more secure does not stop anyone else from working on any other project.
lambdaone··on Powering Planes with Microwaves Is Not the Craziest Idea
The U.S. seems to be able to maintain a quite impressive railroad system for freight purposes, in what is still the largest rail transport network of any country in the world. Passenger transport withered away as long-distance road travel and cheap air flights out-competed it. With sufficient ingenuity and capital expenditure, I wonder if perhaps it could be revived?
← PreviousPage 15 of 18Next →