HNHacker News
TopNewBestAskShowJobs

lonestar

220 karma · joined September 8, 2008

https://github.com/chriskite
submissionscomments
lonestar··on A mechanic offered a reason why no one wants to work in the industry
Some models you can literally just pull a fuse for the telemetry modem and the car will be offline. Worth considering.
lonestar··on Stoicism's Appeal to the Rich and Powerful (2019)
I believe you mean Marcus Aurelius
lonestar··on Google Drive misplaces months' worth of customer data
I was hit by this. It looks like my laptop had not been syncing correctly for a couple months, then GDrive overwrote my local “My Drive” folder with the old cloud copy.
lonestar··on ZeroRPC
Check out JSON-RPC. Jimson is a good JSON-RPC client for Ruby. http://github.com/chriskite/jimson
lonestar··on Plead HN: Please be careful with your information
No, indeed it is not. If the problem is that people are getting phished because they type their info into a spoofed login page, how would making one standard login page be the answer?
lonestar··on Feedback for Phactory - A Database Factory for PHP Unit Tests
I released the first public version of Phactory yesterday, and I'd like to get some feedback from developers here on HN.

Phactory was born from a desire to have something like Factory Girl for my day job writing PHP. A couple of my co-workers and I have been using it for a few weeks now, and we're finding it really useful.

If you have time to give it a try, any feedback/criticism would be much appreciated.

What features would you want to see in a library like this?

lonestar··on Handmade Rails Authentication
"Password hashing scheme" refers exclusively to the algorithm used to transform a plaintext password into a ciphertext value (whether it's a hash or derived-key).

The rest of your library is the part you want to spend your effort on. Make it easy to use, make it flexible, put in some great features like a user admin panel. That stuff is the domain of the webapp library builder. Just trust the crypto part to the cryptographers, and use bcrypt/scrypt.

lonestar··on Handmade Rails Authentication
If you're offering it for public scrutiny, then the good news is you've just gotten a good bit of it from an experienced security professional. Perhaps instead of calling tptacek arrogant, you could take the criticism that you say you're inviting?

The best practice in password hashing schemes is well understood by the security community, so you have to understand that it can be frustrating to watch the same mistakes made over and over again.

As tptacek pointed out, the correct answer is "use bcrypt". He's not telling you not to offer your library for public use, he's just pointing out that there is absolutely no reason to roll your own password hashing scheme.

"Also, could I not continue using SHA2 256, and add an option to specify the number of hashing repetitions, which would increase the time to compute, as well as frustrate dictionary attacks?"

Are you sure there is no inherent property of SHA256 that would allow an attacker to shortcut the computation of successive hashes? I'm not saying there is, but simply that cryptographers have already solved this problem and considered all the angles. Why are you trying to start from scratch?

lonestar··on Handmade Rails Authentication
Actually, slow in this case does not at all mean "this operation isn't implemented in hardware or optimized assembly".

The slowness of an algorithm like bcrypt is a tunable property of the key expansion algorithm. A step in this process will be repeated 2^n times, where n can be configured by the user.

If a password function was only slow because it wasn't implemented in assembly on your server, an attacker would obviously just go implement it in assembly for his brute-force crack.

lonestar··on Telecommuting Culture - What it tells me about your company
Do you have a reference for this? I'd be interested in reading it.
lonestar··on Clojure, Node.js and Concurrency Fail
In what way is pushing 20K requests/second "concurrency fail"?

Node.js doesn't make it easy to share state between processes, but once you're scaling to multiple processes, the jump to multiple machines probably isn't far behind. You'll need to design a distributed algorithm, or just centralize your shared state in something like Redis anyway.

lonestar··on Hacker News, for iPhone and iPod Touch
If Opera started charging $3 for Opera Mini in the App Store, would you be upset? You're paying for a nicer interface to something that is free, not the content of HN.
lonestar··on Nodule: A Node.js Pub-Sub Key-Value Store in 185 Lines
Interesting. I haven't played with CoffeeScript before, I'll have to try it out.

I stuck to straight JS since I'd like the source to be simple for most developers to understand.

lonestar··on Show HN: I just made 4sqvision at SuperHappyDevHouse
Interesting concept, but it would be more useful if I could limit it to my city. Without a local context, it is mostly noise and no signal.

An ideal visualisation would be to show the activity as blips on a Google Map.

lonestar··on Students Build Black Widow Supercar that Gets 2752.3 MPG
"Supercar" seems a little generous seeing as how it has a top speed of 30mph.
lonestar··on Hacker builds tracking system to nab Tor pedophiles
If the alleged pedophile is savvy enough to use Tor, won't he be running his web traffic over SSL, rendering this sort of attack useless?
lonestar··on Lawsuit against "Discovery Math" in Seattle Schools
"Oh well, better for the rest of us."

Do you really think so? I'd prefer to live in a society where everyone was well-educated, or at least enjoyed learning.

I think you'd find there is some spillover benefit for yourself to be had from "these low-income and minority kids" receiving high-quality education.

lonestar··on WakeMate (YC S09) Shipping Delayed
Perhaps they should have announced the monthly fees before the delay. I'm more than a little disappointed to find out that I'm not getting it on time, and that I might unexpectedly have to pay a monthly fee once it does ship.
lonestar··on Improving sales with 3 characters and a misspelling
I think it's odd that you have such a problem with co-opting the use of "Re:" (even though you admit he is using it in the original sense), but you don't have an issue with him co-opting the English language by intentionally misspelling words.

Besides, when a customer requests pricing, many systems will send an e-mail to the salesperson who can hit "reply" to send an e-mail to the customer.

lonestar··on Even more new C++ features
Have you played with Scala? It reminds me in some ways of Ruby, you might find it to your liking.
lonestar··on FIPS 140-2 Level 2 Certified USB Memory Stick Cracked
> Either given enough people poking at it intelligently, or a enough computers brute forcing it nearly anything can be cracked.

That's technically true, but the time frame it takes to find an algorithmic weakness or complete a brute-force is the important factor here. It comes down to a question of how long your data needs to remain confidential.

As is usually the case, no cryptographic primitives were subverted to 'break' the USB stick. A somewhat silly implementation flaw is to blame.

lonestar··on Secret language
Jargon arises because it is useful for compressing information exchanged within a given culture. If this really was an internal posting which was accidentally exposed, what is the problem with using the jargon of Microsoft's culture?
lonestar··on Enchilada Programming Language
The hash could be used as the response in a consensus protocol, but it looks like Enchilada leaves building that protocol up to the developer.

So like I said, it's nice to have that hash for every reference, but I wonder if it's worth the storage overhead, and if a developer will use it when he's building his own distributed system anyway.

lonestar··on [dead]
I agree with you that it's inconvenient, but I can't think of an alternative that would be fair to both Zipcar and the renter. If I let Zipcar inspect the car and take their word that there's no damage, I'll be on the hook for $500 if they miss something. On the other hand if they trust me that I didn't damage it, they lose money if I'm lying.

As an aside, I generally do a quick walkaround on my car before driving away. Check for low tires, see if somebody banged their door into it, etc. For my motorcycle there are even more things I check each ride for safety reasons. It's inconvenient, but worth it I think.

lonestar··on [dead]
"...if a Zipster before you didn’t report their scratch and dent (and the Zipster after you does), that you’ll end up on the hook for the $500 damage deductible for something you didn’t do since you didn’t do the walkaround and report the damage"

It seems like the author is really stretching for things to complain about. If you neglect to inspect the vehicle for damage prior to driving it, what do you expect?

lonestar··on The Fifth Underhanded C Contest is Now Open
My favorite entry is the first runner-up from the encryption challenge in 2007: http://underhanded.xcott.com/?page_id=16

Basically a subtly buggy SWAP() implementation causes the RC4 cipher to output more and more plaintext as time goes on.

lonestar··on Enchilada Programming Language
The section on "verifiable computation" is interesting: http://www.enchiladacode.nl/technology.html#verifyable

"Every ID of an Enchilada Value is calculated by taking the SHA1 hash of the Value's contents."

The docs suggest that this can be used in a consensus protocol. Many nodes can compute the same result, and quickly test for equality by comparing the ID. Seems nice to have this built-in to the language, but I have to wonder:

a) Why SHA1? Why not a member of the SHA2 family? b) If you're creating a distributed system and want to implement a consensus protocol, a hash ID isn't really sufficient. Who is going to end up using this feature?

lonestar··on The Barometer of Hacker News Knowledge Half-life
He said he put his ego aside in regards to redesigning his webapp to appeal to a wider audience, rather than what he wanted.

It doesn't seem terribly egotistical to want to correct people who are spreading an inaccurate representation of his product.

lonestar··on Questions to Ask During a Ruby Interview
These interview questions were about Ruby, not Rails.

If you are hiring for a position where the developer will work primarily with Ruby, it makes sense to ask Ruby-specific questions or have a Ruby coding exercise. That shouldn't be the whole interview of course; as you mention, an all-around strong candidate is preferable.

That said, the questions in the article don't require much Ruby experience. Anyone with a grasp of OOP concepts could probably get most of them right.

lonestar··on When Rails Fails
If you're not a Ruby/Rails dev, it doesn't seem reasonable to expect that all the framework's errors will make sense to you. If you took the time to learn how requests are routed in an MVC framework, this particular error would probably make perfect sense to you.
Page 1 of 2Next →