HNHacker News
TopNewBestAskShowJobs

lsofzz

57 karma · joined November 28, 2018

I keep the in-extinguishable fire under bay.

Been there done that - SRE/DevOps/SecEng/SysEng/SoftEng

submissionscomments
lsofzz··on The Beauty of Unix Pipelines
I think this reply needs more up votes! ;)
lsofzz··on The Beauty of Unix Pipelines
Why not a littel bit more? ;)

  set -euf -o pipefail
lsofzz··on The Beauty of Unix Pipelines
> I strongly disagree although, just like you, I have no evidence to support my claim

Haha. Fair enough!

lsofzz··on The Beauty of Unix Pipelines
> This is where you need to use awk.

I think need is a strong statement in this context.

  echo $(( 1 + $(grep 'cpu cores' /proc/cpuinfo | head -1 | awk -F ':' '{print $2}') ))

Choosing shell vs. [insert modern] programming is a matter of trade-off of taste, time, $$$, collective consensus (in a team setting) and so forth.

[edit]: Forgot code syntax on HN.

lsofzz··on The Beauty of Unix Pipelines
> - Bash is awful (should be replaced with Python, and there are so many Python-based shells now that reify that opinion)

You know that no one uses Bash these days right?

Fish shell, Zsh are the much newer and friendlier shells these days. All my shells run on Fish these days.

I have to tell you that my shell ergonomics has improved a lot after I started using fish shell.

But to your point, _why_ is Bash awful?

lsofzz··on The Beauty of Unix Pipelines
> http://langsec.org

The maintainer apparently has no transport security concerns. It takes literally two minutes to set up TLS these days

lsofzz··on Fuchsia overview
flatpak/snap applications can run on its own confined sanboxes
lsofzz··on Chromium project finds that 70% of security defects are memory safety problems
COBOL
lsofzz··on Apache NiFi
From watching the presentation on Youtube (https://youtu.be/sQCgtCoZyFQ), it seems NiFi is geared towards acquisition of data, gluing/batching/massaging the flow between systems and providing the necessary interfaces to downstream systems;

- Would love to see the ability to develop custom NiFi processors in Go/Rust/Elixir etc.

- XML is a big pain in the rear.

- Being container-aware is big win. Stateless is even better.

I see a good opportunity there for users like me to explorer NiFi's capability in the future.

> They both schedule jobs and move data according to control flow topologies that you build in a GUI, right?

Airflow on the other hand is designed to run scheduled jobs (whether it be batched or otherwise). The 'job' can really be anything - build / data processing pipelines, system configuration management pipelines and so on. In Airflow parlance, one can create connected DAG's as pipelines that massage the data in a way you intend it to.

They both share some commonalities but I do gravitate towards their use cases being subtly different and an important one highlighted above.

lsofzz··on Lots of bugs in 32-bit x86 Linux entry code
> This time, AMD may have stepped up with a steel pipe. We'll see how well they can use it...

:-))))

lsofzz··on Thieves Are Using Bluetooth to Target Vehicle Break-Ins
Expanding on it further, what I mean is that our BT stack should be built from ground up with security in mind. We cannot fight every attack surface but we probably can get to all the low hanging ones that the crims can exploit.

One day in some utopia probably.

I as a user of BT stack do not have to worry about whether it is switched on or off. This is what I mean by _secure by default_.

Downvoter - thank you. I took time to explain what I mean this time :)

lsofzz··on Thieves Are Using Bluetooth to Target Vehicle Break-Ins
> You can disable Bluetooth by default and enable it only when used.

You are missing the point.

Ever heard of secure by default?

lsofzz··on Is true hacking dead? What we lost
> Thousands do care. So here's what I mean: When you take the ratio of the thousands that do compared to the millions who don't, you get a number that's pretty close to zero (one tenth of a percent, back of envelope).

Fair enough.

lsofzz··on Is true hacking dead? What we lost
> And it certainly isn’t dead.

Or to put it another way, it's alive and kicking ass :-)

lsofzz··on Is true hacking dead? What we lost
> If you define hacking as controlling your computer hardware at the lowest level, then hacking is dead because no-one wants to write device drivers.

This is absurd. Dude, let me be clear - Just because you write Java all day long does not mean that there are hundreds if not thousands of embedded system developers who engineer (quite passionately!) the thing that powers your SSD or your wireless card or the thing that heats your home.

We often take these substrates (in this context - the firmware and device drivers etc.) for granted in the modern hardware and often fail to even acknowledge them. I am not one of them and I vehemently defend these silent heroes of our generation.

lsofzz··on Is true hacking dead? What we lost
> There was a term from the early 00's for malicious "hackers", which was crackers.

Yes.

> But if the media is unwilling to budge should we just make a new word?

Not sure how that will pan out :-)

lsofzz··on Is true hacking dead? What we lost
> 1. I have no idea why "hacking" aka "going fast and breaking things" is so glorified while "building good reliable programs" aka "good programming" is not.

The way I see it, `going fast and breaking things' is an iterative process. IMHO, it should not be viewed as `go fast, break things and _never_ iterate to fix things'.

Just thought I'd toss my two cents on it.

> 2. How come that someone thinks of himself/herself that he/she has the right to say who is a hacker and who is not.

No idea why you feel binary. If you like to call yourself a hacker - fuck it - go for it.

The connotation in the beginning were that hackers were pioneers, thinkers, achievers and great motivators. Over time, the meaning has been mutated and engineered by the media to mean `malicious' and `conniving' thieves/criminals.

To this day, I still stick to the original definition of a `hacker'. I don't give a two fuck about what the media likes to call it.

lsofzz··on Sherlock: Find usernames across social networks
> OK: it's fairly trivial for someone like me to do this, and you don't even need "ML" to do it. It's just counting, binary trees and simple models.

Would you be interested in PoC'ing it out for such a trivial project?

lsofzz··on Sherlock: Find usernames across social networks
> I do not have direct ML experience at the moment. I’ve only run simpler regressions. I was making an educated guess as to the tech which may emerge, and it doesn’t seem far-fetched since it probably would not require language comprehension or higher order reasoning. I would love someone who’s worked with ML to weigh in.

Aha. Indeed. I would prefer to have someone actively working in ML to weigh in as well.

lsofzz··on Sherlock: Find usernames across social networks
> Sherlocked :-)

Hehe

lsofzz··on Sherlock: Find usernames across social networks
> Train it on content that you know was produced by someone, then unleash it on the rest of the internet to find content that they wrote anonymously.

I apologies but that's disappointingly vague..

lsofzz··on Sherlock: Find usernames across social networks
> What next? A publicly available ML web crawler that analyzes speech and belief patterns, triangulates them with metadata, and returns someone’s identity with 99% confidence?

Close but no cigar.

But seriously, correct me If I am wrong but if I were to propose a solution to defeat this `ML web crawler' confidence in it's results, then the first thing I would do is to feed the internet with invalid data. How does ML-based analyzers deal with this kind of data set?

lsofzz··on How Is NordVPN Unblocking Disney+?
> Which is basically TOR

Last time I checked Tor's technical paper (probably been 10 or so years), it stated the fact that a relay? node in between can only decrypt the information required to route to next hop and not the actual packet's payload. Is that correct or am I dreaming?

Also, I recall that if someone malicious flooded the tor network with malicious exit nodes, then all traffic details can be `inferred' right? i.e., the assumption was that exit nodes need to route the packet to destination thus it needed to look at every packet but couldn't infer the originating IP address (based on my dated knowledge :))

If a malicious person now floods the tor network with bazillion exit + relay nodes - then essentially all contents (payload + IP src/dst) can be aggregated. Is this still problem in tor network?

lsofzz··on How Is NordVPN Unblocking Disney+?
Yes. To add, any number of middle boxes during egress from the VPN provider can also sniff the SNI in TLS packet (SNI stands for Server Name Indication and stands on its own as a plain text traffic) before a TLS sessions is established (assuming DoT/DoH DNS scheme is in use)

Effort and RFCs are underway to establish what would become part of TLS protocol stack. One of which is eSNI (encrypted SNI).

lsofzz··on How Is NordVPN Unblocking Disney+?
> Either way, yes, your data will also be wiretapped by your carrier themselves and sold on the open market [ ... ]

Woah. Hold your bong son! ;)

Any reference to documentation or any information of what you mean by `sold' on the open market?

If you wanted to prove a point by saying that internet is an insecure medium then yes I agree but `tapped' and `sold' is a whole different ball game that I am not aware of. At least in the internet I know of.

lsofzz··on How Is NordVPN Unblocking Disney+?
> No need for EC2, you can use Digital Ocean or Hetzner Cloud (GDPR ftw) to cut the costs.

Throwing GDPR and `ftw' in the same sentence. Hmm. No GDPR does not work that way hah. At least not in the global context.

GDPR only applies to you _if_ you happen to be a European Union citizen.

lsofzz··on More Intel speculative execution vulnerabilities
> Have you entertained the possibility that the decision to de-mitigate was the result of considered risk and resource management modeling ?

What do you mean by `resource management modeling` in this context? Do you mean `capacity planning` or `system scaling planning` or something else altogether?

lsofzz··on The secret life of open source developers [video]
Definitely a good refresher video. There is absolutely no doubt in my mind that its important to re-visit what we take for granted every single day and at the least be appreciative of all the amazing value open source software community brings.
lsofzz··on BPF Performance Tools: Linux System and Application Observability
Would the final revision include any chapters by Sasha Goldstein? I’d love to get his insights on it.
lsofzz··on BPF Performance Tools: Linux System and Application Observability
Would love to see it on Safari books.
← PreviousPage 4 of 5Next →