HNHacker News
TopNewBestAskShowJobs

m0nastic

5,097 karma · joined April 27, 2010

I'm Chris Gale. I live in DC. Currently I'm working on security data analysis (mostly using graphs and Haskell), but I made my bones in application security.

site: chris.tengulabs.com email: m0nastic@tengulabs.com Twitter: m0nastic

I tend to avoid commenting on things I'm not pretty familiar with. Consequently, I don't post much on here.

submissionscomments
m0nastic··on Announcing Project Zero
I didn't think Grey Hat Python was a great book, but it serves a valuable purpose that I'm not aware of another book supplanting; which is that it shows you that you can use underlying programming to do security-related tasks, instead of being limited to just using tools.

The widest chasm that separates security professionals is the one between those that can only use tools other people provide and those that can write their own tools. And more than just being able to write them, but being able to write them quickly enough to be of use during an engagement (which usually only lasts between 1-3 weeks).

A lot of security testing at the non-entry level is putting together specific tools to accomplish an engagement-specific task. You don't generally spend a lot of time building giant edifices, it's usually lots of small things that you mostly throw away between gigs (minus whatever underlying libraries you favor using as construction components).

In that regard, I think Grey Hat Python is still a good book to introduce you to the idea of using real programming to do hacking, even if you never write a line of Python on an engagement.

m0nastic··on What I mean when I say "I think VR is bad news"
I think there's a good discussion to be had about what the future of VR means to advertising-based social networks, even if I don't share the authors cynicism.

I think their argument about the technology is batty though. It's the same argument that gets made every time a new creative medium is created. People making early motion pictures were basically filming plays, it took a while before the specific affordances of the medium become realized.

I fully expect that there will initially be a lot of shitty VR games. First there'll be existing games "re-skinned" to have VR support, and they'll mostly be terrible. Then there will start to be games that are designed specifically for VR. And most of those will be terrible too. But eventually game designers will discover what makes VR attractive as a platform, and generations of game developers will be born into a world where VR is actual practical tech; and they will make wonderful things.

The first generations of "tablet-optimized" games are awful too. Developers spend a lot of time trying to figure out how to superimpose a control pad on a touch screen that doesn't have any feedback (and obscures the screen when you use it). There will eventually be games for tablets that make use of the benefits of tablets (I think there's actually already a few of those).

I don't know what is so special about VR tech that would preclude that same thing from happening.

m0nastic··on Learn Lisp the Hard Way
I actually liked the Little Schemer a lot, specifically the way it's laid out with just questions in one column and answers in another (it helped establish a rhythm that made it nice to go through); but I did find the tone a little "young".

All the examples are about food, and there's cartoons littered throughout. There's a bunch of books that seem to be of that tone (Learn you a Haskell, Land of Lisp, Realm of Racket, Learn You Some Erlang), and I found myself instinctively recoiling from all of them (I haven't read the Erlang book, but it seems very much in that style).

I think it's important to have lots of different styles of books for learning a language, because I think different people respond better to different approaches, but selfishly, I wish every language had an equivalent to "ANSI Common Lisp" (by this site's benefactor emeritus) and Real World Haskell. I am also a big fan of the way Zed chose to lay out his books.

m0nastic··on The Life And Death Of 'The Internet's Own Boy'
First off, you weren't "silenced". You were down-voted. I don't see what that has to do with "the progressives on HN". I'm guessing you were down-voted because you made a pretty gross and uninformed statement about his mental health.

The fact that opinions aren't objective doesn't magically make them all worthy of consideration. HN is basically an online dinner party. If someone makes ugly statements in the middle of a conversation, the rest of the participants aren't obliged to stop and say "now, now, that's something we have to consider." They'd most likely just roll their eyes and move the conversation on to something else.

Down-voting is basically the digital equivalent of the conversation participants rolling their eyes and trying to continue on with the conversation.

m0nastic··on We put $200k into a site that sucks. Please destroy us with your criticism
After clicking around on some of the lists to get a sense of what the intended content is, I think it suffers from a little bit of an identity crisis.

By which I mean that the base, bottom-feeding type lists are already supremely well-covered by every other slideshow/listicle media property (Buzzfeed, the "suggested" stories at the bottom of every news site), so it would probably be difficult to attract any meaningful marketshare.

Whereas the curated lists of items, or recommendations are all things I'd use Pinterest for. Being able to organize and customize the item information seems like it could be a competitive advantage for you (Basically on Pinterest, your options are: Make a board, put pins on it, maybe comment on the individual pins; there's no sense of "ranking").

And it sounds like you're sort of looking at Pinterest's revenue model, but their user growth is kind of crazy, so they might end up sucking up all the air of that particular vertical.

m0nastic··on Today I published an introductory book on Haskell Data Analysis
Yeah, I've followed Clojure from afar for the past two years or so, but haven't yet had a reason to use it at work. I like a lot about the way the language is laid out, and whenever I watch one of Rich Hickey's talks I find myself instinctively wanting to sell all my possessions and walk the earth handing out "Data is Code, Code is Data" tracts. The few times it's seemed like Clojure might be a good fit for something small, I've ended up using Racket (for whatever reason I find all the infrastructure around writing and deploying Racket to be less cumbersome than all of Clojure's Java-ness)

So far, I've written all the "collection" type stuff in my system in Haskell, and I'm glad I ignored everyone's hemming and hawing about it, because it was actually a really pleasant experience. Now that I'm gathering a lot of disparate data, I'm in the "what the hell do I do with it?" phase of my project. I'm trying to resist sucking it all into Hadoop (partly because I'm a one-person operation and even a small Hadoop cluster would be larger than all of the systems that are generating the data that I'm monitoring, and partly because I can keep about a years worth of data comfortably in memory).

So I'm basically using this as an opportunity to try out whatever kinds of data analysis I think sound interesting, and then hopefully learning what is a good fit and what isn't. This is all uncharted territory for me, and I'm fortunate to be in a position where I can do what I want and don't have any time pressures.

I figure I can try to use this data to learn about statistical modeling, graph analysis, and machine learning. For the time being, I'm favoring Haskell for this, but that's not really any type of requirement. I just find that I enjoy Haskell a lot right now, so I should see how far I can go before the honeymoon ends and the awfulness is revealed.

m0nastic··on Today I published an introductory book on Haskell Data Analysis
I'm excited to read this, I just bought a copy.

I'm presently debating between using Haskell or Clojure for data analysis here at work (or most likely some combination of the two), so the timing couldn't be better.

m0nastic··on Twitter’s Chief Operating Officer Steps Down
I just checked, and it looks like I follow 500 people (which is actually way more than I would have guessed, and I'll admit is kind of ridiculous). Most of them aren't super high-output though, which helps.

I've had to unfollow lots of people who tweet a lot.

I've been using Twitter since 2007 (my account id number is in the 6-figures range). I feel like it took about a year or so to figure out how I wanted to use the service (and for there to be people I was interested in following), and it's only maybe the past year that I've discovered the benefit of unfollowing news accounts and following specific editors instead.

I also have pretty varied interests (I think the mix of people I follow is pretty evenly distributed between fashion people, photographers, news editors, functional programming people, infosec people, and comedians). That mix gets adjusted periodically as my interests shift (I unfollowed a lot of infosec people about a year ago as I've tried to extract myself from that community).

It's a work in progress.

m0nastic··on Facebook open sources Haxl
I agree it's hard to be all things to all people.

I think fundamentally, Hackage is meant to be a centralized package repository. If you look at other similar projects, there seems to be no real consensus as to whether that should just be a launching-off point to the actual project page, or more inclusive.

When I originally wrote this, I was going to say "It's akin to CPAN", but then to make sure I wasn't misremembering, I looked at a bunch of CPAN packages and saw that they were all actually fully-documented (with examples and whatnot).

I think the advantage to having consolidation is that you can then at least try to enforce documentation standards (whether you should, is arguable). What's super frustrating is going to a Hackage page, finding the link to the project home page (frequently on GitHub), going to the GitHub page and then just seeing a barren directory listing of files.

I feel slightly uncomfortable making statements about how Hackage should be set up however, as it's like going to a soup kitchen and then complaining about the specific soup they've decided to give you. "Oh, you mean this community resource we've set up which allows anyone to contribute a package and have it globally available doesn't provide exactly the functionality you'd like? Please tell me more about how the community can respond to your whims."

Also, for what it's worth, all the Haskell libraries that I make frequent use of tend to have very good documentation (you could argue that's HOW they end up becoming the ones I make frequent use of).

m0nastic··on Twitter’s Chief Operating Officer Steps Down
I think people use Twitter for different things, but for me Twitter has completely replaced RSS, IM, and news. Unlike Facebook, where none of the people I follow have relevant interests to me, on Twitter I only follow people who post things I'm interested in.

Over time, I've learned to unfollow actual news sources, but instead I follow a collection of editors (who wind up performing a very useful curation function). I'll still follow links to actual news stories, but I never go to any news web pages directly anymore.

I'm pretty good about constantly pruning my follow list, as I actually read all of my timeline. (Most people seem to have decided that that is futile, and only occasionally read their stream).

m0nastic··on Facebook open sources Haxl
The "documentation" on Hackage is almost universally just the haddock-generated files (which is why it's mostly just function declarations and type signatures).

Most libraries list a "Home Page" that more often than not includes more useful documentation (Haxl's, for example, has the things you've mentioned).

I concur, that most of the time, the documentation on Hackage isn't really sufficient, but I've found that for the most part I just use it to find the homepage, and then go there to read the actual documentation.

I agree that it would be nice if everything was all in one place.

m0nastic··on When Can I Code Swift on the Server?
I would never claim that Apple is a fervent open source company, but here are a bunch of their open source projects:

http://www.macosforge.org/

m0nastic··on When Can I Code Swift on the Server?
WebObjects hasn't been related to Objective-C for a while (It was rewritten in Java in 2001).

While WebObjects is still apparently being used by Apple's Online store and presumably some other internal applications, I wouldn't expect any serious WebObjects integration for Swift from Apple.

m0nastic··on Chris Lattner on Swift
Not that it's particularly complicated, but they mentioned yesterday that the updated version of the WWDC app (which they released right after the keynote) is written in Swift.

I don't know if that means "entirely written" or some parts, but they at least called attention to it.

m0nastic··on US cybercrime laws being used to target security researchers
Correct.

The CFAA requires access without authorization or exceeding authorized access. Presumably you are an authorized user of your own systems.

It is possible that some vendors may try to use User Acceptance Licenses to further restrict what actions can be taken with their software (even in case where you've purchased it and installed it on your system).

I believe (and would love to be corrected by a lawyer), that even those cases would be civilly prosecuted, and still not related to the CFAA.

This is one of the reasons why when providing penetration testing/application testing training we always took great pains to drill into their heads to never use any of those techniques on systems you do not own. Not poking around on your bank's website, etc.

If you knowingly access a system that you do not have authorization for, the owner of the system might not care (or might not notice), but under the CFAA, they can file charges against you.

Reasonable people may disagree what constitutes "exceeding authorized access" (where reasonable people might be your attorney and a prosecutor).

m0nastic··on Ask HN: Which paid apps and services do you use?
I think products like 1Password, Keypass, Lastpass, etc. are a good idea, in that they're making it much easier to encourage a culture of strong, unique passwords for every application and website. Of those, I favor 1Password, because the people making it have a good track record of making generally good security implementations, and being receptive of feedback when issues are discovered. They've been good about updating the apps when an issue is discovered, and haven't made it a super regular occurrence.

They also allow flexibility of storing the password database, which I prefer over the services that store your passwords with them, as you are now reliant on their own security implementations. If you want to, you can store it in dropbox, so that you can access the web-based version anywhere you can log into the Dropbox website. You're now putting an awful lot of faith in the security of Dropbox, but it's an option at least.

But fundamentally, this is a problem which should be solved by the ecosystem providers. Windows, Mac OS X, Firefox syncing, Chrome (I assume Chrome has a way to sync passwords to wherever you're logged into, I don't use Chrome).

I'm comfortable enough trusting Apple to secure all my login credentials that I'm willing to use the built-in functionality. Much like how I use "Reading List" instead of any of the "article saver applications". It works fairly well, I don't have to mess with it, I don't have to give my data to some other company, it just shows up in all my browsers on all of my devices.

m0nastic··on Ask HN: Which paid apps and services do you use?
Yeah, for whatever reason I was constantly having the following problem in 1Password:

->Whenever I auto-generated a password in the browser extension, and submitted it, 1Password would occasionally (like 1 in 20 times, but often enough to be infuriating) lose the new password into the ether. Like it wouldn't be saved in the "recently-generated passwords" field in 1Password, or update the password field under the "Logins" entry.

So when I got a new laptop, like a month ago, I didn't even install 1Password, but the first time I'd go to any site, I'd manually look up and copy the password out of my backed-up 1Password web page, and then let Safari save the login in the keychain. Over time, I migrated all of my passwords into the Keychain, and now I also have access to them from within Safari on my iPhone and iPad (which having to previously open the 1Password app, unlock it, copy the password from the login, and then switch back to Safari and paste it in), was a pretty big win.

So I'm really happy with iCloud Keychain so far. It restricts my ability to log in to only Apple devices (which for now at least, isn't an issue for me), but I've found it a much better experience than using 1Password.

m0nastic··on Ask HN: Which paid apps and services do you use?
Off the top of my head--

Services:

Fastmail.fm (for personal email), Office365 (for more legitimate email), Evernote (had a paid account for a few years, although I never use it), 500px (for non-professional photos), DigitalOcean for VPS, Netflix (not sure if you mean consumer services), Amazon Prime (I only use it for the shipping), Hulu+

Apps (a subsection at least):

Mathematica (I'm happy to pay for the Home version), 1Password (although I've stopped using it since iCloud Keychain Sync), Pixelmator, Capture One, NI Maschine, NI Tracktor, Pretty much every audio app for iOS (iMaschine, Figure, iKaossilator, iMS-20, SampleWiz, Lemur, Vogel CMI Pro, Animoog, Scape)

m0nastic··on Startup that is trying to build an open-source satellite network
They link to their Github page which has their software in it:

https://github.com/satellogic

I agree though that just having the software isn't of much use to anyone. I just think it's very interesting.

Also, I don't know what their business model is going to be (I assume selling access to the data), but in my head I imagined time-sharing satellite access (which is probably way too complicated for them to do).

m0nastic··on The reality show: Schizophrenics used to see demons and spirits (2013)
It seems reasonable that people would adopt schizophrenic hallucinations that are in line with their demographics.

As an anecdotal counterpoint, my girlfriend is schizophrenic, and is mostly afflicted with auditory hallucinations (she hears voices).

Weirdly, despite coming from a Vietnamese family (and being a blend of Đạo Mẫu and Mahayana Buddhist), the voices she hears are of a Christian-like "God".

m0nastic··on Why I Don't Drink
I don't drink very often anymore (maybe a few times a year). I've never liked the taste of most alcohol, so when I drink, it's generally just a lot of shots to get it down easiest. When I went out more, I drank more (the incredible effort I have to maintain to be around people is lessened if I'm drinking). As I got older, it seemed easier to just stop leaving my apartment, and I was never a fan of drinking at home.

I suppose somewhere in the back of my head I always worried about becoming an alcoholic (coming from a long line of stinking drunks), but thankfully, I don't really have any addiction issues.

I'll admit that it's probably a bad thing that so much of our culture is alcohol-centric, but I don't begrudge that other people just like drinking.

m0nastic··on Changes to Android and iOS Apps
Well that didn't take long.

It'll be interesting to see if the increased friction/reduced purchases is more than made up for by the extra 30% they'll be getting.

m0nastic··on Cryptol DSL, a tool for writing correct crypto algorithms, is now open-source
No, it's useful for both.

Here's a presentation they gave in 2012 about Cryptol that does a pretty good job explaining it:

http://2012.sharcs.org/slides/hurd.pdf

m0nastic··on The limits of "unlimited" vacation
I wonder if we're going to eventually wind up with policies similar to commercial aircraft crews. Like, for every N weeks of work you are required to take Y time off. It seems like the logical endgame (even though I hate vacations, and would be annoyed by being required to take them).

I don't think that the companies who are advertising unlimited vacation are doing so as a way to covertly pressure their employees to not take vacation; even if it might be having that effect unintentionally. Or maybe some are, but I can give most of them the benefit of the doubt.

I still have this nagging feeling in the back of my head that the eventual makeup of businesses is a sea of 1099's, self-organizing around particular projects and then dissolving at the project's conclusion. People seem to have way too adversarial a view of employers for this not to seem like the future.

m0nastic··on Larry Ellison Still No. 1, and Doing What He Wants
I love the fact that I live in a world where Larry Ellison is a real person, even if it's only to serve as a cautionary tale.
m0nastic··on Practical Cryptography With Go
Breaking crypto systems isn't the same as breaking "into" systems.

The history of cryptography can basically be described as a series of assumptions which turn out to be invalid. This is either because they were never valid to begin with (and it just took time for problems to be discovered and shaken out), or because the facts on the ground change, making them invalid.

I'm not a cryptographer. I also don't really call myself a hacker anymore (because the loaded assumptions around that word make it useless as a descriptor, you wind up having to explain it in so much detail that it's just easier to start out with a different word), but I do know some cryptographers. They have all described the process in a similar way, which is you start by learning about the pitfalls of everything that's come before you.

Much like if you were learning to build bridges, you'd spend time learning about past bridges that didn't hold up.

So you start with the oldest crypto systems, and learn why those fell out of fashion. One nice benefit to this approach is that it makes it fairly apparent how brittle these constructions are. I don't think I've ever met a cryptographer who isn't suitably hesitant about designing cryptographic systems. Also, a good portion of the time spent as a cryptographer (maybe most of it? I'd love to hear a dissenting view from an actual cryptographer), is in breaking cryptographic systems (initially other people's, and than later, your own).

Cryptography isn't like web frameworks in the sense that everyone is making their own. New crypto systems (at least ones that come from cryptographers) don't spring up out of the ether every week.

One problem that seems to come up in cryptography is that cryptographers themselves "seem" to be mostly only concerned with the primitives. They leave implementation as "an exercise to the reader". This is a problem because I'd say that the overwhelming majority of actual security problems that stem from cryptography aren't problems with the primitives. They're problems with the construction necessary to do anything useful with those primitives. That's why when people heed advice like "Use AES" they're probably screwed.

m0nastic··on NSA Said to Exploit Heartbleed Bug for Intelligence for Years
There seems to be a lot of confusion about what the job of the NSA is, with this most recent Heartbleed incident being the most recent example.

The NSA's primary function is performing signals intelligence. To perform that function, they've spent the past ~60 years building up cryptanalytic capability (pretty much unmatched by any other single organization either governmental or private).

Because of this, they have a secondary function, which is to serve as subject-matter-experts for other government agencies. They provide advice, mainly in the form of influencing NIST standards (overtly by providing recommendations, and as we've come to learn, covertly by fucking with standards). This is a side-effect of their primary function however.

Asimov's first law of the NSA is to intercept and process signals intelligence. Any other function is secondary, and certainly will not take precedence over their first function.

What the Snowden revelations have shown, is that there's a conflict of interest between their primary function and being tasked with providing advice. I think it's a reasonable argument to be had that they probably should get out of the business of providing guidance to other agencies, as now all that advice is tainted.

The security of "US-based companies" is so far down the list of priorities that I hesitate to suggest it exists at all. Reporting vulnerabilities to vendors is at best orthogonal to their primary function, and at worst, counter to it. If you want to argue that someone in the government should be responsible for helping companies fix security issues, that's also a good argument. But it certainly shouldn't be the NSA (and definitely not now that we know they have no compulsion about misleading everyone).

I'm going to ignore your side-note about JS browser-based crypto. Unlike the people on here who diligently try to explain the fundamental issues with doing JS-crypto, I'm now of the opinion that you can't reason with these people.

m0nastic··on CryptoCat iOS Application Penetration Test [pdf]
It's important to distinguish that the places offering the <10k rubber stamps aren't really offering the same service (even if you concede that it's only for compliance).

Places like that are just running a scanner against your website. In the case of an app like this (which was an iOS app), you might find a cheap place to run it through a source code analyzer (either through a cloud-hosted service like Veracode, or by running an app like AppScan).

Assuming you wanted to hire a "respectable" firm to actually perform a real application assessment, I'd say it's closer to 30-50k.

If you look at the report, it was scoped at 3 man-weeks of testing (which in this case looks like it was 3 engineers for 1 week). Even if you don't include any additional overhead (like hours for the report generation, or project management hours), you're looking at ~24k just for the engineers effort (if they just priced it t&m, which hopefully they don't).

To be fair, this is a pretty exotic application though, compared to what a lot of other people might be working on. The scope for a project to test a more "normal" app would be less. Maybe even half that.

m0nastic··on Analysis vs Algebra predicts eating corn? (2010)
Here's the comments from last time this article was posted:

https://news.ycombinator.com/item?id=4368858

(I'm not saying it shouldn't be posted again, I just thought people might want to see the prior discussion)

m0nastic··on The value of an engineering degree
It might be more "specialty-related" than geographically-related. I work in the same field as Thomas (security), am from Boston, and have had largely the same experience as him about degrees.

I've also built security practices for three organizations, and can attest that not only is education not a positive hiring factor, it's at best neutral.

← PreviousPage 2 of 25Next →