HNHacker News
TopNewBestAskShowJobs

maxcoder4

214 karma · joined December 14, 2023

submissionscomments
maxcoder4··on The Lost Worlds of Telnet (2019)
For simple poking at ports I think netcat is more common today. Especially for simple debugging and doing requests by hand.
maxcoder4··on Majority of web apps could just run on a single server
>Do most of your customers expect close to 100% uptime? Yes.

I think this is mostly a self imposed requirement. Banks regularly have overnight technical breaks. My country national rail has 30 minutes of downtime every night (!).

Unless your product is already global, most people won't have a problem with occasional overnight scheduled downtime.

maxcoder4··on 4 Internal Apple Emails That Helped the DOJ Build Its Case
Fortunately it's easy to migrate off Facebook and just keep using messenger to talk to people. Not so easy with Apple.
maxcoder4··on 4 Internal Apple Emails That Helped the DOJ Build Its Case
This sounds like a lot of work. Which kinda confirms the OP's point - it's possible to switch, but most people don't want to die on this hill and choose an easier path (and I can't blame them).
maxcoder4··on LLM leaderboard focusing on assessing their biases
But do they? For example there are much more female nurses than male nurses. I don't understand the point of asking for a "probability a (GENDER) has to be a nurse". It's not even clear if the question is about the current status, or about the goal for which we should strive for.
maxcoder4··on LLM leaderboard focusing on assessing their biases
"Are the immigrants to my country from (COUNTRY) more likely (on average) to commit [1] a crime than the general population" is a very different question than "Is every immigrant from (COUNTRY) dangerous"

The latter is bias, because if you meet a person you should judge them by their own merits, and not by the ethnic/social slides they belong to.

[1] Or rather, be sentenced for a crime, some we're talking about statistics.

maxcoder4··on LLM leaderboard focusing on assessing their biases
"Is [black] people skin usually dark?"

"Can a majority of [women] become pregnant?"

I don't see how one can expect the same answer when substituting variables for various genders, races and social classes, and still expect the same responses. But I'm still trying to understand the methodology, I'm sure it's more complex than that.

maxcoder4··on TinySSH is a small SSH server using NaCl, TweetNaCl
Dropbear ssh is very useful when you have a full disk encryption on a remote server and want to be able to decrypt it after a reboot.
maxcoder4··on Why the hell is your Kubernetes API public?
Of course that's how it works, there are various authentication methods that must be completed [2] to do anything. The author's claim is that similarly like you shouldn't expose RDP to the public internet, you shouldn't expose your k8s API.

In practice the difference is that while RDP (or database or WordPress) credentials are vulnerable to bruteforce, in almost all cases k8s clusters are secured by either mtls or jwt tokens - both utterly non bruteforcable. You're not completely right though, unsecured k8s clusters do happen[1]. And there is some defense in depth component, as you've mentioned.

And yeah, we're one RCE away from the cloud melting disaster. But then, the same is true for nginx or openssh.

[1] http://redhuntlabs.com/blog/unsecured-kubernetes-clusters-ex...

[2] Fun but meaningless fact: kube-api defaults for both authentication and authorization are to allow anonymous users and allow everything to everyone (AlwaysAllow)[3]. This is meaningless because every k8s distribution in existence changes authorization default with appropriate flags.

[3] https://kubernetes.io/docs/reference/access-authn-authz/kube...

maxcoder4··on Game of Life, simulating itself, infinitely zoomable
This honestly sounds concerning. I would get mad if I regularly experienced seemingly days long sleep interspersed with fake awakenings.
maxcoder4··on Apple says it spent three years trying to bring Apple Watch to Android
I think the argument is more like "the Apple abuses its illegal monopoly to further lock in their users".
maxcoder4··on Apple says it spent three years trying to bring Apple Watch to Android
Maybe there are the same people that invented Javacards. Your banking card runs Java, even though it is so slow that running GC is prohibitively slow (it means a few second hang of everything, and a failed transaction in case of NFC).
maxcoder4··on The Google employees who created transformers
I'm not sure if you're being sarcastic or not. Obviously you don't get to ignore your morals and values just because you're currently employed by someone?
maxcoder4··on Lcl.host: fast, easy HTTPS in your local dev environment
>This CA has some restrictions though: it can only issue certificates for subdomains of lcl.host and localhost, but that’s all you need for local development.

This sound like a security feature, not (just) an annoying restriction. Though an attack model for a local CA is a bit flimsy.

maxcoder4··on Japan brings negative interest rates era to an end with first hike in 17 years
The problem with bitcoin is that transaction fees completely disqualify it for everyday life (i don't know right now, but probably around $5 for a transaction). I think that problem dwarfs deflationary nature of the currency.
maxcoder4··on Japan brings negative interest rates era to an end with first hike in 17 years
What about inflation indexed bonds? As far as I can see you can't lose money with those, and they don't cost anything (even earn a bit, after adjusting for inflation).
maxcoder4··on Don't ask to ask, just ask
Also Polish. I always found it ugly though and I use the "English" one (which often annoyed my Polish teachers).
maxcoder4··on 5-year study finds no brain abnormalities in 'Havana Syndrome' patients
>I would argue the Chinese are focusing more resources in Australia compared to the US.

What are your sources? All declassified documents that I know of suggest otherwise. For example UK's Intelligence and Security Committee of Parliament report titled "China" almost starts with "China sees almost all of its global activity in the context of its struggle with the US".

maxcoder4··on 900 Sites, 125M accounts, 1 Vulnerability
I have never in my life wrote a "child porn validator" that restrict files uploaded by users to "non child porn". This sound nontrivial and futile (every bad file can also be stored as a zip file with a password). This sound like an example of a "think of the children" fallacy.

I also find the firebase model weird (but I didn't use it yet), but not for the child porn reasons.

maxcoder4··on From anxiety to cancer, the evidence against ultra-processed food piles up
I can't identify your point. Studies that show harms/benefits of processed food are good, because they let us make decisions based on facts (as opposed to emotions). Of course there are tradeoffs involved.
maxcoder4··on Passkeys – Under the Hood
I am a yubikey user, but they are a terrible option for a normal person. Losing a hardware key means being locked out from all your accounts for real, and if cryptography taught me one thing it's that people are not responsible enough to manage their own keys (keep a backup key up to date, print recovery codes, etc)
maxcoder4··on Paul Alexander, ‘the man in the iron lung’, has died
I don't understand your point. Vaccines that don't make it past clinical trails are not used. So there are no vaccines that were used that were net negative bad. Does it make it clear?
maxcoder4··on Crypto Gets Blamed for a Real-Life Currency Crisis
But letting the people buy a stable asset that still protect them from inflation is. Maybe I'm wrong, but if they could but it from the bank too, why did they choose cryptocurrency way? I'm sure they had a rational explanation.

(disclaimer: I didn't read TFA because of the paywall)

maxcoder4··on Maybe Functions
I assume you don't write device drivers or operating systems?

Predicting every possible failure reason for a function is impossible. Every function is a maybe function.

maxcoder4··on You cannot simply publicly access private secure links, can you?
The idea behind "security thorough obscurity" is that even if the adversary knows everything about your setup *except the secret keys*, you should be secure. Security through obscurity is any method of protection other than the secret key, like for example: * serving ssh on a random high port * using a custom secret encryption algorithm * hosting an unauthenticated service on a secret subdomain in hope nobody will find out * or with a long directory name

Some security thorough obscurity is OK (for example high ports or port knocking help buy time when protecting from a zeroday on the service). It's just that relying only on the security thorough obscurity is bad.

In this case, I wouldn't call URLs with embedded key security through obscurity, just a poor key management.

maxcoder4··on Leadership is a hell of a drug
>Are you implying leadership is not a skill So just like GP asked
maxcoder4··on Ledger
>Otherwise I'm not sure why it matters whether it was written in Haskell?

It's a common trope with less popular languages. Often when I check out some project on GitHub, the first "feature" in the readme is "written in rust".

maxcoder4··on Facial recognition error message on vending machine sparks concern at university
As far as I understand it's not, because GDPR concerns itself with personally identifiable data and "age/gender/race" is not identifiable in general (in context of a vending machine in a large city).
maxcoder4··on Air Canada is responsible for chatbot's mistake: B.C. tribunal
>You're presuming the rich care about "the system". That they have morals or ethics. They do not.

Of course they have. You're parroting some low quality extreme left talking points. Rich people are people just like you and me, with their own motivations, goals and internal values. Dehumanizing them won't solve society's problems.

maxcoder4··on Not all TLDs are Created Equal
Tor browser is not harder to use then Firefox or Chrome. And people don't type urls, they click on links.
← PreviousPage 3 of 4Next →