HNHacker News
TopNewBestAskShowJobs

mdb31

484 karma · joined May 12, 2012

submissionscomments
mdb31··on GitHub will require 2FA by the end of 2023
> There is no sync to provider servers on any TOTP implementation I use

That's hard to dispute, but will you accept https://guide.duo.com/duo-restore as a counterexample?

> Are you perhaps referring to the Google Authenticator or the Microsoft Authenticator apps when you refer to TOTP

No, I'm referring to the actual RFC 6283 TOTP protocol. Which uses a trivially-cloned single private key. Which is, see the example above, in fact trivially cloned 'for convenience' by at least one widely-used 'enterprise' security solution.

> What makes you think they don't "securely" make a few duplicates themselves?

Since that literally makes no sense if you know how hardware tokens work.

mdb31··on GitHub will require 2FA by the end of 2023
> Since when is TOTP obsolete?

Since about the moment that teams all over the world discovered they could just paste the enrollment QR code (a.k.a. private key) into their wikis, and thereby continue unlimited sharing of their role accounts?

So, I guess 30 seconds after its introduction?

mdb31··on GitHub will require 2FA by the end of 2023
The TOTP "private key" can be easily cloned. Targeted malware, a database compromise at your app provider that you "securely" sync your settings to, or just a few minutes access to your "authentication" device, will do the trick.
mdb31··on GitHub will require 2FA by the end of 2023
Yet, if you go into the "enable 2FA" settings on Github, you only get the option to enable insecure TOTP or SMS.

Apparently, once you do that, you might be able to add proper authentication. But no word on whether that then replaces the obsolete methods you were forced to configure earlier.

But, yes, right on track to enforce 2FA in 2023, I see...

mdb31··on GitHub will require 2FA by the end of 2023
Oh, that's lovely UX... "After you configure 2FA, using a time-based one-time password (TOTP) mobile app, or via text message, you can add a security key"

So, after you enable a broken-by-design 1.5FA method, which you don't want, and which will further expose you to account takeovers, you can, possibly configure actual security.

No wonder these guys are raking in the big bucks...

mdb31··on Please stop disabling zoom
I'm still confused. So, can you zoom any site on Safari on iOS or not? And if you can't, what definition of 'control' is that, again?
mdb31··on GitHub will require 2FA by the end of 2023
Well, given that Github today doesn't seem to support meaningful 2FA (only TOTP and SMS), wouldn't it be good to fix that issue before starting to talk about requirements like these?

Maybe it's just my account, but I can't currently enroll my hardware token with Github in any way whatsoever.

Sure, they offer some 1.5FA, but why would I bother with that?

mdb31··on Please stop disabling zoom
I've never experienced any zoom problems (as opposed to Zoom problems...), and I just had a look at all the sites mentioned in TFA.

In all cases, I can zoom all elements (text, images, the works) just fine, up to 500%.

Firefox 100 on Windows. Is this just another one of those "Safari on IOS is broken, so the Web is broken" things, or is there more to it?

mdb31··on Preventing Burnout: A Manager's Toolkit
@john_cogs: Are there any plans to connect a self-assessment of mental state to the assignment of issues/pings about mentions/incident-response pages in the GitLab app?

So, on "I'm on top of the world" days, I get assigned All The Issues, get a full-screen popup about each mention, and will be asked to be incident lead on just about anything.

Then, if my state is "slightly hungover", I mostly get a list of the most pressing issues still pending, without being overloaded with new stuff.

And finally, the "hugging my teddy bear" state: no additional automated workloads, respectful notifications to anyone pinging me, and a note to my manager if it lasts more than a few days?

mdb31··on Preventing Burnout: A Manager's Toolkit
Short-and-easy read that contains much truth. Especially item #10, "Lead by example" which encourages managerial review of recurring meetings (which often boil down to "well, here is my Excel sheet, you tell me how you're doing on each line item: I'll let you talk a lot, but I'll only jot down the completion percentage in the end") is worth emphasizing.
mdb31··on US plans campaign to attract Russian scientists, engineers to America & CERN
Well, the race to attract the outflow of the current Russian 'brain drain' is definitely on.

If the US is able to attract the majority of that (as it most likely will), while keeping out the Putin-aligned plants and/or otherwise mentally deficient factions (which remains to be seen), that will definitely be huge gain for them.

mdb31··on Jump Trading sues 79-year-old Carl Sagan fan over wormhole.com domain
Well, I'm pretty sure you can't even directly sue over ownership of a .com domain? You have to submit to UDNP arbitrage first (https://www.icann.org/resources/pages/help/dndr/udrp-en).

It doesn't seem they even tried this in this case? So this should be a dismissal right away, albeit at great emotional/monetary expense to the original owner. Unfair, but yeah, cryptobros will be cryptobros, and any harm to members of society is just for the good of society, I'm sure...

(Later edit: so, apparently I'm wrong, and there is no binding arbitration clause. Still, lame action, and this seems the exact situation arbitration is designed for, especially since 'local courts' is not exactly well-defined for .com...)

mdb31··on How to professionally say
Nope, people communicate like that internally as well, because "that's what's professional"

In some cases, you can fix this by asking the sender to be, like, normal. This works half the time, the other half involves referrals to HR...

mdb31··on How to professionally say
Nope, not a caricature. Read, for example https://www.atlassian.com/engineering/post-incident-review-a...

This is held up as a great example of transparent communication. For me, this is true, but only for the meaning of 'transparent' which equates to 'you can see right through it, to the extent there is effectively nothing there'.

But as per the article this comment thread is about, this kind of response apparently the 'professional' state-of-the-art.

Yes, I despair too...

mdb31··on How to professionally say
Ah, yes, the same kind of guide that brought us "how to professionally respond to outages"... With classics like "We recognize the incident", "a small subset of customers", "degraded performance" and "the next update (which will be the exact same meaningless drivel as the current 'update') will be in 60 minutes". Don't we just love those? So let's add more of that to the shared vocabulary of IT professionals!

Or... let's just not? In writing, always avoid clichés. Whether it's "do the needful", "by utilizing" or "we did not live up to our customer's expectations", there is one simple rule: if you've seen the exact same sentence or expression before in the exact same context in the last week or so, you should probably avoid it.

And if that makes you unsure what exactly to say, just type what you mean, then get an editor before posting it to your blog or incident report. And if it's time-sensitive, then just ask for forgiveness later, not permission upfront (which is also a cliché but reworded, see what I did there?)

mdb31··on Removing characters from strings faster with AVX-512
> vector instructions are fundamentally necessary

For which percentage of users?

> AMD is actually adding AVX-512

Which is irrelevant to in-market support for that instruction set.

mdb31··on Removing characters from strings faster with AVX-512
Where do I say that the speedup is surprising?

My question is whether Intel investing in AVX-512 is wise, given that: -Most existing code is not aware of AVX anyway; -Developers are especially wary of AVX-512, since they expect it to be discontinued soon.

Consequently, wouldn't Intel be better off by using the silicon dedicated to AVX-512 to speed up instruction patterns that are actually used?

mdb31··on Removing characters from strings faster with AVX-512
Cool performance enhancement, with an accompanying implementation in a real-world library (https://github.com/lemire/despacer).

Still, what does it signal that vector extensions are required to get better string performance on x86? Wouldn't it be better if Intel invested their AVX transistor budget into simply making existing REPB prefixes a lot faster?

mdb31··on Ask HN: Why can't I host my own email?
I've hosted my own email since, at least 1993 (that's on the Internet: I was on UUCP at least some years prior to that).

If you have a static IPv4 in a range that is not actively hostile, and you have proper SFF/DMARC records, things should generally work out?

And otherwise, services like https://www.mailchannels.com/ should help? (Still, you will need proper SPF records.)

I've literally had a 95+% delivery rate from users in actual Lagos Nigeria using the strategy outlined above.

mdb31··on Remote Code Execution via VirusTotal Platform
Tired: exploiting antivirus software for those sw33t 0days.

Wired: exploiting the gatekeeper of antivirus software quality for the lulz.

mdb31··on Commit Level Vulnerability Dataset (For Android)
This is actually very cool: a dataset of 3900 CVEs, with a matching fixing commit for 1359 of them.

So, lots of opportunity to find a big payout w/r/t the unfixed CVEs. Whether successful or not, those attempts will definitely strengthen the ecosystem.

And possibly even shame Google into providing cross-vendor Android security fixes... (note to the uninitiated: this is heavy sarcasm, will never happen, etc. etc.)

mdb31··on No, you can’t save £30 per year by switching off your “standby” devices
Yeah, this particular myth is common in many EU countries as well. Apart from the minimal amount reportedly saved (30 GBP per annum in real currency is 37 EUR/USD per year, less than 10 cents a day), it does not seem to be particularly true.

I measured this (at the wall socket) over the years, and my findings are below.

For battery-powered devices, disconnecting the charger once the battery is full does nothing, other than to cause the battery to be discharged more rapidly than it would be otherwise. For battery health, it's best (if possible) to set a 'start recharging' threshold at 90% or so, but that's mostly a device-lifetime issue, not a power consumption issue.

For 'mains-powered' devices with a 'soft power-off', like many modern coffee machines, microwaves, etc. etc., the power draw in 'idle' mode is truly insignificant. You may have an atypical (broken?) device, but other than avoiding some transistor whine, you truly don't gain anything by powering these off. For devices like printers, monitors and TVs, I've never seen any 'idle' power consumption that was even noticeable.

Some 'always-on' devices do have significant power requirements. Like: your set-top box (since it needs to records the programs you scheduled), your modem and/or media converter, and your fridge. With these: it's always measure, inquire and replace as needed/possible.

For me, my fridge is as efficient as it gets, the fiber-to-Ethernet box from my ISP draws minimal power anyway and my Mikrotik router and APs are pretty power-efficient as well (like, 4 hours runtime on a tiny UPS). The rest goes mostly to my heat pump (which also powers my boiler), and in the summer months, this always offset by my solar panels, unless cooling requirements get way out of hand.

mdb31··on A satirical app that draws attention to problems with AI-powered correction
This seems to take on recent Google developments. Now, for good measure, I would like to see something that perverts GitHub Copilot to a similar extent...
mdb31··on Low-Latency, High-Throughput Garbage Collection [pdf]
Most interesting observation here: Short GC pauses do not assure low latency.

Anyway: this paper is mostly about Java, which I rarely use and basically only known from Elasticsearch (where log entries about GC pretty much always seem to indicate 'add more memory'...), but I've never run into any scenarios where .NET CLR GC was a performance issue either (not on the legacy .NET Framework nor in more recent releases, which are a lot better in most performance aspects).

Most GC complaints from the .NET world seem to be from game developers using Unity. Which mostly tells me that there should be a way to have a 'this is the rendering thread, never pause this for GC, unless I really do bad stuff' in Unity...

mdb31··on Show HN: Badkeys.info – checking cryptographic keys for known vulnerabilities
Cool idea, bad implementation.

This really needs to be a local tool: uploading any kind of key material to a remote site is a privacy risk, and the disclaimer that "uploading private keys is obviously discouraged" is not sufficient, as anyone that has every dealt with 'users' will attest...

mdb31··on Show HN: I Made a Magic Trick
I guess this is supposed to be some Jabbascript trickery, but for me, a 'paste' action in the second text field just yields... blankness...

Which is a pretty good trick, I have to admit, exposing the nothingness of life. Kudos!

mdb31··on My upgrade to 25 Gbit/s Fiber To The Home
Without drowning in fan noise? This world... Sure, I guess you can get a Mac Studio, or some other 'workstation' class PC, but your switch will still need to be within a few meters of that endpoint, and it's not going to be very green nor silent.

2.5Gb/s can easily be done with a lot of laptops and workstations these days; 10 Gb/s isn't quite there yet (and 25, 40 and 100Gb/s are definitely in the server-only fiber-or-DAC-only realm)

mdb31··on EULAs Aren’t Inherently Evil – Proprietary done right can beat free and open
No, it's not like that at all. My original point was that most end-users don't care about the license. Implied was that most end-users determine the state of the market, but whatever.

So, here I am, 4 downvotes to my name for stating the obvious. Despite years of membership, I don't have downvote privileges, so I guess I just have to bow to the galaxy-sized minds that have this ability, and deal with the crumbs that do leave a reply, however utterly misguided?

mdb31··on My upgrade to 25 Gbit/s Fiber To The Home
25Gb/s is just overkill for residential use. It's really cool that's it's available, but I fail to see a use case over my 500Mb/s home connection. Even for the servers that I manage and that are bandwidth-heavy, 10Gb/s is way overprovisioned for now.

WiFi goes up to 1Gb/s, if you're lucky. Sure, some WiFi-6 APs have a 2.5Gb/s connector, but that's not what you want or need, unless you're a high-density enterprise. WiFi-6E will possibly improve that a bit, but it will take WiFi-8 to get anywhere close to saturation.

Wired, you can do 10Gb/s for server systems, which are, amongst other things very loud and not very suitable for placement anywhere near humans. 2.5Gb/s support is spotty, and 1Gb/s still the only thing that works reliably.

So, exactly which residential application requires 25Gb/s is not very clear. Yes, it's cool, but not very useful, and faulting manufacturers (especially in times of crippling supply-chain limitations) for not fully supporting it is questionable.

mdb31··on EULAs Aren’t Inherently Evil – Proprietary done right can beat free and open
My take: end-users don't care very much about the license, and even for technical users, the value of an 'open' license is overstated. I simply cannot fix bugs in, say, GCC, and it would also be pretty hard for me to pay someone to do so, despite this project being pretty much the poster child (other than, of course, Linux, but that is not exactly a typical case...) for the GPL.

Corporate users want a way out of an abusive or impossible vendor relationship: source escrow can fix that as well as the GPL can (which is to say: not exactly entirely, but, close, I guess?).

Regular users want... things just to work, and someone to shout at if it doesn't. The license of the underlying source code is pretty much irrelevant for that. There are at least three levels of support/indirection prior to that making any difference.

Page 1 of 4Next →