HNHacker News
TopNewBestAskShowJobs

mdisraeli

653 karma · joined May 17, 2010

Michelle D'israeli: Feminist Hacker based in the Midlands, UK, working in Security and Service Management

@mdisraeli on twitter, for everything else there's Google ;)

The usual disclaimer: Anything I write is my own personal opinion and may not reflect that of my employers past, present or future, etc

submissionscomments
mdisraeli··on Show HN: Transmissions over time-based side channels across a network
Neat little experiment! Delays between packets are not normally logged, so detecting this would be a challenge - any ideas of the best way to detect this sort of channel?

Interesting side note: If I recall correctly, a variant of this can be used to de-anonymise Tor connections if you have visibility over the entry and exit connections. Measure time and size relationships between packets and look for corresponding matching ones at the other end. Not 100% accurate, but with lots of connections it builds in confidence.

mdisraeli··on The Real Mayors of 'SimCity'
Something similar was done by journalists for the UK 2015 General Election. They took Democracy 3, an indie game with a very complex neural net simulation, and attempted to find out how the various main parties' policies held up: http://www.newstatesman.com/writers/116017
mdisraeli··on As a math professor, how can I help grad students find nonacademic jobs?
Get in touch with your previous students, both those in academia, and those in industry.

If they're in academia, ask about their industry connections. If they're in industry, ask if they can help you. If you can't get direct contacts, at least find out what skills and knowledge is being looked for, and what options exist.

It's very easy to forget the power of an 'alumni' network. Who we know is often our greatest asset.

mdisraeli··on Why I killed my standing desk
If you are finding it difficult to stand for extended periods, consider getting your feet checked, and if you have already, using your prescribed orthotics (insoles/shoes/other supports) whilst standing.

When I come home, I routinely take my outdoor shoes off. I spent most of my time at home sitting at my desk, but last year I began to learn bass guitar. I found that standing to play for less than an hour was enough to wipe me out for the entire evening, with knock-on exhaustion until the next day.

I have pes cavovarus - a deformity of the feet characterised by high arches and inward turned heels. When I finally got orthotics and placed them into my outdoor shoes, walking suddenly became easier and instances of debilitating cramp reduced in frequency and severity.

Following my experiences with playing my bass, I placed a spare pair of orthotic insoles into my slippers. This was not something my medical team had suggested previously. Suddenly I found it less exhausting to stand for extended periods. The change was actually quite immediate and significant.

Flat arches are far more common than what I have, but I suspect the same concept still applies - and orthotics for flat arches are far more widely available to consumers!

mdisraeli··on Ask HN: Anyone familiar with Namecheap's JavaScript bot detection method?
I thought that was probably what you were doing, and it's a good check - one of the ones I tend to do myself when investigating strange things!

Just thought I'd add for other readers some security industry commentary :)

mdisraeli··on Ask HN: Anyone familiar with Namecheap's JavaScript bot detection method?
The Google results start with things like VirusTotal, which has several scannners which declares the gif as being a malicious site.

The gif itself is almost certainly not malicious. There's probably two things happening here. Firstly, the hosting domain of the gif scanned could be known to be malicious. And secondly and more generally, Cloudflare is heavily used by the criminal scene, so to play safe a number of scanners may flag any cloudflare element as malicious.

mdisraeli··on My Girlfriend Dissociated and Forgot Who I Was
For the record, I'm completely in agreement with "feature, not a bug". For myself and many people I know, mental health stuff makes more sense when looked at like that, and it also matches up with core concepts of Cogitative Behavioural Therapy. At some point your brain needed certain bits of code to survive, but unfortunately the brain can't be cleanly patched once those times have passed (which is also an awful analogy, but works enough for this).
mdisraeli··on My Girlfriend Dissociated and Forgot Who I Was
It is often difficult to get a diagnosis of PTSD when you've not been at war or subjected to a singular catastrophic event. And even if you did, there may not exist treatment pathways for those with PTSD from more complex or long lasting situations :(
mdisraeli··on My Girlfriend Dissociated and Forgot Who I Was
And on a far more simple level, disassociating and returning from it is utterly terrifying, and worse still one might know that their loved ones will have also had a very difficult experience
mdisraeli··on My Girlfriend Dissociated and Forgot Who I Was
Disassociating doesn't always work like played out in films or TV, sadly. It's terrifying, and often find it hard to trust what's in front of you. Familiarity is needed, as it acts to ground you, and a key part of this is to feel safe on a number of different levels. Simply having photos alone may not be enough, unless those photos are something you regularly examine and experience.

Grounding is a common method of dealing with anxiety and other mental health issues. The idea of finding your place, finding familiarity, centring yourself. Something you are very used to doing normally and when safe is important, as is having that also associated very strongly with being safe.

For some people, photos will work well for this - they might capture moments with strong association with safety and happiness. Some people may be able to instead use an object, a talisman of sorts.

For others, or for when the disassociation is worse, a single grounding method may not be enough. It's about building the complete story - getting home and watching something familiar. The grounding only happens from weight of evidence.

Finally, there's something you don't hear talked about much. Coming back around from disassociating can be utterly terrifying in it's own right. Both as one tries to return, and after coming back. Having multiple entirely different means to ground helps with this.

mdisraeli··on Leonard Nimoy, Spock of ‘Star Trek,’ Dies at 83
Glad it wasn't just me!
mdisraeli··on Leonard Nimoy, Spock of ‘Star Trek,’ Dies at 83
Leonard Nimoy gave many of us a role model to look up to, and his work inspired many future works of fiction that inspired even more.

How many of us were called "Spock" by bullies, but actually found comfort in knowing that Spock was six shades of badass?

mdisraeli··on Flow Hive: Honey on Tap Directly from Your Beehive
Anything where you can turn a batch job into a constant stream is going to be of major appeal to large scale industrial production. Pretty much a perfect example of a disruptive invention!

Looking for how industrial manufacture of honey works, I found this video: https://www.youtube.com/watch?v=ctIqmhTo7E4

This method would do away with uncapping 'super' frames and centrifuging them. You could just plumb in the frames, and add control motors to rotate which frame is released.

As others have pointed out, however, there are risks to this method. It does make over-harvest more likely, and could lead to fewer inspections of the bees for parasites and other issues. This is where industrial scale operations actually would cope very well - the entire system turns into chemical engineering, leaving bee keepers to focus on the (productive) welfare of the bees. It could even allow for integrated analysis of the honey, opening up greater control and closer control of harvest levels.

mdisraeli··on The Ghost in the MP3
Neat, thanks for running the experiment to see how differing MP3 encoder settings affect the lost portion. This explains why 320kbps is generally accepted amongst DJs, as any loss is significantly less than that caused by the club sound system :P
mdisraeli··on The Ghost in the MP3
If you can't hear it, was it ever information?
mdisraeli··on The Ghost in the MP3
320kbps with highest quality setting is pretty much an industry standard now, and many DJs, myself included, make use of that.

As you've looked into this before, do you know what the similar difference is like for such professional-grade encoding?

mdisraeli··on The Ghost in the MP3
That would explain the phasing/flanging like sound which gives the ghost recording such an eerie feel
mdisraeli··on The shipping network that keeps the world running
At EMF Camp last summer, Dan W gave a great talk about his similar Unknown Fields trip on a container ship. This by far was one of the highlights of the event, as it was extremely insightful into this hidden world. You can watch the talk at http://www.iamdanw.com/said/emfcamp/

Dan is now writing up the journey, you can follow his tales at http://www.iamdanw.com/postcards/

mdisraeli··on Twitter CEO: 'We suck at dealing with abuse'
I get your overall point, but in turn you've overlooked the Relationship layer - basic compassion means that the victim gets to make the call as to if something hurt them.

If someone is stabbed, do you require empirical measurements of their injury before you accept their pain?

mdisraeli··on The Horrible Implications of the EU VAT “Place of Supply” Change
Can anyone give any insight to the impact of these changes to businesses in EU countries other than the UK?
mdisraeli··on Sexism Isn't Simple (2013)
Thanks for the additional context, both for the importance of the repost, and in general regarding this incident.

As a woman working in tech, I was understandably very upset about the whole affair. I'm very much glad that actual outreach happened behind the scenes, and learning of this makes me feel safe to be part of certain communities again.

mdisraeli··on “I don’t think Wikipedia can be saved at this point, but I might be wrong.”
It should be noted that the link is to a supplemental, providing running updates on the response to Mark's series of articles:

Infamous http://markbernstein.org/Jan15/Infamous.html Thoughtless http://markbernstein.org/Jan15/Thoughtless.html Careless http://markbernstein.org/Jan15/Careless.html

As such, it will be hard to read, appearing like a rant when taken on its own. A better place to start will be with the above articles, which provide context for the Reckless post.

mdisraeli··on How My Mom Got Hacked
Polymorphism typically referred to worms and viruses that changed their own code base as they spread. Most infections, however, happen from phishing emails either with attachments or linking to the payload. Changing the files produced so as to no longer be caught by antivirus signatures is trivial, and you can even create a unique variant for each phish.

Many legitimate programs will seem to act similarly - opening files and overwriting contents with something else. ID3 tag writers for MP3s, file type converters, batch image processing, etc. This means you can't match easily against the types of actions being taken.

Let's imagine, however, that the antivirus was still able to detect that something odd was happening. If it prompts the user, they will inevitably click 'yes run this file', because that's what they have always done. If it quarantines the file... well, you just add another few lines to the phishing email saying that the attachment is perfectly safe ("scanned by symantec" apparently...) and to go ahead and bring it back out from quarantine

mdisraeli··on Over 30 vulnerabilities found in Google App Engine
Worth noting that us in the Security industry are regularly seeing malware using Google's cloud services as command and control systems for their botnets (at least in terms of the IP addresses seen).
mdisraeli··on Hard disk hacking
Worth noting that it is quite common these days for USB flash drives to be nothing more under the shell than a SD card with a USB adapter
mdisraeli··on MS14-068 Kerberos vulnerability: A simple overview
FYI: I've yet to set up cloudflare's free service, I will look into this when I get home from the office - until then, apologies for the dire performance
mdisraeli··on Ask HN: Would you pay for honeypot logs?
I work within the security operations team of a major global service company, working with private businesses, local, regional and civil government.

Our main pain point is never information - we can get that in spades. Our pet Unix engineer is constantly finding interesting new feeds for us, and I spend a notable amount of time each week keeping up to date with latest developments and any new information sources that crop up.

The challenge is translating this information into sound, actionable, intelligence that measurably provides value to our business and customers. Raw logs of random honeypots are of no interest to us, and if we wanted such a thing we could roll our own relatively easily.

Honeypots based outside of our organization would only be of interest in a few limited scenarios: Firstly, when a major new vulnerability lands it would be invaluable to know right from the start what sort of attacks are being seen in the wild. Ideally it would also be able to look back in time and discover if this zero-day being exploited prior to the vulnerability. Secondly, what we couldn't do is set up honeypots in multiple different sectors and compare attack profiles - eg, between a hospitality company and say a local council.

In both those cases though, what we would want is the results of the analysis and expert recommendations, not the raw logs.

As others have already suggested, what we would be very interested in is honeypots-as-a-service: Being able to drop a fake finance server into our estate and detect access attempts. Create a fake company division website and see who tries to attack it and how. Be alerted to targeted attacks before they actually entire the production estate.

Something I'm fond of saying is that whenever an investigation or assessment is performed, what actually earns you the money is the report at the end. That report and the actionable intelligence within is your product, not the tool you use to generate it.

mdisraeli··on Music Theory for Musicians and Normal People
I recall once seeing a link on HN for music theory for physicists and engineers, but I didn't bookmark the URI at the time - anyone recall this, and how to find it?
mdisraeli··on if (osName.startsWith("windows 9"))
Readers of Raymon Chen's blog The Old New Thing may be familiar with exactly this sort of thing, which forced windows 95 to have the version number 3.95, instead of 4.0 [http://blogs.msdn.com/b/oldnewthing/archive/2004/02/13/72476...].

Making the libraries cope with bad programming is not good practice, but it is what keeps businesses using your software for decades. The Old New Thing really should be standard reading, because this sort of thing is barely the tip of the iceberg.

Other similar API avoidances that Microsoft have found programmers using to check things include obscure undocumented registry keys, API implementation bugs (seriously!), the padding data in tangentially related structures returned by API calls, and more

mdisraeli··on India’s Answer to Google Glass: The Smartshoe
On a similar note, check out Northpaw, a project to help people develop a sense of north - http://sensebridge.net/projects/northpaw/. This exact same method might actually be an easier way to get wearable navigational aids, as it will work with all shoes.

What I found interesting was that the insoles featured had a surprisingly similar height profile to my medical orthotic insoles for pes cavovarus (high arches, inward-turned heels)[1]. I'm all for tech that fits disabilities by default! (although this is probably an accidental by-product of the required space for the tech)

Page 1 of 7Next →