HNHacker News
TopNewBestAskShowJobs

mschempp

72 karma · joined December 20, 2022

github: https://github.com/beac0n

blog: https://schempp.dev/

contact: hn@schempp.dev

submissionscomments
mschempp··on Gender Equality and Work
Not sure I understand you correctly, but the study I linked shows that mother's earnings drop significantly after the First child. That has nothing to do with the significant monetary cost of children, which are added on top of that.
mschempp··on Gender Equality and Work
Most of the gender pay gap can be attributed to children: See https://www.henrikkleven.com/research/published/kleven-landa...

On page 43, it shows very clearly, that women who do not have children have almost no earnings gap.

Society can "fix" this in two ways: - introduce the same penalty for fathers, so that both earn less - which would IMHO lead to even less children - lift up families/mothers and help women not experience this gap, by having full time high quality child Care, have laws that allow mothers to take their children to Work, etc etc.

Second one is much harder to accomplish, because it costs money and time and effort.

The first one is Just forcing fathers to stay at home while mothers go back to Work.

mschempp··on Gender Equality and Work
Not sure where this "pushback" comment is directed at, but I was not trying to Push back - I am agreeing with you in general.

Just because institutions are oversimplifying doesn't mean we have to

mschempp··on Gender Equality and Work
"There is definitely social sexism being surfaced by the wage gap statistic, but it's against men, not women."

I would say against both genders.

mschempp··on Gender Equality and Work
As a father, I really can't understand how every article about this topic talks about as if fathers and mothers are just interchangeable. We are not.

Mothers carry their child for ~9 months, they give birth to that child. The bond between a mother and her freshly born child is bigger than that of the father.

Of course fathers are very important too, and yes fathers should spend more Time with their children in general.

But it's Just crazy to ask mothers to get back to work as soon as possible. Many mothers want to Work part Time, because they want to spend more time with their children. The issue is, that care work is not paid or valued nearly the same as work for money.

Also if you're feeding your young child like you are supposed to, the father simply can't feed the child, because we don't give milk.

Nearly all articles about this topic care only for how to get women back to Work instead of what's best for society and for families.

If that would be the Focus, we would talk way more about how to integrate children into the work Life and less on how to grow GDP.

mschempp··on Show HN: Ruroco – like port knocking, but better
btw.:

ruroco DOES prevent replay attacks, by saving the deadline (which is in ns) in a blocklist. It does not matter if the deadline has "passed", the deadline is added to the blocklist as soon as the packet reaches the server and is deemed "valid". So each packet is only valid exacly ONCE

mschempp··on Show HN: Ruroco – like port knocking, but better
a replay attack won't work, because every UDP packet data has deadline in nanoseconds.

Once this UDP packet reaches the server the deadline will be added to the blocklist.

If an attacker sends the same packet again, the server will check its blocklist for the deadline. It does not matter if the deadline has been reached or not. once the packet reaches the server, the deadline of that packet will be added to the blocklist.

mschempp··on Show HN: Ruroco – like port knocking, but better
hmmm just validated my implementation

the deadline that is sent from the client is being added to the blocklist after the command was executed, so sending the same packet again will not work, because the deadline (which is in nanoseconds) is already on the blocklist and therefore the command will not be executed again.

This effectively means that replaying a packet is not possible, because the server will deny it.

mschempp··on Show HN: Ruroco – like port knocking, but better
"Modern port knocking also incorporates secure cryptographic hashes."

Are you referring to fwknop? Thats not "port knocking" but Single Packet Authorization. That is very different from port knocking.

How can one incorporate secure cryptographic hashes with simple port knocking?

mschempp··on Show HN: Ruroco – like port knocking, but better
the client COULD use something like https://www.ipify.org/ to get the IP, which can then be used as an additional client argument.

But if an adversary uses the SAME network, then the IP address that the server sees will be the same for the client and the adversary, so it only matters if the adversary takes the packet and sends it from a different network, which the adversary won't have to do, because they still control the network where the packet was originally sent from.

mschempp··on Show HN: Ruroco – like port knocking, but better
I think what rmholt means is that ruroco does not improve security in the sense, that it has stronger and safer encryption/algorithms/... but that it merely "hides" existing services.

I would argue that it does improve security in the way that it reduces the attack surface of potential vulnerable services, because they are simply not accessible for adversaries.

On the other hand, having another tool running increases the attack surface, but imho that's very small.

mschempp··on Show HN: Ruroco – like port knocking, but better
Thanks for the feedback and pointing out ostiary. Fixing replay attacks is on my todo list, maybe I can learn some things from how ostiary does it.

Kind advice from my PoV:

Your comment could be read as "your project is shit, there is ostiary which has replay protection and yours doesn't".

I'm sure you didn't intend for you comment to not come across that way, and I also did not read it that way, but others could have.

Also keep in mind that ruroco is a very young project and is by no means finished. I was thinking about using one-time-pads or other encryption algorithms as well. I also posted this here to get feedback to improve my project.

So hopefully when I release version 1.0.0 all the issues that this project has atpit are resolved ;)

mschempp··on Show HN: Ruroco – like port knocking, but better
that is correct. The configuration is not even ufw specific, you could run any command that you like. This means you could also, for example, disable or enable certain nginx configurations.
mschempp··on Show HN: Ruroco – like port knocking, but better
You are right, but if you are in a network that blocks every packet that is sent to any port which is not 80 or 443 your port knocking capabilities are very limited.

Ultimately reading firewall logs to do port knocking is most secure way, because - as you said - there is virtually no attack surface.

I would argue that port knocking is extremely inconvenient and does not work in every scenario. So for me it's a tradeoff between "ultimate" security and convenience.

mschempp··on Show HN: Ruroco – like port knocking, but better
"Maybe the OP simply hasn't yet heard about or used Wireguard."

I have, but I do not want to run a VPN solution on my private sever, for which I barely have any need. Also Wireguard, although VERY secure is still not "simple" software.

In addition there are usecases where Wireguard would not help, for example when I want to open up an http service for the current network that Im in.

mschempp··on Show HN: Ruroco – like port knocking, but better
"The example shows you opening port 80 (HTTP standard port)"

that's because I run my ssh on port 80, but that's not standard, so I agree that it's confusing. Thanks for pointing it out. I will fix it :)

mschempp··on Show HN: Ruroco – like port knocking, but better
yes thats correct. Should have stated that in the headline
mschempp··on Show HN: Ruroco – like port knocking, but better
Thanks for the link. Looks interesting!
mschempp··on Show HN: Ruroco – like port knocking, but better
I used port knocking in the description, because anyone here probably knows what port knocking is and ruroco is kind of similar to that.

Ruroco can be used for more than just keeping sshd logs clean, for example I could also enable a service other than ssh, for example a private file server that I want to get access to when I'm on my phone (although I haven't implemented an android version yet, it should be doable).

mschempp··on Show HN: Ruroco – like port knocking, but better
One of the reason why I wrote ruroco is, that I can run this from probably anywhere in the world, if I put the service on port 53, because thats DNS and that does not get blocked by any wifi whatsoever.

I used to use port knocking, but at some point found myself in a hotel where they blocked ALL ports, except TCP 80 and 443 (did not check UDP at the time).

My ssh port is on 80, so I can use all of my tools, even if the network I'm in blocks everything else.

mschempp··on Show HN: Ruroco – like port knocking, but better
"+ Relatively infrequent access by limited # of people to servers which are not top targets for attacks. Solutions like the one above are great for this."

Thats exactly what I'm using it for - I'm the only one on my server :)

mschempp··on Show HN: Ruroco – like port knocking, but better
RSA
mschempp··on Show HN: Ruroco – like port knocking, but better
Thanks for the feedback! Will definitely put some thought into it.
mschempp··on Show HN: Ruroco – like port knocking, but better
Did not know fwknop, but since it came up multiple times in this thread, I'll look into it.

I have no protection against DoS attacks, but I'm working on it (there is also a WIP in the README about that :) )

mschempp··on Show HN: Ruroco – like port knocking, but better
I'm not good at describing things easily. I will put the hn description on top of the git repo :)

Thanks for the feedback!

mschempp··on Show HN: Ruroco – like port knocking, but better
RSA allows encrypting with the private key, see https://github.com/beac0n/ruroco/blob/ce766751b51c8ff6246a2b...

and decrypt with the public key, see https://github.com/beac0n/ruroco/blob/ce766751b51c8ff6246a2b...

using RSA, one can easily derive the public key from its private key (see https://security.stackexchange.com/questions/172274/can-i-ge...), that's why the private key is kept safely on the client

Also for SSH the public key is also stored on the server, while the private key is kept safely on the client, see https://www.ssh.com/academy/ssh/public-key-authentication#ke...

SSH can also be used with RSA: https://www.ssh.com/academy/ssh/keygen#creating-an-ssh-key-p...

mschempp··on Show HN: Ruroco – like port knocking, but better
Funny. Haven't thought of that, probably because I'm german.

The way I pronounce it is with long vowels.

So in an extreme way it would be ruuurooocooo :)

mschempp··on Show HN: Ruroco – like port knocking, but better
Hi Tepix. Im the author of the tool.

Thanks for the feedback! It doesn't describe how it prevents that attack, because it doesn't prevent this attack :).

As someone else wrote, I could put the IP address of the sender into the encrypted data and validate that in the backend and drop the packet + block the IP address.

I will add that in the next release!

mschempp··on Ask HN: Who is hiring? (March 2023)
Maddox.ai | Software Engineers | Full-time | German + English | Germany | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen

https://www.maddox.ai/en/ | https://maddox-ai-gmbh.jobs.personio.de/?language=en

Our product, Maddox AI, is an AI-based visual quality control solution, which can automate manually performed quality inspection for manufacturing companies. Maddox AI is an asset-light SaaS solution, which addresses those visual inspection tasks that are still performed manually, as conventional (=rule-based) computer vision methods fail. In product development, we closely collaborate with leading AI researchers from the Cyber Valley. Prof. Dr. Matthias Bethge, Prof. Dr. Alexander Ecker and Dr. Wieland Brendel have been researching in the field of machine learning and computer vision for years and are part of our founding team.

Maddox AI is used by DAX-30 companies as well as by large medium-sized enterprises. Our team consists of scientists, former strategy consultants, mechanical engineers, and software engineers. We know that Maddox AI's success is only made possible by our unique team. As we continue to grow, we want to convince the best and brightest minds of our mission to establish Maddox AI as the modern quality management platform.

We are looking for new colleagues for the following positions:

(Senior) Software Engineer, Edge (m/f/d) | ONSITE Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894530?display=e...) - Main Technologies: Python3, PyQT/QML <- If you are good in one of those, we want to get to know you :) - Other Technologies: Ubuntu, (Embedded) Linux, ONNX, TenorRT, CUDA, Nvidia Jetson Platform, L4T, Systemd, neoapi - As part of the edge software team, you will contribute to the development of our edge software framework, which is crucial to enable running models in nearly real time on the customer's manufacturing site. Your code will be responsible to connect all the dots: from image acquisition via our industrial cams, integrating cutting-edge machine-learning techniques into low-latency edge environments, providing industry-standard interfaces for full automation to implementing UI components for our touchscreen interface, and communicating with our cloud infrastructure. You will be working closely not only with your software engineering but also with machine learning and hardware engineering peers.

(Senior) Software Engineer, Frontend (m/f/d) | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894528?display=e...) - Technologies: Typescript, React, Redux, Next.js, Material UI, react-query, HTML5, CSS3 - As part of our frontend team, you will contribute to the development of our B2B cloud application that enables our customers to control various aspects of our AI-based visual inspection product through easy-to-use tools – from production monitoring to building new machine learning models. In order to take our visual inspection platform to the next level, you will be working together with our designers and product management to integrate consistent UIs into a user-friendly single-page application using a modern tech stack. Your work will include writing cutting-edge tools for our canvas-based image annotator, creating interactive visualizations for our dashboard, and designing and integrating new API interfaces in close collaboration with our backend developers.

mschempp··on Ask HN: Who is hiring? (February 2023)
Maddox.ai | Software Engineers | Full-time | German + English | Germany | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen

https://www.maddox.ai/en/ | https://maddox-ai-gmbh.jobs.personio.de/?language=en

Our product, Maddox AI, is an AI-based visual quality control solution, which can automate manually performed quality inspection for manufacturing companies. Maddox AI is an asset-light SaaS solution, which addresses those visual inspection tasks that are still performed manually, as conventional (=rule-based) computer vision methods fail. In product development, we closely collaborate with leading AI researchers from the Cyber Valley. Prof. Dr. Matthias Bethge, Prof. Dr. Alexander Ecker and Dr. Wieland Brendel have been researching in the field of machine learning and computer vision for years and are part of our founding team.

Maddox AI is used by DAX-30 companies as well as by large medium-sized enterprises. Our team consists of scientists, former strategy consultants, mechanical engineers, and software engineers. We know that Maddox AI's success is only made possible by our unique team. As we continue to grow, we want to convince the best and brightest minds of our mission to establish Maddox AI as the modern quality management platform.

We are looking for new colleagues for the following positions:

(Senior) Software Engineer, Edge (m/f/d) | ONSITE Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894530?display=e...) - Technologies: Python3, C, PyQT/QML, Ubuntu, (Embedded) Linux, ONNX, TenorRT, CUDA, Nvidia Jetson Platform, L4T, Systemd, neoapi - As part of the edge software team, you will contribute to the development of our edge software framework, which is crucial to enable running models in nearly real time on the customer's manufacturing site. Your code will be responsible to connect all the dots: from image acquisition via our industrial cams, integrating cutting-edge machine-learning techniques into low-latency edge environments, providing industry-standard interfaces for full automation to implementing UI components for our touchscreen interface, and communicating with our cloud infrastructure. You will be working closely not only with your software engineering but also with machine learning and hardware engineering peers.

(Senior) Software Engineer, Backend (m/f/d) | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894526?display=e...) - Technologies: Python3, Flask, Azure, MongoDB, Gitlab, PyTorch, ONNX - As part of our back-end team, you will contribute to the development of our APIs which is crucial to enable our data-centric approach to AI-based visual quality control. Your work will include writing server-side algorithms for analysing dataset quality and aggregating model predictions for visualisation purposes. Furthermore you will help taking our AI automation pipeline to the next level, reducing the effort for model training and deployment to a single mouse click.

(Senior) Software Engineer, Frontend (m/f/d) | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen | (https://maddox-ai-gmbh.jobs.personio.de/job/894528?display=e...) - Technologies: Typescript, React, Redux, Next.js, Material UI, react-query, HTML5, CSS3 - As part of our frontend team, you will contribute to the development of our B2B cloud application that enables our customers to control various aspects of our AI-based visual inspection product through easy-to-use tools – from production monitoring to building new machine learning models. In order to take our visual inspection platform to the next level, you will be working together with our designers and product management to integrate consistent UIs into a user-friendly single-page application using a modern tech stack. Your work will include writing cutting-edge tools for our canvas-based image annotator, creating interactive visualizations for our dashboard, and designing and integrating new API interfaces in close collaboration with our backend developers.

Page 1 of 2Next →