HNHacker News
TopNewBestAskShowJobs

mulander

1,409 karma · joined May 30, 2009

Twitter : @mulander

Blog : https://blog.tintagel.pl/

OpenBSD developer, Senior Program Manager for Citus: Distributed PostgreSQL on Azure at Microsoft.

Interested in database engineering, distributed systems, information security and gaming.

[ my public key: https://keybase.io/mulander; my proof: https://keybase.io/mulander/sigs/dQXCBLcpFOM2v-GKDKC8TG6d7XevLe4ZwjrLInY5qII ]

submissionscomments
mulander··on “Someone was typing in a URL and WhatsApp was fetching it off my server”
Hi HN, op here.

I posted this not because I was angry on having a GET request sent to my server on a char by char basis. My main concerns were privacy related, since I posted this some additional things came to light:

1) This leaks the IP address of the person writing the msg

2) When property="og:image" is used it also leaks the User Agent and Android version [1]

3) When presented with invalid headers as a reply it can cause a crash on IOS, which mean this is a potential RCE vector [2]

4) It leaks the exact time an URL is typed into a chat

5) It's on by default, this is the default behavior in E2E encrypted conversations [3]

I don't use WhatsApp, I found this out by accident as I just have a habit to tail my logs. I know though that Signal doesn't do any of this pre-fetching. I am aware this is a 'feature' but there's no place for it when security is involved.

[1] https://twitter.com/0xjomo/status/874585822158352384 [2] https://twitter.com/dr4ys3n/status/874725257722179584 [3] https://mastodon.social/@rysiek/9146943

mulander··on OpenSSL Security Advisory - 26 Sep 2016
http://marc.info/?l=libressl&m=147490843900748&w=2

    Just a quick note that LibreSSL is not impacted by either  
    of the issues mentioned in the latest OpenSSL security 
    advisory - both of the issues exist in code that was 
    added to OpenSSL in the last release, which is not 
    present in LibreSSL.
mulander··on FreeBSD Core statement on recent freebsd-update and related vulnerabilities
Regarding OpenBSD. No. When shit hit the fan we gave out a heads up.

https://marc.info/?l=openbsd-misc&m=145278077920530&w=2

http://undeadly.org/cgi?action=article&sid=20160114142733

mulander··on Alleged founder of world’s largest BitTorrent distribution site arrested
He reportedly is Ukrainian and not Polish.

This makes it even more interesting. I also didn't hear any Polish media reporting his arrest (I live in Poland).

I would like to know where in the country he was arrested and what he was doing in Poland - no luck so far.

mulander··on Why OpenBSD Is Important to Me
Wine doesn't and probably never will work on OpenBSD.

- http://lwn.net/Articles/360312/

- https://www.winehq.org/docs/winedev-guide/x2803

mulander··on Why OpenBSD Is Important to Me
FreeBSD is pretty anti-secure too. https://vez.mrsk.me/freebsd-defaults.txt
mulander··on Syndicate Wars Port
Here you go: http://gynvael.coldwind.pl/?id=279
mulander··on Year of the OpenBSD desktop
> I actually didn't like the post, I hate the notion that one person using something means others should, but that's besides the point.

I'm sorry if it came out that way. The intention of the post was totally opposite. I was referring to the fact that Linux on the desktop already happened for a lot of people (including me) and that OpenBSD for a lot of people is already on the desktop in the same way. I'm happy with people using whatever system suits them, the whole thing was just a comment on recent tweets & comments online about 2016 being the year of the OpenBSD desktop.

mulander··on Year of the OpenBSD desktop
> That's true. The biggest takeaway, though, is the assumption that people will care to port mainstream software to OpenBSD when virtually nobody using that software runs OpenBSD & their community discourages amateur programmers. It's not a wise expectation. Instead, they should expect to have to port it all themselves to their particular OS of choice while being thankful when people do it for them with great portability.

You got it a bit wrong or didn't read the linked github issue in detail. I run OpenBSD and I ported Dart to OpenBSD. I tried to work with upstream (Dart team at Google) to incorporate my changes or work on a way that allows them to take the changes and for me to maintain the code long term. In this specific case the upstream works behind closed doors which makes it hard to cooperate on things like this.

mulander··on Year of the OpenBSD desktop
That's pretty much ongoing work. Mostly affecting Firefox in the browser front. Try -current with Chromium I don't feel a difference compared to GNU/Linux.
mulander··on Support of OpenBSD pledge(2) in programming languages
Additional info in comments on lobste.rs: https://lobste.rs/s/dmhmdc/support_of_openbsd_pledge_2_in_pr...
mulander··on Decommissioning a free public API
Sounds like how Telize started. Look at the first[1] article from the author. He decided to bring the service down after being contacted by a malware research company that his service is used by ransomware.

Would you like to risk someone contacting you and possibly threatening with legal action because they would believe you might have taken part in their data being held hostage?

There was a story floating around with the curl author receiving emails like that just because he showed up in credits. I personally would pull the plug from a free service immediately if I found out it was used by malware and I would have no accountability for the person I was enabling with my software.

[1] - http://www.cambus.net/adventures-in-running-a-free-public-ap...

mulander··on SSH Backdoor found in Fortinet firewalls
Who does the great job again?

https://www.reddit.com/r/BSD/comments/391nyj/pfsense_conside...

mulander··on Building an OpenBSD Router
OP's link was written by the same guy who wrote the bsdnow tutorial. The one on openbsd.org should be considered the canonical source now.
mulander··on Tor Anonymity: Things Not to Do
Should we also avoid the Internet itself then?

- https://en.wikipedia.org/wiki/Arpanet

mulander··on Postmortem: Server compromised due to publicly accessible Redis
One person wrote and linked an automatic tool exploiting the attack you detailed in the original blog posts comment section.

[1] - https://github.com/matiasinsaurralde/evilredis

mulander··on The Story Behind the New WordPress.com

  Today we're announcing something brand new, a new approach to WordPress, and open sourcing the code behind it.
  Written purely in JavaScript, leveraging libraries like Node and React.
That's their lesson from WordPress?
mulander··on Adventures in running a free public API
Malware using the service really sucks. Especially without any accountability - someone could actually target you with legal action for enabling the software.
mulander··on Do you know how much your computer can do in a second?
I wonder if [x for x in xrange(NUMBER)] would be any faster. Yes it allocates an array but list comprehension is executed differently by python. I recall a talk by some Dropbox guy stating that it was one of their optimization strategies.

Didn't find the original talk but found this: https://wiki.python.org/moin/PythonSpeed/PerformanceTips#Loo...

mulander··on OpenBSD developers: Landry Breuil
Essentially that's 'thinkpad' & anything else from lenovo coming as second. I also saw a large uptick of Dell laptops (the latitude series). Now, the thing with laptops is - they all lie.

One model can ship with 5 different wifi chips and they are never provided on the spec sheet - same for other components. So you have the highest chance with specific models but it still depends on the guts that were shipped with your specific device.

mulander··on OpenBSD developers: Landry Breuil
Well my wife uses the OpenBSD laptop probably much more than me now. Main things I hear?

- it doesn't break random stuff on upgrades

- just works, if something worked yesterday it works today

Yeah, and that's on OpenBSD -current upgraded about once a week - that has the perception of being more stable than Ubuntu, Archlinux & Debian.

I didn't notice battery live degradation but I never ran Linux on that laptop. I do notice performance decrease on Firefox but at this point it's hard to pin point if it's the OS & SMP support (which the developers actively point out as an active area of focus) or Firefox itself (also being actively worked on by upstream).

All in all, my wife is using the OpenBSD laptop daily and I don't hear here complaining that much.

mulander··on OpenBSD developers: Landry Breuil
Actually OpenBSD is really great for a desktop especially on laptops - the only downside is almost non existent nvidia support, though you will be fine with intel & most radeons.
mulander··on OpenBSD developers: Landry Breuil
We have 6 more queued :) Could be more if some devs decide to send out a later answer ;)
mulander··on OpenBSD developers: Landry Breuil
You can find older interviews at http://beastie.pl/tag/wywiad/ or by checking out my recent submission history for HN ;)

Assuming that the server survives the hn death hug ;)

mulander··on Female violinist exposes 10 years of lewd, fetishizing messages from men online
Would be funny if they experience harassment out of being exposed as a harassing person. This seems something that could happen on the internet.
mulander··on LogMeIn acquires Lastpass
Be happy there is no mobile version. I don't know about you but I personally can't trust a mobile phone this days with anything sensitive. :(
mulander··on NetBSD-7.0 developer interview: Leonardo Taccari
Well seems we got the hn death hug :)

Contacting the server admin, here's a google cache of the content, sorry for the trouble folks!

http://webcache.googleusercontent.com/search?q=cache:NqbcMBC...

mulander··on Using htop to generate a live website background
I wonder how https://github.com/ansilove/AnsiLove-C would fare for generating the PNG compared to the current solution.
mulander··on Netflix Switch – dim lights, turn on the TV, order food, and silence your phone
There was this old Perl script for ordering Pizza at Domino's but I don't think it used an API (web scraping if I recall correctly).

http://www.coryarcangel.com/things-i-made/pizzaparty/

https://github.com/coryarcangel/Pizza-Party-0.1.b

mulander··on Launching NginScript
A web server with a JavaScript engine. What could ever go wrong?

My eyes start to bleed when I imagine what some cowboys will implement on top of that.

← PreviousPage 3 of 5Next →