HNHacker News
TopNewBestAskShowJobs

oshiar53-0

152 karma · joined July 28, 2021

submissionscomments
oshiar53-0··on New atomic clock loses only one second every 300B years
Does this mean that 0 Hz bandwidth leads to the ideal clock?
oshiar53-0··on What Every Programmer Absolutely, Positively Needs To Know About Encodings (2011)
Fun fact: GB 18030 is a Unicode Transformation Format.

Example: \N{THINKING FACE}\N{FACE WITH TEARS OF JOY}\N{FACE SCREAMING IN FEAR}\N{SMILING FACE WITH SMILING EYES AND THREE HEARTS}\N{PERSON DOING CARTWHEEL}\N{FACE WITH NO GOOD GESTURE}\N{ZERO WIDTH JOINER}\N{FEMALE SIGN}\N{VARIATION SELECTOR-16}\N{EYES}\N{ON WITH EXCLAMATION MARK WITH LEFT RIGHT ARROW ABOVE}\N{SQUARED COOL}\N{VARIATION SELECTOR-16}

In UTF-8:

  00000000: f09f a494 f09f 9882 f09f 98b1 f09f a5b0  ................
  00000010: f09f a4b8 f09f 9985 e280 8de2 9980 efb8  ................
  00000020: 8ff0 9f91 80f0 9f94 9bf0 9f86 92ef b88f  ................
In GB 18030:

  00000000: 9530 cd34 9439 fc38 9530 8335 9530 d636  .0.4.9.8.0.5.0.6
  00000010: 9530 d130 9530 8535 8136 a439 a1e2 8431  .0.0.0.5.6.9...1
  00000020: 8235 9439 cf38 9439 e537 9439 8b32 8431  .5.9.8.9.7.9.2.1
  00000030: 8235                                     .5
oshiar53-0··on Skip: A programming language to skip the things you have already computed
I assume this uses thunks not unlike some lazily-evaluated languages?
oshiar53-0··on Uniting the Linux random-number devices
Doesn't this mean that non-blocking reads from /dev/urandom can now potentially return -EAGAIN (at e.g. very early boot time)? I think that's enough to subtly (nondeterministically) break userspace, in the short time window the entropy pool is not seeded enough, even if (C) and (D) do not hold.
oshiar53-0··on Skip: A programming language to skip the things you have already computed
To be fair, it has computed the page at least once at some point...
oshiar53-0··on Some neurons are active when adding, others when subtracting
a truely randall number
oshiar53-0··on Weak vs. Strong Memory Models (2012)
https://man7.org/linux/man-pages/man2/membarrier.2.html provides a good example of when a processor memory barrier is eliminated but a compiler memory barrier is still required.
oshiar53-0··on “Unix is a junk operating system designed by a committee of PhDs.” -Dave Cutler (2004)
Are you mad? I didn't even criticize Unix at all!
oshiar53-0··on “Unix is a junk operating system designed by a committee of PhDs.” -Dave Cutler (2004)
> I think that an operating system where you can't rename or delete a file that is open by some process is idiotic beyond words,

This is not an inherent limitation of the VMS or NT architecture; I'd rather argue it's for compatibility.

> even without MS-DOS drive letter names thrown in.

This is also legacy carried over from DOS and OS/2.

oshiar53-0··on Aro: A C compiler written in Zig
How about static inline functions?
oshiar53-0··on The FSF’s relationship with firmware is harmful to free software users
This is the insight I wanted.

Now I want to hear what FSF has to say about this...

oshiar53-0··on The FSF’s relationship with firmware is harmful to free software users
> it's almost mandated by law that there can't be. FCC regulations require that devices be made resistant to attempts to change their function in an effort to limit people's ability to transmit stuff unintentionally (or intentionally). Modern radio protocols are heavily dependent on SDR (software defined radio), so fixed function is probably infeasible. You could make the firmware unchangeable, but now any bugs discovered in your public source code are now entirely uncorrectable.

1. You can use signed firmwares to make it both compliant and upgradable.

2. You can separate the controller/receiver and the transmitter, and only lock up/restrict the transmitter part. Alternatively, you can implement the restriction at the hardware level if feasible (effectively making it fixed function).

3. Finally, you can sell the parts individually to serve a separate market segment.

oshiar53-0··on The FSF’s relationship with firmware is harmful to free software users
>"They should die for the cause."

In his stance, more like "proprietary driver vendors are holding hostage of patients."

oshiar53-0··on The FSF’s relationship with firmware is harmful to free software users
See https://www.fsf.org/campaigns/free-bios.html for the rationale.

Basically, FSF had to make a compromise here. If you use Flash ROM (or other writable medium), the firmware counts as a nonfree software. However, if you use actual ROM, the firmware might as well have been a circuit baked right in the product, so it counts as hardware; nevertheless, it counts as non-free.

FSF's ultimate goal would of course be to be able to certify that every component (hard or soft) of the system is actually free. However, this isn't very practical, since no consumer-grade computers will be considered free due to proprietary CPUs (e.g. Intel, AMD, ARM), which is why FSF is stuck in a weird situation. (How would you make exceptions for the CPU stock microcode and not the BIOS, for example?)

For that matter, I hope RISC-V helps us go a step forward...

oshiar53-0··on Dear sir, you have built a compiler
Make sure you don't roll your own crypto on your way, though.

Unless when it somehow becomes the absolute necessity...or it's for your dissertation.

oshiar53-0··on People behave more sadistically when they’re bored
Talk about lockdowns...
oshiar53-0··on An annoyance with Debian postinstall scripts during package upgrades
It's worth noting that Fedora/RHEL's postinstall is generally less intrusive than Debain's, though.

For instance it doesn't just automatically create databases or starts/enables services.

oshiar53-0··on _Application.Run(Object, Object, Object, Object, Object, Object, Object, Object
Clearly you haven't heard of HasThisTypePatternTriedToSneakInSomeGenericOrParameterizedTypePatternMatchingStuffAnywhereVisitor

http://dev.eclipse.org/viewcvs/index.cgi/org.aspectj/modules...

oshiar53-0··on A single line of code made a 24-core server slower than a laptop
(Commenting here since the other thread is going nowhere)

To clarify, the main property of a non-blocking algorithm is that it's exclusively composed of simpler, smaller ("atomic") operations that demonstrate time-bound/progress-making guarantees, in turn making the bigger algorithm generally easier to reason about (Note "generally").

The consequence of this argument is twofold:

1. It's entirely possible to make a blocking algorithm provide the same guarantees as a non-blocking algorithm, as long as the underlying operations (blocking or otherwise) are proven to be correct. Blocking algorithm tend to throw other complex systems into the mix (e.g. the scheduler), and all of the dependencies and their usages have to be correct (w.r.t. whatever property we desire) to show that the final blocking algorithm is also correct. For instance, it can be argued that the priority inversion problem stems from the lack of scheduler's correctness, or alternatively, the incorrect use of the scheduler. However, in the absense of such problems, there are effectively no disadvantages on blocking algorithms on this respect.

2. If it turns out any atomic operations below the non-blocking algorithm do not meet the expected guarantees, then the non-blocking algorithm itself also becomes unsafe. I think the OP clearly demonstrates this problem--the CPU atomic instructions are but some kind of hardware "locks" (either a LOCK# pin on older processors or some complex cache coherency protocol, but this is an implementation detail) on their own that can sometimes fail to meet the programmer's expectations, leading to surprising results.

In short, the fine line between blocking algorithms and nonblocking algorithms can be drawn by whichever smaller operations or components we assume to be correct.

oshiar53-0··on Do we need a link step?
OpenBSD does something similar but in a reverse manner. It's called Kernel Address Randomized Link (KALR).

What it does is bundling kernel object files into an archive, which is linked at boot time to form the final kernel image. Note that the link order is randomized each time the kernel boots, since KALR is a security vulnerability mitigation designed to thwart exploitation attempts.

oshiar53-0··on You can't copy code with memcpy
Related: https://devblogs.microsoft.com/oldnewthing/20190902-00/?p=10...
oshiar53-0··on You can't copy code with memcpy
Is there anything else that should be done except flushing D-cache and invalidating I-cache? I'm genuinely curious.
oshiar53-0··on You can't copy code with memcpy
It's AllocDStoCSAlias.
oshiar53-0··on Glibc is still not Y2038 compliant by default
Is there something wrong in particular for using built-in fixed-point types for timestamps?

Yes, overflow/underflow issues and yada yada, but virtually every type can be mised in its own way.

oshiar53-0··on Show HN: Embed your source code in PNG files
...why are you even talking to some stranger here then, is it worth enough to risk being exploited with a RCE 0day

Like, uh, just define a clear threat model, accept risks, and move on??? Or just don't use computers

oshiar53-0··on Show HN: Embed your source code in PNG files
> Yeah, but because of NSO I now look at every mandatory or common practice process that is used on a file to see if the NSO methods can be used for exploitation.

NSO is definitely neither the first nor the only one to do this, but let's move on.

> For example, PNG seems benign, but what it was stored in a zip file of sorts, could the MS windows zip process be exploited, could 7-Zip be exploited or even PKzip for that matter, do you see where I am coming from?

Any nontrivial parser written in an unsafe language has a potential for being exploitable, that's for sure.

> What about if I embedded some icons and image files as a resource in an application exe or dll. You have persistence then, even if its just a beacon or some unique domain name lookup to track the app online.

This is why we have code signing. Well, that works unless the ASN.1 parser or the signature verifier has got some security issues, of course.

> Likewise, what about compression built into HTML/Web browsers, could that be exploited? https://en.wikipedia.org/wiki/HTTP_compression

It's usually much easier to just exploit the renderer/JavaScript engine.

> Would it be possible to build something into a webpage or imagefile on a popular website where it can exploit the methods NSO have/are using?

This is basically how malware distribution works over the web, just look for some VirusTotal samples...

> Maybe we should go back to reading the internet using wget?

If we're at that level of paranoid, bugs in the HTTP parser, TLS implementation, or the TCP/IP stack should be just as sensitive.

oshiar53-0··on Linux Ate My RAM
Hint: disable or minimize overcommit and you're good to go.
oshiar53-0··on Show HN: Embed your source code in PNG files
No, that's irrelevant here.

PNGSource embeds code in ancillary chunks. That's it. No code execution. No steganography (yet).

oshiar53-0··on Groups never admit failure
>I realized this was because there was no objective feedback. Because there is no loss—it’s all social profit—they couldn’t fail.

>If you want to change the world to a better place, the best way to do it is a for-profit because for-profits have to take feedback from reality.

Why would it be the "best"? Non-profit organisations do have many other ways to have their performance validated and evaluated from "reality" transparently and objectively, just like e.g. a public company.

Sure, non-profit is not sustainable and legally binding etc etc, but the author doesn't provide concrete reason that a specific organisation model serves best for "building a better world." I'm not arguing that non-proft is the "best," but a foundation may receive funding and/or grants from a consortium of various non-profit and for-profit organisations, individuals, and etc.. This does not necessarily make the foundation itself "for-profit." The foundation could operate under critical scrutiny of stakeholders.

If anything, I'd blame the lack of transparency to interested parties (e.g. donors) as the main factor of organisational failure. This applies to both for-profits and non-profits.

oshiar53-0··on ADSL works over wet string (2017)
This is basically "near field" communication /s
Page 1 of 3Next →