HNHacker News
TopNewBestAskShowJobs

phlo

733 karma · joined December 7, 2012

ycombinator@y.ly
submissionscomments
phlo··on Pressing YubiKeys
The threat actors are SOC employees or visitors who might (maliciously or unwittingly) use their smartphones to record sensitive data.

The risk is data exfiltration. A selfie in front of the SOCs giant screen wall; a compromised phone that keeps recording audio.

The problem is that a third-party SOC will generally need a way to connect to their customers' systems. Sometimes that gets properly implemented as a site-to-site VPN with isolated jump hosts and session recording. In other instances, the SOC gets to use normal employee VPN access, and usually a handful of VPN tokens.

And now you have a fun conflict: One customer insists that no mobile phones are carried inside the secure SOC area. Another uses a VPN solution that requires a smartphone (and, e.g. Duo Push) as the second factor. How do you satisfy both? You take a set of mobile phones, possibly add some measures to stop them from being used as recording devices, and bolt them to a table so they can't leave the secure area.

phlo··on Apple, ARM, and Intel
Duplicate of https://news.ycombinator.com/item?id=23538826 (which was posted a few minutes earlier).
phlo··on Neofeudalism: The End of Capitalism?
So there's two numbers at play here: balance sheets and market cap.

A company's market cap is its share price multiplied by the number of outstanding shares. Using parent's Netflix example, there are approximately 450m Netflix shares, times a market price of $450, for a market cap of approximately USD 200b. So it's fair to say that Netflix, right now, is worth some $200b.

Now the market cap can sometimes be misleading: Say you start Runaway Co and issue 100m shares. Each of these shares is worth what the market is willing to pay for it. If I agree to buy one off of you for $100, then we've just spent $100 to make a $10bn company. That's where the trade volume comes in.

Netflix is a publicly traded company. Today, some 7.5m Netflix shares were traded at prices ranging from $443 and $456. Given that volume, you can be relatively sure that the market price accurately reflects the company's current value (as seen by the market).

On the other hand, a company's balance sheet is listing its assets and liabilities. That's where the huge numbers come in for banks. Let's say a bank receives $1m of deposits from its customers, and uses that money to fund a $1m mortgage. That bank's balance sheet is now $1m.

Of course, that doesn't necessarily mean that the bank is now worth $1m -- all of the $1m in mortgage debt that it is owed is offset by $1m in deposits that it owes to its depositors. Instead, the bank would be valued according to the profit it can generate from this. If it charges 2% for the mortgage and pays 1% interest to its depositors, that leaves 1%, or $10k per year. Valued at 10X profit, that bank might be worth $100k or so, even though its balance sheet lists a far bigger number.

Which takes us full circle.

As you said, Citi has some 2tn assets on its balance sheet. In 2019, it generated some $75bn in revenue from this, and made a profit of some $20m. At approximately $45 per share, its market cap is right around $95b.

Netflix, on the other hand, had about $33b on its balance sheet. Way fewer assets, but also way fewer obligations. In 2019, it generated revenues of about $20bn and some $4bn in profits. Investors appear to believe that there is a lot of growth still ahead, because they value the company at $200b.

phlo··on Human Rights at a Global Crossroads – Robert Tibbo and Edward Snowden [video]
PSA: This is the live streaming URL. An archived version will be available a few hours after the talk with the rest of the archived talks, on media.ccc.de [0]

All talks at 36C3 are live-translated between English and German, and into one additional language (in this case, French)) [1].

If you find any talks on the schedule [2] that seem interesting but are in a language you're not fluent in, use the 'native'/'translated' switcher in the video player.

[0] https://media.ccc.de/c/36c3

[1] https://c3lingo.org/

[2] https://fahrplan.events.ccc.de/congress/2019/Fahrplan/index.....

phlo··on 36th Chaos Communication Congress – Streams
It's available, but a bit hidden on media.ccc.de. There's a cog wheel icon on the lower right corner of the video player. Hover over it, and a list of languages ("deu" is German, "eng" is English, "fra" and "esp" are French and Spanish, respectively) should pop up.
phlo··on 36th Chaos Communication Congress – Streams
PSA: All talks will be live-translated between English and German, and into one additional language (primarily into French or Spanish; on occasion there were translations into Russian and Mandarin) [0].

If you find any talks on the schedule [1] that seem interesting but are in a language you're not fluent in, use the 'native'/'translated' switcher in the video player.

Subtitles will be available after congress, here [2].

Finally: Congress is an amazing experience, and it's all volunteer-driven (including the crazy network infrastructure, the live streams, the translations and everything). If you have some spare time between Christmas and the new year, consider visiting next time around. It's a lot of fun!

[0] https://c3lingo.org/

[1] https://fahrplan.events.ccc.de/congress/2019/Fahrplan/index....

[2] https://c3subtitles.de/

phlo··on Google is investing $3.3B to build clean data centers in Europe
Yes and no.

A heat pumpt doesn't generate heat, it /pumps/ it from one location to another. It can only achieve above-100% efficiency if you don't include the source of the heat in your calculation.

For a more practical example, consider a (simplified) geothermal heating system. It consists of a probe that's drilled some 10-15m into the earth, a radiator in your living space as well as a pump and piping connecting the two. The earth's temperature surrounding the probe is relatively constant at 10-15 degrees C.

In winter, when the outside temperature falls below those 10-15 C, you pump warm water from the probe into the radiator. Using the example numbers, 100W of electrical energy might provide you with 400W of heating output. The 100W has no part in generating the heat though, it only moves it from the warmer probe to the cooler radiator. The reverse applies in Summer, when the surface temperature is higher than 10-15 C.

What you're describing exists in the form of district heating. Heat is generated in a central location (e.g. as a side product from garbage incinerators), and a heat pump is used to transfer the thermal energy from that location into a bunch of surrounding houses. But, in any case: the whole process only makes sense as a way to capture excess energy from the heat-generating process; and you are always limited to (at the theoretical maximum) capture all of the excess energy output, but not one Joule more.

phlo··on France and Germany Agree to Block Facebook's Libra
Wrong.

The relevant law (art. 3 WZG[0]) requires persons to accept all banknotes (and up to 100 coins per transaction) as payment, but this only applies after a contract has been formed. It's perfectly legal for any store to indicate to customers that it will not accept large-denomination notes or cards[1]. If the customer is not willing or capable to pay using the accepted means of payment, no contract is formed, and the chewing gum remains with the store.

[0] https://www.admin.ch/opc/de/classified-compilation/19994336/...

[1] https://www.srf.ch/sendungen/kassensturz-espresso/geschaefte...

phlo··on Xip.io: Wildcard DNS for Everyone
It depends on the implementation of the DNS rebinding protection.

I have just checked, and my pfSense firewall (which claims to block DNS rebinding) blocks local addresses from resolving through xip.io (tested with loopback and several RFC1918. All blocked, regardless of whether they match the subnet in use). External addresses (e.g. 1.1.1.1.xip.io) resolve fine.

phlo··on The New Austrian Railways' Intercity and Nightjet Sleeper Train Interior Design
Interestingly, the Swiss railway system publishes real-world figures on its Co2 efficiency per passenger-kilometer. [https://www.mobitool.ch/de/tools/vergleichsrechner-15.html, german-only, un nfortunately]

They report some 80 passenger-km per liter of Diesel equivalent energy, compared to 13 passenger-km in a modern hybrid. Both values include the energy production, utilization and energy expenditure for infrastructure.

This assumes a modern network with electric trains though. I'm not sure if the article you cited still uses diesel-powered trains to arrive at such extremely different figures.

phlo··on Golden Rules for Making Money (1880)
I'm not aware of any countries where no fees at all would be levied, but to provide two examples from Europe:

- In the EU, interchange rates are limited to 0.3% [1] for credit card transactions at physical terminals ("card present transactions"). That's not free, but it's an order of magnitude below US levels. Caps for other payment methods (card not present transactions and transactions made with debit cards) range from 0.2 to 1.5%.

- Some banks, or groups of banks, operate their own schemes (i.e. payment processing networks competing with Visa and Mastercard), and generally achieve lower fees. See [2] for one example where the price per transaction starts at $0.23 and goes down for transactions below $10, and for customers processing more than 10k transactions per year.

[1] http://europa.eu/rapid/press-release_IP-18-6655_en.htm

[2] https://www.postfinance.ch/en/business/products/accounts-rec...

phlo··on Phishing Is the Internet’s Most Successful Con
In practice, FIDO U2F (Universal 2nd Factor) provides the same benefits and side-steps the major pains associated with mutually authenticated TLS (convoluted user experience, complex trust relationship management).

Google reportedly managed to all but eliminate phishing targeted at employees [1].

They also kind of solve your point 2: since the credentials live on the token, it's easy to move them from one device to the next. For devices with USB/NFC, that is.

[1] https://krebsonsecurity.com/2018/07/google-security-keys-neu...

phlo··on The Hidden Cost of Touchscreens
This makes you appreciate the attention to detail, and the countless painfully learnt lessons, that goes into user interface design for airplanes.

Compare a Cessna 400's cockpit [1] to a switch cluster in a recent Mini [2]. The car still has physical switches, which is better than a touchscreen. It's also styled to resemble an airplane cockpit. But all the switches look the same, and some of them have two positions while others have three; some of them disable things while others turn them on.

In the Cessna, each control has a different color, and a different surface texture. The flap lever is styled to resemble an actual flap. The same goes for gear levers on planes with retractable landing gears: they are styled as little wheels. As the pilot, if you touch the wrong lever, you'll immediately feel the difference, avoiding dangerous mistakes.

In the Mini, all switches have the same color and they feel the same. Their status is indicated with a little LED on the switch itself. You neither feel the current status from touching the switch, nor is there any tactile feedback of whether you are touching the right switch. With a touchscreen, that remains true, but additionally the location of the switches changes too.

[1] https://qph.ec.quoracdn.net/main-qimg-f37712d0cd771d5aee97ac...

[2] https://www.gunaxin.com/wp-content/uploads/2017/10/2017-MINI...

phlo··on Certificates for localhost
No, 127.0.0.1 should never appear on any network, and no network device should ever route it.

The earliest documentation I was able to find is in RFC 1122 [1] from 1989, but according to RFC 6890 [2], the principle dates back to 1981.

[1] https://tools.ietf.org/html/rfc1122#section-3.2.1.3

[2] https://tools.ietf.org/html/rfc6890 (table 4)

phlo··on Why We Disagree with The New York Times
In this specific instance, the Times article might be overblown.

They specifically mention that they were able to use BlackBerry Hub with a reporter's account to query Facebook data. The article never states whether BB Hub connects to Facebook directly, or whether it receives data from a BlackBerry-operated service.

The latter case is clearly user-hostile. If BlackBerry (the company) can read user data and Facebook claims not to allow 3rd-party access, then that is bad, and it should be treated as a breach of the user's trust.

The former case is more complex. As a user, I care a great deal that I can access Facebook using my choice of browser, whether that's Chrome, Firefox or Edge. I shouldn't be limited to the top three either. Some users may prefer a browser that works with their screen readers, others may prefer the built-in browser in their smart TV, and others yet might prefer a unified messaging app, like BB Hub.

The distinction between what happens locally or in the cloud is often unclear, and it's not getting any better. Chrome on Android wants to accelerate mobile connections by routing them through a compressing proxy. I can get an extra-secure version of chrome from authentic8 to protect against malware, with the caveat that it runs in their datacenter.

I feel that the tech industry in general, and Facebook in particular are struggling to tell users what happens with their data. Sometimes it's because things actually are complicated, and sometimes just to hide obvious overreach. The obvious blowback: complaints, strict regulation and mistrust. As the people who build and run systems, we should strive to do better. Regain the trust lost by past mistakes, and get back to the point where one could realistically apply hanlon's razor to reports of user surveillance.

phlo··on Prices for dried coffee husks are outstripping those for beans
USD per lb of green beans in bulk. According to one finva I visited at some point.

On some quick research, apparently on the extreme high end, lots can go for as high as $600 per lb.

https://dailycoffeenews.com/2017/07/26/record-coffee-earns-6...

phlo··on Prices for dried coffee husks are outstripping those for beans
Conventional.

For comparison, fair trade ranges from $1.40 to $1.90 (organic on the higher end). Direct trade starts at $2 or so at the low end, averages around $3.50 or so and can approach double digits for top-end specialty coffee.

Afaik the quality of the cascara is even more sensible to farming and processing conditions that the bean, so I'd expect a large part of the cascara production to come from higher-end farms anyway.

phlo··on Gmail Icons are Hard
For those too lazy to fetch everything to local (like me), the same shortcuts are available in the web interface as well. Pressing '?' pops up a full list of options.
phlo··on Google is rebranding storage plans as “Google One”
One of my favourite benefits about bundling services is that it can more closely align the platform operator's incentives with my interests.

For ad-driven sites, it becomes crucial to keep viewers engaged as often and as long as possible. Every second spent on Facebook is another shot at an ad impression, every video on YouTube another chance for a pre-roll ad. Cue Facebook's notification spam and YouTube's autoplay.

In a bundled service, the incentives shift. The provider's revenue will stay mostly constant, as long as they can demonstrate enough value for me to maintain the subscription. I might still get the good parts (next episode in a series autoplays), but I'll be spared the clickbaity follow-up video that autoplays because there wasn't any other related item.

phlo··on A Recycled IP Address Caused Me to Pirate Books by Accident
> Not sure how you could do that efficiently...

You could probably do that quite efficiently with Passive DNS data. There are a bunch of providers (e.g. FarSight, RiskIQ, many others) that collect and aggregate DNS request data and make it searchable over time.

RDNS is probably not going to be helpful. I'm not aware of any cloud provider setting a PTR record by default, and I think most won't allow you to do that at all.

phlo··on Video suggests huge problems with Uber’s driverless car program
> willful contempt for safety

To play Kalanick's adversary, he might be arguing for more real-world data collection. Tesla famously equipped most of their cars with more sensors than were required at the time of delivery, using the data to drive development of the Autopilot function that was later added to the cars.

phlo··on Potent malware that hid for six years spread through routers
There's a project called SCION [1] that (among other things) does roughly this. In essence, participants announce their presence over a multicast-type protocol, and in order to send packets to anyone, you must have received a recent announcement from them.

It's a quite fascinating re-imagination of the Internet, solving many of its problems (and probably introducing a whole slew of new ones).

[1] https://www.scion-architecture.net/

phlo··on The Natural Rate of Interest Is Zero (2004) [pdf]
In Switzerland, the current target interest rate (set by the Swiss National Bank) is -1.25 to -0.25 percent, with current rates around -0.75%.

This means banks need to pay the SNB on their funds deposited there. Many of them pass that on to their customers: Deposits don't earn any interest to speak of, and for large sums (starting from 1M or so), banks commonly charge interest. At some points, the yield on Swiss Gov't bonds was even negative.

If you can offer a safe (and bank-accepted) way to store that money, you stand to make a killing.

On the other hand, even in that environment, mortgages aren't free. Rates range from 0.5 to more than 2%. Part of that is the banks' margin, part of it comes from fixing the interest rate for some (2-10) years.

[1] https://www.snb.ch/en/iabout/stat/statpub/zidea/id/current_i...

phlo··on Cierge – passwordless authentication
Not OP, but I do the same thing using wildcard addresses on a domain I own. I might use hn@my.domain for Hacker News, amzn@my.domain for Amazon and so on.

Foregoing the custom domain, some email providers also let you add tags to your address (e.g. your_address+tag@gmail.com). I'm aware of some people who use that functionality to have unique email addresses for each service.

phlo··on Net Neutrality’s Holes in Europe May Offer Peek at Future in U.S
In Switzerland, some cities have started to break this up, and it's wonderful: Responsibility is split between the local utility and telcos. The utilities are responsible for the last mile (just as they are for power and water), and provide a fiber connection from the customer to one of several points of presence per city. Telcos rent space in these PoPs. They get to skip the expensive last mile and focus on Internet connectivity.

In places where FTTH is available, a wonderful ecosystem of mini-ISPs has sprung up, serving different niches. Some focus on integrated multi-play (Internet/TV/Phone/etc.) setups, others offer affordable quick connections without the bullshit. Choice and competition are alive and well, despite (or because?) part of the infrastructure is publicly funded.

phlo··on Passing the torch
TBH I mostly just lurk there and use it as a feed of interesting things when my need for procrastination exceeds what even HN has to offer. It's surfaced some nice stories though, that I didn't see on HN.

From what limited view I've had into the community, the quality of the discussion seems similar to HN. With a lot less volume, of course.

phlo··on Passing the torch
If you (or anyone else on here) would like an account, feel free to post a comment with your email address or shoot me a message (address in profile).

Edit: Invites sent for any requests up to 14:50 UTC. I'll check the thread later on for updates.

phlo··on Get Rid of Equifax
> But a government agency that has all the info about all my accounts...

I'm quite happy with the approach that Switzerland has taken. Firstly, there are no credit scores or credit reports. Instead, there is a well-defined and regulated way to collect on overdue bills: The creditor requests debt collection from the state debt collection agency. At this point, collectees may decide to pay, to object to the prosecution or not to react. Objecting leads to a defined legal process where the creditor must prove the debt, and the collectee can defend themselves. In case of no reaction, authorities may proceed to seize assets.

As for the reporting, the debt collection agency will only keep a file on people against whom a collection request has been filed, and only make it available to the person in question and entities with a qualified interest in it. In practice this means that when renting a flat or getting credit, you request your own (empty) record and submit it to the landlord/bank in question. The agency is also responsible to expunge entries from that record after a defined time. And since responsibility for collection lies with a state agency, there's very little risk of the kind of harrassment you hear of in horror stories from the states.

The implementation has room for improvement: records are kept locally, tied to the state you live in and there's no immediate way to get online confirmation. Those are details though, that could be fixed in a clean implementation of the same system.

phlo··on Scotland plans to make petrol and diesel cars obsolete by 2032
Same goes for the fuel tanks. It's considered good airmanship to do a quick visual check of the fuel level and compare it to what the gauges tell you. And to drain some fuel from the lowest part of the tank to check it for water or other impurities.
phlo··on Scotland plans to make petrol and diesel cars obsolete by 2032
> The worst thing that happens is the sensor breaks and then they become manual headlights...

Don't be too quick to disregard automation dependency. I agree that a headlight switch is probably quite low-risk, but every action you automate carries the risk of overloading the operator if it fails at the wrong time.

Even two decades later, I find the 'Children of Magenta' talk highly illuminating. Maybe you'll find it interesting as well: https://www.youtube.com/watch?v=pN41LvuSz10

← PreviousPage 2 of 7Next →