HNHacker News
TopNewBestAskShowJobs

professorTuring

335 karma · joined February 13, 2013

Cybersecurity
submissionscomments
professorTuring··on You've just inherited a legacy C++ codebase, now what?
How good is AI refactoring the code? Haven’t tried it yet, but… as someone who has need to work on tons of legacy in the past… looks interesting!
professorTuring··on Why diets backfire: A year after weight loss, the desire to eat grows (2018)
Have you thought why isn’t sustainable for you?

The main problem I faced was giving in “just this time”. Fat and sugar are addictive and when you fall, it makes it easier to fall again.

About healthy food, I had overweight and I mostly ate “healthy food”. I needed to go to a nutritionist and ask him why.

This is what O was eating a year and a half ago:

Breakfast: two bread slices with avocado.

Meal: mostly salads with lettuce, tomato, tuna, avocado, carrots, salt, vinegar and extra virgin olive oil. (I really wanted to lose weight).

Dinner: chicken, sushi, eggs… normally I would add a handful of seeds/nuts.

This is what my nutriotionist told me: you have been eating quite healthy, the problem are the fats: too many healthy fats (extra virgin oil, avocado, nuts… nuts have a lot of fats).

Only add protein shakes when you are trying to gain muscle and you are not able to add normal proteins. I started on protein shakes once I was slim and not able to eat that much food to gain muscle.

A year later I am fully conscious of what I eat. I can have eventually a burger, but I am fully aware that it is really unhealthy.

My proteins today are mainly chicken and salmon, carbs: quinoa, rice, lentils… and almost no fat (I’m trying to get my fat % to 12… it’s quite difficult)

Also read all packaged ingredients you will find nasty surprises in form of fats and sugar in diet / “high protein” meals.

Also no juices!

professorTuring··on Why diets backfire: A year after weight loss, the desire to eat grows (2018)
What worked for me: - quit sugar - quit processed foods - avoid fried food - little fat (even the healthy ones) - no nuts/seeds - lifting weights - little cardio

I have completely changed my life in one year.

It has been a very tough path, mostly socially, going out and not having a beer, burger… social pressure… but when you believe in eating healthy everything goes smooth. Also measure the results, once you get 12-15% of body fat, you may be gaining muscle weight.

The goal should be changing your lifestyle to one that is healthy and sustainable.

professorTuring··on More students are turning away from college and toward apprenticeships
I believe it’s a good thing this shift towards apprenticeships, we don’t really need so many university graduates (I’m talking from an Spanish point of view).

More and more the university is degrading its own nature, focusing on preparing “workers” instead of cultivating the arts of knowledge: research, philosophy, history…

It is good that people from university goes to the private sectors, but we are doing it the wrong way, we do not need CS to go develop for Funny Startup, we need developers (technical apprentships) and probably some software architects (CS) that focus on how it should be done.

Private sector is pushing universities toward work training and we are falling back in advances and knowledge. The fine art of learn to learn, the place where people that love the field go instead than the people that searches for a job and money.

professorTuring··on Password Requirements: Myths and Madness
Not anymore, we used to do that and maybe a bunch of customers still have that device to log in, but we have been replacing them (the “hard token”) with a “soft token”, kind of a Google Authenticator linked to your mobile.

It is interesting how “yubi”things have moved in the opposite direction (back to the physical device) and it has its value, after all, leaving your home with all your savings in your pocket is a risk we need to address.

professorTuring··on Password Requirements: Myths and Madness
I lead Security in a quite large bank. I love this article, I’ve been advocating for this line of thoughts for more time that I can remember.

I have spoken to regulators hundreds of times, over this and a bunch other security topics that are definitely obsolete. Security policies that just don’t make sense…

The most important thing for this kind of things to advance is to have the correct people in the correct places, and usually in this positions you have dinosaurs…

professorTuring··on Binance outflows hit $6B as Mazars halts ‘proof of reserves’ work
We will end up using good old banks to hold those assets… at least the regulations make them solvent.

We need to read history and see what happened when the banks weren’t regulated enough and we are letting the crypto zoo run free and bankrupt many people.

Such a bliss the “we don’t need traditional ecosystem to thrive”.

I know how this is going to end, we will replicate the finance ecosystem into the cryptosystem.

I still remember the “don’t be evil” slogan in google, let’s give random people the power to store all our crypto investment and let’s see what happens…

professorTuring··on Security through obscurity is underrated (2020)
I loved the “5 monkeys” comparison and I agree that everything depends on the real case scenario.

My point here is that what the article propose it is no “security through obscurity” it’s just good configuration practices. Change username, port…

Security through obscurity goes along in the line: “I have this algorithm in the js that obfuscate the password in the front end, and nobody is gonna guess it because it’s super complex”.

professorTuring··on Gmail 2FA causes the homeless to permanently lose access 3 times a year
I can understand your statement, but by doing that you will find that A LOT of people will check the insecure options because “that a not going to happen to me”.

Remember you have the “rescue keys” from google to avoid these kind of problems.

The bigger problem is how you teach those people how to use the services in their situation.

professorTuring··on Want cleaner code? Use the rule of six
It is not new, it’s been ages since some developers try to show off by bringing “cool” one liners to solve problems. Stretching operators, bringing up imaginative uses for lambda expressions or kind of abusing parts of the language to make some other teammate or reviewer, What did you make there?

I believe, definitely, that they are quite intelligent people that know a lot about the language or maths, but definitely they are not usually making the smartest choice, because you should use “languages” in order for the people to understand you.

So you can call those: “50 cent expressions”

They help no one but their ego…

professorTuring··on Ask HN: How does your company handle late running projects?
There was a Saint that said: “I meditate one hour everyday, well everyday except when I have a lot of work, that day, I meditate two hours.”

That proverb is superb, when something is wrong and the team seems stressed I usually use it and we call a meeting to try to re-evaluate the situation.

Definitely you end up prioritizing and cutting in order to keep things on track.

Usually delays come from two sources: 1. Bells, whistles and nice to have functionality that are already working and keeps refining. 2. Engineers Ego: refactoring when they find that a nicer approach is possible. Just stop that and keep in mind that business comes first and you will eventually have time to rethink (if everything goes smooth).

Good luck!

professorTuring··on Show HN: Correct Horse Battery Staple password generator
lower, upper and numbers = 62 options | wordlist = 10 000 options:

    62^12     = 1e21
    10 000^5  = 1e20

The problem is you not using a word generator and instead relying in your invention, most of the people will use top 5000 words (5000^5 = 1e18), imagine you can even lock one of the words (a color maybe?).

So this way of thinking might be good if you know what you are doing and use uppers and lowers and symbols, if not, it is actually a bad advice.

professorTuring··on For $39, Frontier Air Will Let Passengers Keep Their Distance
So they are taking advantage of something that should be mandatory.

These are the things that let you know the kind of company you are dealing with.

professorTuring··on Which of these Amazon Prime purchases are real?
That is exactly what I feel.

More and more I find Amazon to be closer and closer to a Chinese Bazar of cheap quality items (kind of an AliExpress or dx but with a different perceived quality).

I believe they will gain a lot of customers among people who just want cheap stuff (or don't care if it is original as long as the brand is clearly visible and is cheaper) but definitely they will lose customers that use Amazon for convenience (more or less the same price, better refund policies, availability of products...)

It's a pity. Hopefully others will fill that space.

In Spain, El Corte Inglés with its new on-line platform is getting closer and closer.

professorTuring··on TeamViewer stores user passwords in registry, encrypted with hard-coded key
No, you can only access browser's stored passwords if you can log in as the user in the machine (see second response).

In this case, anyone can access that registry and get the pwd.

professorTuring··on TeamViewer stores user passwords in registry, encrypted with hard-coded key
I guess they were proud for using encryption instead of hashing, hence, more secure!

Definitely they didn't follow the one and only rule of security: don't roll your own.

professorTuring··on TeamViewer stores user passwords in registry, encrypted with hard-coded key
Kudos to the security expert for the finding but his web page gave eye cancer.

Seriously, consider lowering the contrast or chaging typography... Don't know, but it was hard to read in its original form...

professorTuring··on SMS is not 2FA-secure
There is a reason for that, most average Joes just can't handle the technology. You can change OTP-SMS in Banks for TOTP, but it involves more complexity and probably it will be more prone to user errors.

Configuring the seed, remembering an extra password to use the OTP... For me it's not that hard, but probably my mom will need some help in order to remember all the steps...

professorTuring··on SMS is not 2FA-secure
Not true. Not true by far. That's an over statement. 2FA is only one of two factors, you need the the password, you need the mobile number and you need to obtain a duplicate or being close to your victim.

You should be worried if you are a POI or you are being targeted personally. And if it is so, SIM Swapping it's just one option and if it doesn't work there are other methods (breaking in, stealing yubikeys, mobiles...)

professorTuring··on SMS is not 2FA-secure
Is SMS 2FA Secure? No, I agree.

Is SMS 2FA enough for most of the people today? Yes

Is SMS a cost-benefit solution for most uses? Yes

professorTuring··on Visualising the amount of microplastic we eat
Not long ago I watched a tv show from Spain that wanted to make some awareness about this topic. They bought some fish and prawns and more seafood that should contain "lots of microplastics".

They took all of it to a laboratory and the laboratory found nothing at all. The presenter told the audience that it was surprising for him, and that they thought that the results were a letdown for the purpose of the documentary but that it was "good news" that we can still enjoy food without microplastics...

I would say that the results will vary vastly depending on the place you obtain the samples, but anyway, we should change our relationship with plastic...

professorTuring··on Undocumented Catalina file access change
I'm reading comments and I think some of them are unfair.

First of all, I can see how this functionality is oriented towards the average Joe, not developers, sysadmins or hackers in general.

This helps the user, to an extent, to protect his assets from malware or accidents.

Also, it is undocumented, probably for a reason, this could be an early version that will be evolved and announced once the feel comfortable.

professorTuring··on Luxury hotel guests keep stealing mattresses
I was asking myself, how would I steal a mattress in a hotel?

Probably buying a new one, the cheapest for the size, I will exchange packaging, make the bed and... profit?

How long till the staff detect it?

professorTuring··on I stood up to my boss, then he got promoted
Some places = every big corp and big consultancy firms.
professorTuring··on I stood up to my boss, then he got promoted
I agree with you, and I've done that approach, but it is really more painful and it only works if later on you are considered a Guru (by them, not by you), hard worker and a go-to guy who always helps. And it takes longer to work.

The subtle way is less painful and you begin with the right foot.

professorTuring··on I stood up to my boss, then he got promoted
Communicating openly is a mistake. You should communicate in the way it serves both your purpose and the enterprise and to communicate you must know your audience and how the message should be passed in order to succeed.

Sometimes the only way to change things is to incept the idea.

professorTuring··on I stood up to my boss, then he got promoted
I read it all. Mistakes were made due to inexperience. Lessons should have been learnt. Wiser should he be by now.

Being aware of enterprise politics and learning how to play them will give you the opportunity to really impact the business.

Never be the guy who says:

1. "nobody does this in the enterprise"

2. "we are doing all of this wrong"

3. "we need to start from the beginning"

4. "my manager is wrong"

Whispers and grabbing coffees with people are much better weapons than being the one that always brings the harsh truth into the meetings.

Beware: pointing fingers to a colleague or your manager to upper management is telling them that they are not making their job good enough, they are not noticing things, and since they tend not to fail and to notice everything, the failure must be you.

professorTuring··on Scammers deepfake CEO’s voice to talk underling into $243k transfer?
I can see your point, but babblers != industry.
professorTuring··on Scammers deepfake CEO’s voice to talk underling into $243k transfer?
You are utterly wrong.

The real problem is that there is a vast need for professionals and the lack of them calls a lot of smoke-sellers. And for a lot of people is hard to tell wether they are legit.

Just look at the Machine Learning / Artificial Intelligence industry. Also "fraudulent" if you apply the same logic.

professorTuring··on ‘Juice Jacking’ Criminals Use Public USB Chargers to Steal Data
Don't get distracted, if they are exploiting an USB vulnerability the "don't allow" feature by default will do nothing.
Page 1 of 6Next →