HNHacker News
TopNewBestAskShowJobs

provost

606 karma · joined April 23, 2014

submissionscomments
provost··on Border Search of Electronic Devices – CBP Directive [pdf]
Section 5.3 pertains to requesting passcodes, and that an Officer may ask you for the passcode (I don't see anything about individuals being obligated -- though see 5.3.4, which could be interpreted by "legal remedies"). However, section 5.3.3 says:

> If an officer is unable to complete an inspection of an electronic device because it is protected by a passcode or encryption, the Officer may, in accordance with section 5.4 below, detain the device pending a determination as to its admissibility, exclusion, or other disposition.

Section 5.4 elaborates further.

Also, I found 5.1.2 interesting:

> Officers may not intentionally use the device to access information that is solely stored remotely. To avoid retrieving or accessing information stored remotely and not otherwise present on the device, Officers will either request that the traveler disable connectivity to any network (e.g. by placing the device in airplane mode), or, where warranted by national security, law enforcement, officer safety, or other operational considerations, Officers will themselves disable network connectivity.

provost··on China offers 10-year visas to 'high end talent'
Looked into the taxes: for regular employees there are 7 brackets. Anything over 80,000RMB (12320 US Dollar) is taxed at 45%. Though it looks like if your income is derived by a company outside China, and you live there for >=1 and <= 5 years, you are exempted from taxes. Freelancers have 3 levels (between 20% to 40%).

[1] https://www.ecovis.com/focus-china/individual-income-tax-iit...

provost··on Announcing Rust 1.23
I haven't started playing around with Rust yet, but I'm interested in it.

If you're using Rust -- tell me, what are you building in it? And what do you love about Rust in your experience while building it? (Get me excited)

provost··on “Negative Result: Reading Kernel Memory from User Mode” (Intel CPU Bug)
For those that may be confused, I was also confused by the author's "negative result" comments at the top, but he elaborates near the end..

> So at this point my experiment is failed and thus the negative result.

> While I did set out to read kernel mode without privileges and that produced a negative result, I do feel like I opened a Pandora’s box. The thing is there was two positive results in my tests. The first is that Intel’s implementation of Tomasulo’s algorithm is not side channel safe. Consequently we have access to results of speculative execution despite the results never being committed. Secondly, my results demonstrate that speculative execution does indeed continue despite violations of the isolation between kernel mode and user mode.

provost··on In the time you spend on social media each year, you could read 200 books
TL;DR : To read 200 books, author estimates you need 417 hours a year reading. Assumes 50,000 page non-fiction books and 400 word per minute. Supposedly, average American spends 2250 on social media + TV.

The author also mentions multi-medium, which is what I do too (reading on phone, Kindle, and audiobook). And amazon whispersync pairs your kindle book to Audible narration, and lets you easily switch between reading and listening.

provost··on U.S. oil production booms as new year begins
128 fresh drilled-but-uncompleted wells in a month seems impressive (they show 94 as the change, but are subtracting 34 that were completed). Drilling roughly four a day.
provost··on GovCon7
Should have a [2011] tag. Not sure why this Palantir content is posted now?
provost··on Exmo Bitcoin exchange chief executive kidnapped in Kiev
Wow, this is awful. I've met coin exchange directors, and one of them mentioned to me that this was a topic of concern within their management. Specifically that their families might be targeted too. I don't know anything about Mr. Lerner, but hopefully the police will find him safe, soon.
provost··on The Door Problem (2014)
And the inevitable, "It shouldn't be that hard to add a door, you can do that in 30 minutes, right?"
provost··on At Vice, Cutting-Edge Media and Allegations of Old-School Sexual Harassment
I'll criticize Murs as well -- his behavior is also disgusting. However, please leave racial comments out of this.
provost··on Ten years in, nobody has come up with a use for blockchain
Hopefully this thread will be different than all the others. Someone is likely to appear here with a counterargument, which I'm looking forward to reading.

However, in addition to any counterarguments, please describe why standard tech and/or a 3rd_party is insufficient for your proposed use-cases. This is HackerNews after all, and we desire the deeply technical discussion and context, not propaganda.

provost··on At Vice, Cutting-Edge Media and Allegations of Old-School Sexual Harassment
> In 2003 Vice reached a $25,000 settlement with the freelance writer Jessica Hopper. The deal involved defamation claims tied to an interview she did with the rapper Murs that was published in the February 2003 issue of the magazine, according to a copy of the agreement viewed by The Times. During the interview, Murs asked Ms. Hopper if he could have sex with her. She said no and included that answer in her article.

> But before the article was published, the magazine changed her response to yes and printed it under the headline, “I Got Laid But Murs Didn’t.”

> Mortified, Ms. Hopper hired lawyers. The two sides struck a settlement that, in addition to a payout, required Vice to print a retraction and a formal apology.

Wow. I feel so poorly for Ms. Hopper. They defamed her and shamed her, yet a $25,000 settlement likely only paid for her lawyers. Disgusting -- they should feel ashamed.

provost··on Show HN: Build your Linux from Scratch inside Docker with one command
So if I'm understanding this correctly, this builds the LFS kernel inside a docker container into an ISO image that can be used with VirtualBox, but cannot be used within a Docker container itself?
provost··on Internet protocols are changing
No mention of BGP in the article?
provost··on Bitcoin Futures Start with a Bang as Rally Trips Circuit Breaker
Sounds like if a fork were to happen soon (not that it will) they would have to freeze the exchange, as they don't have a plan. I've noticed Coinbase does this as well, though they email a clear explanation about each upcoming fork-freezes and their intentions for each scenario.
provost··on DuckDuckGo XSS vulnerability
Thanks for the update and follow-up answers.

Could you comment on the "Reported in March 2017, emailed them 9 times about the issue since then. Still unfixed as of now." claim, as it seems imperative to the discussion?

Is there something that can be improved here? Perhaps that inbox not as actively monitored as it could be?

provost··on Ask HN: Huge enterprise customer wants to see our source code
There is a list of pre-approved apps, and a method to request approval if it is not on the list. Also, there is a list of approved licenses for open source software.
provost··on Regarding the NiceHash security breach
> Importantly, our payment system was compromised and the contents of the NiceHash Bitcoin wallet have been stolen. We are working to verify the precise number of BTC taken.

That should be easy to find via the transactions. Are they still in your wallet? What's the address? If they are still in there, then use a backup key to move the BTC now. Do you have a backup of the keys?

Being that it is connected to a payment system, it's surely the hot-wallet. No mention of a cold-wallet makes it seem they've been completely wiped.

Multi-edit: Stream of consciousness

provost··on A Final Farewell
Had to look up their page (getfinal.com). Had I known about this product, I probably would have embraced it. Wish the team the best of luck, and hope it gets revived!
provost··on Ask HN: Huge enterprise customer wants to see our source code
One thing I would note is that the individual employee might not be authorized to sign a legal document, such as "a non-compete and or a non-disclosure". My company informs us told to actively refuse to sign any legal documents (even at visitor check-in) -- we have a Legal team for that. All documents should be signed by Legal before I step on site.
provost··on Hearing on Cybersecurity of Voting Machines: Testimony of Prof. Matt Blaze [pdf]
They don't. This post is a rare congressional testimony by a subject matter expert, on a security & technology topic.

The rest of the posts you're alluding to are weak, media articles by non-experts.

provost··on Which cryptocurrencies are you buying and why?
None, because while I like the technology, I don't trust the politics, propaganda, and decision makers.
provost··on Sinking container ships by hacking load plan software
It's interesting that the lack of this data was one of the failure points for Target's $4.4 billion USD Canadian expansion that ended in failure. It's a really interesting story [0]

> A team assigned to investigate the problem discovered an astounding number of errors. Product dimensions would be in inches, not centimetres or entered in the wrong order: width by height by length, instead of, say, length by width by height. Sometimes the wrong currency was used. Item descriptions were vague. Important information was missing. There were myriad typos. “You name it, it was wrong,” says a former employee. “It was a disaster.”

> Getting the details from suppliers largely fell on the young merchandising assistants. In the industry, information from vendors is notoriously unreliable, but merchandising assistants were often not experienced enough to challenge vendors on the accuracy of the product information they provided.

> The investigative team estimated information in the system was accurate about 30% of the time.

[0] Source: http://www.macleans.ca/economy/business/what-really-happened...

provost··on “Security problems are primarily just bugs”
> Things are no secure or insecure in general, thus non-functional.

I would disagree with this assertion. A really common phrase in the infosec community is that "Security is not binary"

provost··on The Cost Center Trap
This is a clever analogy. Did you get this from somewhere? I'm curious what other finance analogies mix with IT/business?
provost··on Denver Radically Expanded Its Transit, So Why Are More People Driving Cars?
> our section of the rail to beyond 2040

Whoa, what's their explanation for it to take 23+ more years? That seems unreasonable.

provost··on NOw Google is locking journalists out of their Google Docs
Headline is exaggerated and does not reflect the tweet's update. Google says that it was a code mistake that identified it as "abusive" and has reverted the change. Still interesting, but the headline here is misinformation if taken at face-value.
provost··on Parity Wallet security alert
> This means that currently no funds can be moved out of the multi-sig wallets.

Wait, am I reading this right? All multi-sig wallets are frozen due to this? This is surely concerning, as I've seen others recommend multi-sig wallets as a security best practice.

Can anyone comment on the method in which they might revert this? Would it require a hard fork.. again?

provost··on Daydreaming means you’re smart and creative
Wow, I thought this was normal. Didn't consider it disturbing until now that you and the other comments mentioned it, and reflecting on how little I think about driving.
provost··on Boom has orders for 76 of its future supersonic passenger jets
Because we simply can't trust computers & systems engineering 100%. Go read about Flight QF72:

http://www.theherald.com.au/story/4659526/the-untold-story-o...

← PreviousPage 2 of 5Next →