HNHacker News
TopNewBestAskShowJobs

rainforest

347 karma · joined April 15, 2013

submissionscomments
rainforest··on Pulling JPEGs out of thin air
See also: Microsoft Code Digger [1], which generates inputs using symbolic execution for .net code, and EvoSuite, which uses a genetic algorithm to do the same for Java [2].

[1] : http://blogs.msdn.com/b/nikolait/archive/2013/04/23/introduc...

[2] : http://www.evosuite.org

rainforest··on FTDI driver kills fake FTDI FT232s
They have a track record of trying to fingerprint and screwing with counterfeits, so it would appear there's evidence the driver doesn't happen to disable counterfeits, but actively disables them. To me there's a fuzzy distinction (possibly not reflected in law) between software that breaks when you make it do stuff you didn't design, versus having it attack things you don't want it to work with.
rainforest··on Everything you need to know about the Shellshock Bash bug
The latter. Some daemons, like CGI scripts will spawn a shell populated with environment variables from the client. With a vulnerable bash, commands in these get executed.
rainforest··on Why the Security of USB Is Fundamentally Broken
You could have the OS randomly generate a token and give it to the device and require it to repeat it each time it's plugged in.

Devices without tokens or with unrecognised tokens would need user approval, those with the correct one would be trusted. That still doesn't solve the problem of deciding if a device should be trusted or not though.

rainforest··on Why the Security of USB Is Fundamentally Broken
> maybe this medium can also be compromised.

Indeed it can. Bunnie & xobs recently showed how to get code running on the controller chips of SD cards [1]. With your own implementation you could have the card present alternative files (clean vs infected) to different machines based on read patterns [2] or just a mount count. Without an exploit for the kernel, you'd still need the user to click on one the files, however.

That's not to say your suggestion isn't safer; SD cards don't present a threat to HID attacks (where a USB stick pretends to be a keyboard and is trusted to send inputs), but as with anything, it's not totally safe.

[1] : http://www.bunniestudios.com/blog/?p=3554

[2] : http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.h...

rainforest··on Hacking POS Terminal for Fun and Non-profit
That doesn't surprise me. I've seen these things (Aloha terminals) still running Windows 98. BOH was on Windows XP at least. From my experience, it's less about not having time, and more about being completely unaware of the requirement to patch the things.
rainforest··on Human data shows how we move in cities
Google Location History might have something (even if you don't expect it to) [1]

[1] : https://maps.google.com/locationhistory/b/0/

rainforest··on Tor exit node operator prosecuted in Austria
Exit nodes are already unnecessary; TOR allows you to operate services on the network itself ("hidden services").

However, it seems not everything is kept on the TOR network. I would've assumed that if someone were using TOR for criminal purposes, they wouldn't expose themselves to monitoring by accessing resources off TOR, but that doesn't seem to be the case.

rainforest··on Theresa May pushes for greater surveillance powers
Playing devil's advocate a little, the value in the data from an intelligence perspective is probably in the network it uncovers. If you know a circle of people are regularly exchanging encrypted messages, then you can try to target one member and get them to compromise the group by turning them into an informant. Similarly, if you suspect someone, you can look at their records to discover the networks of potential conspirators, then fan-out for each member until you have a big picture of interactions between different networks.

There's a great example of exploiting simple person-person interaction graphs to generate this information here: http://kieranhealy.org/blog/archives/2013/06/09/using-metada...

rainforest··on Google Cardboard
I don't think you'll get the right effect, if you cross your eyes your left eye will see the image intended for the right eye (the lenses don't focus on the opposing image). Still seems to give some sense of depth, though.
rainforest··on Android Needs A Simulator, Not An Emulator
I like this idea as well, it seems fruitful enough that at least one organisation is providing it [0]. I would have thought overheads of getting new devices might cut into revenue though. I'd be interested to see what the difference in experience is for something on an emulated device (with HAXM) and a remote real device though, and if it's substantial enough to be worth paying for.

[0] : http://www.keynote.com/solutions/testing/mobile-testing

rainforest··on "We need a pony. And the moon on a stick. By next Thursday."
This paper appears to claim up to 91% accuracy (precision) [1] by looking at hashtags, with a description of the approach they use (and a link to the software). The approaches probably aren't directly comparable since one depends on hashtags while the other doesn't though.

[1] : https://gate.ac.uk/sale/lrec2014/arcomem/sarcasm.pdf

rainforest··on Static energy consumption analysis of LLVM IR programs
See also: Wattch[1], a similar framework based on a similar idea. Wattch relies on simulation of the target rather than static analysis, however, but the application of instruction-level cost models seems the same.

[1] : http://www.eecs.harvard.edu/~dbrooks/isca2000.pdf

rainforest··on Using Genetic Algorithms to Break Things
EvoSuite springs to mind for that one [1]. Java only though, but their publications describe how it works well enough to port the ideas from what I can tell.

[1]: http://www.evosuite.org

rainforest··on Adaptive Parallel Computation with CUDA Dynamic Parallelism
I think Nvidia is at a point now where the CUDA toolkit is well-established that it can afford to start squeezing the people already using it. Based on my perspective (academia), universities seem to have invested heavily in CUDA, meaning a lot of faculties tend to use it (or rely on builtin CUDA support in FEA/CFD/MATLAB) for HPC where they need performance .

I'd be interested to see how much of the breakdown in revenue for their compute cards is for academia, government and industry though.

rainforest··on Vulnerability in Internet Explorer Could Allow Remote Code Execution
It seems from the subtitle that this isn't just a known vulnerability, but one being exploited in the wild, if I'm not mistaken. Definitely a serious concern either way though.
rainforest··on QEMU 2.0.0 Released
In addition to KVM use couradical points out, it's also used in the Bitblaze BAP tool's TEMU component[1], which does dynamic analysis (including taint tracking) over x86 programs and kernels.

[1] http://bitblaze.cs.berkeley.edu/temu.html

rainforest··on 5-year-old Ocean Beach boy exposes Microsoft Xbox vulnerability
The article mentions the field was for a verification password; would Microsoft really admit that they'd implemented such a backdoor (a very strange one at that)?

To me it seems more plausible that the verification answer was a series of spaces. Perhaps the bounty was paid for noticing insecure verification answers weren't rejected?

rainforest··on Ottawa Bitcoin exchange defrauded of $100,000 in cyber currency
In this case the wallet was stolen from the machine after it was rebooted into single user mode. With FDE the machine wouldn't have been usable when it was rebooted so the attack wouldn't have worked.
rainforest··on Introducing the new BBC iPlayer
That's interesting. Do you know why content providers are OK for content to go to iOS without DRM (beyond client certificate checks) but not to Android or the desktop?
rainforest··on App-pocalypse Now
The iOS model uses App Store reviews (with whatever static analysis secret sauce they do), plus user permission requests for access to some things like location and contacts.

I'd suggest Nokia's Symbian permission model was better, if a little annoying. It asked each time the app tried to use a given permission (until you permanently allowed/disallowed it).

rainforest··on Important Kickstarter Security Notice
Does that mean that Facebook will revoke them, or are they useless to an attacker?
rainforest··on Apple's Remote Desktop client is bundled for free with every Mac
Works with the open command from a shell too: open vnc://my_remote_mac
rainforest··on Sony’s 2001 offer from Steve Jobs to run Mac OS on Vaio laptops
Could you elaborate on that? I would assume that most compiler steps are linear traversals of graphs and the time comes from lots of small IOs.
rainforest··on Ray Kurzweil is wrong: The Singularity is not near
Isn't that part of the author's point? That Kurzweil is picking and choosing exponential developments because they fit his narrative? Since none of us know what the requirements of the Singularity are, it seems odd to extrapolate from a single abstract indicator and assume that it will happen "somewhere" on that line.
rainforest··on Ray Kurzweil is wrong: The Singularity is not near
Externally yes, but what if you can't hot swap consciousness? What if "you" remain in your body and all that happens is a clone of you is produced? Externally, both you and the clone behave identically and assert that you're the same person.
rainforest··on Printable True Bugs Wait Posters
It's worth noting that strncpy doesn't always null-terminate strings (on some platforms), so strlcpy is preferable.
rainforest··on Why I'm Betting On Julia
Patrick Burns' R inferno[1] enumerates a lot of R's eccentricities and workarounds for them. I think R gets a lot better once you switch to using the libraries Hadley maintains like plyr and ggplot. I still think proficiency in R is akin to a type of Stockholm syndrome.

[1] : http://www.burns-stat.com/pages/Tutor/R_inferno.pdf [PDF]

rainforest··on A useful Caps Lock key
One solution for the menubar shortcuts on OSX is to use the help menu. Hit Cmd + Shift + / and it'll jump to it, from there you can type any menu command and invoke it when you hit return.
rainforest··on UK Porn filters block sex education websites
The big deal is that the filter is beyond your control, and the cost is transferred to the customers regardless of their use of the filter or lack thereof.

This is clear evidence that filtering is a terrible way to block "objectionable" content, that it won't make anyone safer; any confidence in it is baseless so the whole thing is just a waste of customers' money.

← PreviousPage 4 of 6Next →