HNHacker News
TopNewBestAskShowJobs

randywaterhouse

194 karma · joined October 26, 2013

submissionscomments
randywaterhouse··on Many FBI agents are struggling to make ends meet. Housing costs are to blame
This is common practice across the US and the rule-of-thumb 40x generally tries to take most cases into account. i.e., 40x after taxes and other typical debt levels is "risk appropriate" for landlords... Though don't get me started on how this reduces landlord risk to a level where they should not see profits...

It does seem odd though when you consider one person with 40x may have a completely different net than another.

randywaterhouse··on The new Paris métro
Underground, perhaps (although German's U-Bahn is the equivalent). Metro, accent aside, is in common use worldwide, isn't it? (Tokyo, Washington DC, to name two Metro systems)
randywaterhouse··on Wiretrustee CM4 Stata Board (Discontinued)
Posted this after receiving an email from the Wiretrustee team this afternoon. Unfortunately it seems their RPi CM4 SATA board has been cancelled (supply chain!). Full text of the email appears below.

---

After you haven't heard from us since August, we are calling you with some news today. It is with a heavy heart that we have to announce that we have stopped working on the Wiretrustee CM4 SATA board. It was a very exciting time for all of us in the team during which we received a lot of support from all of you. Almost 10,000 followers of our Crowd Supply page show that we were not completely wrong.

But in the end, we don't see any improvements in the current situation of the global electronic components supply chain. So far, there's no telling when we might be able to offer you the board at an acceptable price.

To offer you at least something, we have decided to open-source all the design files that we created so far. You will find them soon on GitHub under the following link: https://github.com/wiretrustee/cm4-sata-board

In the meantime, we have fully dedicated ourselves to another project and further expanded the P2P network developed for the board. We will now continue to pursue this with full force and extend it with further functionalities to a full open-source alternative for traditional VPN.

We would be very happy if you support us in this project and leave us a star on GitHub. https://github.com/wiretrustee/wiretrustee

randywaterhouse··on Tracking Covid-19 variant B.1.1.529
I think it's largely too early to say (in the sense that it has yet to be thoroughly researched in vaxx'd areas). It's clearly taken over the population of infections in South Africa but they're rolling with fairly low vax rates (I have seen a few figures reported but < 40%).

There are some protein/spike characteristics of this variant which alarm scientists who think it might evade vax-generated antibodies better--i.e. alpha/delta-targeting vax antibodies may provide less resistance to this one.

So on the one hand it //could be// worse than Delta but I am personally waiting for more data to flow out (esp. beyond SA).

randywaterhouse··on Ask HN: Was Your Turkey Dry?
Deep fried at 350F for just over an hour. Bird was ~17lbs. Pulled with the thickest part of the breast at 155F (other parts were hotter).

Did pseudo "dry brine" by salting it lightly 48h before it's molten bath. Came out juicy and, more importantly for the skin lovers, crackly.

randywaterhouse··on UK national extradited to US for film/TV piracy
> "for his involvement in the Sparks Group, an international piracy group that illegally distributed movies and television shows on the Internet."

(from the announcement) in case you were wondering if this was some "simple" torrent usage or what...

> "In furtherance of its scheme, the Sparks Group fraudulently obtained copyrighted DVDs and Blu-Ray discs from wholesale distributors in advance of their retail release date by, among other things, making various misrepresentations to the wholesale distributors concerning the reasons that they were obtaining the discs prior to the retail release date."

randywaterhouse··on Binance's Insurance Fund
Thought this was a compelling illustration of how market dynamics intersect w. potential shenanigans... Carol is careful to not level any direct accusations, which I appreciate--but the presentation definitely suggests the data is either inaccurate or the liquidation was in Binance's favor (unwittingly or otherwise).
randywaterhouse··on Why do recipe writers lie about how long it takes to caramelize onions? (2012)
Wholeheartedly agree about process vs. color-by-number recipes... For those who do like to read offline, I do recommend Ruhlman's "Twenty" [0]. It is well written and illustrated and provides a lens into process via carefully selected recipes.

[0] Full title being ``Ruhlman's Twenty: 20 Techniques, 100 Recipes, A Cook's Manifesto (The Science of Cooking, Culinary Books, Chef Cookbooks, Cooking Techniques Book)``

randywaterhouse··on How I Learned Symmetric-Key Cryptanalysis
Cracking DES as set 9 of cryptopals [0] :) ? Awesome challenges in general, of course, but iirc no actually breaking a symmetric key cipher ("actually" doing a lot of work here, I admit, since there's all kinds of oracle attacks which are awesome!).

[0] For the uninitiated: https://cryptopals.com, which is of the parent's and collaborators' creation!

Ninja edit to add: This is all in good fun, recognizing that cryptopals focuses on real-world crypto that actually is used today!

randywaterhouse··on Crypto crash deepens, stocks slip
And, as usual, Coinbase is also down at the moment [0]. Don't have a super-strong opinion on the crash itself (or whether we should call it a crash given crypto's volatility)--but it does seem peculiar that the exchanges in the space tend to drop when things get rough.

[0] https://status.coinbase.com as of 13:51 UTC status was "intermittent downtime" and "delayed withdrawals"

randywaterhouse··on Unbound DNS Blacklist
I use Unbound in a similar way, although I return 0.0.0.0 rather than NXDOMAIN. Don't really know why I decided to go that route, but when I was setting my Unbound server up I'd read how quad 0's was the pi-hole's preferred setting [0]. Seems the articles' script would accept such a setup too, via the ${TYPE} parameter (or maybe a slight rewrite of the `echo` later on there).

[0] https://docs.pi-hole.net/ftldns/blockingmode/

randywaterhouse··on Wirecard offices searched as prosecutors probe management board
Seems to be using a university proxy to get around FT's usual paywall. I had not seen this method before, am somewhat surprised the university proxy doesn't require some kind of SSO/auth. (if it's indeed working the way I surmise.)
randywaterhouse··on Virtual private networks with WireGuard
While I have no idea given the... oddity... of this subthread, I might posit `tinc` is being referred to here: https://www.tinc-vpn.org/faq/

ETA: this is based on the open source code which may be modified, userland daemon status, /dev/tap usage... Portability... etc.

In any case - tinc is excellent

randywaterhouse··on Bitcoin (BTC) is up by +22% in a single day, valued at over $14,600
Might be an indicator of the old FOMO maneuvers. Whether the underlying realities are solid (fast, cheap transactions) or not is less relevant if people were, say, profit taking on their alts and pouring it into BTC since they feel BTC is rallying more/consistently with the spotlight on it.

Interesting observation, in any case.

randywaterhouse··on High-Speed Trading: Lines, Radios, and Cables
Sniper in Mahwah [1] details a lot of the structure of HFT trading infrastructure, especially how microwave towers are used. It's a rabbit hole though, he's got tons of stuff on the various ways HFT networks make things work, including their licensing and contracting.

[1] https://sniperinmahwah.wordpress.com

randywaterhouse··on Bitcoin Mining Now Consuming More Electricity Than Many Countries
I've heard a number of conflicting arguments about the reliability of Ethereum switching to proof of stake... From "they will" to "this is difficult, why bother". There's also the other side of the equation - what's the value-add, and is it justified by the consumption? (e.g. the banks, trucks, etc. do something for the financial system, which has value. Is value / cost higher for BTC or lower?)

I do not know.

randywaterhouse··on Bitcoin Mining Now Consuming More Electricity Than Many Countries
I recall seeing this comment as well. Measuring BTC in GWP is an odd concept - maybe I misread - but I take it that means 2 trillion worth of global world product is made in BTC? Or just that BTC price X coins in existence = 2 trillion?

Apparently today we consume 100% of our energy (hah!) for GWP of 78 trillion (nominal) [1]. So 2% for 2 trillion would actually appear to be more efficient. But again, I am not sure if this definition is even real, nor does this math apply.

Maybe this is up there with bitcoin "market cap" or "price to earnings" terminology... :|

[1] https://en.wikipedia.org/wiki/Gross_world_product

randywaterhouse··on Warning Signs About Another Giant Bitcoin Exchange
One thing I have been remarking recent conversations with other long-interested crypto-friends hasn't been about the price action, or about the drama, or about the lack of transparency on exchanges like Bitfinex -- but rather about the comparability of discussions today to those we were having in 2013. (Disclaimer: I attempt to avoid holding strong opinions in this space)

There are certainly patterns in the environment (maybe marketplace) which are repetitive and reminiscent of the early days. Confusion around price is one. Two viscerally opposed schools-of-thought is another.

One thing I think, though, that has suffered is the availability of information assessing the market structure or environment on it's merits/deficiencies without bias. This is likely hard to achieve, in general, but these days you cannot find reliable news without being sucked in to the swirl. Coindesk is pulling a CNBC-of-crypto, articles flying out every hour with opposing themes. I totally understand the model, captivating the audience, but it makes it hard to observe what's happening fundamentally (without having a grasp on the core narrative).

I continue to follow, in a casual way, but as I said continuously impressed by how the environment remains young -- trends from '13 persist to '17 and probably '18 (still young!).

randywaterhouse··on FBI Is Building a Watchlist That Gives Companies Real Time Updates on Employees
We've already lost when an arrest is equivalent to a conviction.

Although, in some ways, we've been here for a while. Maybe less-so for individuals but for corporations, whom the law generally treats with a degree of "individual" rights (IANAL), it's long been that an indictment is worse than a conviction. After an indictment, clients turn away -> revenue flees -> shutters.

What's scary is an indictment is, in theory (under fair application of the principles of law), is more severe than a simple arrest. If we're living in a system (US) where a simple arrest results in a database entry which can result in the end of your productive life, we're living in a... [up to the reader to determine the severity]

Ultimately, the power of gov't to drop charges after such a consequence (firing) is powerful and unfair to the individual. Indeed.

randywaterhouse··on J.S.G. Boggs, artist and trickster, has died
Interesting bit on the authorities viewing him as a counterfeiter. I'd guess that if parties are willing, and none are misrepresenting the note as currency, it's alright and a transaction of goods/services in exchange for art. His Wikipedia article [1] profiles a few cases where he ended up arrested - interesting. I suppose in some cases, like the waitress example in the article - the waitstaff may not be able to legally accept the fake note on behalf of the establishment (so hopefully the waitstaff would put one of their own $10 in the register...)

Further, I suppose, there's an argument for counterfeiting of bills being legally interpreted simply as their production even without the misrepresentation bit. This'll lead me on a merry chase, I'm sure.

[1] https://en.wikipedia.org/wiki/J._S._G._Boggs

randywaterhouse··on Vancouver house prices are falling
Granted, short-term losses are undeniable.

But long-term, ordinary Canadians living in these properties stand to make out alright (indeed - assuming this is not a long-term depression in prices). They get their utility out of the property (if city rents are 2-3K/mo for a 2 bedroom, that's 480K over 20 years in "cost of renting the space" which they don't end up incurring).

I cannot speak for Vancouver, but scenarios in the US where cities saw non-trivial % declines had those % returned in-kind within a decade. So we're seeing short-term losses, it will impact folks selling today or tomorrow, but not in 10 years (as I've caveat-ed along the way: probably).

randywaterhouse··on Yahoo sold to US telecoms giant Verizon
Interesting to consider the reasons for the past valuation -- before everyone realized Alibaba was blowing up (I believe it was < $1bn of that $44bn deal).

So, in 2016 dollars we're talking $5bn for their core web business vs. 50bn+ (2016 dollars) for the 2008 MSFT offer.

randywaterhouse··on Poll: how many productive hours do you have in a day?
I answered 6-8 hours, although its rare they are adjacent hours of productivity. I am a student though, which may make me a little off-topic for this question, but it is time spent researching, designing, and implementing complex physical models in C++, Python, and/or Matlab (I'm a physicist, computational).

As I am a student... The hours can be very weird. I can walk around my room aimlessly, repeatedly, not capable of doing a single thing for entire hours. But then I sit down at my desk and churn out a few hundred lines of code and write up a report that uses the results of that code. "In-the-zone" can be anything from 3 hours to 6 consecutively, and what triggers it I do not know.

Some of my compatriots feel the need to fool themselves into working 12+ hours a day on their assorted homework/code-work... I try not to do this, and generally I'm very low-stress, because I know when I need to be I crank out pages upon pages of (hopefully high quality) empirical work (assuming I have the data). It's much less frazzling than "omg I can't see my friends or chill for even an hour for coffee... Because I have an exam on Monday". An hour never killed anyone :D

Just my 0.02

randywaterhouse··on The user is drunk (2013) [video]
It's perhaps a slight exaggeration, but it is to make his point that "UI dead simple" >> "Complex UI that you can't tell what's what with a blur".

You may not have had blurry vision... But your attitude may have been as if you did have blurry vision. Oh there's no big colorful button? X. Oh this sight is monotone? Boring. X.

His points are prescient, if exaggerated.

randywaterhouse··on Bitcoin Falls Below $400
Sure. If one had conviction that it would rise. One could buy now and see it at 10 bucks by the end of the week. If one had that belief... One would not invest.

If you have conviction BTC will be back then of course you'd get in now. But people thought getting in at 600 was a deal at one time... Look where we are. Those people aren't too pleased if they had conviction it was going to 1000 again.

If volatility has taught us anything, it is to be wary. Volatility means up-swings and down-swings. Perhaps the past year was just an up-swing and we're doing some mean-reversion. It's foolish to make blanket statements.

randywaterhouse··on [dead]
Without stated context I of course jumped on this link like "oh jeez what's Mozilla done, broken some click-to-flirt functionality on OkCupid"!?

But alas, it is not a technical reason. Nor even a product oriented one. It is a political statement regarding the head of the nonprofit Mozilla Foundation. So he made a mistake. Once. Maybe many times. That's his personal dealings, and while one may dislike Eich personally for this, and one may be inclined to not vote for Eich in, say, a public election, I find it absurd to protest a product that has but a tenuous connection to the man.

Firefox is, has been, and probably will be for a long time into the future (we hope) a product of many hardworking people, perhaps the least of which is the CEO, so far removed from the product we all know and (some) love. The speed, the engineering... Has nothing to do with Eich. He drives the overall vision of the foundation, naturally, as CEOs do. Does his personal preference/mistake mean he's going to destroy Firefox? No. Does it even mean he will destroy Mozilla with his personal viewpoint on social issues? Probably not. Does it mean he a "bad" guy? Well, on the whole one is inclined to say no, although it will and is argued he has a character flaw, this may be true.

The philosophy of dropping one of the most widely use browsers (outside of corporate environments) simply due to one man's one-time view... Seem absurd.

(I've tried my best to avoid putting my own opinion on his viewpoint in here, but perhaps he's made a mistake or two in the past. Given the amount of criticism recently, this much is clear, now.)

randywaterhouse··on GitHub under DDoS attack right now (again...)
There are two types of DDoS attacks, which Github actually wrote about last week (thereabouts[1]), although you'll be unable to read the blog post until the site is back (unfortunately).

But I can outline the two they discussed. The first is a "complex attack", which basically consists of doing things that make the server overload itself (repeatedly handshaking SSL, etc.), and that would be mitigated to some extent by reducing the complexity of the site (i.e. you can't SSL handshake with a server that only knows HTTP). Similarly, dynamic content could be an attack surface, so static content would make it more difficult to use such a complexity attack.

The other type of attack, a simple bandwidth attack, doesn't care if your server is a top-of-the-line quad-chip Xeon server or an RPi in your basement, because all it does is exploit the bottleneck that is bandwidth. This attack just pumps packets like mad in your direction, and your network will likely become congested (and eventually fail) at some level other than your server (i.e. router level, firewall can't handle 100 Gb/s so the packets never even make it to your server).

So, in light of the second there, DDoS'ing static content is just as easy as DDoS'ing dynamic content sites, as long as you're using a bandwidth type attack.

I encourage you to read the blog post when the site is back up, it's definitely worth a read!

[1] https://github.com/blog/1796-denial-of-service-attacks

randywaterhouse··on Ten Years of Coding Horror
"Along with the new design, you may also notice that comments are no longer present. Don't worry. I love comments. They'll all be back. This is only a temporary state, as there's another notable open source project I want to begin supporting here."

He's just shifted over to a new platform, as you likely would've understood from reading the article. And he explicitly states, as quoted, that comments will be back... Unsure how irony computes in this circumstance.

randywaterhouse··on TrueCrypt Master Key Extraction And Volume Identification
Implementations of crypto, such as Truecrypt, rely on algorithms/ciphers such as AES which (in some modes) basically appears random... But the appearance of randomness is not enough if someone is convinced there is meaningful data there. Of course, a break such as "we can tell if there's a hidden truecrypt volume" is bad, and if I recall correctly there are ways of doing this now.

You'd need to basically never transmit the data, transmission automatically implies there is something there. If you didn't transmit, just used the data locally... And it appeared random, you'd have a pretty solid case for "they can't know". But if you slip up just once it's all over. They know.

randywaterhouse··on TrueCrypt Master Key Extraction And Volume Identification
Right.

This would emphasize the need to always be cautious in your use of cryptosystems, since you cannot simply claim "oh my data is Truecrypt'd". That will not save you from everything by itself. But if you look into the documentation, Truecrypt itself warns you about using it, and the threat model is very careful in defining what steps you need to take to adequately protect your data with Truecrypt.

It's one of those things where for most people, just a file-volume (the simplest kind where it's just a file that can be mounted as a block device), will do fine. The write-to-disk wouldn't happen very often, and to lose your data to a thief would require both the unlikely "OS dumped the memory to disk" (meaning the OS doesn't respect the flags TC puts on that memory), AND on top of that "a thief stole your laptop/desktop/external". If your adversary is organized crime, a law enforcement agency, or some other state-like actor with heavy-duty resources and specifically wants y-o-u... Then you'll need to be very careful and use a full disk encryption solution, or rather just not use a computer.

Know your tools. Know your adversary. Sleep a little easier knowing both. Or turn paranoid.

Page 1 of 2Next →