HNHacker News
TopNewBestAskShowJobs

red0point

635 karma · joined March 23, 2015

submissionscomments
red0point··on I wasted $40k on a fantastic startup idea (2020)
I think the takeaway from the blog post is wrong and comments focusing on building a faster MVP miss the point.

Not everything is a startup. This is a research project - and should be approached that way. There should be donors, a foundation, free access to all participants, reputation-building by writing (& publishing in reputable journals / conferences) studies about its efficacy, a board of doctors actually reviewing & cross-checking recommendations, a doctor-to-doctor helpline, etc.

As the author found out - it's not something people want to buy, but the public. So I think if you approach it from that direction - it might just work.

red0point··on Show HN: Bionic Reading – Formats text to make it faster to read
The rules implemented are very simple (taken from the patent application [1], the exact numbers are configurable).

  If there are <= 3 letters, one letter is bold.
  If there are == 4 letters, two letters are bold.
  If there are > 4 letters, 40% of all letters are bold.
There is this claim as the first text on the website:

  We are happy if as many people as possible can use the advantage of Bionic Reading. For this reason, Bionic Reading should be able to be integrated into existing apps and services. The benefit for the reader should be the main focus.
If that is truly correct, why not publish these 3 rules? Why hide it behind multiple patent applications and trademarks? Why spend all this time and money on patents and an API that probably involve sending all text to some servers, just so that these 3 lines of code can be executed?

[1] https://patents.google.com/patent/DE102017112916A1/en

red0point··on LTrack: Stealthy Tracking of Mobile Phones in LTE
It‘s a very cool approach, I think where it falls short is that each UE will get the same key.

Much of the infrastructure around LTE & 5G is based on the assumption that noone but the operator has this key. However, since everyone has this key, it must now be considered public (since every SIM card can be used decode and encode any connection from any user).

This means that:

- The full connection plaintext will be leaked (yes, you should do TLS, but Metadata) - The IMEI (unique and persistent identifier of a phone) can be requested at will from an attacker (and is often requested by the operator at the beginning), thus allowing you to be tracked not only by the operator, but by any entity sniffing the wireless channel - Measurement Reports containing the exact GPS coordinates can be sniffed or requested by anyone

Still, it could be something for 6G for sure.

red0point··on LTrack: Stealthy Tracking of Mobile Phones in LTE
They still do, since in 5G you can capture a SUCI, replace it on a later connection attempt, and observe if the phone can still attach. See [1], section 5.2.3, and it‘s implemented in [2].

Finally, localization attacks could potentially still work as well.

[1] https://arxiv.org/pdf/1806.10360.pdf [2] https://dl.acm.org/doi/10.1145/3448300.3467826

red0point··on LTrack: Stealthy Tracking of Mobile Phones in LTE
It doesn‘t need any keys, since the protocol itself is vulnerable to this. The Identity Request message that is sent is unauthenticated, but the phone replies with the IMSI nonetheless.

Note that this is just one part of the attack, the attack also includes fully passive localization of phones.

red0point··on Hackers claim to have breached Okta systems
Keycloak is pretty standard for this.

https://www.keycloak.org/

red0point··on Modern smartphone lenses are crazy
Maybe dumb to suggest, but when this happens usually the lens is dirty / a bit greasy, at least from my experience with iPhone cameras.
red0point··on AWS S3: Sometimes you should press the $100k button
I want to know what the absolute cheapest way of doing this is, without having a lot of CapEx. I thought of renting dedicated storage servers (e.g. Hetzner) and slapping Ceph on them.

Do you have another, better, idea?

red0point··on Ask HN: What should I do with my unused 1Gig internet?
As soon as you use a significant portion of it all the time, you don‘t have „1Gig internet“ to advertise anymore.

Be happy to be able to provide actual 1Gbps as a best-effort to your coworking space! If I were a customer, I‘d be glad that I can download my 50GB of whatever I need asap and use the full connection I paid for, and not have 50% of it clogged by some TOR relay or stuff like that.

I mean, the customers are paying for it, right? So they should be able to use it for whatever they need, as much or as little as they need.

red0point··on Ask HN: What is your system for backing up family photos and video?
Congrats on building such a nice tool! I‘d gladly pay for something self-hosted, or some tool that allows me to download it on my own hardware.

I don‘t want to solve the problem by

A) paying even more money every month, much less even more than for Google Drive & Photos storage itself!

B) uploading my personal photos to a completely untrusted provider (at least I can trust Google to some degree to not leak my photos to any stranger on the internet).

red0point··on Issues with Cloudflare Images
Hi, fantastic product! It seems that you also do video transcoding - how are the limits there? I can't find explicit info alluding to video in your pricing page.

Thanks!

red0point··on Tempo, Beat and Downbeat Estimation
Does anyone know something able to do this in real-time? So it‘s able to sync, e.g. an LED light with music being played?
red0point··on Spork: Peer-to-peer socket magic in the air
This is very cool, but it seems extraordinarily cumbersome to pass on the generated super long string to another computer or mobile device.
red0point··on Wearable Microphone Jamming
So what is the effect in the first part of the video on the website then? Are you saying they‘ve faked it?
red0point··on Ask HN: How to start with formal verification to find bugs
It is indeed just an extension of that very idea, developed at the same institution where design-by-contract has been introduced a few decades ago.

However, instead of crashing at runtime due to a failed assertion, you get a guarantee that your program will in fact not violate said assertions and behave correctly.

It also entails a nice speed bonus, instead of checking the assertions all the time, which could be quite a complex feat for non-trivial post-conditions, you do it once, symbolically, for all possible executions.

red0point··on Ask HN: How to start with formal verification to find bugs
I think you’re looking at a program verification problem.

With this tool: http://viper.ethz.ch/ You essentially sprinkle your functions with pre- and post conditions (& loops), press „verify“ and it will verify the correctness of your program code.

There are multiple frontends you can use for different languages. Behind the scenes your code + annotations are converted from e.g. Python/Rust/Go to an intermediate language (Viper), which is then verified.

red0point··on OWASP Top 10 2021
Can you tell me how the limitation of the creation of read grants in luna is done?
red0point··on Ask HN: What problem are you close to solving and how can we help?
Sure, how can I reach you?
red0point··on Backblaze: “Why does the private key still need to be sent to your datacenter?”
Well done on that analysis. This is crazy and should be fixed by Backblaze as soon as possible.

Did you publish your findings somewhere or notify Backblaze?

red0point··on Backblaze: “Why does the private key still need to be sent to your datacenter?”
You’re saying that security isn‘t black and white, but trust somehow is, which I find a bit weird, since they‘re intimately related.

Backblaze could easily reduce the trust required, which they‘re not doing, but have been promising to do for years, with nothing happening.

Also, given your threat model, I‘d say the risk-mitigation is not applicable. Attackers lying low and continuously collecting and exfiltrating data is nothing new. Especially if this data includes passwords, private keys and data „zipping-by“.

Or does your threat model include specifically only an attacker being advanced enough to compromise Backblaze, but somehow not being able to persist for a while?

No, it‘s Backblaze‘s job of keeping data safe the best way possible, it shouldn‘t be necessary for customers to find excuses for their bad encryption scheme or to add another layer of encryption, especially if the fix is quite obvious and has been promised for years.

red0point··on Backblaze: “Why does the private key still need to be sent to your datacenter?”
Of course, but it's not like other providers offer this ability already "baked in".

At the same time, Backblaze only offers a security-theatre for encryption - they give you the ability to encrypt your backup private key with a password before sending it to them. But during restore, they collect this password and decrypt everything server-side. What's the point of offering encryption then?

red0point··on Backblaze: “Why does the private key still need to be sent to your datacenter?”
My issue with their encryption scheme is that although you can encrypt your private key before sending it to them, during restore, you still need to hand them the unencrypted private key.

This feature is thus pure security theatre.

You gain nothing - the provider may still access your data at some point (yes, they only "fly-by fast on a super-secure-server"), but still lose the ability to restore without the password.

The thing is, it wouldn't be hard to do the decryption during restore on the client. Why haven't they done this in all these years?

red0point··on Ask HN: What problem are you close to solving and how can we help?
Just take a look at the egress pricing of B2 (10USD/TB) S3 (92 USD/TB) and then look at Hetzner's 1 EUR / TB. There is quite a margin there - same thing with the storage costs (23,5,1.5).
red0point··on Ask HN: What problem are you close to solving and how can we help?
I‘m trying to re-/sell cheap bulk object storage, by renting cheap dedicated servers (e.g. Hetzner), connect them using 10GbE and putting them into a big Ceph cluster.

My problem is how to bill people for consuming object storage properly. Do you do it retrospectively and take the fraud risk? Are there any pre-existing platforms that do Ceph billing?

red0point··on Ask HN: What problem are you close to solving and how can we help?
I think you could leverage SKIP LOCKED for this - this blog post https://www.2ndquadrant.com/en/blog/what-is-select-skip-lock... explains it nicely.
red0point··on A simple software fix could limit location data sharing
Thanks! You mention that this is the simplest version, is there one where you use distinct keys?

Also, regarding the IMEI - let‘s assume the UE nullified it, how would you distinguish between a legitimately nullified UE and a stolen UE that had its IMEI nullified?

red0point··on A simple software fix could limit location data sharing
Additional question for my understanding - this needs an app running in the background to send the signed token at every other time interval, correct?
red0point··on A simple software fix could limit location data sharing
I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by the AUF when it doesn’t know the shared key K between the USIM and the network?

Can you elaborate a bit on that? Is every USIM using the same shared key?

Thanks!

red0point··on TLS certificates have at least two internal representations of time
Edit: I‘m on mobile so sorry about that weird comment repeating the same thing again and again, I was rewriting these paragraphs a few times, should‘ve come out as one. Oh well.
red0point··on TLS certificates have at least two internal representations of time
He proposes a new standard in his repo. He doesn‘t explain why it‘s better (not in the repo, nor in the comment), just mentions that all others are bad.

I call him out for just re-inventing the wheel by mentioning the xkcd. He proposes a new standard in his repo. He doesn‘t explain why it‘s better (not in the repo, nor in the comment), just mentions that all others are bad.

I call him out for just re-inventing the wheel by mentioning the xkcd. And indeed, critical self-reflection is necessary when developing a standard - why is it necessary? What does it do better? Otherwise, it‘s just as in the xkcd - a standard that nobody will ever use.

And instead of explaining just that he choses to attack me.

But you‘re right, a little accompanying text wouldn‘t have hurt.

← PreviousPage 2 of 5Next →