HNHacker News
TopNewBestAskShowJobs

reginaldo

1,400 karma · joined October 12, 2008

Reginaldo Silva

Contact: reginaldo at ubercomp.com

Links: http://www.ubercomp.com/ https://github.com/ubercomp/

submissionscomments
reginaldo··on Ten predictions (2004)
corresation: I can't answer your post directly, so I'll answer my own. It's absolutely not vague handwaving. HTML or JSON parsers can't make arbitrary network connections. XML parsers often can.

XML remains the lingua franca or most enterprise systems and interchanges (meaning the ones that people are most interested in trying to compromise

That is one of the reasons attackers are so happy. They are not trying to compromise. They are succeeding. Show me a SOAP/XMLRPC web service and I will show you a compromised machine, with very high probability.

See, for instance, last year's BlackHat presentation about SAP. Root with 1 request. Granted, there was an overflow involved, but the entry point was XML. Many more instances of this are available (I've compromised tens of systems in the last six months through the "magic" of XXEs, but unfortunately can't talk about them).

http://media.blackhat.com/bh-us-12/Briefings/Polyakov/BH_US_...

reginaldo··on Ten predictions (2004)
I think the 50% less bulshit figure is pretty generous. Let's not forget that, unless you opt out of it, most XML parsers, when given user-generated input, will do lots of crazy stuff. In the best case scenario, the machine that parsed the input will fall victim to DoS. In the worst, we have good old remote code execution. Tipically, an attacker will be able to read lots of files from the servers and make arbitrary network connections, many times from the viewpoint of a machine inside a corporate firewall. As a spare-time security researcher, let's say I absolutely love XML. As a developer, I despise it.
reginaldo··on Fabrice Bellard: Portrait of a super-productive programmer (2011)
I was inspired by jslinux and decided to write one such emulator myself. Of course, the architecture I'm emulating (Lattice Mico32) is much much simpler than X86.

It is open source, available at http://www.ubercomp.com/jslm32/src/

I did both an interpreter and a (much faster) dynamic code generator that generates blocks of code in Javascript so it doesn't have to decode every instruction over and over again.

Oh, and before doing the project, I sent Bellard an email, and he was very polite and helpful. Even sent me some compliments after I was able to optimize it to run at a decent speed. A true master!!!

reginaldo··on Modeled on man: Breathable skin for buildings
The article is talking about temperate climates, whereas Florida is humid subtropical in the north and central parts and tropical in the south.

In temperate climates, the temperature outside might be just cold enough, but not too cold, that "opening the windows", or something equivalent, might be a viable strategy.

reginaldo··on Ford Releases An SDK For Their Cars
Which means that briefly we'll live in a time where a stack overflow vulnerability will cause your car to break or accelerate at very inappropriate times.

Just google for "researchers car software vulnerability" (without quotes) to see what I'm talking about.

[1] http://www.computerworld.com/s/article/9229919/Car_hacking_R...

reginaldo··on How to Contribute to Open Source without Being a Programming Rock Star
In the same area, OpenHatch[1] seems very nice. From their own landing page:

OpenHatch is a non-profit dedicated to matching prospective free software contributors with communities, tools, and education.

[1] http://www.openhatch.org

reginaldo··on How I got a $3,500 USD Facebook Bug Bounty
Actually it is $3133.7 (eleet). I got it, of course. The security team at Google is, simply put, awesome.
reginaldo··on How I got a $3,500 USD Facebook Bug Bounty
I recently found a pretty simple one on https://accounts.google.com/, which is arguably Google's most valued domain. I believe XSS is the most common vulnerability these days. One doesn't even have to be able to inject javascript per se. Only a CSS style is enough in many cases.
reginaldo··on NoSQL: The Love Child of Google, Amazon and ... Lotus Notes
There's a nice Stack Overflow podcast[1] on the same subject, where Damien Katz talks a little about what he liked on Lotus Notes. I thought it was a nice episode.

[1] http://blog.stackoverflow.com/2009/06/podcast-59/

reginaldo··on A Tutorial on Anonymous Email Accounts
Thank you for the heads up. I didn't know that the Browser Bundle also took care of fingerprinting.
reginaldo··on A Tutorial on Anonymous Email Accounts
Actually it's a little harder still. For instance, when your browser makes requests in your behalf, it provides the destination server with a lot of information which can be used to identify you (at least temporarily)[1]. To get a better level of anonymity, one should at least use a combination of Tor and privoxy [2].

[1] https://panopticlick.eff.org/ [2] http://www.privoxy.org/

reginaldo··on Virtual machine used to steal crypto keys from other VM on same server
I don't know how things are today, but in 2009 it was possible. See, for instance, the paper Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds at http://cseweb.ucsd.edu/~hovav/dist/cloudsec.pdf

From the abstract: Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine. Scared yet?

reginaldo··on Conway's Game of Life, using floating point values instead of integers
Lifelike might be the term you're looking for... :)
reginaldo··on Web Server in your Browser (Chrome Apps API)
Shameless plug: and also https://github.com/ubercomp/jslm32/ (includes a mechanism that generates Javascript on the fly).
reginaldo··on Stripe CTF Writeup
filename=file_that_doesnt_exist&attempt=
reginaldo··on Stripe CTF Writeup
Yes. You can do $x = file_get_contents("http://news.ycombinator.com) and it will work (well, in that case it wouldn't as the machine had locked down network access, but you get the idea).
reginaldo··on Apple v. Samsung juror: we “wanted to send a message”
I believe he fantasized himself. Does anyone know of post 1990s a case where the small guy won in patent litigation against BigCo (I'm genuinely curious)? If it was his patent, I think he would want to defend it, but I doubt he could.
reginaldo··on PHP finally gets finally
Have you heard about Racket's custodians? [1] http://docs.racket-lang.org/reference/eval-model.html#(part....
reginaldo··on Think Relevance podcast with Rich Hickey
The book linked from the show is The Principle of Product Development Flow: Second Generation Lean Product Development.

Link (no affiliates): http://www.amazon.com/The-Principles-Product-Development-Flo...

reginaldo··on Gittip stats
Currently there's no other way to sign up. I believe he'll add other ways to sign up soon.
reginaldo··on Gittip stats
I'll tell him to put a giant Sponsor button on every screen.

First you'll have to click the tiny "Login with google" button in the upper right corner, then the "Sponsor new issue" button. Then you paste the link to the original issue. After that, the site will guide you a little bit better.

reginaldo··on Gittip stats
I know a guy working on a related idea. Instead of funding people, his system works by funding issues. The link is http://www.freedomsponsors.org

The workflow, as I understand it, goes something like that:

1) There's an issue on a project you use that's getting no love.

2) You go to freedomsponsors register that you'd like some issue solved, so much that you'd be willing to put your money where your mouth is. Also, you'll probably want to put a link to freedomsponsors on the project's issue tracker.

3) When one or more people solve the issue, the sponsor pays them (if more than one person has worked on the issue, the sponsor can distribute the money in anyways).

reginaldo··on Machine learning for the impatient: algorithms tuning algorithms
When you develop a model, for instance, when implementing a classifier, you supposedly want to apply the developed model to other data, i.e., data you don't have available during development.

In many situations, it doesn't make sense to test your model only when it's put to make or influence decisions in the real world (although you have to test in the real world too). You'll want to test the predictions of your model on data you already have the actual results for. To test your model you'll split your data into data you know and will let the model know about (training dataset), and data you know but the model can't know about (test dataset). That way you can use the data the model doesn't know about to make controlled experiments and compare models (and, if your data is really representative of the real world, your mofrl comparison and the performance of your chosen model will hold).

The moral of the story is: if you don't split your data, you won't have any idea of how it performs in the real world, you'll only know how it performs with data it already knew about.

reginaldo··on Distribution of colors in movie posters between 1914 and 2012
Especially the empty search part. In my experience, the three search terms most likely to return all results are:

  1) %%% (many sites limit the minimum search term length to three so a single % will not do the trick).
  2) '   ' (trhee spaces)
  3) '' (empty string)
Edit: formatting
reginaldo··on When Bad Theories Happen to Good Scientists
typically only happened when older scientists retired

There is a much less subtle quote attributed to Max Planck that summarizes this idea: Science progresses funeral by funeral.

reginaldo··on Implementing Fast Interpreters
This article is awesome. I had read it before but lost track of it. It was nice reading it again. Mike's code is a bliss to read, I don't know how to explain, it shows such a clear way of thinking... I believe one of the best ways to learn about dynamic language implementation this days is by reading his code and the things he writes when participating in discussion forums. He is the real deal.

For an example see: http://lambda-the-ultimate.org/node/3851 (he goes by MikePall - without spaces)

reginaldo··on Microsoft comes under fire for five-figure Xbox 360 “patch fee”
I'm not saying they want to do that. I said it creates the incentive, not the action per se. Not all facets of a given incentive are acted upon.

I even understand the reason for the fee. It's to make sure developers give their maximum before submitting a game so they can avoid the need to patch and the fee in the first time. It creates an incentive for the developers, too... Hell, maybe it even costs more than $40000 for Microsoft to review the patches so they're being benevolent here and the whole thing is moot. I don't know, I don't work there.

My post was merely to point that, when one creates an incentive, there might be many sides to it, therefore one must be careful when creating incentives.

I'm an XBox owner who buys a lot of games (even arcade ones). I think it's the best Microsoft product I ever use (their awesome keyboards of circa 2001 being a close second). That XBox games on demand thing is just awesome.

Will try to be less succinct when commenting in the future.

reginaldo··on Microsoft comes under fire for five-figure Xbox 360 “patch fee”
IMHO, that "policy" is kind of odd anyway. It creates an incentive for Microsoft to not do a very through review of the first patch, which is free, so they can get paid to do a review of the second one.

When coining such things, one must be very aware of the incentives they create. Bad incentives will accumulate and potentialize and then come to haunt you...

reginaldo··on Operating System Development
Yes, you're right. For my OS class when I was in school, instead of doing the proposed homework, I convinced the professor to let me do a x86 OS. We were a group of 3. I started doing everything in C with as little as assembly as possible, but the other two decidet to do an all-assembly little monster.

At the end of the course, we had only the boot loader and a little command interpreter, aside from FAT-12 support.

Then, much later, I messed with OS by playing with the code from the Minix Book [1].

Last year I wrote a little emulator for a virtually unknown architecture that can run uClinux on a modern browser (i.e., Chrome)[2].

[1] Operating System Design and Implemenation: http://www.amazon.com/Operating-Systems-Design-Implementatio...

[2] https://github.com/ubercomp/jslm32/

reginaldo··on Operating System Development
Only when you want to run it on real hardware. Most qemu targets can boot straight from a binary blob or an ELF image (the emulator initializes the emulated hardware and then sets the PC to the address where the blob is loaded). Those that can't are easily modifiable to do so.

Also, U-Boot can boot a lot of things this days.

So if I were to build an OS for ARM or MIPS I would:

1) Build it on an emulator that can boot from ELF or a binary blob.

2) When it's time to run on real hardware, try to use U-Boot.

3) If that fails, write my own boot loader.

The moral of the story is: bootloaders are not my kind of fun, so I'll avoid writing them at all costs.

← PreviousPage 4 of 8Next →