HNHacker News
TopNewBestAskShowJobs

reza_n

310 karma · joined March 24, 2015

Reza Naghibi https://reza.naghibi.com

I write fast code, fast.

submissionscomments
reza_n··on Simple Linux kernel memory corruption bug can lead to complete system compromise
You can use `explicit_bzero()` to bypass DCE (dead code elimination). Otherwise, simply initializing your memory before using is enough to trigger magic failures when you use-after-free. C programs barely function if they do not initialize memory. Context, I work on Varnish which the OP referenced for this.
reza_n··on Ask HN: Who is hiring? (April 2021)
Varnish Software | Dev Ops | NYC onsite or US based remote | Full-time

Varnish Software is the company behind Varnish Cache, a hugely popular open source caching solution installed in front of millions of websites globally. We build high performance caching, CDN, and edge logic solutions. We are looking for a talented dev ops engineer to join our growing US based engineering team. You will be responsible for building, managing, and monitoring our cloud, on-premise, and hosted Varnish solutions. These are Linux based architectures with 100+ gbit/sec network capacity and hundreds of TB of disk capacity. Skills desired:

* Experience managing Linux based systems (bonus points for high performance systems experience)

* Experience troubleshooting and problem solving Linux based issues

* Experience with Ansible, Bash, Git, Docker, Kubernetes, and Terraform

* Knowledge of at least 1 programming language

* Knowledge of how websites and HTTP works

* Knowledge of security best practices

We are considering candidates of all skill levels, if you are new to the field but passionate about Linux and Dev Ops, please apply! Varnish Software provides an open laid back work culture with competitive salaries, full benefits, and generous vacation time. You will be working alongside some of the best and brightest in the industry!

Please apply at: nyc@varnish-software.com

reza_n··on Latin in the Voynich Manuscript
Bummer, he pretty much proved he was on the right path with his translation theories. Maybe this was done to protect his work? As in, hes now working to complete the translation and did not want others to beat him to it. One can hope...
reza_n··on I love coding in C
Time and experience. Learning the syntax and wrapping your head around pointers and memory is the first step. After that, just try and write as much C as possible. Help out with projects, start projects, write tools and APIs. Most importantly, study existing code bases to learn real world techniques. Best case, get a C job where you have to write a diverse amount of C code day after day.
reza_n··on I love coding in C
I write C full time and I love it (Varnish Cache). In our team of about 10 full time C engineers, we spend less than an hour a month dealing with things like “memory safety”. When you are writing C at a professional level, your time is spent on things like performance, algorithms, accuracy, hitting requirements, and delivering software. We have numerous safety and fuzzing systems humming in the background checking our work 24/7. The tooling ecosystem (Linux) is top notch.

(If you want to write C full time professionally too, contact me!)

reza_n··on Hyperscan: High-performance multiple regex matching library from Intel
I wrote something very similar many years ago. I described it as a reverse search index. The queries/regex gets indexed into a search tree and then text is run thru it. It supported hundreds of thousands of parallel regex searches. I called it dClass:

https://github.com/TheWeatherChannel/dClass

reza_n··on Simple Dynamic Strings library for C, compatible with null-terminated strings
This is a bit on the unsafe side since it blindly trusts user input. At minimum, there needs to be some kind of magic number in the struct header to validate its looking at the right memory. Best case, some kind of pointer accounting. Unfortunately, magic doesn't come for free.
reza_n··on SSH gets protection against side-channel attacks
We have no problem sharing our codebase with customers, especially if there are concerns like this. Shoot me a msg if you are genuinely interested in anything you have read.
reza_n··on SSH gets protection against side-channel attacks
Possibly, but memory is accessed using plain CPU instructions, so it would be hard to transparently encrypt all memory for an application at the kernel level. You do have virtual memory, but I dont think that could be leveraged for this. But who knows whats possible there, maybe if you align and address each memory value at the page boundaries and always force a page fault you could have a really poor implementation :)

Transparent disk encryption, not a problem since devices have filesystems which can implement encryption at that layer.

reza_n··on SSH gets protection against side-channel attacks
Yup. When something goes wrong in these kinds of applications, you sometimes tend to just randomly dump memory, which is a huge data leak. Or even worse, if someone figures out a way to force a data leak, then your are completely compromised. Having each piece of data with its own key and that key is a combination of data outside of the process address space drastically lowers the chances of data leakage and total compromise.
reza_n··on SSH gets protection against side-channel attacks
Closed source, write up would be here:

https://info.varnish-software.com/blog/introducing-varnish-t...

reza_n··on SSH gets protection against side-channel attacks
Yup, we added this feature to Varnish Cache a few years ago, random key encryption. It generates a random key at startup and encrypts all memory with it. Since this kind of memory is only resident for the lifetime of the process, it works. We stored the random key in the Linux kernel using the crypto API [0] just because its not safe storing any kind of keys in a memory space used for caching (Cloudbleed [1]). We then use the key to generate a per object HMAC, so each piece of data ends up with its own key, which further prevents something like Cloudbleed. Since we used kernel crypto, overhead was about 50%. If you stay completely in user space, its probably much lower.

[0] https://www.kernel.org/doc/html/v4.17/crypto/userspace-if.ht...

[1] https://en.wikipedia.org/wiki/Cloudbleed

reza_n··on Fastly S-1
Edge facilities are warehouses in regional locations with excellent backbone connectivity, basically your modern datacenter. Cellphone towers can probably host a few racks, that's not a profitable business and its not "internet scale". If the regional datacenter has a 15ms ping to each tower in the region, then you have pretty good coverage.
reza_n··on Nginx to Be Acquired by F5 Networks
https://hitch-tls.org/
reza_n··on At 18 Stories, Mjøsa Tower Is World’s Tallest Wooden Building
Exactly. I used to live in a low rise apartment building which used modern wood construction. Not only did I hear everything above me, but the shock waves (from foot strikes) would also travel thru the structure, so you could feel everything as well.
reza_n··on Essential C (2003) [pdf]
We are always hiring full time C developers doing exactly what you said. Msg me if you (anyone) is interested.
reza_n··on Is Saudi money becoming radioactive?
If history is any guide, regime change doesn't need to come from within. Many parallels have been drawn to Saddam.
reza_n··on Is Saudi money becoming radioactive?
Believe it or not, US support has made KSA extremely weak, especially militarily. So its more like keep your enemies close, or in this case, oil targets. US could topple KSA in a matter of months.
reza_n··on Is Saudi money becoming radioactive?
> ...Diplomatic murder, women's rights arrests, Yemen war, Canada row, royal imprisonmemt...

There is also the failed blockade of Qatar. Seems like this has been a pretty disastrous few years for MBS and he isn't even king. Im surprised he hasn't been replaced. These are pretty massive blunders.

reza_n··on Pointers Are More Abstract Than You Might Expect in C
True, and I meant this in the context where you could embed assembly into your functions if needed.
reza_n··on Ask HN: Who is hiring? (July 2018)
Varnish Software | Frontend Developer | New York City or Oslo, Norway

Varnish Software is the company behind Varnish Cache. Varnish Software works with top global enterprises helping them use Varnish to increase web performance, build CDNs, and advanced edge platforms.

At Varnish Software, we take pride in our software and products and we value innovation. We offer an open, honest, and international culture in a laid back and stimulating work environment. You will be working with some of the brightest and most talented people in the industry. We offer competitive salaries, full benefits, generous vacation time, and much more.

We are currently looking for a frontend developer to join our team in New York City or Oslo.

Requirements:

  * Strong design aesthetics
  * JavaScript (ES6), HTML5, CSS3
  * Rapid prototyping
  * Frontend frameworks (React, Angular, etc)
  * Responsive frameworks (Bootstrap, Foundation, etc)
  * Build tools and testing frameworks
  * Real world experience
What we offer:

  * New product and greenfield development
  * Product ownership
  * A happy, creative, and flat hierarchy environment
  * International travel
  * Conferences and meetups
Please send your resume or questions to jobs@varnish-software.com
reza_n··on Pointers Are More Abstract Than You Might Expect in C
> C aficionados often claim they love C because it's "simple"(it isn't) That's what they mean, they love C because you can't really do OO with it

I do not think C programmers are anti OO. Infact, a lot of C patterns are modeled on OO (struct + function). I think the appeal of C is that you are able to write the fastest implementation any given algorithm, something that just isn't possible in most other languages.

reza_n··on Is the Age-Old Quest for a Baldness Cure Reaching Its End?
It works and can even allow you to regrow hair. However, your sex drive will take a nose dive. When you stop, things go back to normal, including the hair loss.
reza_n··on Getting Google to ban our entire company
I pay $5 a month for a custom domain gmail account and last year I had an issue connecting to their POP3 service. Opened a support ticket and got extremely high quality support immediately. Basically, my experience was the opposite of all the horror stories which always get echoed in these support threads.
reza_n··on ls | grep “echo ${data}” – Why/how does this work?
Are the files all empty? Looks like echo is part of the search string and the expansion might be interpreted as the file list. ls is ignored. Just a guess...
reza_n··on You know how HTTP GET requests are meant to be idempotent?
> This would still happen even if there was a token or session associated.

This is exactly the scenario a CSRF token is support to prevent. But I understand your point.

reza_n··on You know how HTTP GET requests are meant to be idempotent?
To me this sounds like a CSRF problem. There's no token or session associated with these calls, so a browser was able to inadvertently CSRF the calls. Changing this call to POST or PUT would still leave this API vulnerable.
reza_n··on Drupal Remote Code Execution vulnerability exploited widely
Is there some pattern or rule you can put into Varnish/CDN/nginx to prevent this??
reza_n··on Is sorted using SIMD instructions
Maybe have a parent function which passes in the array as 4k chunks/offsets and checks the return? 4k is a random size, there is probably a value which hits the sweet spot here.
reza_n··on Effects of CPU Caches
Most variables are registers, so it would have no effect on cache since there is no memory used to store the data. Only if that variable is pushed onto the stack/heap would it then consume cache. However, the size of the stack is much smaller when compared to the size of the data structures in play, so only a small percentage of cache is used for this control data.
Page 1 of 4Next →