HNHacker News
TopNewBestAskShowJobs

rmast

175 karma · joined April 28, 2016

submissionscomments
rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
That part was humor, sorry you missed it. I’ll elaborate.

If it’s unprocessed beef it could be considered a whole food — but often people don’t bother checking the ingredients for the meat they buy and just assume that it doesn’t have things added.

That said, there is research that points to eating too much beef and other red meats potentially being bad for health.

rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
I thought the “typical” keto diet tends to be higher in meat, egg, seafood, and dairy-based product consumption than the western diet. Which would make it lower fiber, since that comes from plants.
rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
Beans and brown rice would be… unless you’re eating the whole cow. But actually, it’s surprising how many things like preservatives get added to things like ground beef.
rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
That adelaide article claims that meat was a staple pre-agriculture, but doesn’t do much to back it up.

Studies of feces appear to indicate plant consumption was high. There’s also one I came across on Neanderthal diet 50k years ago that suggests they ate more plant stuff than previously thought. https://www.researchgate.net/publication/329486931_Dietary_f... https://link.springer.com/chapter/10.1007/978-1-4684-2481-2_...

This one says meat was an important component, but that fiber (only from plants) consumption was much higher than it is now. https://socialsci.libretexts.org/Bookshelves/Anthropology/Bi...

rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
Specifically, keto was aimed at helping manage epilepsy.
rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
There’s a recent twin study from Stanford where they took a bunch of identical twin, and gave one an omnivorous diet and the other a plant-based diet. Both were also supposed to follow an exercise routine. For the first several weeks they had pre-prepared healthy meals, before switching to individuals preparing their own meals with guidance/advice.

Vitals were taken and blood work was done before making the diet/lifestyle changes, and again after.

rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
There’s also research showing fruits (the whole thing with the fiber, not juice) can be eaten without causing an insulin spike — as in, X grams of natural sugar eaten in the form of an apple is not the same as getting those X grams as refined sugar such as a can of soda.
rmast··on Ketogenic Diet Intervention on Metabolic and Psychiatric Health
Basically leave out things like added oils and refined ingredients (sugar).
rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
I do have a history of going years between comments on social media platforms. The last event that got me actively commenting this much on other platforms was all the Trump discourse.

If I didn’t know any better, I’d say you’re enjoying this spirited conversation ;)

rmast··on Xz: Can you spot the single character that disabled Linux landlock?
At least for newer C++ standards it seems like there is decent support for feature test macros, which could reduce the need for a feature check involving compiling a snippet of test code to decide if a feature is available: https://en.cppreference.com/w/cpp/feature_test

Handling the output from several of the most recent GCC and Clang versions would probably cover the majority of cases, and add in MSVC for Windows. If the output isn’t from a recognized compiler or doesn’t match expectations, the only option is falling back to current behavior. Not ideal, but better than the current status quo…

rmast··on Xz: Can you spot the single character that disabled Linux landlock?
It would be interesting to see what the most common compile feature checks are for, and see what alternative ways could be used to make the same information available to a build system — it seems like any solution that requires libraries being updated to “export” information on the features they provide would have difficulties getting adoption (and not be backwards compatible with older versions of desired dependencies).
rmast··on Xz: Can you spot the single character that disabled Linux landlock?
It seems like there should be a way to catch these types of “bugs” - some form of dynamic analysis tool that extracts the feature detection code snippets and tries to compile them; if they fail for something like a syntax error, flag it as a broken check.

Expanding macros on different OSes could complicate things though, and determining what flags to build the feature check code with — so perhaps filtering based on the type of error would be best done as part of the build system functionality for doing the feature checking.

rmast··on Xz/liblzma: Bash-stage Obfuscation Explained
The use of head/tail for deobfuscation also isn’t visible as plain text in the repository or release tarball, which makes searching for its use in other repositories more difficult (unless a less obfuscated version was tested elsewhere).
rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
I suppose I think verbose-ness will help people see the other side of things. I think I was also trying to convince myself that you aren’t just into conspiracy theories, but given that you’re now accusing me of being suspicious… :shrug: it did come full circle where in my first comment I said you would start accusing me. I guess neither of us have anything more to say to each other because we are both too locked into our own beliefs.

As for motivation… https://xkcd.com/386/ enough said :)

rmast··on Xz/liblzma: Bash-stage Obfuscation Explained
Maybe some analysis of odd patterns in entropy of binary files committed to repositories could pick out some to look at a bit deeper?
rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
As I understand it Jia was contributing things like tests, not making changes that involve “security”. They just turned the commit, and eventual ability to make releases on the xz GitHub after “earning” more trust (+ access to GitHub pages hosted under tukaani domain), into something they could use to insert a backdoor.

No questions. Anyone can become a victim to social engineering — I believe the short answer to your question about all the downvotes is that a lot of people recognize how they could have fallen for something similar, and empathize that Lasse is likely now going through a rather difficult time.

rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
Well, good for you being one of the few exceptions who would make everyone submit themselves to a proper background check (presumably also covering the cost) before giving any write/commit access to the repo. That’s more than even most large open source projects do before giving access.
rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
You might not be trying to start a rumor, but other people could when they try to answer the questions from a place of ignorance — if you take a look at the comments on a gist summarizing the backdoor, there are quite a few comments by z-nonymous that seem to be insinuating that other specific GitHub users are complicit in things by looking at their commits in various non-xz repositories.

No one is running cover, just that most information so far points to the original maintainer not knowing that the person brought on to help out had ulterior motives, and likely wasn’t even who they purported to be. If you were running an open source project and facing burnout as the sole maintainer, I’d imagine you’d exercise perfect judgement and do a full background check on the person offering to help? I think many of us would like to believe we’d do better, but the reality is, most of us would have fallen for the same trick. So now imagine having to deal with the fallout not just on the technical side, but also the never-ending questions surrounding your professional reputation that people just keep bring up — sounds like a recipe for depression, possibly even suicidal thoughts.

rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
I don’t stalk all of your social media posts, so from my perspective I don’t see any of the solutions you’ve posted elsewhere — which brings up a good point to keep in mind: none of us see the complete picture (or can read minds to know what someone else really thinks).

The possibility can be kept in mind and considered even if it isn’t being actively discussed. I think in this case, most people think he is not malicious — and feel that unless new compelling evidence to show otherwise appears, potentially starting a harmful rumor based on speculation is counterproductive.

rmast··on Backdoor in upstream xz/liblzma leading to SSH server compromise
Recall that the original maintainer had mental health issues and other things that likely led to the perceived need to bring on someone to help maintain xz.

This brings up some integrity questions about you and other people bringing forth accusations in order to make the original maintainer feel pressure to bring on someone else to replace the one that inserted a backdoor after several years of ostensibly legitimate commits.

Hopefully this helps you see that these sorts of accusations are a slippery slope and unproductive. Heck, you could then turnaround and accuse me of doing something nefarious by accusing you.

rmast··on Show HN: Devstream.tv – Watch developers code live
If twitch offers an option for sound on embedded videos to be muted, that would be perfect -- at least on the home page where people who are checking out a site for the first time are most likely to land, getting blasted by unexpected sound is annoying.
rmast··on Ask HN: What simple tools or products are you most proud of making?
Assembly is related to the process of reverse engineering a game - disassemblers translate compiled code back into assembly, so knowing how to read assembly would have been very useful.

I think answering the questions about decryption and finding the key would make a pretty nice blog post, if OP has a blog.

Edit: Looks like he made a really detailed follow up comment describing the process. Impressive.

← PreviousPage 3 of 3