HNHacker News
TopNewBestAskShowJobs

rosnd

27 karma · joined May 11, 2022

submissionscomments
rosnd··on Leak of a cancelled 1996 “Duke Nukem Forever” side-scroller
refresh
rosnd··on Cannabis is legal in most US states but federal laws block businesses from banks
> By paying taxes they’re essentially admitting to a felony to the US government, which makes them trivially easy to raid.

That's not how it works, taxpayers enjoy fifth amendment protections against self incrimination.

IRS can't share this information with other LE without a warrant anyway.

rosnd··on ChatGPT no longer displays a clear left-leaning political bias
How do you define "politically neutral"?
rosnd··on LastPass breach is worse than you think because URLs were unencrypted
>Remember that last pass has just been caught lying about their security, and you can't trust what they say.

I'm curious, what were they caught lying about?

>What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?

LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.

>Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.

This is not logical at all.

>You cannot trust last pass security from this point forward.

Why not? Because they disclosed a breach?

rosnd··on How Did Sam Bankman-Fried Get Bail?
He waived extradition, definitely makes him seem like much less of a flight risk.
rosnd··on LastPass breach is worse than you think because URLs were unencrypted
How is the LastPass encryption badly implemented?

In your other comment you claimed it was "likely" to be badly implemented, but here you state it as a fact. What's up with that?

rosnd··on LastPass breach is worse than you think because URLs were unencrypted
Why do you think it is likely? That's a very strong claim.

> such as bad RNG

How could that be a problem? The attacker doesn't control your passwords. How would you exploit a known IV as an attacker in this context?

rosnd··on LastPass breach is worse than you think because URLs were unencrypted
If you don't trust LastPass to encrypt your passwords properly, why would you use it at all?

>That exact kind of thing happens constantly

Like when?

>And of course, the nature of the concern here involves us not knowing that LastPass was fucking up.

What do you mean? The cryptography used by LastPass is very well understood.

rosnd··on LastPass breach is worse than you think because URLs were unencrypted
> Your encrypted data is compromised, it is in the hands of an attacker who really wants to decrypt it. You're pinning all of your digital security on encryption holding against an active attacker.

Well, yeah. Just like you leak your encrypted password to the internet every single time you log into a website.

>What if there is an undiscovered or undisclosed vulnerability in the encryption?

lmao, if aes-256-cbc is broken then LastPass is probably the least of anyone's concerns. This happens to also be one of the more difficult AES modes to screw up.

>What if last pass isn't using encryption as secure as they claimed?

Shit, if that was a real concern you would have to be a complete idiot to use LastPass in the first place.

rosnd··on ChatGPT no longer displays a clear left-leaning political bias
Do we really need robots steelmanning Hitler?
rosnd··on ChatGPT no longer displays a clear left-leaning political bias
Exactly, the only thing this test reveals is David Rozado's far right biases.
rosnd··on ChatGPT no longer displays a clear left-leaning political bias
Does that even fit on the spectrum? From Europe things like the "Stanford's guide to political correctness" feel super niche in the same way that some weirdos on the left used to advocate for getting rid of ages of consent.
rosnd··on LastPass breach is worse than you think because URLs were unencrypted
Only the encrypted randomized passwords were leaked. Unless you knowingly used a bad password for your cloud-based password manager, you're fine.

If you did use a bad password for the cloud based password manager, you're the walnut. The whole sales pitch is that lastpass can't fuck you as long as you have a reasonable password protecting your vault.

rosnd··on LastPass breach is worse than you think because URLs were unencrypted
>Seems like instead of spending Christmas with my family, I will spend it changing passwords for 100s of accounts.

Why didn't you just use decent passwords in the first place? You were using a password manager, what's the fucking point if your password is still "kittens1"?

This is all on you.

rosnd··on Linux Kernel Ksmbd Use-After-Free Remote Code Execution Vulnerability
"Crazy amounts of data" isn't the main concern, it's latency. It's the people storing giant amounts of data who generally don't worry about that so much.
rosnd··on Linux Kernel Ksmbd Use-After-Free Remote Code Execution Vulnerability
> rather that introducing new remotely accessible attack surface to the kernel in 2022 when we know it's likely unsafe is silly.

This is the worst possible take on this.

> Building an SMB server in the kernel because "well, NFS was secure eventually" overlooks the fact that NFS shouldn't be in the kernel either.

The way Linux works, NFS unfortunately has to be in the kernel to achieve reasonable performance.

rosnd··on Caroline Ellison and Gary Wang are cooperating in the criminal case against SBF
Yes, but federal drug crimes are not the only kind of drug crimes.
rosnd··on Caroline Ellison and Gary Wang are cooperating in the criminal case against SBF
Well, that's a lie which at times has real impact on trial outcomes. I wouldn't really put it in the same category.
rosnd··on Caroline Ellison and Gary Wang are cooperating in the criminal case against SBF
That doesn't make any sense, everyone on the receiving end of these threats has a lawyer. Even the shittiest public defender will translate this for you.

These numbers exist solely for the audiences at home.

rosnd··on Netflix password sharing may be illegal, says UK government
I mean, various laws covering unauthorized access to computer systems seem like they would be directly applicable here.

https://www.cps.gov.uk/legal-guidance/computer-misuse-act

>There must be knowledge that the intended access was unauthorised; and

Check? If not currently, Netflix could trivially ensure that this is the case by just adding a banner on the login page.

>There must have been an intention to secure access to any program or data held in a computer.

Check.

rosnd··on Older iPhones bricked for being too outdated, locking users from data [video]
What does that look like? Stolen parts will always be cheaper.

The warehouses full of people in Shenzhen tearing down millions and millions of stolen iDevices would still be chugging along, inserting stolen parts into the supply chain.

Apple enforcing DRM on parts is very much a pro-consumer move, steadily taking us towards a world where a stolen iPhone will be worth nothing.

rosnd··on Older iPhones bricked for being too outdated, locking users from data [video]
Of course they do. Until third party repair shops created a huge market for stolen iPhone parts, stealing them was significantly less attractive than other phones.
rosnd··on Older iPhones bricked for being too outdated, locking users from data [video]
Well, they do. iPhones are still valuable after being parted out, although Apple has been combating this by requiring parts to be registered by them (and shamed for much of the same on HN)
rosnd··on OneCoin co-founder pleads guilty to $4B fraud
No, only about 1 in 5 mice become addicted to it. The number with humans will be far lower.
rosnd··on Tell HN: Uber has blocked my account for years, won't tell me why
It depends, enforcementtracker.com shows that the authorities have been willing to chase after a rather diverse mix of violators.

But indeed, leaving GDPR enforcement to government authorities was a huge mistake. Anyone should be able to sue over GDPR violations impacting them.

rosnd··on OneCoin co-founder pleads guilty to $4B fraud
Who the fuck are those people overdosing on crack cocaine, and how? This is literally one of the most difficult drugs to dangerously OD on.

You can't snort crack, you can't IV crack. You can only smoke crack, the onset is super fast and doesn't encourage you to rapidly redose. Dosage tends to be limited by your lung capacity.

Maybe with some very impressive lung capacity?

It's easy to overdose on Cocaine HCl using any of the popular RoAs. Insufflated, the onset is very slow, enabling you to take way too much before you actually start to feel the effects. Intravenously, your dosage is not limited by your lung capacity as it would be while smoking crack.

rosnd··on Tell HN: Uber has blocked my account for years, won't tell me why
SSNs are not unique for a whole lot of reasons. https://www.nbcnews.com/technolog/odds-someone-else-has-your...
rosnd··on Tell HN: Uber has blocked my account for years, won't tell me why
It sounds like banning an Uber account would qualify

> In addition, processing can significantly affect an individual if it influences their personal circumstances, their behaviour or their choices (for example an automatic processing may lead to the refusal of an online credit application).

rosnd··on Winter & Cold Weather EV Range Loss in 7,000 Cars
It's definitely much more than 5% of new ICE cars.
rosnd··on Tell HN: Uber has blocked my account for years, won't tell me why
This EU commission page suggests that a human review should be conducted before a client is informed of the decision, not only in the case of an appeal.

https://commission.europa.eu/law/law-topic/data-protection/r...

Page 1 of 8Next →