HNHacker News
TopNewBestAskShowJobs

sarnowski

894 karma · joined July 6, 2011

submissionscomments
sarnowski··on ICQ will stop working from June 26
It is from a time when we were used to remember phone numbers, and where we shared our phone numbers to keep in touch (calls, sms). ICQ directly picked on that and it was just another „phone number“.

Unfortunately I only remember the first half of mine after so many years. In the age of smartphones, at least my brain degenerated to not be able to recall more than a handful of important phone numbers.

sarnowski··on Draggable objects
Playing around with a hex based game myself, the bookmark to the Hexagonal Grid is a constant companion over the years. It was updated slightly over the years with some visual cues. Amazing presentation, and so great to learn.
sarnowski··on ChatGPT Enterprise
If it goes to the direction of Microsoft Copilot, then you can check out the recent announcement. Microsoft currently estimates that 30/user/month is a good list price to get „ChatGPT with all your business context“ to your employees.

https://blogs.microsoft.com/blog/2023/07/18/furthering-our-a...

sarnowski··on FiraCode: Free monospaced font with programming ligatures
When downloading Berkeley Mono, you can choose some configurations and I love the slashed 7 (as well as zero). Something feels off to me with the line but overall it’s fun to have in a font.
sarnowski··on Brute-forcing a macOS user’s real name from a browser using mDNS
And in some/many jurisdictions, your ISP is more regulated by your local government (also in regards to data protection) than cloudflare who has no obligation to you.
sarnowski··on Big Tech can transfer Europeans’ data to US in win for Facebook and Google
In parallel, there is a quite different point of view and after the last two dramas (Safe Harbor, Privacy Shield), the outcome is quite predictable in my opinion.

https://news.ycombinator.com/item?id=36677578

Edit: of course for the next 1-3 years, compliance departments in the EU can declare themselves not guilty and business will continue as usual.

sarnowski··on New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
> The part of the cookie law that’s dumb is that it’s too narrowly scoped and should apply to all tracking technologies and techniques, for whichever purposes and vendors are or aren’t okay with the user.

A recent definition of the German authorities clarifies that with „cookies“, they don’t interpret it narrowly as the specific browser technology but any kind of beacon or mechanism for tracking[0]:

> Gemeint ist damit beispielsweise der Einsatz von Cookies und anderen Technologien wie LocalStorage, Web Storage, das Auslesen von Werbe- und Geräte-IDs, Seriennummern, aber auch der Einsatz von ETags oder TLS-Session-IDs zum Zwecke des Trackings, Fingerprinting (z.B. durch das Auslesen von installierten Schriften oder Anwendungen) und vieles mehr. Der Einfachheit halber wird das im Folgenden i.d.R. unter dem verkürzenden Begriff „Cookies“ zusammengefasst.

They name as explicit examples not only cookies but LocalStorage, Web Storage, reading of any kind of serial numbers, ETags, TLS Session IDs (if used for tracking), and any other method for fingerprinting such as font profiling.

[0] https://www.baden-wuerttemberg.datenschutz.de/faq-zu-cookies...

sarnowski··on The Surprising Power of Documentation
What degree of „searchable“ are you missing from apropos?

https://man.openbsd.org/apropos.1

sarnowski··on Civilization II
That was Civ 1. I think they dropped it in Civ 2.

Edit: actually not sure. In Civ 1 you build up your palace, not the throne room per se.

sarnowski··on Initial support for guided disk encryption in OpenBSD installer
You absolutely can and if you know that you don’t install software that needs it, there is no reason to install X during installation.
sarnowski··on Initial support for guided disk encryption in OpenBSD installer
I think/assume OpenBSD is mainly used as a server OS. Yes, passionate people use it as a desktop but those mostly read the FAQ anyway.

Currently and as far as I know, bioctl does only support user typed in passwords or key disks. You certainly want also encrypted disks on your server but requiring user typed in password is oftentimes a no-go (think of various firewall appliances doing a reboot and not having remote hands). A compensation can be the key disk but I don’t know how widely that is used.

Hardware bound encryption like with a TPM is not supported. Also Linux is still exploring here as far as I can tell (no installer offers that).

In sum: I think disk encryption in the current form is not a tradeoff many installations will take.

sarnowski··on Initial support for guided disk encryption in OpenBSD installer
Yes, there is a dedicated question for how to do a full disk encryption:

https://www.openbsd.org/faq/faq14.html

It’s 3 commands to type in that are explained and that will work as is in most cases.

sarnowski··on Initial support for guided disk encryption in OpenBSD installer
There are packages like image libraries, Java etc that rely on X11 libraries. The safe default is to have it around.

You can always choose to not install all X* packages. In fact, for a server oftentimes you don’t need more than the base package (you barely need a compiler either or games).

sarnowski··on New headless Chrome has been released and has a near-perfect browser fingerprint
TPMs do not reveal a unique serial number or similar identifier by design for privacy reasons.

A TPM can attest that some measurements were done with it and it can attest that it comes from vendor X. You can block an entire vendor if they don’t behave but not individual TPMs via remote attestation.

You can use a scheme in which you can set up an „identity“ on first use and then on next use authenticate the same identity. But that identity is kinda per use case.

sarnowski··on StarFighter 16 inch: 4K Coreboot/Ryzen Linux laptop
Regarding scaling: If you use 2x scaling it should be easy with any distribution. Fractional scaling is a bit trickier to get.

I am using a Framework with 1.5x scaling using Fedora KDE and it’s amazing. Didn’t find any app yet that doesn’t conform. One difference to years ago is Wayland vs X. With X it was a constant struggle for me while with Wayland and more years invested, scaling became a non-issue on Linux (for me).

Regarding burp suite, iirc this is a JVM based app. I am running Jetbrains products without any issues and no configuration needs. Assuming burp suite uses swing, I would assume no issue. Generally, you can quickly check with a VM. Using Fedora KDE is a great „Just Works“ experience.

sarnowski··on WW2 Bomb Explodes in England
In Germany it is mandatory to do a bomb search on a plot before you are allowed to start building a building.

Also photos of bomb drops are used to check where bombs might have fallen and not explode.

https://www.spiegel.de/international/business/firm-uses-hist...

sarnowski··on 2022 was the year of Linux on the Desktop?
Microsoft just released Linux support (Ubuntu) in their MDM Intune. It’s very barebones yet but provides first fundamental capabilities.

https://learn.microsoft.com/en-us/mem/intune/fundamentals/su...

https://learn.microsoft.com/en-us/mem/intune/user-help/enrol...

sarnowski··on Snap Store administrators removed signal-desktop from Ubuntu Snap
You get your private snap store and upload your snaps to it. Signing and delivery is only assured between the IoT device and the snap store. Not between you (the developer) and the device.
sarnowski··on Snap Store administrators removed signal-desktop from Ubuntu Snap
And last time I checked, they refused to let you use your own signing keys. Means you do not get end to end trust for your own bits but need to rely on Canonical that they don’t screw up - with the obvious effect of strong vendor lock-in as I cannot sign and run my own bits.
sarnowski··on Gamification affects software developers: Cautionary evidence from GitHub
Every BSD license has this, which is for that purpose:

THIS SOFTWARE IS PROVIDED „AS IS“ AND WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.

sarnowski··on 40% of Google users now connect via IPv6
Oftentimes you can just ask the customer service of Vodafone. If you reach a good agent, they will switch you away from CGNAT and you get a proper /56 public routable prefix on your cable line. Also works great for me. Be aware, the Vodafone modem won‘t forward the prefix for you. Use a Fritzbox or one of the other few cable modems where you get full control.
sarnowski··on SAML Is Insecure by Design
Correct, it’s officially a framework and not a protocol. It’s a framework to build a specific protocol which then is using the same patterns as other OAuth2 based protocols but not necessarily compatible. For example URL endpoints are not defined in a strict sense and the provider can also add arbitrary parameters to calls as long as the basic OAuth2 parameter are present as well. OpenID Connect 1.0 builds on that to make the framework more strict.

RFC6749 The OAuth 2.0 Authorization _Framework_

sarnowski··on Are dynamic languages going to replace static languages? (2003)
By which metric? TIOBE paints a different picture where also Python and JS are high but not exclusively.

https://www.tiobe.com/tiobe-index/

sarnowski··on Anom Encrypted App Analysis
I guess it’s related to https://www.europol.europa.eu/newsroom/news/800-criminals-ar...
sarnowski··on Producing a trustworthy x86-based Linux appliance
Dealing in absolute terms does not help security. It depends entirely on your threat model.

If you consider NSA or similar agencies a problem then you are in a world of pain anyway and using an entry level guiding blog post is certainly not appropriate.

For everyone else, this puts already quite a big defense layer to your arsenal even if not unhackable in absolute terms.

sarnowski··on Noyb aims to end “cookie banner terror” and issues more than 500 GDPR complaints
Not all cookies require consent. There are many legitimate reasons to collect personal data - consent is only required if you cannot find another legitimate reason.

For cookies that mean: technical cookies that you need to technical provide your offering (think of authentication session cookie, loadbalancer sticky session cookies, but also cookies to understand if someone opted into tracking) can be set with legitimate interest and do not require a consent.

A consent under GDPR is strictly opt-in. This means, by default you must not track a user (EU citizen) that just landed on your site. After consent, you can load your GA plugin.

sarnowski··on IPv8: Authenticated Private P2P Communication
Sounds like I2P[0]; what are the differences?

[0] https://geti2p.net/en/about/intro

sarnowski··on Plausible Analytics Isn't GDPR Compliant
The cookie banners come from the ePrivacy Regulation and are supposed to inform you that the website is storing data on the your device and that you can opt out (not in) of it.

Consent is required by GDPR but not for the technical circumstance that you store a cookie but that you use it for profiling. Some lawyers argue that basic web performance is legitimate interest especially in e-commerce, others don’t risk it and ask for consent (which is strictly opt in).

sarnowski··on With broad, random tests for antibodies, Germany seeks path out of lockdown
My vague understanding is, that the tests can also test positive for antibodies from other similar viruses. They have a significant false-positive rate that you should not rely on a positive („you are immune“) result but overall they will provide a big picture approximation how many citizens might have already resistance. They are not good enough for a rumored „immune certification“.
sarnowski··on Website data leaks pose greater risks than most people realize
As one step to raise awareness about the differences I really like this overview:

https://fpf.org/wp-content/uploads/2017/06/FPF_Visual-Guide-...

Page 1 of 5Next →