HNHacker News
TopNewBestAskShowJobs

schlowmo

1,012 karma · joined March 29, 2015

submissionscomments
schlowmo··on HP Allegedly Time Bombs Unofficial Ink Cartridges from Working in Its Printers
Old, but still so true:

"Why I Believe Printers Were Sent From Hell To Make Us Miserable"

http://theoatmeal.com/comics/printers

Had this one printed out (oh that irony) and taped it to our office wall when we had to deal with crappy printers on a daily basis working for a big DAX company.

schlowmo··on German Federal Intelligence Service BND Violates Laws And Constitution
> "It may be isolated incidents"

Yes, "it may". German agencies are famous for "isolated incidents". It's only a matter of definition what's to be called "isolated".

Those isolated incidents reach back even to the "Operation Gehlen"[0], the predecessor of the BND which was founded in 1946. One could say that the history of German agencies is the history of isolated incidents. While this may hold true for intelligence agencies all over the world, the historic ties leave a very bad taste regarding right-wing-terror in Germany. The "National Socialist Underground" (NSU)[1] was only the tip of the iceberg.

[0] https://en.wikipedia.org/wiki/Gehlen_Organization [1] https://en.wikipedia.org/wiki/National_Socialist_Underground

schlowmo··on German Federal Intelligence Service BND Violates Laws And Constitution
If you look at the media coverage of this topic in Germany so far one could come to the conclusion that those mass-surveillance operations which reach the public are considered more harmful when they are carried out by foreign agencies (Surprise!...I know). This report hit the major news front pages for only one day - my guess is that it has been longer if it was the NSA (or at least the GCHQ) instead of the BND.
schlowmo··on Rclone: rsync for cloud storage
Does anyone know if rclone preserves Linux File Permissions regardless of the cloud storage?

It's not in the feature list and my guess is that this would be hard to implement if you can't take assumptions of the underlying file system.

schlowmo··on Rclone: rsync for cloud storage
Looks promising, but I'm not sure about the crypto-part. Can someone give some notes about the security of NaCl Secretbox using Poly1305 as authenticator and XSalsa20 for encryption?

Is it justified to assume that this is adequate crypto as long as the nonces are choosen correctly (= as random as possible) and the keysize is bigger than 128bit (rclone uses 256bit key derived from user password)?

Documentation of the crypto part can be found here: http://rclone.org/crypt/

EDIT: added constraint regarding keysize.

schlowmo··on “How do I choose not to share my account information with Facebook?”
If their own FAQ is correct, then definitively NO.

Q: So how do you encrypt data?

We support two layers of secure encryption. Server-client encryption is used in Cloud Chats (private and group chats), Secret Chats use an additional layer of client-client encryption. All data, regardless of type, is encrypted in the same way — be it text, media or files.

Our encryption is based on 256-bit symmetric AES encryption, RSA 2048 encryption, and Diffie–Hellman secure key exchange. You can find more info in the Advanced FAQ.

https://telegram.org/faq#q-so-how-do-you-encrypt-data

schlowmo··on Spatial-Temporal Recreation of Android App Displays from Memory Images [pdf]
TL;DR The researchers claim this is a new memory forensic method to gather information from recently used apps from Android devices. Instead of extracting GUI-data from memory images, they extract app-internal data from them (which persists longer than the GUI-data) and restore the View from that data. With this method they can recreate multiple views in the past instead of only one if GUI-data is targeted directly. The method is app-agnostic and doesn't need any knowledge about the targeted apps. They tested their attack against at least 15 apps with success.

They call their method "RetroScope", sourcecode of their forensic tool can be found at Github:

https://github.com/ProjectRetroScope/RetroScope

schlowmo··on Tavish’s excessively long programmer biography
While I second this recommendation I would also think that it doesn't make much sense that most HR people would prefer a "classic" resume over such a piece.

It tells you a lot more about a person WHY and HOW he/she started several different things then the fact THAT those things were done.

Try to imagine how this text would read in a resume like style: strip out all the anecdotal things about how and why and just leave the "facts". To a HR person this would read like "Oh my gosh, this person isn't knowing what to start next." But with all the anecdotal parts it reads more like "Oh a person which knows how to train different skill by theirself."

schlowmo··on What Apple should tell you when you lose your iPhone
> "How does phishing like this scale?"

I assume that the thief which actually steals the phone isn't the same guy which puts this kind of scam on. And if you're the one which buys the stolen phones at larger scale (e.g. by running a used-phone-shop) this kind of scam scales very well I would think.

schlowmo··on Passport Index 2016
When I first heard of Passport Please I was reminded of "Neal Stephenson - Error": the story contains a MMORPG which is used to "automate" stupid security tasks like screening people at an airport by "mapping" them to the MMORPG world were players are awarded when they detect a security threat. I hope this never becomes real.
schlowmo··on Passport Index 2016
While you find reciprocity in many visa-agreements, it's not mandatory. If you look at the example from the parent comment:

Germans can enter Vietnam visa-free, while Vietnamese can't enter Germany visa-free. You find those one-sided visa-free agreements especially for many African countries.

schlowmo··on Passport Index 2016
I think this is a result of "visa agreements on EU/Schengen level" vs. "bilateral visa agreements". Why some EU-countries have bilateral agreements and some not could have different reasons, two I can think of (warning: speculating):

1. No need for a bilateral agreement meaning too few people would be affected by this (think of: number of expats/tourists).

2. Historical reasons, e.g. due to colonialism. This could be true for your vietnam example since The Netherlands got colonies on now-Vietnames territory.

schlowmo··on Your Phone Has an FM Chip. So Why Can’t You Listen to the Radio?
I wasn't aware of Lightsquared. But it seems like they were a "new player". If you look at the winning bids of the "Digitale Dividene (= digital dividend) I" and "Digitale Dividende II" in Germany it's easy to see that you have to be a big player to have real chances (or being even allowed to bid) in those frequency auctions.

"Digitale Dividende I": six 5 Mhz wide bands (always in "pairs") each between 570.849 and 627.317 million €. Winners: O2, Telekom, Vodafone. (source: https://de.wikipedia.org/wiki/Digitale_Dividende#Frequenzver...)

"Digitale Dividende II": thirty-one 5 Mhz wide bands (some of them "paired") each between 39.011 and 255.967 million €. Winners: Telekom, Vodafone, Telefónica (formerly O2). (source: http://www.bundesnetzagentur.de/cln_1432/DE/Sachgebiete/Tele...)

Further I know of some radio stations (especially community radios) which refuse to accept special offers from broadcast carriers for digital radio (DAB+ and DVB-T(2)) broadcasting because of the fear that this could be used as another argument against them having an own analog FM frequency.

schlowmo··on Your Phone Has an FM Chip. So Why Can’t You Listen to the Radio?
There's possibly one reason why carriers (and probably vendors) haven't much interest in FM radios which the article and (if I don't overlooked) no comment mention: digital dividend.

At least here in Germany carriers awaiting the moment when FM broadcast is finally declared dead and their frequencies become free for sale. The VHF band between 87.5 to 108.0 MHz is of big interest especially for rural areas.

schlowmo··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
> "But also directly opposite of what you'd expect from a "cult compound", which people go more to escape what is most popular, than to experience what is most popular."

Agreed, I thought of this point while sending my comment but wasn't sure how to put that in words. So maybe it's the "most crowded garden party".

schlowmo··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
Kind of, but you can only "opt-in" by using so called "secure chats". From their FAQ at https://telegram.org/faq#q-so-how-do-you-encrypt-data:

"We support two layers of secure encryption. Server-client encryption is used in Cloud Chats (private and group chats), Secret Chats use an additional layer of client-client encryption."

It seems like many people (especially users/advocates of telegram) are confused by this, since telegrams marketing sounds like it's fully end-to-end encrypted.

schlowmo··on Facebook Messenger begins testing end-to-end encryption using Signal Protocol
Never heard "cult compound" in this context so far and by thinking about it I really think it better fits then "walled garden". "Walled garden" sounds like you go there because of its beauty or for getting the best crops while in reality you go there because it's the most crowded place.
schlowmo··on Devastating Amazon hardware review of a wireless power switch
> "This word of caution is likely to get lost among the noise."

Not any longer ;). I didn't have the stats for helpful-votes on this review before it was posted on HN, but now with over 600 votes it's #1.

(How many potential buyers care about is another question...)

schlowmo··on Show HN: “OK Google” – Explore Google Now voice commands
Here is a good reading from the Electronic Frontier Foundation on domains like that:

"Avoiding Gripes About Your Gripe (or Parody) Site": https://www.eff.org/wp/tips-shutting-down-g

schlowmo··on Defending Our Brand
They always provided free "personal" certifcates with a validity of one year. But they market the "Start Encrypt" thing like you now get wildcard and EV certificates for free (which isn't true). Talking about scummy practices...
schlowmo··on The Intel ME subsystem can take over your machine, can't be audited
In this case x86 means both 32bit x86 (also referred as IA-32) and x86_64.

From https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...

  "The Management Engine (ME) is an isolated and protected coprocessor, embedded as a non-optional part in all current (as of 2015) Intel chipsets."
schlowmo··on CHIP $9 Computer
Same with Lenovo where mini-DP is the standard for Ultrabooks.
schlowmo··on Konrad Zuse and the digital revolution he started 75 years ago
> "Zuse is an interesting example of history being written by the victors."

This may hold true for the Zuse story, but he's also an example for german history about german scientists. While the Wikipedia article (both german and english) mentioning his ties to the NS and the german defence industry of that time, you probably find no hint about that at universities where lecture halls are named after him. For example in Hamburg, where the only "real" lecture hall at the CS department is named after him. In the small exhibition about his scientific life beneath this lecture hall you don't find a word about that (at least the last time I was there).

schlowmo··on Merkel Grants Turkish Request to Prosecute German Satirist
> "The current government also announced that'll soon throw out this obscure paragraph [...]"

I'm not sure if I would call 2018 (like Merkel announced) soon. At least it's after her current period of governance (which will end September 2017).

schlowmo··on Merkel Grants Turkish Request to Prosecute German Satirist
> "says a big "F* Y" by eliminating the law and saving the comedian"

I don't think that this is "saving the comedian", since the law should be eliminated as of 2018. It's likely that judgement (at least at the first level of jurisdiction in case of objection/revision against) will be made sooner. Further who knows what proposed legislation come up since then, or like the Germans say: Since then, a lot of water will flow down the Rhine.

Currently Germany isn't known for its great process against odd repressive laws, I would say it's even the contrary developement when it comes to state authorities, which leaves me sceptic about that.

schlowmo··on Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor
You can read those mentioned qualifications for this particular officer in the Affidavit for Search Warrant at page 2:

https://www.thestranger.com/images/blogimages/2016/04/08/146...

My favorite is "Basic Computer Skills for Law Enforcement" which could be literally everything, starting with "How to play minesweeper?"

schlowmo··on Pwncloud – Bad crypto in the Owncloud encryption module
> "or any other cloud storage provider"

I just wanted to point out that as long as you're not in full control of the server hosting Owncloud (and not connect your Owncloud to third party cloud spaces) you've to care about your own client-side crypto like on any other cloud provider (self hosted or not). So there's nothing special about Dropbox - but also not so much special in security terms about Owncloud.

Anyway I would still recommend using Owncloud over any other cloud storage provider if you're able to host it or know someone hosting it. But you should consider the security implications if you care.

schlowmo··on Pwncloud – Bad crypto in the Owncloud encryption module
If you want to go along with owncloud (and I don't know a proper alternative) there's not much you can do then upgrading to Owncloud 9 and hope that the fix was done right. In the meantime you could encourage your users to use their own client-side encryption while giving up the idea of an easy setup.
schlowmo··on Pwncloud – Bad crypto in the Owncloud encryption module
Yes, maybe I should've made this emphasis stronger in my comment. Also I didn't meant to say that using owncloud is worse than using dropbox in security terms - but you should use your own (client-side) crypto either way if you care about data security.

For myself I use my selfhosted owncloud (running on a cheap VPS) with EncFS, encourage other users on that server to use client-side encryption as well and never lied about how secure their data is when they decide not to. But this isn't so easy as it should be.

schlowmo··on Sample workflow for LP digitization
Word! I just like to add that it's especially indispensable for many community radios across the world. Maybe there are more powerful tools out there (FOSS or not), but I never saw an audio tool with such capabilities which people got used to so quickly like they do with Audacity. The absolutely perfect fit for those community radios where almost everything has to be self-taught.
← PreviousPage 4 of 5Next →