HNHacker News
TopNewBestAskShowJobs

sexmonad

49 karma · joined January 13, 2014

submissionscomments
sexmonad··on George Orwell's review of Mein Kampf (1940)
I don't see the parallel as intended to put Napoleon down, but instead to attribute the same force of personality to Hitler. As someone who never met either man (perhaps that's obvious :), I'm not sure the connection works with me.
sexmonad··on Lattice's $24.99 FPGA Evaluation Kit
Can you list some of the boards that are both cheaper and more capable?
sexmonad··on It's Time For a Hard Bitcoin Fork
Why do BitFury and Petamine use a pool at all? At their scale, wouldn't they have low enough variance through solo mining? Or perhaps P2Pool?
sexmonad··on 5 Tiles Keyboard
That video is just auto-complete after the first letter...
sexmonad··on Poll: What OS do you use on your primary computer?
I use Linux basically everywhere - Arch Linux on development machines, Ubuntu or Debian on servers. I use Windows for gaming maybe 5-10 hours a week.
sexmonad··on US files criminal complaint against Credit Suisse
Can someone explain to me how the US has jurisdiction over Credit Suisse? I see how they could have gone after the individual tax fraudsters (American citizens), but how can they police foreign banks?
sexmonad··on The pre-play vulnerability in Chip and PIN
We really ought to completely skip over Chip and PIN to something like Google Wallet or another NFC system...
sexmonad··on The NSA Is Recording Every Cell Phone Call in the Bahamas
Yes, this is the NSA's job - foreign SIGINT. If you don't like this, you need to use encrypted communications.
sexmonad··on The shock of playing the Ouya, one year later
I take this sentiment a bit further - unless it's throwaway-cheap, the reviews and word of mouth are stellar (they're usually not for any but the biggest hits), or the concept immediately clicks for me, I will pirate the game to try it out. If I like the pirated version, I _usually_ purchase the full game (but not always). Not having reasonable demos just increases game piracy.
sexmonad··on The shock of playing the Ouya, one year later
No. If I shut down my laptop, my hard drive is encrypted and keys are no longer in RAM (modulo a cold-boot attack, but that is only really useful for <30 minutes after shutdown without preparation).
sexmonad··on Quantum Random Number Generator Created Using A Smartphone Camera
The obvious solution for this would be for Android to expose "derive random numbers from image frame" as a permission. But this is unnecessary, because they can just seed /dev/random from this source at boot (or if the device is unseeded).

That said, mobile devices really aren't lacking in entropy sources. With all the radios and sensors in a modern smartphone, why do they need additional methods to generate random numbers?

For information security purposes, a cryptographically secure PRNG is typically at least as secure as the encryption algorithms that it protects.

sexmonad··on Quantum Random Number Generator Created Using A Smartphone Camera
https://www.tindie.com/products/ubldit/truerng-hardware-rand...

But I'll give two cautions:

1. This device has received less auditing than linux's software crypto. And some HWRNGs are quite bad: https://news.ycombinator.com/item?id=6060636

2. You don't really need that much randomness. After your machine has been on for a while and has seeded correctly, /dev/urandom is just as secure as /dev/random. Entropy is not gasoline - it does not disappear as you use it.

sexmonad··on Using Dnsmasq for local development on OS X
I use "lvh.me" - it has a wildcard DNS record to redirect any subdomain to localhost. So I'll use something like "example.com.lvh.me" to test.
sexmonad··on Distrusting StartSSL
StartSSL's default usage mode is to generate private keys on their website. Yet another horribly insecure system.

I'd much rather that people used self-signed certs (and browsers had certificate pinning) by default, and could then step up to real CA certificates. Self-signed certs provide almost the same amount of trust that StartCom does.

sexmonad··on "OpenSSL has exploit mitigation countermeasures to make sure it's exploitable"
That bug affected OpenSSL as well. Admittedly, it was caused by the Debian maintainer, but still, OpenSSL's poor design is partially to blame.
sexmonad··on The Heartbleed Bug
Update to 1.0.1g, redo all crypto. That is, revoke certs and keys and regenerate.
sexmonad··on Note the commit hash
Each hex character represents 4 bits. That means that a 7 character string is 28 bits. That's about 268 million possibilities. On average, it would take around 134 million commits to get one that started with "badc0de".
sexmonad··on How I Hacked a Router
>sha1sum putty.exe

>google "44ac2504a02af84ee142adaa3ea70b868185906f"

>see results are mostly "putty.exe"

Three steps, all relatively painless.

sexmonad··on What I Would Do If I Ran Tarsnap
My favorite thing about tarsnap is how damn reliable and trustworthy Colin is. If I see tarsnap start to move towards whatever fad all the other SaaS platforms are following today, I'll probably assume that they're trying to be the next Dropbox. That might be the right decision for tarsnap, but I'd move my backups.
sexmonad··on What I Would Do If I Ran Tarsnap
Deduplication. And like any other SaaS or cloud model, not hosting it yourself.
sexmonad··on Introducing Opencall
What is <insert technology>, and why do I have to learn it if <insert worse technology> is sufficient?
sexmonad··on Tarsnap now accepts Bitcoin
This is my question too. Tarsnap is cool, and Colin deserves to get paid for his hard work, but the cost differential is far too much for me to use tarsnap right now. If they cut their costs in half, I'd be able to afford to use them over raw S3.
sexmonad··on Dear founders: Children are not a distraction, they are motivation
I'm curious how it compares to the average quality of upbringing with three parents.
sexmonad··on Satoshi Nakamoto denies being Dorian Nakamoto
Yes.

http://sks.pkqs.net/pks/lookup?op=vindex&fingerprint=on&sear...

http://sks.pkqs.net/pks/lookup?op=vindex&fingerprint=on&sear...

sexmonad··on The Face Behind Bitcoin?
It's true. The blockchain is at best pseudoanonymous. If you are careful about how you get your coins, and use a high latency mixer (which don't exist as far as I know, but can be faked by multiple runs through a low latency mixer) and take your profits out slowly, you can make them quite anonymous. While they are a richer stream of data that a purely cash business, they don't have the same hassles (mostly physical size and security issues) as cash.
sexmonad··on Silk Road 2 Hacked, All Bitcoins Stolen
You can also use something like blockchain.info for slightly better security than coinbase. They do client-side encryption and decryption of wallets. Of course, if you forget your password, your coins are gone. And blockchain.info could always modify their code to steal your coins later. At least they couldn't steal them without you logging in.

But a thin wallet like Electrum is probably your best bet.

sexmonad··on Comcast Acquiring Time Warner Cable In All Stock Deal Worth $45.2 Billion
Twitch shooters, at least, definitely do _not_ have built in latency, and 250ms is unplayable.
sexmonad··on Level 3 are now hijacking failed DNS requests for ad revenue on 4.2.2.x
I'm not sure if it's a certain way to tell, but try running a traceroute. If your traffic seems to go into Level3's network, that's a good sign that it's not getting rerouted.

Here's what I see from my DigitalOcean droplet.

root@derpy:~# traceroute -I 4.2.2.1 traceroute to 4.2.2.1 (4.2.2.1), 30 hops max, 60 byte packets 1 198.199.122.1 (198.199.122.1) 12.055 ms 12.123 ms 12.314 ms 2 xe-10-3-3-100.edge3.Newark1.Level3.net (4.28.6.69) 0.948 ms 0.959 ms 0.959 ms 3 ae-31-51.ebr1.Newark1.Level3.net (4.69.156.30) 1.396 ms 1.477 ms 1.478 ms 4 ae-10-10.ebr2.NewYork1.Level3.net (4.69.132.97) 1.530 ms 1.630 ms 1.659 ms 5 ae-62-62.csw1.NewYork1.Level3.net (4.69.148.34) 1.465 ms ae-82-82.csw3.NewYork1.Level3.net (4.69.148.42) 1.464 ms ae-62-62.csw1.NewYork1.Level3.net (4.69.148.34) 1.390 ms 6 ae-1-60.edge2.NewYork1.Level3.net (4.69.155.16) 1.363 ms 1.389 ms 1.395 ms 7 a.resolvers.level3.net (4.2.2.1) 1.456 ms 1.466 ms 1.421 ms

sexmonad··on Level 3 are now hijacking failed DNS requests for ad revenue on 4.2.2.x
It's still hijacking, but they're under no obligation to provide service.
sexmonad··on Dispelling Backblaze's HDD Reliability Myth
Anecdotally, at my last job, we had used them on several of our internal file and VM servers (because they were cheap), and they had a nasty habit of falling off the bus overnight, causing the RAID controller to go berserk.