HNHacker News
TopNewBestAskShowJobs

sslalready

500 karma · joined September 18, 2014

Telecom. Berlin, Germany.
submissionscomments
sslalready··on Are we going to use the same Desktop UX forever? [video]
What an amazing guy. Very refreshing concepts. I would love to see them materialize some day.
sslalready··on I've acquired a new superpower
And then there’s Banksy’s “in the future, everyone will be anonymous for 15 minutes“. For pretty much the same reasons you stated above, I assume.
sslalready··on ESPHome
ESPHome is awesome. Any chance you can get MQTT running on RP2040W?
sslalready··on Fidelity has cut Reddit valuation by 41% since 2021 investment
Link: https://old.reddit.com/r/apolloapp/comments/13ws4w3/had_a_ca...
sslalready··on BratGPT: The evil older sibling of ChatGPT
1992 A.D. even.
sslalready··on How to draw dotted lines on chalkboards, MIT style (2021)
I was surprised there was no mention of him in the text. There's more of him on YouTube: https://www.youtube.com/results?search_query=walter+lewin+do...
sslalready··on Trolley.co.uk is shutting down – pricing data is apparently owned by a company
A lot of E-commerce software have data feeds that are ingested by parties like pricespy. These feeds are typically either public or made available after mutual agreements. Scraping a large amount of sites for data is just too much labor in the long run.
sslalready··on Sunset of libspotify
Kudos to Spotify for supporting libspotify and its use-cases for so many years. I'm sure it hasn't been easy and that copyright owners haven't been very fond of it.
sslalready··on Pocket-sized cloud with a Raspberry Pi
Anecdata: I’ve found USB powered external drives to be unreliable on the Pi, even when powering the Pi with an official power adapter. I’d recommend using an external drive that comes with its own power adapter.
sslalready··on “The Pirate Bay can’t be stopped,” co-founder says
IIRC, the uTorrent guy (Ludde Strigeus) was employeed by Spotify and worked on, among other things, the P2P feature in Spotify.
sslalready··on Gitlab servers are being exploited in DDoS attacks
Reasons for self-hosting: GitLab.com's not-so-great availability [1], slow code searches (compared to self-hosted with GitLab Advanced Search) and the fact that you can keep your code and resources off the public Internet.

The fact that you do need to upgrade it yourself regularly is indeed a drawback. On the other hand, an Omnibus upgrade has only failed me twice in the last five years or so, so there's little reason to not do automatic upgrades at night and fire off an alert in case something doesn't work as expected afterwards. Their releases are typically solid, so kudos to the team.

[1] https://status.gitlab.com/pages/history/5b36dc6502d06804c083...

sslalready··on Newly discovered Vigilante malware outs software pirates and blocks them
I think GOBBLES pioneered this technique in like 1992 A.D. with their “Hydra”. Iirc it was claimed to exploit (jinglebellz.c) .mp3 players on behalf of the RIAA and to spread through file sharing networks. https://www.theregister.com/2003/01/14/is_the_riaa_hacking_y...
sslalready··on Massachusetts health notifications app installed without users’ knowledge
I too found this after reading about it here. I contacted them and received the following reply.

> Exposure notifications cannot be enabled without user consent, so if you have not turned MassNotify on, then it is not active on your phone. However, a recent Google update, which makes MassNotify available as an option in your phone's settings, is causing some users to see MassNotify in their app list. Apologies if this caused any confusion.

>

> The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533

>

> You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.

sslalready··on It appears that Reddit is forcing me to use their app to see deep linked content
Sounds like he hasn’t been introduced to banana with tomato ketchup yet.
sslalready··on Intent to issue €2.5M fine to Disqus over GDPR breaches
You could already download most of the comment data from them by querying their API. Similar to profile pictures on Gravatar, emails were only hashed with MD5. They’re easy to reveal with some wordlist attacks.
sslalready··on Gitlab's 2021 Survey uncovers a new DevOps maturity model
Use the download button in the top right of the pdf viewer thingy. That’ll render the actual pdf without html and annoying modals.
sslalready··on BitLocker Lockscreen Bypass
Reminds me of the Solaris TTYPROMPT in.telnetd bypass: https://packetstormsecurity.com/files/114491/Solaris-TTYPROM...
sslalready··on “Before cancelling your subscription, you must agree to the following”
I think it’s just a strategy to take advantage of unique content to drive traffic to the site. I’ve seen this before.
sslalready··on Ask HN: What are some problems solved in unrelated domains?
This one has been relevant for the last 10 years: https://picturesofpeoplescanningqrcodes.tumblr.com/
sslalready··on Dream Vendor "Canna_Bars" Sentenced to Prison
I’ve reflected on the fact that some makers on YouTube wear gloves and wondered if this is for privacy reasons. I see globes being worn even when they’re not obviously doing anything that risk getting their fingers dirty.
sslalready··on The Linux Backdoor Attempt of 2003 (2013)
Not that I'm aware of, but I wish. Memory is getting hazy these days. AFAIK the kernel.org breaches were made by the kind of hackers doing it for fun and games (if you get that thing) and not the kind working for nation states. I'm sure you can (or at least, at some point could) find others who know more details at your favorite compsec conf.
sslalready··on The Linux Backdoor Attempt of 2003 (2013)
If memory serves me right the CVS bug was originally discovered and exploited by a member of an infamous file sharing site. After descriptions(?) of that bug were leaked in underground circles, an east European hacker wrote up his own exploit for it. This second exploit was eventually traded for hatorihanzo.c, a kernel exploit, which was also a 0-day at the time.

The recipient of the hatorihanzo.c then tried to backdoor the kernel after first owning the CVS server and subsequently getting root on it.

The hatorihanzo exploit was left on the kernel.org server, but encrypted with an (at the time) popular ELF encrypting tool. Ironically the author of that same tool was on the forensic team and managed to crack the password, which turned out to be a really lame throwaway password.

And that's the story of how two fine 0-days were killed in the blink of an eye.

sslalready··on Vitamin D looks powerful, underutilized for Covid-19
I believe he has claimed that vitamin D deficiency is associated with worse upper respiratory tract infections in one of the earlier videos.
sslalready··on A Chapter from the FBI's History with OpenBSD and an OpenSSH Vuln
There’s nothing that suggests that those experiments had anything to do with OpenBSD.
sslalready··on A Chapter from the FBI's History with OpenBSD and an OpenSSH Vuln
Several people have looked into the issue over the years but so far no traces of malicious intent have been found.
sslalready··on A Chapter from the FBI's History with OpenBSD and an OpenSSH Vuln
I remember ftp.openbsd.org being owned around 2002. Possibly this hostname was pointed to the www.openbsd.org machine, which was running Solaris. I have a vague memory that this machine also hosted something else in addition to the OpenBSD site, and that people managed to get root on it via two (chained) 0day exploits of which at least one involved a Solaris daemon related to printing services. (Feel free to correct me if I got it wrong.)

I also recall cvs.openbsd.org being owned but I no longer remember how that happened. There's a high chance it was made possible thanks to a remote CVS exploit that was making rounds in some hacker circles[1]. FWIW, cvs.openbsd.org is mentioned under "memorable places I've been" in the Phrack #65 prophile of the UNIX terrorist.

2002 was a particular bad year for OpenSSH and OpenBSD. In March, 2002, it was found that OpenSSH 2.x/3.0.1/3.0.2 had an exploitable (post-auth IIRC) integer overflow in its channels handling. In June, 2002 that preauth Challenge-Response vulnerability was made public and shortly afterwards GOBBLES Security made public an exploit (sshutuptheo) for the vulnerability that among other things targeted OpenBSD 3.1 default installations. Early August, 2002 it was discovered that several OpenSSH packages had been backdoored on ftp.openbsd.org on June 30th, 2002 (google: "openssh 3.4p1 trojan").

Incidently the sshutuptheo exploit was written by the Australia division of GOBBLES Security. Later postings on public mailing lists suggests that this division fell off the earth shortly afterwards (can't link).

Some of these things had ties to the community around #phrack and the autonomous Phrack High Council "movement". PHC had nothing to do with the official Phrack magazine and instead was similar (in actions) to the Global Hell (gH) movement that happened earlier (around 2000, I think). PHC kind of spun out of the anti-sec movement that existed at the time, but really it was just a setup to trick kids into thinking they have a common purpose and do damage for the lulz; think early "anonymous" or lulzsec and you'll get the idea.

I know FBI had at least one informant in the #phrack and PHC circles at the time: soupnazi a.k.a segvec a.k.a [2]. So perhaps those contacts mentioned in a child post aren't OpenBSD developers but.. other people?

The nickname of the Hungarian wasn't pipops but I'll leave it out since you got the reference right the first time: "PaX Team" ;) Regarding the feud, you can find some pointers in this poster defacement[3] attributed to the Micke Mouse Hacking Squadron. The picture is from the OpenBSD tent at the Chaos Communication Camp in Berlin, Germany in August of 2003. MMHS was one of several GOBBLES Security copycats. They generally lacked the effort but MMHS was the only one that, like GOBBLES, produced a few (arguably funny) comic strips.

Grsecurity/PaX team did a hell of a job identifying vulnerabilities and working around them or hardening code long before anyone else. It's not surprising that they would've mingled with others interested in that sort of things, possibly sharing hints of vulnerable code paths or having discussions around the vulnerabilities and/or workarounds.

[1] https://news.ycombinator.com/item?id=18179805

[2] https://en.wikipedia.org/wiki/Albert_Gonzalez

[3] https://web.archive.org/web/20060512113602/http://www.grsecu...

sslalready··on Anyone made the jump from MySQL to PostreSQL? It is worth it?
Care to expand on why MySQL < 8 will be problematic for analysts? Anything else than the lack of window function?
sslalready··on Ask HN: Open-source feature flag service?
https://github.com/Unleash/unleash

> Unleash is a feature toggle system, that gives you a great overview over all feature toggles across all your applications and services. It comes with official client implementations for Java, Node.js, Go, Ruby and Python.

sslalready··on Table-Saw Kickback on Camera (2012) [video]
Thanks for the detailed write up!
sslalready··on Table-Saw Kickback on Camera (2012) [video]
Second this. It’s super hard to imagine in what ways things can go wrong before you have seen or experienced them.

Kick-backs would never even have been on my radar, even though I’m seeing myself as a careful person, if it wasn’t for YouTube and people like him taking their time to educate the rest of us.

Page 1 of 3Next →