HNHacker News
TopNewBestAskShowJobs

tbrowbdidnso

219 karma · joined February 19, 2017

submissionscomments
tbrowbdidnso··on An In-Depth Study of More Than Ten Years of Java Exploitation
I agree. Who runs arbitrary code in a JVM these days? We have real hardware based virtual machines now, making this irrelevant.

Back in the day Java JVM was the best way to run untrusted code close to native speed. That hasn't been the case for many years now...

tbrowbdidnso··on Prenda copyright trolls made their own porn, seeded on Pirate Bay
Yeah same here, can somebody find us a pirate bay link?
tbrowbdidnso··on To fix L.A.'s traffic, we need tolls
For the love of God it's not the traffic its lack of public transport. Once you hit a certain density CARS_DONT_WORK . Having lived in NYC, visiting LA was a joke.

The first thing I did after my first cab ride from the airport was look up public transport since I noticed traffic was worse than NYC. There wasn't any

tbrowbdidnso··on Google featured snippets are worse than fake news
What we seem to be running into, is that any strategy based on trusting some sites and not others breaks when very large groups of sites have opposite opinions. Depending on your starting set you will end up with wildly diverging trust scores
tbrowbdidnso··on Major Experiments That Still Haven’t Found What They’re Looking For
Seen the pictures of guys in boats floating out in the kamiokande? I always thought it was the coolest looking experiment.

I was really sad when all the bulbs broke years back :'(

tbrowbdidnso··on IBM Building First Universal Quantum Computers for Business and Science
Are they? This news saddens me greatly.
tbrowbdidnso··on Google featured snippets are worse than fake news
Fake news is just a new version of spam sites. They mostly exist to make money or enforce an agenda.

People figured out that Google's algorithms could tell when things were generally factually false, unless those things were recent news.

This leads me to believe their algorithms largely relied on news as a source of truth. They're going to have to do something about that

tbrowbdidnso··on IBM Building First Universal Quantum Computers for Business and Science
Does that change anything I said? All this marketing doesn't seem to lead to anything tangible unlike similar releases from other big companies. It's just fluff.

I'm aware the IBM does consulting and that's possibly the most boring software realm there is.

tbrowbdidnso··on To keep Tor hack source code secret, DOJ dismisses child porn case
https://www.google.com/amp/s/nakedsecurity.sophos.com/2015/0...

Not the FBI per se, but it shows that someone is clearly attempting to compromise TOR users.

Also there's been whispers about it forever. Much like the "black rooms" at datacentres before all the NSA leaks.

The FBI has a long history of tracking down and compromising CC theft and CP rings, along with silk road and the hoards of clones. Most of these sites are primarily or only accessible over TOR.

Running compromised TOR nodes would be an extremely cheap way to monitor a large portion of illicit Internet traffic. The frequent busts are usually attributed to other reasons to shift attention away from TOR, but this is classic parallel construction.

The feds will nearly always get you on secondary evidence when the primary means is too sensitive... See stingrays. The sheer number of TOR based site busts however is telling.

Anyone relying on TOR for security is a fool. It's more heavily monitored than the regular net.

tbrowbdidnso··on Google featured snippets are worse than fake news
If anyone had one it would be Google :)
tbrowbdidnso··on IBM Building First Universal Quantum Computers for Business and Science
Can somebody tell me something cool IBM actually does for real besides run softlayer?

I'm so tired of endless waves of marketing bullshit with no substance. At least when most companies announce something it's a tangible product I can actually expect to use at a non ambiguous point in the future

tbrowbdidnso··on Google featured snippets are worse than fake news
You can see from this that google considers text earlier in the page more important.

This page is odd because the false answer is presented first, so google fails to see it. It could tell that the form of the sentence was an answer to the question, just not that it wasn't the right one

tbrowbdidnso··on Google featured snippets are worse than fake news
I'm no wizard, but in writing blog articles I've found ways to fool Google into believing me.

The problem with their algorithms.... is that all that statistics in the world can't help you when you're listening to a guy telling the truth vs an equally good liar.

I can tell you what Google doesn't have, a strong AI. It thinks it knows "facts" but these are merely patterns, and these can be gamed.

Because Google still lacks a strong, truly thinking AI, they rely extremely heavily on statistical models to rate content.

So how do you cheat google search?

Google's systems attempt to figure out the topic of your writing, the style, and quality. Is it scientific? An opinion piece? News? Is it a technical topic? A playful one? Fiction or nonfiction ?

The quality classifiers are much easier to game than topic and style analysis. They determine things like reading level of text but also things like the number of rare nouns, number of technical words, number of typos. Readability as far as font and formatting. Trustworthy signal of your domain and possibly the company and people they determine to be linked with it.

I also have a feeling google uses sneakier signals as well. These include your DNS registrar, phone number, email, and address listed on the site. Who you host with and what technologies you're using. Your mail servers and how trustworthy they are. Geo location, and visitor traffic info as soon as you put analytics on the site (or use amp)

Basically when Google says they have tons of signals, they do. They have a dataset that amounts to every site on the internet for the past 15 years, and they regularly run automated and manual "theory provers" much like quants do with historical stock market data. They find new signals constantly, and run tests to see if their new algorithms are better.

You know how sometimes google randomly takes a bit longer to load search results? My tin foily theory? They'll occasionally guinea pig you on prototype search results to see if they're better. I noticed their response time getting really bad a couple months before the public rollout of new AI powered search for example.

So gaming google? Do exactly everything that a large, legitimate, no-nonsense company would do. From where you host, what you host with, to who you link to. Bonus points if you have significant real looking mail and other traffic from your domain. Extra bonus points if you actually sell something real as cover and do it for at least a few years.

Once you've done enough convince google you're a big important thing IRL...write a ton of really subversive bullshit. Make it sound a real as possible, hell make 90% of it real, just with a single unverifiable fact. Keep pumping this shit out and make sure your garbage is never fake enough to get called out on. Or just make the fake part so hard to verify that nobody will waste the time, kinda like half the science world does when publishing papers.

tbrowbdidnso··on Why we are not leaving the cloud
You should remember that the early cloud unicorns are getting super low rates for their name clout as well. Their discounts are passed as extra costs to everyone else.

So while it may be worthwhile if you're huge enough to get a big discount, that doesn't mean it applies to small or medium size companies

tbrowbdidnso··on Why we are not leaving the cloud
I believe the truth is somewhere in the middle. The hype will eventually die down and we'll see some kind of equilibrium.

I've been experimenting with "cloud over" where I only use cloud servers for spare capacity. With docker it's getting easier. My baseline CoLo has the same performance as a super high end AWS instance and costs a third as much after my fixed investment.

I still have the cloud if my box goes down or takes a big traffic hit, but I'm not paying for a bunch of cloud servers all the time either.

tbrowbdidnso··on Why we are not leaving the cloud
Google ran on desktop computers for a long time. If anything, the cloud is less reliable than individual machines once were. You have no control over when or why one of your VM's goes down, and there's nothing you can do but wait and hope everything comes back in short order.

I've had degraded instances screw my customers websites many many times in AWS. On our VMware cluster I never have any such issues because I make sure not to touch anything running production sites

tbrowbdidnso··on Why we are not leaving the cloud
I know it's a controversial opinion. And probably not even true in a lot of cases... but I'm glad it sounds like I'm out in left field.

The echo chamber needs a devil's advocate and sometimes the resulting discussion gets interesting enough that I question my original beliefs.

In this case I believe owning my hardware is cheaper for me because I already do. I might be a rarity though, or just old fashioned and wrong

tbrowbdidnso··on Why we are not leaving the cloud
Possibly outgoing bandwidth. These costs are directly proportional to traffic and regularly 20-30x the unmetered rate for a colocated box
tbrowbdidnso··on Why we are not leaving the cloud
Running on rented hardware is the equivalent of a traditional product company renting all of their factories. Almost any company of reasonable size will want vertical integration of their supply chain and web companies are no different.

Using Netflix as an example again, if they're pitted against a company that runs their own hardware but is otherwise equal, they will lose. A portion of their profit is siphoned off as Amazon's profit. What's already happened is Netflix is directly funding development of Amazon Prime Video.

tbrowbdidnso··on Why we are not leaving the cloud
There is nothing hard about running hardware. The current VM trend gives you bare metal access. the only difference is you have to plug in your machines, and you get to look at them every once in a while.

Really, what software dev hasn't put together a desktop PC and plugged in some Ethernet jacks? That's all you need to Colocate.

Your response echos what cloud providers want everyone to think. Hardware is too hard for us, let's pay someone to do it and make 50% profit margins on us

tbrowbdidnso··on Why we are not leaving the cloud
So everyone says the cloud is the future. I get it. But is this the truth, or what all the tech giants want people to believe? Don your foil hats for a moment and listen to me.

All the original internet companies run their own hardware. They rent out excess production capacity to us peons in the form of cloud services.

These companies that all run their own hardware exclusively are telling everyone that it's stupid to run your own hardware... Why are we listening?

Look to the newer tech giants as a prequel of what's to come. Netflix for example, is completely at the mercy of Amazon. They might as well be "Netflix brought to you by Amazon". Their edge is in software alone, nothing that causes a huge barrier to entry like custom hardware. This makes them much easier to dethrone. Hilariously, they rent all their hardware from a direct competitor who has access to all their software secrets. Does anyone else see something wrong with this?

The cloud as a money saving venture is and always has been a damn lie.

It's the same tactic as when automotive companies paid off local governments to destroy Americas public transport many years ago. All the big tech companies have their hands in the cookie jar besides Facebook, who remains mostly silent but runs their own hardware as well.

The major tech companies have every incentive to make you think running your own servers is nigh impossible. Don't drink the fucking koolaid. If the industry continues to consolidate rapidly AmaGooSoft will be the ONLY places you can have web servers in ten years

tbrowbdidnso··on AMD Zen and Ryzen 7 Review: A Deep Dive
What? I've never run a parallel op on the GPU but I do on my CPU multiple times a day. GPU acceleration besides games is still extremely rare. You're grasping straws here.

You're also missing that even on chrome the js and layout engines run different threads. Same with audio and video rendering. Same with downloads. The average page is probably running things on 10-20 random threads. And the average user has multiple tabs open.

Multicore CPU is so common these days that any performance critical code that can be parallelized, is. This includes GZIP and HTTP which are used heavily by web browsers. The network stacks underneath those in the OS are also multi core capable.

Single thread performance is not all that important anymore. It's better to have 2x the number of fast cores than half the number of slightly faster cores in almost every situation these days.

tbrowbdidnso··on Dilution
I never understood this logic. Investors want unicorns but it's not like they're going to hate you for only giving them a 5x ROI.

Most startups either fail or become small businesses. Investors are giving you money to fund a business that you own. Depending on the terms you can, and should, use that money for whatever you want.

Its the investors problem if 5x returns aren't good enough, not yours. Does the bank call you to complain that your mortgage interest rate is too low? No. They gave you the loan with what they thought was reasonable terms at the time. It's not your fault they gave you the money too easily.

You should be focused 100% on building a successful sustainable business. Investors can fuck right off if they push for risks that could turn their 5x return into 0.

tbrowbdidnso··on Dilution
I will never take startup advice from investors. They care about your company and their money, not you.

Of course they're going to tell you not to worry about giving more of the company away, they don't care who owns it. More money flying around is almost invariably a good thing for early investors.

You don't really need advice about funding from anyone, just look at some successful companies and see what they did. Funding is one of the few aspects where you can mimic your startup idols because it's public info.

The fact is, all the biggest unicorns had enough promise and brains behind them to retain majority ownership, or at least full control well into billion dollar territory. If you're good enough investors will be practically begging to give you their money.

Yeah, so fuck the advice from investors. Make sure you keep as much ownership and control over your company as possible until it's sending people to the moon.

tbrowbdidnso··on Split Tokens: Token-Based Authentication Protocols Without Side-Channels
You can mix the hash with a salt that the attacker doesn't and cannot ever know. This is pretty standard and prevents the leak of timing from revealing anything about the hash. The only time this fails is if your hash function is broken, and if that's the case you've got much bigger problems
tbrowbdidnso··on Split Tokens: Token-Based Authentication Protocols Without Side-Channels
If you want to avoid timing attacks on the username and pw isn't the easiest way to just hash them as if they're both passwords? (at least on initial login). Since the hashes are cryptographically secure you can't infer any timing information from incorrect guesses
tbrowbdidnso··on Incident management at Google – adventures in SRE-land
Also keep in mind that even the mighty Google has some rusty and pointy internal tools. There's no reason to mention any crappy things in a book about good practices ;).
tbrowbdidnso··on Uber Executive, Linked to an Old Harassment Claim, Resigns
He resigned on his own terms. I know executives pull that crap all the time to avoid getting "fired" but the fact is he quit voluntarily
tbrowbdidnso··on Split Tokens: Token-Based Authentication Protocols Without Side-Channels
The author is mistaken about the side channel existing. In the most common case of login and token generation it just doesn't.

With logins you compare the hashed password to a stored hash. The author mentions that you can tell how much of the hashes match because the compare function exits early if they do. This might be true, but it doesn't give you anything.

When using a secure hash function with a salt, the attacker being able to guess how much of the two hashes match gives him no information because:

1) he doesn't know what hash is stored 2) he doesn't know what his password attempt hashed to 3) he doesn't know the salt

The only thing that the attacker knows is that he created a hash with his attempt that matches the first few bytes of the real hash. If you use a strong hashing algorithm this is useless information and will happen at random.

tbrowbdidnso··on BlueCoat and other proxies hang up during TLS 1.3
The TLS negotiation is mutual. Both endpoints tell each other what they support and they agree on a protocol that's mutually supported.

If merely advertising 1.3 while still advertising older versions causes blue coat to break, it has a bug in TLS version negotiation.

There is no downgrade or whitelist or failing closed. Each end says what they support and BlueCoat blows up the connection if it sees that the other end supports a newer version. It should say "oh we both support 1.2 let's use that" And apparently it's done this before so there's even less an excuse for it.

Page 1 of 2Next →