HNHacker News
TopNewBestAskShowJobs

throwaway7767

2,104 karma · joined March 20, 2014

Please delete this account, HN admins
submissionscomments
throwaway7767··on Linus' reply on Git and SHA-1 collision
> 1) Git doesn't rely on SHA-1 for security. It relies on HTTPS, and a web of trust.

Some security-focused developers sign git tags and/or commits, specifically to have things verifiable end-to-end and not having to trust HTTPS and all the middle men that entails.

Would that not be a case where git relies on SHA1 for security? Someone could replace a tag or commit with a malicious version that verifies fine since it has the same hash the original developer signed.

> 3) Even if someone managed to pull off a preimage attack, creating a "poisonous" version of one your git repository's objects, they'd still have to convince you pull from their repo. This requires trust.

In the case of signed commits/tags, this opens projects up to malicious action by hosting companies and others. Usually signed commits and tags are used specifically to avoid that exposure, because the developers don't trust the infrastructure.

> 4) Even if you pulled it in, your git client would simply ignore their "poison" object, because it would say, "oh, no thanks, I already have that object". At worst, the code simply wouldn't work. No harm would be done.

That only protects existing checkouts that already have fetched that commit. What about new checkouts, or older checkouts that haven't been updated yet?

Not disputing that this SHA1 collision does not signal any immediate emergency, just pointing out that git is used in different ways by different people, and some of those uses very much do depend on git's SHA1 for security.

throwaway7767··on It took less than a minute of satellite time to catch illegal fishing vessels
Good work. We'll never use resources sustainably if we can't properly account their usage.

> Plus, unregulated fishing boats often use incredibly dangerous equipment to fish, like trawlers. Dolphins, turtles, and seals get caught up in these nets along with the target species and are ultimately killed and thrown away. "It’s not like a guy with a rod and reel," Hammerschlag said. "Trawls are basically underwater bulldozers. When they take up shrimp or crabs, they pretty much bulldoze bottom of ocean and pull up everything. That creates an uninhabitable area for other organisms. You’re kind of putting salt in the fields, and it takes hundreds or thousands of years to grow things there again."

I'm curious why they focus on these illegal fishers being trawlers as if that's something unusual. Trawlers are very common in legal fishing, including in western countries. But I don't see much focus on curtailing their use there. Are they as bad as the article makes them out, or are these trawlers somehow especially bad?

throwaway7767··on Four of Iceland’s main volcanoes are preparing for eruption
It's the foreign section of mbl (morgunblaðið).

Morgunblaðið is a highly partisan newspaper in Iceland owned by the fisheries industries. It's run at a loss but noone cares because their primary purpose is propaganda for their owners (to some extent this is the case for all media but they are particularly blatant about it).

The english-language section on their site is just a place for them to sell ads-disguised-as-news to tourists. They have low-paid teenagers translating stories from the Icelandic version to maintain some semblance of being a news site. You'll never find good information in these, and oftentimes it's just plain bullshit.

throwaway7767··on Four of Iceland’s main volcanoes are preparing for eruption
> I don't know for certain, but I'd guess WOW does the same thing Norwegian does: hiring staff on short-term contracts from places where labor is cheap (IIRC Norwegian hires its flight-deck crews from Estonia and cabin attendants from Thailand) in order to get low wages and avoid the overhead of full-time employment, registering most business operations in places like Ireland with favorable tax situations, and then ensuring most flights pass through at least one second-tier airport with low fees.

Every time I've flown a WOW air flight, the attendants were Icelandic. So I don't think that's true.

throwaway7767··on Four of Iceland’s main volcanoes are preparing for eruption
> Also, you can't buy good sausages in this country. They're all pork, no one makes an honest aussie beef snag on the whole island. How can you make good hotdogs without good snags? :(

I haven't tried australian hot dogs, but if you're looking for something better than the mainstream hot dogs in Iceland you should look at the polish specialty shops. They have more variation, some of them are quite good.

throwaway7767··on Four of Iceland’s main volcanoes are preparing for eruption
> Please refrain from eating shark, puffin or whales. The only reason why we are still killing endangered species is solely tourism. The local population does not eat them. Please try lamb soup instead. Or one of the amazing Iceland hotdogs.

I don't know where you get the idea that Icelandic people don't eat these things. Admittedly puffin is not a very common dish, but whale meat is consumed by Icelandic people, and shark meat also has some following.

My friend's company in Iceland invited their employees to dinner a few weeks ago. The menu? Hrefnukjöt (minke whale meat).

throwaway7767··on Man jailed 16 months, and counting, for refusing to decrypt hard drives
Yes, the court system exists precisely to determine fuzzy things like this.

I'm still curious, what kind of evidence or testimony might be considered believable in this case. Whether someone remembers a particular sequence of words and symbols seems like a thing that's very hard to determine, and by its nature it's unlikely there is any evidence either way.

From the quote you give (and I'll admit I have not read up on this case beyond the article, so it's possible I'm missing something), it sounds like he claimed he didn't remember the password, the court responded with "I don't believe you because you haven't proven that you don't remember it, so have fun in jail until you decrypt."

How would you prove, if you were brought into court, that you don't remember a specific password?

throwaway7767··on Tesla employee writes of low wages, poor morale; company denies claims
If that's your image of working, you should consider working for different companies. This would not describe my workplace, or most of the ones I've worked for.
throwaway7767··on Backing up a Linux system to Usenet
> Exactly. I rather trust well proven math more than people or infrastructure. One famous example nowadays is Bitcoin ... nobody was able to break the fundamental math behind it.

Well, there was the integer overflow bug years ago where someone could essentially create money out of thin air. But that's the only one I know of and it's a pretty amazing security track record for such a high-profile and lucrative target.

That said, this is just me being pedantic, I agree I'd much rather trust solid crypto than a promise from a person somewhere, even if that promise is in writing.

throwaway7767··on Arch Linux pulls the plug on 32-bit
Those scripts should probably be using something like the following, if they really are python2-only: #!/usr/bin/env python2

I get your frustration though, it's a change that breaks a whole lot of existing scripts.

throwaway7767··on Sous Vide startup Anova gets acquired by Electrolux
I think you're being much too paranoid about this.

Most multimeters I've seen, cheapo or not, are rated to at least 1000V (sometimes 2-5kV). Now, as with all cheapo chinese electronics, you have to assume there is no safety margin on that so I wouldn't probe 1000V with such a meter. But 110 or 220V? Go for it. I'd be genuinely surprised if any common multimeter can't handle that (assuming it's operated properly, set on the right scale and such).

A fluke meter rated for 2kV can measure 2kV, because you know they have a decent safety margin there.

throwaway7767··on Intel’s Atom C2000 chips are bricking products, and it’s not just Cisco hit
I had one of those. The shop I bought it from refused to replace it from their inventory, all they would do is take the motherboard, send it back and then give me the replacement some weeks later when the RMA process was completed.

Since I needed that machine functioning, I never replaced it (the mobo had some extra SATA ports handled by a different controller, so they kept working and I switched to using them). I suspect a lot of people are in the same boat. I'll never do business with that store again.

throwaway7767··on Windows DRM Files Used to Decloak Tor Browser Users
The list of file formats that can trigger the viewer to fetch a resource over the internet is so large that it's impossible to cover them all. Unless you're working with plain text or something you know is safe, don't open files downloaded over Tor if you're running on a standard OS (and not, say, in a whonix workstation that's isolated from direct internet connections).
throwaway7767··on Data Loss at GitLab
As a sysadmin, I'd find it incredibly distracting to be on a livestream while trying to fix a critical issue. For your employees sake I hope you don't do this again.

Have a single point of contact that provides information about the recovery process. Being transparent and providing technical info is good, but that task should not be handled directly by the admins at the same time they are focusing on the drop-everything-shit-is-broke emergency.

throwaway7767··on Data Loss at GitLab
It sounds like a terrible working environment for the sysadmins. When shit is broke, you focus on fixing it. Being on camera is distracting, and setting up the livestream probably takes a bit of time that could be spent on actually fixing the problem.
throwaway7767··on Cryptkeeper sets the same password “p” independently of user input
If you'd read the article you could have answered the question yourself: no, it is not.

But why let facts get in the way of some easy karma-whoring?

throwaway7767··on Cryptkeeper sets the same password “p” independently of user input
It wasn't, did you read the article? No stable release ever included this. It was caught while in the testing repository, which is for, you know, testing stuff and finding issues.
throwaway7767··on The Psychomachia: An Early Medieval “Comic Book”
This link is returning a 404 right now, unfortunately.
throwaway7767··on Dutch secret service tries to recruit Tor-admin
If your goal is to collect everything like the western intelligence services, infiltrating hackerspaces and the CCC seems like a very efficient use of resources. Especially if they're focusing on Tor and related projects, which they seem to be.
throwaway7767··on The Steam Controller Configurator's Untapped Power
I have an xbox controller and a steam controller. In my experience, if the game has out of the box controls for an xbox controller, using it is always superior.

I don't regret my steam controller purchase though because it fulfills a useful niche: allowing me to play games that weren't designed for controller input from my couch. This is mostly because of their awesomely powerful configuration tool - they really thought of everything. The two touchpads on the controller and the ability to use the overlay for on-screen menus also increase flexibility when mapping controls for complex games.

This is mostly useful for older games in my experience, as newer games that would make sense with a controller generally already come with Xinput support.

throwaway7767··on The Steam Controller Configurator's Untapped Power
Not all controllers run on batteries. You can get wired Xbox controllers for example.
throwaway7767··on Ways we harden our KVM hypervisor at Google Cloud: Security in plaintext
> Non-QEMU implementation: Google does not use QEMU, the user-space virtual machine monitor and hardware emulation. Instead, we wrote our own user-space virtual machine monitor that has the following security advantages over QEMU: [...] No history of security problems. QEMU has a long track record of security bugs, such as VENOM, and it's unclear what vulnerabilities may still be lurking in the code.

Has this alternative VMM/hardware emulator been released? As far as I can tell, the answer is no. In that light, it's more than a little weird to congratulate yourself on not having a "long track record of security bugs" in your internal-use-only unreleased tool compared to generally available software in wide use.

throwaway7767··on A Story of a Fraudulent Coder
Someone they regularly talk to 1-on-1 (with "Bryan" often initiating the interaction) is not "someone they don't even know".
throwaway7767··on Simple Wi-Fi Yagi (2014)
When you upgrade from consumer-grade equipment into dedicated APs, they start looking more like something you can put into the center of your living room without being ashamed of it.

The Unifi APs for example look like oversized smoke detectors. They have obnoxious blue LEDs like seemingly all modern equipment, but you can turn them off and then it emits no light at all, and fits quite well into the living room when mounted on the ceiling.

throwaway7767··on Did Pixar accidentally delete Toy Story 2 during production? (2012)
"secure delete" (actually "secure erase") is a term from the ATA standard, it's supported by practically all ATA and later SATA devices for a very long time. The idea was you'd tell the disk to erase everything, it would do the actual deletion in the background but would not allow reading the old data. This was also the way to reset passworded harddrives, you could send a secure erase command without authentication, the drive would wipe itself and once done, the password is gone.

Once SSDs arrived on the scene, they were limited by the interface as ATA didn't specify a way to mark sectors as unused. People found that their performance would degrade with use as all the sectors became utilized. But a secure erase command would mark all sectors as erased, so the drive would work like new. Later on, ATA got the TRIM (and later queued versions of TRIM) so the OS can mark specific sectors as erased. But the result is that a lot of people confuse flash sector erasing with secure erase.

throwaway7767··on Did Pixar accidentally delete Toy Story 2 during production? (2012)
The reason for marking it as erased is so the firmware can physically erase the flash sector. It could happen immediately, a minute later or next week. But a well-written SSD firmware will try to erase blocks any time it's not busy doing something else, as erasing blocks takes way longer than writing them.

You might be able to recover something from the physical flash, but there's definitely no guarantees.

throwaway7767··on Freenom World – A fast and anonymous Public DNS resolver
DNSCrypt is not the same thing as DNSSEC.
throwaway7767··on Adobe angers Chrome users by bundling browser plugin with security update
I expect to see these same companies try ever more fragile and bad methods to bypass these restrictions. If chrome refuses to load extensions from disk, they'll inject themselves into the process address space somewhere, which as a bonus will likely introduce sandbox escape vulnerabilities. This is what the AV vendors are doing these days.
throwaway7767··on [dead]
How to buy bitcoin anywhere in the world, as long as it's in one of the 31 countries on the list.
throwaway7767··on Debugging mechanism in Intel CPUs allows seizing control via USB port
Yes, the story here is that new Intel platforms expose such debugging functionality over regular USB ports. This is not what most people expect, so it's newsworthy.
← PreviousPage 2 of 22Next →