HNHacker News
TopNewBestAskShowJobs

throwaway_391

95 karma · joined January 21, 2019

submissionscomments
throwaway_391··on exFAT in the Linux kernel
I had a really awesome boss who probably overshared about stuff like this but a lot of it also comes with general distrust in the business world. People are out to make a buck and they'll do it anyway they can. Every time you come across a business, consider how it works and where their profit comes from.

A tactic I've used in the past is buying a burner number (prepaid sim), called recruiters with a fake name, number and resume and asked them to provide details about the job which many of them name completely. The ones that don't generally indicate that other recruiters do exactly what I'm doing to them in order to steal clients.

I don't feel bad about screwing over an industry which has no place in the modern world, particularly when they're opportunistically trying to make a buck from me and/or my future company while adding very, very little value :)

throwaway_391··on MacBook Pro Keyboard Drives Me Crazy
Do you use an external monitor? That's the most important part of the setup, IMO.

I said two monitors but what I mean is one for each location - many people I know seem to prefer two but I think it's an antipattern (move your head, instead of alt+tab or similar)

throwaway_391··on exFAT in the Linux kernel
Thanks for the tip, I learnt this a long time ago, I've also moved into an industry where dealing with recruiters would probably indicate other issues like lack of ability to research prospective employers, etc.

I'm glad it's becoming more common knowledge though. Recruiters have long been redundant compared to job search websites like seek.

throwaway_391··on exFAT in the Linux kernel
Probably likely to do with the toolkit used to build the Windows version and inability or unwillingness to port it to Mac.

They really need to start from scratch and build solid, easily testable product because the current methodology doesn't work.

I especially love the bugs where when in one specific track changes mode typing in the comments section drops keys, or when using 'read aloud' the voice randomly changes gender. Office 365 on a Windows 10 LTSC virtualised host w/ no other software.

throwaway_391··on MacBook Pro Keyboard Drives Me Crazy
> For the most part, it sits on one of two desks that I use or it sits on my lap on the train.

If this is the case, do yourself a favor and go and buy two ergonomic screens, keyboards and mice - one for each location.

It'll save you becoming a hunched over laptop gremlin.

throwaway_391··on exFAT in the Linux kernel
I would recommend against using Office 365 web ui for word/excel etc, I'd also recommend avoiding the MacOS Office build for the same reason:

They're both buggy as hell, the type of bugs that will make your document render in unintended ways when somebody opens it on the other side. At some point, Word for Mac decided to remove whitespace between words on my resume - I couldn't see them and generally exported to PDF, but I didn't hear back from prospective jobs that asked for a word format specifically.

Office 365 Web and desktop application really need a complete revamp, they have reproducible bugs and horrible UI/UX in edge cases.

I also really hate when Microsoft decides I want to store my sensitive data on their cloud for no apparent reason despite saving to local disk, it really seems like a 'whoops we accidentally did this but you should try it!' kind of move from MS. This is the perfect example of a monolithic application with chronic feature creep.

throwaway_391··on YAML: Probably not so great after all
So your comment is vaild. Having strict and not-strict validation would be a nice compromise though (:
throwaway_391··on YAML: Probably not so great after all
My personal JSON Pet hate is: ``` x = [ "Foo", "Foo2", ] ``` Is not valid, but the following is: ``` x = [ "Foo", "Foo2" ] ``` Makes dealing with packer configs feel like punching yourself in the face.

I still prefer it over YAMLs awkward initial learning curve.

throwaway_391··on Kaspersky AV injected unique ID allowing sites to track users in incognito mode
Funny that you namedrop like three security products but fail to evaluate which hypervisor should be used, which is probably the most important part of a secure environment if unauthorized code execution fits in your threat model.
throwaway_391··on Kaspersky AV injected unique ID allowing sites to track users in incognito mode
I don't fully understand why everyone gets upset over browser leaks when in private mode - most websites interested in tracking private sessions will just associate private and non-private sessions by IP address.

If you're paranoid enough to use a VPN for 'private' traffic, you should probably be running such sessions in a VM using something like the tails live CD.

throwaway_391··on Kaspersky AV injected unique ID allowing sites to track users in incognito mode
For those interested: https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...
throwaway_391··on Key Negotiation of Bluetooth Attack
From the article 'Key Negotiation of Bluetooth'.

Basically, researchers started naming vulnerabilities when they thought they mattered. 'Shellshock' and 'EternalBlue' are both deserving of names, IMO.

Then researchers started naming everything, many of the vulnerabilities had zero real world impact, were almost entirely theoretical (many crypto vulns), or required chaining of other attacks to actually achieve anything.

The KNoB description says 'is vulnerable to packet injection by an unauthenticated, adjacent attacker that could result in information disclosure and/or escalation of privileges.' which is sounds extremely caveated. They haven't demonstrated an actual attack so my guess is they've overplayed the significance of the vulnerability entirely and this grants the ability to PITM traffic (which really isn't a defensible boundary, anyway).

Most decent hackers I know laugh at named vulnerabilities unless their technical impact actually matters. Dirty COW took the piss entirely, https://dirtycow.ninja, https://www.zazzle.com/collections/white_theme-1195879626504... .

throwaway_391··on The Horror of Microsoft Teams
Renaming executables to explorer.exe worked with the application whitelisting solution my school implemented.

That's how we ended up with 8-player age of empires 2 deathmatches after hours ;)

throwaway_391··on Warning as 4G Hotspots Are Hacked
Seems silly to care so much about your tethered connection when the average home network has a bunch of computers, random IOT kit, a end-of-lifed smart TV, friends mobile devices and the random MAC addresses in your DHCP lease pool that you can't even account for.

Network security is unmaintaniable. Start caring about defensible boundaries instead.

throwaway_391··on What Does a Coder Do If They Can't Type?
Grantparent poster here. Hrm, you're right, I remember purchasing keys 'lighter' than browns, possibly silvers. They're very light, but I'd probably prefer 'too light' over 'too heavy'.
throwaway_391··on Hackers ship their exploits directly to their target’s mailroom
zero-day malware probably makes malware writing sound difficult. Bypassing fingerprint-based scanners is reasonably easy with the use of 'packers' (which can be bought from hacker markets for pretty cheap, or built pretty easily). Bypassing heuristic based scanners is a little more research-intensive[1], but some 'packers' do this too.

https://wikileaks.org/ciav7p1/cms/files/BypassAVDynamics.pdf

throwaway_391··on Hackers ship their exploits directly to their target’s mailroom
Yeah but 'APTs' are generally shitty low end numbers-game attacks that target HR with terrible macro based malware to breach company perimeters.

Unless you're emulating nation state actors, your ideology of a 'red team' which focuses on physical access is a disservice to your client and your industry.

throwaway_391··on Unikernels: The Next Stage of Linux's Dominance [pdf]
Size, Content. Pick one.

I'm not suggesting it's a good idea, but it's there. I'm sure there's more minimal, and less minimal options available.

I don't think there's any security impacts with using alpine Linux specifically, aside from default credentials in a bunch of containers a few months back.

throwaway_391··on About the “Security Issue” on VLC
I've heard some interesting arguments about publicly dropping 0days to make organisations pull their heads in - Places like Microsoft which historically weren't -great- at security 'deserved' it. I'm not saying that argument is right or wrong, but it was interesting nonetheless.

But dropping a 0day irresponsibly can lead to actual impact - what happens if a good person is persecuted, or executed because of the information you disclosed publicly? What about a hundred. Or a thousand?

throwaway_391··on About the “Security Issue” on VLC
It's both:

"A successful attack depends on conditions beyond the attacker's control. That is, a successful attack cannot be accomplished at will, but requires the attacker to invest in some measurable amount of effort in preparation or execution against the vulnerable component before a successful attack can be expected. For example, a successful attack may require the attacker: to perform target-specific reconnaissance; to prepare the target environment to improve exploit reliability; or to inject herself into the logical network path between the target and the resource requested by the victim in order to read and/or modify network communications (e.g. a man in the middle attack)."

But you could also argue 'Attack complexity' of any exploit which has per-os/arch exploits requires reconnaissance. There, I just boxed MS08-67 (which is arch-specific, iirc) as 'Attack Complexity: High' with pretty much any theoretical crypto attack which would cost billions to exploit :)

Lets not forget CVSS doesn't assess likelihood or business impact well (or at all) either. Your org is far more likely to get rekt if you do not enforce application whitelisting, compared to an intranet-exposed drupalgeddon vulnerability.

throwaway_391··on About the “Security Issue” on VLC
CVSS is an insane rating system made for a simpler time by antiquated practices which doesn't account for many factors either well if at all.

Hover your mouse over each button https://www.first.org/cvss/calculator/3.0 . There's Attack complexity 'low' and 'high', for instance. You're either a script kiddie or have a two billion dollar exploitation budget and all the human resources you need, but nothing in between.

throwaway_391··on About the “Security Issue” on VLC
Most / all software has a disclosure policy, send your vulns privately and provide/negotiate a public disclosure date.

Not doing so is an asshole move.

In this case, the solution would be to track down distributions which did not package the software and (privately) disclose to them that the relevant lib needs updating.

throwaway_391··on About the “Security Issue” on VLC
Slightly offtopic, but are vulns related to overflows no longer pocced publicly or are there mitigating factors which make exploitation impossible (eg K/ASLR etc)?

The specific CVE listings I'm referring to are: https://www.cvedetails.com/vulnerability-list/vendor_id-5842... https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...

throwaway_391··on Unikernels: The Next Stage of Linux's Dominance [pdf]
Alpine Linux is a reasonably small (20mb) Linux distribution, I've seen it run on bare metal but it's more common to see it in Docker environments.

Building minimal bootable to be very small is possible, but is difficult in comparison to an apt install - I imagine for the most part porting docker container configs to a bootable OS might be the best approach for small-medium projects.

throwaway_391··on What can we learn from the matrix.org compromise?
So it's a less audited application than *SSH that the author is recommending over SSH because it doesn't require user authentication but runs in a daemon with root privs?
throwaway_391··on Banish missing glyphs with Unifont
As a resident of a western country, I don't fully understand how to implement or test Unicode compatibility on my browser, website, terminal, etc. Is there a test suite of characters I can use to validate etc?
throwaway_391··on Firefox Experiments I Would Have Liked to Try
It always gets me that both Firefox and Chrome both refuse to provide the ability to configure keyboard shortcuts. Sure, it's probably a bad idea to allow users to change them, but provide some easier way to do it than hacking source, please.
throwaway_391··on Ask HN: What made you change your mind about a programming language/paradigm?
http://mypy-lang.org/
throwaway_391··on Lime scooters are causing some issues for Brisbane's vision impaired community
I used to feel the same way until I realised the caliber of both the cyclists and drivers in the ACT meant that permitting riding on footpaths would save a considerable amount of lives.