HNHacker News
TopNewBestAskShowJobs

tilpner

29 karma · joined June 12, 2015

[ my public key: https://keybase.io/tilpner; my proof: https://keybase.io/tilpner/sigs/-_3H5koO2AjeU1EOSFl4xpVODHVDOdE_JELWzQ-bYiw ]
submissionscomments
tilpner··on A Go Custom Flutter Engine Embedder for Desktop
This also works for comments: https://github.com/dear-github/dear-github/issues/166#issuec...
tilpner··on Show HN: Docker-based immutable workstation
While Nix can use a lot of memory while evaluating larger systems (or searching all of nixpkgs by evaluating everything), it is usable on systems with 2GB RAM.

Nix 2.0 had a bug which caused excessive memory use, but it's been fixed in 2.1: https://github.com/NixOS/nix/commit/2825e05d21ecabc8b8524836... https://github.com/NixOS/nix/commit/48662d151bdf4a38670897be...

tilpner··on Announcing gRPC Support in Nginx
https://google.github.io/flatbuffers/ and https://capnproto.org/ are both successors to protobuf
tilpner··on Hetzner Cloud
nixops has hetzner deployment support, but I don't yet know how well it works (my account verification is still pending)

https://nixos.org/nixops/manual/#opt-deployment.hetzner.crea...

tilpner··on Kata Containers – The speed of containers, the security of VMs
> Kata Containers combines technology from Intel® Clear Containers and Hyper runV

but I can't find a mention of Hyper-V anywhere (which doesn't mean there was no inspiration). Maybe you confused Hyper runv and Hyper-V here (the naming certainly doesn't help)?

tilpner··on LightVM – A new virtualization solution based on Xen
An example for such an alternative backend would be runv, which can apparently be used with Docker (though I couldn't get it to work well, but that was probably just my fault)

https://github.com/hyperhq/runv#run-it-with-docker

tilpner··on What is Nix and why you should try it
I was told guix has some support for importing normal Nix packages, but I don't know how well it works in practice.

https://www.gnu.org/software/guix/manual/html_node/Invoking-...

tilpner··on Show HN: Termplay: Play videos in your terminal
I see these every so often, but they never mention Sixels, which could be used to display videos with much more detail (like with https://github.com/saitoha/FFmpeg-SIXEL ).

Sixels aren't widely supported, and the implementations I tried were lacking in stability, but they offer some interesting possibilities, like embedding images into your text browser (and not with a hack like w3m uses), or playing Battle for Wesnoth inside your terminal [ https://github.com/saitoha/libsixel ]

tilpner··on Ask HN: Is there a “solve my programming problem” website?
StackOverflow strongly prefers "Short, Self Contained, Correct (Compilable), Example"s [sscce.org] that showcase a specific problem.

If you go and paste several files with a few hundred lines of code, you're unlikely to get any help. People will not usually make the effort to set your project up locally (because you likely didn't paste the project configuration), debug it, and send you the diff to the fixed project.

But more importantly, any answer to your question is hard to transfer to problems other people have. It can't be used as a reference or solution repository anymore, because there's so much distraction around the essence of your problem.

The help center also has an entry about this: http://stackoverflow.com/help/mcve

tilpner··on Wire open-sourced
ring.cx and matrix.org seem promising in that regard.
tilpner··on A smarter kind of password manager
Nadya already mentioned the problem of having a common password, but I think that's actually not such a big problem here, as you do some checks to make sure "123456" doesn't pass.

As I can see from "salty", you know that applying a hash function once or twice is not a good way to store a password (even in a hashed form).

Now, you're applying that hash function a lot more often than once or twice, but that still only takes a fraction of a second.

Quoting the "hashlib" documentation:

    Key derivation and key stretching algorithms are
    designed for secure password hashing. Naive algorithms
    such as sha1(password) are not resistant against
    brute-force attacks. A good password hashing function
    must be tunable, slow, and include a salt.
Your approach is not too tunable, in the sense that you can't configure its memory usage, only the time it takes.

What if your attacker just throws more money at the problem? Sha256 has been shown to be feasible to implement in hardware, and that fraction of a second will melt away, partly possible because not much memory is consumed.

And then there is the well-known advice to not roll your own crypto. In this case, that means using a well-known key derivation function that's meant to be used in scenarios like this, instead of using your custom method with a "I think this is safe enough" attitude. Personally, I'd have a little more confidence in something that says "uses scrypt", simply because I know that name and that it's suitable for this application. It can still be used wrong, but I wouldn't feel compelled to check if you rolled something yourself. :)

Also check: http://security.stackexchange.com/questions/211/how-to-secur...

Lastly, I'm saying all this because I made one of these things myself, which used a dangerously custom method of seeding a "cryptographically strong" Sha1 PRNG for password generation. Yes, that bad.

If I said anything wrong, please correct me.

tilpner··on A smarter kind of password manager
I'd embarass myself if I tried to explain this with the correct terms, so I won't try.

One of those articles, but there may be better or more correct ones: http://www.justgohome.co.uk/blog/2014/02/salting-hashing-and...

tilpner··on A smarter kind of password manager
There are so many of these. I don't discourage building one for fun, but they're usually not practical.

The common problems are password resets, different password restrictions/formats, and the need to remember these.

Also... Sha256 for password generation? I've been told that's wrong™, even if you do it a lot of times, and was pointed at key derivation functions like scrypt, bcrypt, etc.

tilpner··on Show HN: Herodotus – An IRC bot that logs a channel's activity to JSON
I wonder whether any large network keeps logs of channels, let alone one per server. And if they do, they probably don't have much use for a merged log except for taking up less space.

My own IRC log tool [GH: tilpner/ilc] can be used to merge logs, but I rarely use that functionality.

For two log files "a" and "b", in weechats default log format:

    ilc sort -f weechat -i <(cat a b) | ilc dedup -f weechat
I've never tested this with logs over 200MB, but sort will read the combined log into memory, which is definitely not optimal.
tilpner··on Show HN: Herodotus – An IRC bot that logs a channel's activity to JSON
I'm curious, in what circumstances would you merge multiple log files (from different perspectives, I assume) because of a netsplit?

That'd require one log/connection per server of the network, which isn't something ZNC or weechat will do by default.

Have you ever needed that functionality?

tilpner··on Introducing the Keybase filesystem
insert checkmark
tilpner··on Introducing the Keybase filesystem
That email isn't public, I think. In any case, you should have one now.
tilpner··on Introducing the Keybase filesystem
Considering keybase-release[0] was "Last Updated: 2015-11-03 22:36", community/keybase is a lot more recent, but still from January, so not recent enough.

[0]: https://aur.archlinux.org/packages/keybase-release/

tilpner··on Show HN: 'Signed Blogs' with Keybase.io filesystem
I may be doing something wrong, but it says "message wasn't encrypted for any of your known keys".
tilpner··on Introducing the Keybase filesystem
I was going to send you one, but... I can't find your email in your profile.