HNHacker News
TopNewBestAskShowJobs

tomfitz

159 karma · joined August 1, 2013

submissionscomments
tomfitz··on Ask HN: What distributed storage technology are you using?
How do you backup your git-annex repositories?
tomfitz··on Ask HN: Mailing lists that HN readers ought to know about?
Cryptography/Security:

* General cryptography http://www.metzdowd.com/mailman/listinfo/

* SSL/TLS news https://www.feistyduck.com/bulletproof-tls-newsletter/

* Cryptography concerns for ops (typically TLS) https://lists.eff.org/mailman/listinfo/crypto-ops

* General cryptography https://lists.randombit.net/mailman/listinfo/cryptography

I stopped following a bunch of cryptography twitter feeds, because the Bulletproof TLS newsletter was lower volume and higher signal.

tomfitz··on Ask HN: Do you still use browser bookmarks?
No.

I use Google Keep to store URLs, typically with some note, for example: * "Specialized Sirrus bike rear derailleur. Model number: DO20. URL: https://www.amazon.co.uk/dp/B0047D192E/ " * 2015-03-01: Visited doctor. They referred me to physio, and told me to read http://www.arthritisresearchuk.org/arthritis-information/con... for exercises/stretches to relieve pain."

Google Keep supports tagging and search, so I can usually find things. For things I want to read later, I either put it in Pocket or use Google Keeps' reminder functionality.

Chrome integration looks decent (save web pages as an image), but Firefox integration is lacking.

tomfitz··on I was a multi-millionaire by 27–here's what I learned
> new age money related philosophies

Do you have any links relating to this?

tomfitz··on Keeping David MacKay's 'Sustainable Energy – without the hot air' up-to-date
Great idea! This book is excellent, and though the principles are timeless, it would be a shame if the data became outdated.

Sadly the source code for the book doesn't appear to be published. This is unlike David Mackay's otherbook, "Information Theory, Inference & Learning Algorithms", does have the LaTeX source published (see http://www.inference.phy.cam.ac.uk/mackay/itila/book.html ), though not in an open source license.

tomfitz··on Java libraries you can't miss in 2017
When I load tested async HTTP clients at the BBC (for 1000rps), both https://hc.apache.org/httpcomponents-asyncclient-dev/ and https://github.com/AsyncHttpClient/async-http-client/ performed well. We used Apache's since it exposes connection pool statistics.

Apache's client doesn't have CompletableFuture, but it was easy to add one: https://gist.github.com/tomfitzhenry/4bb032f6a9f56d95f6fb544...

async-http-client is the HTTP client used by Gatling (same developer, in fact).

tomfitz··on Java libraries you can't miss in 2017
JDeferred, a promises library, is what CompletableFuture does, a recent addition to Java's standard library in Java 8.

CompletableFuture is becoming supported in a bunch of other libraries: https://github.com/AsyncHttpClient/async-http-client/, https://github.com/ben-manes/caffeine , https://github.com/mp911de/lettuce .

tomfitz··on YubiKey 4C
U2F and HOTP (Google Authenticator style 2FA) are not mutually exclusive.

I have both enabled on the sites that support both.

I use U2F when I have the key near me, and use HOTP on my phone otherwise (like you, my phone is typically closer to me than my U2F key).

A common response at this point goes "But then doesn't introducing HOTP remove the security benefits of U2F?" No. One of the main benefits of U2F is that it is phish-proof: the U2F key cryptographically authenticates the server, rather than the user eyeballing the address bar, which is how server "authentication" works with HOTP.

tomfitz··on Artificial Addition (2007)
https://en.wikipedia.org/wiki/Graphical_model
tomfitz··on Moving 12 years of email from GMail to FastMail
I was a Fastmail customer for 3 years (2012-2015), but have since migrated to Gmail.

I outlined the factors in this decision in https://gist.github.com/tomfitzhenry/d73fef19752cbf6ccdda3eb... .

tomfitz··on Improved Digital Certificate Security
Thanks for letting me know.

Yes, I'm using CloudFlare, for its trivial SSL, DDOS protection, and caching.

I have CloudFlare's DDOS protection (the thing that causes captchas) set to "Essentially Off", the lowest available setting on their free plan.

I just tried to query https://api.ctwatch.net/domain/ycombinator.com multiple times, each on multiple Tor circuits, but was unable to trigger the CloudFlare captcha.

Did you see the captcha on my site, or is it just that you've noticed captchas on some other CloudFlare sites?

I can look into setting up a Tor hidden service, which'll allow Tor users to bypass CloudFlare, if CloudFlare is actually causing issues.

tomfitz··on Improved Digital Certificate Security
https://api.ctwatch.net/domain/ycombinator.com is an RSS feed of all issued certificates for ycombinator.com and its subdomains.

Feel free to use that to check your own site's certificates!

(It's possible to directly query the multiple Certificate Transparency log servers for your site's certs, but non-trivial, hence why I implemented the above functionality.)

Code: https://github.com/certificate-transparency-watch/

tomfitz··on How Pocket Hit 20M Users with 20 People
"Save to Pocket (mini)", an unofficial extension, can only "Read and change data on getpocket.com" https://chrome.google.com/webstore/detail/save-to-pocket-min...
tomfitz··on Show HN: Snapception – Intercept all snapchats received over the network
Snapchat use ECB as the cipher mode of operation: https://github.com/thebradbain/snapception/blob/781ebb13cd7e...

To see why this is a problem, see the ECB-encrypted Tux image on http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#...

Oops.

tomfitz··on Ask HN: How do you backup 200TB across 15 servers onto a single 50TB server?
tahoe-lafs, https://tahoe-lafs.org/trac/tahoe-lafs , is "an open source, secure, decentralized, fault-tolerant, peer-to-peer distributed data store and distributed file system."

It has the server-level RAID you desire. The FAQ states: ``You know how with RAID-5 you can lose any one drive and still recover? And there is also something called RAID-6 where you can lose any two drives and still recover. Erasure coding is the generalization of this pattern: you get to configure how many drives you could lose and still recover. You can choose how many drives (actually storage servers) will be used in total, from 1 to 256, and how many storage servers are required to recover all the data, from 1 to however many storage servers there are. We call the number of total servers N and the number required K, and we write the parameters as "K-of-N".''

It's a very active open source project, with full-time contributors (I think?), funded by their commercial arm, https://leastauthority.com/ .

tomfitz··on Thoughts on Twitter's new Two-Factor Authentication
I have the same problem with the Android version. I'm just waiting it out, and hoping my session doesn't expire. :)
tomfitz··on New attack plucks secrets from HTTPS-protected pages
You're right. My mistake. Search functionality on sites will often exhibit this. Maybe even stylised 404 pages would too.
tomfitz··on Awk in Haskell
Also, the introduction of a 'Sed' monad was a lightbulb moment for me during this project: https://github.com/tomfitzhenry/hs-sed/commit/0eb7797439e54a...

In particular, the changes in Execute.hs are where using a monad made this code more clear.

If you're new to the usefulness of monads, I don't suggest you read this code, however, and that instead you read:

1. "You Could Have Invented Monads!" http://blog.sigfpe.com/2006/08/you-could-have-invented-monad...

2. "Monad Transformers Step by Step" http://www.cs.virginia.edu/~wh5a/personal/Transformers.pdf

tomfitz··on Awk in Haskell
Relatedly, I have an incomplete Haskell port of sed: https://github.com/tomfitzhenry/hs-sed

It parses a sed script into an AST, then interprets that AST. sed is simple enough that such an interpretor is easy to write. e.g. each input line is only processed once, and in order

Maybe one of the more interesting parts is the testing of the parser using specification-based testing. First, define how to generate an arbitrary sed script (in its AST form). Haskell's QuickCheck will then generate 100 random sed scripts, and check that upon being pretty printed (to a sed script in its usual textual form), and then parsed, produces the original AST.

Specification-based testing is a nice complement to unit-based testing, that I'm beginning to rely more on, to avoid the tedium of writing so many unit tests.

The parser does not yet support nested sed expressions that contain more than one subexpression. The qualifier "suchThat (\xs -> length xs == 1)" at https://github.com/tomfitzhenry/hs-sed/blob/master/tests/Pre... documents this, and as a side-effect serves as a todo list [which I have since ignored for months :)].

tomfitz··on New attack plucks secrets from HTTPS-protected pages
My understanding of the attack:

Suppose the target web server has an endpoint /foo?probeMe=bar such that the HTTPS response will include 'bar' in the HTML. (Quite an assumption, sure.)

Suppose the target web server compresses its responses.

Suppose the attacker can make requests to the target web server, on behalf of the target user (e.g. when the target user is on an attacker-controlled webpage, and the attacker can make AJAX requests to the target web server).

In the case that the HTTP response already contains 'bar', and doesn't contain 'cbs', then a HTTP response to /foo?probeMe=bar will have a shorter length, than a HTTP response to /foo?probeMe=cbs , since compression will mean 'bar' is deduplicated.

Using this, the attacker is able to mount an Oracle attack. That is, if they know something of the form *@gmail.com , and they want to know the whole email address, they can make 26 probes, with probeMe set to: a@gmail.com, b@gmail.com, ..., z@gmail.com

and whichever produces the shortest response is part of the response.

Suppose the shortest is the probe for probeMe=y@gmail.com . They try another letter: ay@gmail.com, by@gmail.com, ..., zy@gmail.com . Again, one probe will have a shorter response than the rest.

They continue, until they find larry@gmail.com .

Now they know larry@gmail.com appears in the response. Success!

← PreviousPage 2 of 2