HNHacker News
TopNewBestAskShowJobs

tomfitz

159 karma · joined August 1, 2013

submissionscomments
tomfitz··on Project Euler
That's a neat visualisation.

n^2 = sum(1..n) - sum(1..n-1) = 2sum(1..n-1) + n

=> n^2 - n = 2sum(1..n-1) => n(n-1) = 2*sum(1..n-1) => sum(1..n-1) = n(n-1)/2

And you can rewrite that as... sum(1..n) = n(n+1)/2

tomfitz··on HAProxy 1.8
https://www.haproxy.com/blog/dns-service-discovery-haproxy/ (which is a link on the OP) says TTL on SRV records "is ignored by HAProxy as HAProxy maintains its own expiry data which is defined in the configuration".

Is this true for A records too?

If so, neither haproxy nor nginx expire cached A records.

Nginx Plus does, and a few nginx plugins do, however.

https://github.com/airbnb/synapse is a process that polls DNS, and updates haproxy config accordingly and SIGHUPs haproxy I've used synapse to solve this issue, but it's a moving piece I'd rather not have involved.

tomfitz··on Tracking friends and strangers using WhatsApp
The author has a few well written pieces. These two are hilarious: https://robertheaton.com/2014/10/25/tales-from-a-san-francis...

https://robertheaton.com/2014/07/14/getting-nothing-done-a-m...

tomfitz··on Anatomy of a Moral Panic
https://en.wikipedia.org/wiki/2017#August
tomfitz··on Firefox Focus – A new private browser for iOS and Android
Pressing "Erase browsing history" in the Android persistent notification bar seems to do this.
tomfitz··on Se­cu­rity Keys
U2F keys are linked to the associated domain (e.g. google.com or dropbox.com), so your U2F would not present your google.com key to a U2F prompt on googlehax.com

This stops the proxy attack you describe getting a session key, but not getting your password. Of course, the password alone is insufficient.

tomfitz··on Se­cu­rity Keys
Use TOTP as a fallback.

You might argue "well why bother with U2F, if you are going to set up TOTP anyway", to which I respond that using U2F is still a net win, because for the times you use U2F, you are safe from phishing attacks.

That in an emergency situation you have to use TOTP, and thus be vigilant that you aren't being phished, does not negate the benefits from having used U2F previously.

I can see that by enabling TOTP as a second-factor, it increases your attack surface. That is, you now have to care about whether your TOTP secret has been leaked. I consider this cost to be small, compared to the benefit of being able to fallback to TOTP. Others may decide this tradeoff isn't worth it.

tomfitz··on Facebook – You are the Product
I just tried deactivating, and upon logging in to Messenger (which works) it logged me into Messenger, but not FB.

Sweet!

tomfitz··on Proof of Work Without All the Work
https://en.wikipedia.org/wiki/Stellar_(payment_network) is a decentralized currency that already isn't the "ecological disaster" that Bitcoin is.
tomfitz··on Message encryption a 'problem' – UK home secretary
> First, pointing out that there are harms and she's aware of them, despite not addressing them, because she refuses to disclose her communications.

Though I'm skeptical of how much a 3m42s interview can be said to represent the entirety of her views, I'd say she alludes to the harms by referring to such access as "warranted". That is, authorisation is restricted [because of the costs of unrestricted access].

> Second, that the spying will be used asymmetrically - you, dear citizen, will have all your communications recorded, stored indefinitely, and subject to discovery when some prosecutor or large corporation decides to do away with you.

This law would apply to politicians too, right? If they're suspected of a crime, a warrant could be issued for their communication details.

> But try and find out which corporations are sponsoring which politicians, who owns them, and what kind of deals those politicians are making in your name, and you'll meet a stone wall of silence - just like in the TTIP negotiations.

As mentioned, if those are crimes I expect them to be investigated similarly.

> I don't think this is a stronger argument. In fact, I don't think this is an argument at all.

Sorry yes, my single sentence wasn't the entirety of the argument. I was referring to arguments that rely on the benefits of privacy, rather than defeating a strawman (my, as you say, literal reading of top-level comment).

tomfitz··on Message encryption a 'problem' – UK home secretary
This is the argument raised by security experts in http://dspace.mit.edu/bitstream/handle/1721.1/97690/MIT-CSAI... , which I'm not qualified to disagree with. It seems strong! Even if it were technically possible, I expect there's also a strong argument along the lines of asserting our right to privacy.
tomfitz··on Message encryption a 'problem' – UK home secretary
> I think GP's point is the warrant isn't needed.

GP?

> Whether [...] you are simply pointing out that those in authority have a default duty/right to an individual's private conversations

Certainly not. Whether they do ought to should be decided by society and its representatives via the legislature.

tomfitz··on Message encryption a 'problem' – UK home secretary
> She wants to institute pervasive spying (targeted spying can be achieved by individually planting hardware backdoors, or simply recording the suspect entering their password).

I can see targetted spying is possible today. It sounds like she wants targeted spying to be cheaper, and restricted by the judicial system.

> But pointing out the harms of pervasive spying is a weak argument, because she didn't deny (or even address) those harms?

The argument I replied to wasn't pointing out the harms of pervasive spying. Nor was your argument.

"If she wants law enforcement to be able to see other's metadata, she should expose her metadata" is weak. We needn't waste time with that.

There are stronger arguments, such as asserting our right to privacy, or perhaps that it isn't technically possible without critically compromising encryption for everybody.

tomfitz··on Message encryption a 'problem' – UK home secretary
I'm not sure of the relevance of this to jstanley's argument, nor my rebuttal.
tomfitz··on Message encryption a 'problem' – UK home secretary
Is the home secretary using that argument?

We ought to use strong arguments. This thread's arguments aren't strong.

tomfitz··on Message encryption a 'problem' – UK home secretary
Are you law enforcement with a warrant?
tomfitz··on 'Using Emacs' Series
https://github.com/technomancy/better-defaults aims to be "a small number of better defaults for Emacs".

I use it, though I'm not a heavy emacs user.

tomfitz··on VISA offers restaurants $10,000 to stop accepting cash
Same in other parts of Europe, Australia, and New Zealand
tomfitz··on The Presence of One’s Own Smartphone Reduces Available Cognitive Capacity
I do this, which helps a lot. I still find myself mindlessly browsing during "downtime", however.
tomfitz··on Mozilla and NSF offer $2M prize to decentralize the web
https://github.com/cjdelisle/cjdns/blob/master/doc/Whitepape...
tomfitz··on Mozilla and NSF offer $2M prize to decentralize the web
CJDNS is a self-organising IP address allocation and routing layer. A node's public key acts as its IPv6 address, and routing uses a DHT of those nodes.

This style of network has the property that you can take two independent CJDNS networks, link them together, and all nodes are mutually addressable/routable. This is in contrast to The Internet, whose addressing is centralised on IANA.

cjdns is moderately active, though most links between nodes are via an overlay on top of the public Internet. The goal is to have physical/wireless links between geographically close nodes.

Use https://peers.fc00.io/ to find a cjdns node geographically close to you.

Decentralized protocols such as ipfs/scuttlebutt work particularly well on cjdns, as a file shared on ipfs in one network, will automagically become available on another network, once those networks are linked.

cjdns: https://github.com/cjdelisle/cjdns

tomfitz··on Casync – A tool for distributing file system images
Oops. Just realised my comment contains a mistake.

casync does not act as a server. Its on-disk representation and client behaviour is designed in such a way that the server need only serve static files. This makes deployment easy.

tomfitz··on Casync – A tool for distributing file system images
SHA-256 seems to score well on https://www.cryptopp.com/benchmarks.html .
tomfitz··on Casync – A tool for distributing file system images
Great. The chunked model (inspired by Borgbackup/Tarsnap) seems preferable to Docker layering, and diff-based approaches.

As far as I can tell, the advantages compared to Borgbackup seem to be:

* casync offers control over which FS metadata is included

* casync, the server, exposes chunks over HTTP

* casync, the library, is written in C so is more easily used by systems software.

I'm betting we'll see machinectl integration. Excellent!

tomfitz··on Ask HN: How do I dress better?
Thread (YC12): "Let one of our stylists help you find clothes you'll love. All online and completely free. ". https://www.thread.com/
tomfitz··on Swift is like Kotlin
Sorry, I didn't explain myself well.

Range.closed(1,5) is the syntax used to refer to what a mathematician would call [1,5].

Guava is just a Java library. In Java 9, a two-Integer-element list literal will be List.of(9000, 9001).

tomfitz··on Swift is like Kotlin
Fixed, thanks.
tomfitz··on Swift is like Kotlin
An alternative approach is Guava's Range class:

Range.closed(1,5) == [1,5]

Range.open(1,5) == (1,5)

Range.openClosed(1,5) == (1,5]

Range.closedOpen(1,5) == [1,5)

Range.greaterThan(1) == (1,infinity)

Range.atLeast(1) == [1,infinity)

That class always strikes me as having high power-to-weight. It has methods like encloses(anotherRange), contains(aValue), and others.

https://google.github.io/guava/releases/19.0/api/docs/com/go...

tomfitz··on Swift is like Kotlin
When I see "0..n" I wonder whether the range is inclusive or exclusive of n.

When I see "0..<n" I know the range is exclusive of n.

tomfitz··on Is Memory Mapped File This Fast in Java?
If you find ByteBuffer's API awkward/insufficient, you might want to consider one of the replacements:

* Netty's: https://netty.io/4.0/api/io/netty/buffer/ByteBuf.html as used by Netty

* Agrona's, as used by Aeron and SBE: http://insightfullogic.com/2015/Apr/18/agronas-threadsafe-of...

Page 1 of 2Next →