HNHacker News
TopNewBestAskShowJobs

trishankkarthik

12 karma · joined August 10, 2016

https://karthik.trishank.com
submissionscomments
trishankkarthik··on PyPI now supports digital attestations
Very cool, and congrats!

The corresponding ToB blog post says the following:

> Longer term, we can do even better: doing “one off” verifications means that the client has no recollection of which identities should be trusted for which distributions. To address this, installation tools need a notion of “trust on first use” for signing identities, meaning that subsequent installations can be halted and inspected by a user if the attesting identity changes (or the package becomes unattested between versions).

Agree: signing is only as good as verification. However, trust-on-first-use (TOFU) is not the most secure way to map packages to attestations because nothing stops attackers who have taken over PyPI from tampering with the _unsigned_ mapping of identities to attestations in package lockfiles for new clients (certainly in containerized environments where everything could look new), and even just new versions of packages.

Although [PEP 458](https://peps.python.org/pep-0458/) is about signing the Python package index, it sets the foundation for being able to securely map packages to signed in-toto _policies_, which would in turn securely map identities to attestations. I think it is worth noting how these different PEPs can work together :)

trishankkarthik··on RIP Flynn.io
Sorry to hear the bad news, John and Daniel. Thanks for all your great work, especially in promoting TUF. Hope you guys have found greener pastures now.
trishankkarthik··on Dependency Confusion: How I Hacked Into Apple, Microsoft and Other Companies
I work in this area. This is not a supply chain attack. This is a typosquatting "attack" people keep rediscovering every year or two.

I know, because I wrote an as yet unpublished paper on safely pulling packages from private and public repos.

trishankkarthik··on Dependency Confusion: How I Hacked Into Apple, Microsoft and Other Companies
This is NOT a supply chain attack. Solarwinds was a supply chain attack. This is a typosquatting demonstration that happens every one or two years.
trishankkarthik··on A Better Crystal Ball?
How was I "attacking" others, when they were allowed to put words in my mouth? Go ahead and ban me: @paulgraham and @sama were right about the intolerance of free speech in Silicon Valley.
trishankkarthik··on A Better Crystal Ball?
Thanks, yes, I try to write in a way where even I don't fall asleep, unlike our "nirvana fallacy" friend below...
trishankkarthik··on A Better Crystal Ball?
Not a criticism if the worst you can say about someone is that he is "mean," not that he is wrong.
trishankkarthik··on A Better Crystal Ball?
Show me the money: did they warn about COVID-19 way BEFORE it be came a problem, or did they not? If not, why should we take them seriously? It is easy to prognosticate AFTER the fact.
trishankkarthik··on A Better Crystal Ball?
You cannot fundamentally predict the future, fuhgedaboutit, partly for the same reasons we cannot use Turing machines to solve the halting problem for Turing machines.

What you can do, however, is control your exposure to outcomes of unpredictable events. You don't know when a pandemic will hit, but you know it is is matter of time, just like getting hacked. So prepare and design accordingly. Simple. No need for this superforecasting nonsense which doesn't even work.

trishankkarthik··on A Better Crystal Ball?
This is the most dangerously stupid thing I've ever heard. Tetlock is a known academic charlatan pushing his absolutely useless "superforecasting" nonsense which @nntaleb keeps debunking on Twitter. If Tetlock and friends are so good about forecasting the future, why didn't they predict and warn us about COVID-19 BEFORE @nntaleb and friends (including myself) did?

P.S. I have been downvoted for saying this.

trishankkarthik··on Apprentice, Journeyman, and Master: The Medieval Guild (2018)
100%

Tech companies could hire and train students straight from high school instead of making them go through the academic priestly class, but nope, everyone wants expensive degrees and pay more for it.

trishankkarthik··on Learn Big-O and stop hacking your way through algorithms
BS. Big-O is designed by academics for academics. This is not how you would teach high school students with an apprenticeship model.
trishankkarthik··on Google resumes its attack on the URL bar, hides full addresses on Chrome 86
I was just thinking about this the other day: at the same time, they keep adding weird, inscrutable nonsense at the end of every Google Search URL, so what's the point of hiding the protocols and www and whatnot?
trishankkarthik··on Signing .jars is not worth the effort
This is why you should use a well-designed system such as The Update Framework (TUF) that aims to make security as usable as possible:

[1] https://www.python.org/dev/peps/pep-0458/ [2] https://theupdateframework.io/

trishankkarthik··on Falsehoods programmers believe about build systems (2012)
If you guys can't even take a "bad" joke, gods help you all. Feel free to ban me.
trishankkarthik··on Falsehoods programmers believe about build systems (2012)
dang, I was clearly joking...
trishankkarthik··on Falsehoods programmers believe about build systems (2012)
YAML IS NOT AN EFFING PROGRAMMING LANGUAGE, EVEN IN 2020
trishankkarthik··on Backstabber's Knife Collection: A Review of Open Source Supply Chain Attacks
That's a bit like saying: well, encrypting the iPhone isn't all that jazz, because all I have to do is hit the owner with a $5 wrench.

I mean, yes, but cryptography alone cannot solve that problem. TUF and in-toto provide cryptographic solutions to cryptographic problems, which is much more than anyone else is doing today.

trishankkarthik··on Backstabber's Knife Collection: A Review of Open Source Supply Chain Attacks
This is why we designed TUF and in-toto to detect MitM attacks anywhere in the software supply chain between developers and end-users themselves, and provide E2E compromise-resilience.

It's strange that the paper doesn't mention us considering that we have considerable expertise in this very area.

https://www.datadoghq.com/blog/engineering/secure-publicatio...

trishankkarthik··on The new Microsoft Edge is out of preview
Last I checked, Chrome uses CUP, which is more like TLS than TUF
trishankkarthik··on Exposition of a New Theory on the Measurement of Risk (1738) [pdf]
Hi Stan!
trishankkarthik··on Exposition of a New Theory on the Measurement of Risk (1738) [pdf]
Hihi, me too: https://github.com/trishankkarthik/notebooks/blob/master/Eva...
trishankkarthik··on Why no one is exponentially smarter than others
1. ?? You do realize there are self-appointed geniuses who actually make this kind of arguments, right?

2. That snake-oil AI paper guy, right though he may be here, you know he's jealous of Bitcoin, right? Wrote a whole academic paper trying to justify how Bitcoin wouldn't exist w/o academia. If he was so smart, why didn't he write Bitcoin himself?

3. If this was so obvious and you're so smart, why didn't you write it yourself?

trishankkarthik··on Why no one is exponentially smarter than others
If you're so smart, and this idea so obvious, why didn't you write about it?
trishankkarthik··on Why no one is exponentially smarter than others
Define it rigorously. We have, in terms of the amount of computation in m time steps.
trishankkarthik··on Why no one is exponentially smarter than others
You get it (I was a PhD, too)
trishankkarthik··on Why no one is exponentially smarter than others
You tell me: why would it? And if it could, why can't we build similar machines?
trishankkarthik··on Why no one is exponentially smarter than others
Firstly, have you read ImaCake[1]?

Secondly, if you're so smart, why didn't you write this essay, and refute it yourself?

[1] https://news.ycombinator.com/item?id=21622871

trishankkarthik··on Why no one is exponentially smarter than others
Related to the G's essay[1] on genius. AMA!

[1] http://paulgraham.com/genius.html

trishankkarthik··on Hypercomputation: Computing more than the Turing machine (2002)
We're talking past each other. Please revisit Sipser's proof for why the halting problem is TM-uncomputable, and you'll see what I mean.
Page 1 of 2Next →