HNHacker News
TopNewBestAskShowJobs

usmannk

2,553 karma · joined September 3, 2015

hn@usmannkhan.com
submissionscomments
usmannk··on CUDA 11.0
I noticed CUDA 11.0 was almost ready for release last week when I went to install CUDA and the default download page linked to the 11.0 Release Candidate. The 10.1 and 10.2 links were buried behind a link off to the side labeled "legacy". The thing is, no library you use is going to be supporting the CUDA 11.0 RC, that's ridiculous. For example, Pytorch stable is on 10.2 and Tensorflow only goes up to 10.1.

This is generally indicative of how poorly organized the CUDA documentation and installation instructions are. The Conda dependency manager has made this a lot easier recently. Especially by, e.g., providing pytorch binaries. Though if you want to use packages like NVIDIA Apex for mixed precision DL[0] you're going to be in for a huge headache trying to compile torch from source while also managing your cuda and nvcc version, which sometimes must be the same but sometimes can not be![1]

[0] Yes, I'm aware that Apex was very recently brought into torch but it seems that the performance issues haven't been ironed out yet.

[1] https://stackoverflow.com/questions/53422407/different-cuda-...

usmannk··on Every Public Engineering Career Ladder
Square: https://developer.squareup.com/blog/squares-growth-framework...

https://docs.google.com/spreadsheets/d/12h50IYqd7fsO7tJ0l1Ou...

Noticed you linked the blogpost but may have missed that it also includes a spreadsheet.

usmannk··on Snowden: Tech Workers Are Complicit in How Their Companies Hurt Society
What’s interesting about those robots txt files?
usmannk··on My dad launched the quest to find alien intelligence
In this series they move on to gravitational waves.
usmannk··on My dad launched the quest to find alien intelligence
This is exactly the scenario in the books ;)
usmannk··on My dad launched the quest to find alien intelligence
> Maybe something is out there, but out of reach, or deliberately silent?

Have you read The Three Body Problem series by Cixin Liu? It's a terrific (and recently quite famous + awarded) sci fi trilogy that explores this idea. That all sufficiently advanced civilizations have learned to be extremely radio silent in order to escape detection. Reason being that they all eventually conclude that, from a game theoretic standpoint, the only reasonable thing to do when you detect another civilization is to eliminate them before they do you.

usmannk··on Responding to the Controversy about YOLOv5
Is this article addressing a strawman? I certainly raised an eyebrow at their use of the name but is there actually a "controversy"? And if so, why not be similarly upset over YOLOv4? That edition confused me just as much as v5, given that neither one came from Reddie.
usmannk··on How SGX Fails in Practice
Oh huh, I see. Thanks for the papers. "Someone was going to have to go first. Intel happened to take greater risks in the name of performance, and all of their technologies (including their first-to-market enclave technology) are suffering reputational hits as a result." Very true, and a point worth making. Just curious, do you work closely with SGX/SEV? You were quick with the links!
usmannk··on How SGX Fails in Practice
> Signals new PIN thing relies (almost) entirely on SGX being secure to make their encrypted profile and contact backups secure.

This just seems irresponsible. How could they excuse this? It seems like anyone who has even peripherally been working with TEEs recently is _well_ aware that SGX is broken beyond repair. It's not just a matter of patching bugs, this whole model seems bunk.

usmannk··on How SGX Fails in Practice
At this point SGX is just so broken that it seems like its only purpose is to provide PhD students something to write a paper on :)

I'm hesitantly excited for AMD's SEV enclave to roll out. Anyone know if it's shaping up to be any better?

usmannk··on Catalina is checking notarization of unsigned executables
Agh, I think it was cert pinning. Looks like the connection is terminated if you're snooping. I see the same results as you now. Thanks!
usmannk··on Catalina is checking notarization of unsigned executables
Ah I see, looks like we're not running quite the same experiment. I suspect that anything including an app bundle ID is going to see some more interesting traffic.
usmannk··on Catalina is checking notarization of unsigned executables
This is odd, my proxy doesn't seem to show this. I will try to load my root cert into Wireshark and check.

Edit: Checked and double checked: When I run a new shell script, syspolicyd just makes a connection with no application data

usmannk··on Catalina is checking notarization of unsigned executables
That's a string found in the disassembly of syspolicyd (I've found it as well). However, the actual URL you see in the TCP logs has no path whatsoever.
usmannk··on Catalina is checking notarization of unsigned executables
I did see the previous article (another comment of mine should be easy to find on its HN post). Do you know how to find the issue that was referenced? There was an ID given but I have no clue what tracker that was on.
usmannk··on Catalina is checking notarization of unsigned executables
There is so much confusion here. The OP and most others are missing one of the biggest points: Look at the packet trace. There is _no data_, not even a hash, being sent. It's a TLS negotiation and then the connection ends. I have to suspect it's a bug...
usmannk··on MacOS Catalina: Slow by Design?
0.0.0.0 is non-routable and generally only valid as a src not a dest
usmannk··on MacOS Catalina: Slow by Design?
If the connection fails it goes ahead and grants permission.
usmannk··on MacOS Catalina: Slow by Design?
Yes but it looks like there is no actual session, at least for shell scripts that don't have an app bundle ID. There is just an HTTP CONNECT, TLS negotiation, then nothing.
usmannk··on MacOS Catalina: Slow by Design?
I can't edit anymore but it seems like the OCSP link could potentially be a red herring just checking the cert for the next request to https://api.apple-cloudkit.com/. It's worth looking further!
usmannk··on MacOS Catalina: Slow by Design?
It seems like there is a lot of confusion here as to whether this is real or not. I've been able to confirm the behavior in the post by:

- Using a new, random executable. Even echo $rand_int will work. Edit: What I mean here is generate your rand int beforehand and statically include it in your script.

- Using a fresh filename too. Just throw a rand int at the end there. e.g. /tmp/test4329.sh

I MITMd myself while recording the network traffic and, sure enough, there is a request to ocsp.apple.com with a hash in the URL path and a bunch of binary data in the response body. Unsure what it is yet but the URL suggests it is generating a cert for the binary and checking it. See: https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...

Here's the URL I saw:

http://ocsp.apple.com/ocsp-devid01/ME4wTKADAgEAMEUwQzBBMAkGB...

Edit2: Anyone know what this hash format is? It's not quite base64, nor is it multiple base64 strings separated with '+'s but it seems similar...

Edit3: Here is the exact filename and file I used: https://gist.github.com/UsmannK/abb4b239c98ee45bdfcc5b284bf0...

Edit4 (final one probably...): On subsequent attempts I'm only seeing a request to https://api.apple-cloudkit.com and not the OCSP one anymore. Curiously, there's no headers at all. It is just checking for connectivity.

usmannk··on Applying to PhD Programs in Computer Science (2014) [pdf]
This is very helpful! Thanks for taking the time to reply. "The better thing though to discuss is new potential funding directions that you would enable them to avail themselves of." This is something I haven't considered before and will be mindful of now.

"No matter how smart, successful, elite they are in their area they're not robots they're fleshly people first." Hah, +1. I actually wasn't aware of my current group's "status" until well after my initial contact. I just thought our research interests matched perfectly and I was excited to learn about what they were doing. Enthusiasm goes a long way.

usmannk··on Applying to PhD Programs in Computer Science (2014) [pdf]
This comment is extremely helpful to me right now and I'm sure may be to many others as well. Thanks for writing it. If I may, how did you prep for those chats? What did you .. say when you got there? Read some of their papers and bring followups to their conclusions?

For anyone else reading, I want to echo the sentiment here 100x. I'm currently working closely on a research project with a CS prof who is one of the most senior/accomplished at a top-4 (by the ranking in the original pdf, but this is widely agreed upon) CS school due to networking my way in. Though this took way more initial effort than a chat, they had a substantially involved form they used for vetting inbound inquiries.

usmannk··on Lamest Edit Wars
American English perspective:

We'd never say "in future, could you please refrain from eating loudly." There would always be a "the" after "in".

"I'm in hospital." same thing, "in the"

If someone said "Isn't she lovely. A great car, this one." I'd think they were trying to imitate a Brit.

usmannk··on Ask HN: What website, from your early days on the net, do you miss?
So true. My first thought was this as well. I'm about the same age as you and played RS at much the same time. Personally the experience was greatest due to the huge black market community. Hell, I even first learned to code in order to bot RS. Learned a lot of the exact same lessons (Trading and bartering, getting scammed, talking to people to get help moving forward) but in real life and with real money.

I still haven't gotten over suddenly getting banned from PayPal for selling virtual goods when I was 14. The ~$1000 USD I had made, pretty much all the money to my name, was held hostage for 6 months!

usmannk··on Python 2 Is Dead
The parent is talking about the former.
usmannk··on Google Maps SDK is crashing
Try opening Lyft on iOS, hard crash on boot. I don't wish to be someone working on that right now!
usmannk··on Show HN: DNS over Wikipedia
Nitpicking nitpicking: "Technically" CNAME is DNS insofar as DNS is "technically" defined at all.
usmannk··on Bose QC 35 Firmware 4.5.2 Noise Cancellation Investigation Report
I don't mean "it's not a high tech native experience with dark mode". I mean the app works poorly, all the time, and gets in the way of actually using the headphones. For example: whenever my headphones are paired with both my phone and laptop (because the app allows for two devices to be paired at once??) I have to manually disable my laptop in the app to listen to phone audio, the "drag down to connect" interface rarely works properly, etc. It really is a very poor experience when compared to BT headphones that don't require an app to manage their state.
usmannk··on Bose QC 35 Firmware 4.5.2 Noise Cancellation Investigation Report
Yeah, you can change the functionality of the button via the Bose app. However, the Bose app is awful.
← PreviousPage 6 of 10Next →