HNHacker News
TopNewBestAskShowJobs

v8dev123

1 karma · joined April 13, 2021

submissionscomments
v8dev123··on Mighty Makes Google Chrome Faster
Encryption is "obscurity". For example, Quantum computers will break RSA.

> Quantum computers will break RSA

Now here it will take X amount of time so is breaking any protection like DRM.

The goal of any security method is increasing attack time.

TLS got attacked, SSL got attacked. History repeats itself. Period.

> Oh, and there's no need to call people "communists", "attackers", or "criminal scum". Be civil.

Why? I have a right to use these terms. What should I use instead?

Would you call Osama Bin Laden as "His Highness Bin Laden"?

The words exists for reason. I use them in appropriate context.

People don't understand Russian soul. I'm very direct and speak my mind!

>> Second, several other email providers don't think they need to rely on some performance-killing DRM to "protect" their web app (oh no, what of all the value!).

>> Outlook has a part of their files minified, but doesn't use any obfuscation; apps like ProtonMail[0] and Tutanota[1] are even open source.

So? What's your point?

You have Linux which is Open Source and you have Windows (A lot of parts including their licencing is obfuscated)

The performance hit is minimal. ProtonMail & Tutanota are way slower than GMail and lack cutting edge features we offer.

Gmail vs Outlook is like Ferrari vs Toyota.

Gmail has great UX even my grandmother can use it.

v8dev123··on Mighty Makes Google Chrome Faster
>> Why Google needs DRM for a web email app?

The reason we use such tactics is to increasing barrier of reverse engineering because our teams value their work. Some people claim that security through obscurity is bad. I challenge this view. I claim that every security defense such as RSA is a obscurity.

It's a matter of time until RSA breaks in the same way as Obfuscation does.

Gmail is not your let's make it weekend kind of app. It's highly sophisticated and deliver huge value.

There are lot of people who hate Obfuscation. Some are communists and others are attackers.

My wife (she works in the fraud detection department) found an interesting attacker who masqueraded as a security researcher and student of X University, but in fact he was a a criminal scum. He has reverse engineered anti-fraud scripts of many websites and published them on Github for everyone to see. His main goal was to attract malicious buyers and sell them scripts that bypass this protection. It was one of the heck of marketing.

Brian Krebs also had similar story on his blog.

v8dev123··on Modern C++ Won't Save Us (2019)
I believe he imply two different things. Boost heavy on templates and the malware heavy on OOP.

His original comment was,

"Using boost to turn the code into a clusterfuck of OOP and sadness)"

Whatever. Everything is true because I've done RE my-self.

It's hard.

Another one also said,

"Reverse engineering objective-c code with heavy QT framework usage makes me seriously doubt my life and career choices."

I guess the same applies with C++ with heavy QT framework usage.

v8dev123··on Modern C++ Won't Save Us (2019)
These Rustic people write very dishonest articles. They write all flaws of C++ and then compare how bad C++ is. It really harm the Rust language itself not the C++. Professionals will dislike Rust because of it's community not the language. Rust people should put more effort writing a formal specification else many people will consider Rust as undefined. My comment getting flagged and downvoted and therefore posting here.
v8dev123··on Modern C++ Won't Save Us (2019)
OOP and Boost also Templates has benefits when it comes to increasing barrier of static reverse engineering.

For example, Security researcher "Marcus Hutchins" famously echoed that Boost is a cluster fuck of OOP sadness [0]

Similarly, a close friend of mine "Omer Yair" mentioned [1],

"A well written OOP malware might be harder to RE statically than a poorly written C code. Writing OOP malware badly though just makes it similar to C code so not sure of the benefits going that route."

[0] https://www.malwaretech.com/2017/04/the-kelihos-botnet.html [1] https://twitter.com/yair_omer/status/1262020385203200000

v8dev123··on JavaScript for Data Science
Well, nowadays you can use WASM with JS to access libraries at near native speed.
v8dev123··on Alien Artifacts on Earth and in Our Solar System Is Possible, NASA Reports
I have one hypothesis why Aliens are hiding. It's just they are simply afraid of humans torturing them for their color and appearance.
v8dev123··on Get better at Googling
DDG uses Bing.
v8dev123··on Get better at Googling
Sometimes Stackoverflow own's search is better than Google.
v8dev123··on The Rise of North Korea's Hacking Army
Maybe but it will be like Stephen Hawking hosting a party for time travelers.
v8dev123··on Cerebras’ new monster AI chip adds 1.4T transistors
Why it's called as "AI"?
v8dev123··on Unreleased MacBook Schematics Stolen in $50M Ransomware Attack on Apple Supplier
The author of this Ransomware [0] scrounged through the trash heaps and smoked cigarette butts. He walked 10 km one way to the school. He wore the same clothes for six months. In his youth, in a communal apartment, he didn’t eat for two or even three days.

By the way, the guy donates money to open source projects.

Netflix probably interested in his story. He is like Digital Version of Pablo Escobar.

[0] https://therecord.media/i-scrounged-through-the-trash-heaps-...

v8dev123··on _hyperscript: A jQuery and JavaScript Alternative
This won't scale. It will be like AppleScript for Web :)
v8dev123··on First steps with Rust
Compiler identification is not fairly straightforward when you remove all metadata that gives you hints. It gets worse when you fake the metadata.

My opinion echoed by many top people in reverse engineering industry.

Modern C++ is obfuscated by default due to templates, inlined functions and of course OOP.

For example, Marcus Hutchins famously echoed Boost is a cluster fuck of sadness.

My point is not about obfuscation anyway but it does helps obfuscation to some extent. It's about reverse engineering the optimized code and recover the original non-optimized code which can have a lot of use-cases.

https://www.msreverseengineering.com had a course on this subject. Experienced ones can reverse everything but my point is that it increase the barrier.

v8dev123··on A Universal I/O Abstraction for C++ (2020)
> The quote was Around 70% of our high severity security bugs are memory unsafety problems.

This quote simply means there are 70% high severity security bugs and it doesn't implies anything about sandbox.

You can have a use-after-free exploit but it's worthless without a sandbox escape.

Sandboxing is very effective at memory bugs but certainly bad at logical bugs.

v8dev123··on A Universal I/O Abstraction for C++ (2020)
The thing with memory bugs is that you need another bug for Sandbox to fully exploit the browser.

Here is a real world logical exploit that knock sandbox and Rust won't prevent this stuff,

https://bugs.chromium.org/p/chromium/issues/detail?id=386988

v8dev123··on A Universal I/O Abstraction for C++ (2020)
> read-before-write is still undefined behaviour, dereferencing null is still undefined behaviour, divide-by-zero

You rarely do these in Modern C++.

It's your responsibility to check the input of program before doing anything with it.

Structured Exception Handling aka SEH Exceptions can catch things like divide-by-zero, read-before-write, dereferencing null

> The C-style footguns will probably still be there in 20 years.

It's your job to know these footguns. Actually, it will take 2-3 months for a new programmer to separate C++ and C and understand what Modern C++ actually about.

> I have mixed feelings on function overloading. It makes it harder to reason about what function is being called.

It doesn't because overloading depends on the arguments not on the function names

Without overloading, things become ugly.

v8dev123··on A Universal I/O Abstraction for C++ (2020)
> Relying on integer overflow’s wrapping behavior is considered an error

Your doc also says this.

> I hear there are some who want to dilute the safety guarantees of Safe Rust

Unfortunately, I don't use Rust at work. I can't talk about it anymore, either. I can't use an informal reference to reason about its actual behavior. At the end of the day, C++ puts food on the table. I try to improve C++ as much as possible, knowing that it is an imperfect language. C++ is heading into safe direction, and I'm sure C++26 will be able to provide more features to write code safely.

Rust seriously need to add Function Overloading, Generics.

v8dev123··on A Universal I/O Abstraction for C++ (2020)
> integer overflow does not cause undefined behavior

Source please?

I ask this since Rust doesn't have a formal specification and I can't keep up with it's inner changes.

It did cause undefined behavior in my case but that was 4 years ago.

v8dev123··on A Universal I/O Abstraction for C++ (2020)
Rust doesn't prevents logical bugs. Chromium had plenty of those. Most are capable of RCE. They were more dangerous than memory ones because they bypass sandbox in one-click.

As for Windows, The Russians exploited a logical bug in kernel for privilege escalation.

Rust also doesn't prevents overflows, DoS, UaF, OOB.

For example, see CVE-2018-1000657

Another dangerous thing about Rust is Crates. Crates doesn't audit packages for malware and you will face far worse than NPM like situation in future.

v8dev123··on Flashlight: Fast and flexible machine learning in C++
Okay. I suggest you to try Clang's Cling. It's the JIT version of C++ and everything is instant.

https://root.cern/cling/

v8dev123··on A Universal I/O Abstraction for C++ (2020)
llhttp different from the original http-parser. It has lesser bugs because it's written in Typescript which transpiled to C and it's faster than the original http-parser
v8dev123··on A Universal I/O Abstraction for C++ (2020)
You might love evpp instead ASIO. It's just pain to install it but once you do it's a heaven.

As for HTTP parsing, llhttp does great job. It however lack multipart parsing.

v8dev123··on Flashlight: Fast and flexible machine learning in C++
I was asking C++ version not compiler version. So, C++11 or C++14?
v8dev123··on First steps with Rust
Graydon Hoare is a OCaml developer.

Graydon Hoare mentions Rust as linear ML in C++ clothing.

https://twitter.com/graydon_pub/status/1154476823557754880

I empathized the can't deny relationship between Rust and FP. It doesn't means Rust is a pure FP language. I always said same thing about C++ templates too.

v8dev123··on First steps with Rust
I don't want people even competitors to steal my intellectual property so making job of those reverse engineers harder is a feature not a bug.
v8dev123··on First steps with Rust
I don't spam C++ and I comment on C++.

There is no fight. There is made-up flame-war. Every war happen at HN and Reddit's Echochamber not at Real World.

Every languages has headaches. You won't find a perfect language ever.

You can't do serious Rust if you don't understand functional aspects.

I know C++, Haskell and Rust. Like many says Rust is a functional language disguised as imperative. There were case studies on Rust where a one with Haskell background more like to learn it faster than a one with C++ background.

The Rust book don't show you the functional parts at beginning to build your intuition but once you drive deeper you will realize what I meant.

https://ceronman.com/2020/09/17/is-rust-a-functional-languag...

v8dev123··on Are top websites using WebGL for fingerprinting?
Network level fingerprinting has nothing to do with IPs. It works by using protocol artifacts.

But VPN do migrate the problem.

v8dev123··on First steps with Rust
In that sense Democracy is also a bug then. In some ways it's a feature. It's a feature because it makes harder for reverse engineers to know which compiler generated the code. When they figure out the compiler, they can reverse the compiler logic.
v8dev123··on First steps with Rust
I suggest you try a functional language before driving into Rust.
← PreviousPage 2 of 3Next →