HNHacker News
TopNewBestAskShowJobs

vesche

1,021 karma · joined June 8, 2014

Software Engineer & Security Researcher
submissionscomments
vesche··on Samsung plans $17B chip plant in Taylor, Texas
I doubt it. The land is just cheap and widely available over there. Also, they know workers will be attracted to being a short commute from Round Rock. The storm that caused the grid failure is a very rare occurrence ("100-year storm").
vesche··on Micro – a modern and intuitive terminal-based text editor
I tried Micro on for size for a few months earlier this year. I like it a lot, but stopped using it over time. Any time I reach for a text editor I kind of muscle memory open vim if it's something quick or VS code if it's a larger project.

Micro is like nano re-built for the 2020's. It feels really natural to use with sane key bindings and text selection. I like that it's written in Go and has a nice plugin framework. I might have used it more if a file manager / code tree off to the side was a built-in feature. I found a plugin that could do it, but I had some hassles with it iirc - https://github.com/NicolaiSoeborg/filemanager-plugin

vesche··on Lidar reveals hundreds of long-lost Maya and Olmec ceremonial centers
“The Lost City of the Monkey God” is an absolutely fantastic read if you’re interested in the usage of LiDAR for archeological discovery.
vesche··on Morse Code Palindromes
Very cool, I'd never thought about Morse code palindromes before. Using a list of ~370K English words I discovered a few other neat ones: rotor, taint, swigs, unsad, and waiting. There's only 27 morse code palindromes that are 5 characters or more in length.

Here's the Python script I cooked up: https://gist.github.com/vesche/ada491d63d77d8afa55a599c787df...

vesche··on Ghidra: A software reverse engineering suite of tools developed by the NSA
For anyone confused (as I was) rizin is a fork of radare2. I don't have anything constructive to say other than I'm confused why the project was forked.
vesche··on Learn by reading code: Python standard library design decisions explained
Reading tons of Python code has really helped me as a Python developer. Several times a month I'll checkout GitHub's trending Python repositories: https://github.com/trending/python?since=weekly By pursuing this list I can dip into repositories that interest me, see the "beat on the street", skim interesting project code, keep up to date with the latest design decisions, etc. It's also fun to see that sometimes a trending repository has "bad" code. It's nice to be able to recognize good code from bad code, which is a skill I only developed by reading and writing tons of code. Also, it's nice to realize that fun projects don't have to be coded well to be cool.
vesche··on “Please don't waste maintainers' time on your KPI grabbing patches”
In case anyone forgot about this: https://grsecurity.net/huawei_hksp_introduces_trivially_expl...
vesche··on Librem 5 Evergreen vs. PinePhone (Part 2)
I'm unsure what you mean by this. Android is based on Linux. The web runs on Linux. Hell, the thermostat in your house probably runs Linux. I've been using Linux on my laptop I do all my professional work on for many years. I'm responding to your comment right now on that Linux laptop.
vesche··on Librem 5 Evergreen vs. PinePhone (Part 2)
> ... this is all somewhat biased since if this was 2009 both of these phones would seem as if they’re the future. On the other hand it isn’t 2009 anymore, and these phones are here today.

This is interesting and something I hadn't thought about. I have a PinePhone that I've been hacking around on for the past few months. If I had this phone a decade ago I would have been over the moon. I'd really like to make it my daily driver, but I simply can't because of the experience I'm now accustomed to on modern smartphones. My future of being a happy hacker with a fully open-source Linux smartphone in my pocket still seems a few years away, but the future is bright.

vesche··on Show HN: DarkHN – Dark Mode Mirror for Hacker News
I use Stylus and this stylesheet: https://userstyles.org/styles/22794/a-dark-hacker-news

Works great for me. I use dark themes via Stylus for most of the common websites I visit like HN, GitHub, StackOverflow, etc. All other websites that cause me to squint I just toggle Dark Reader: https://darkreader.org/

vesche··on Show HN: Mmm.page – Drag and drop personal website creator
https://mmm.page/vesche.main
vesche··on Deno 1.10 Release Notes
Yup, it uses rusty_v8 which are Rust bindings for V8's C++ API - https://github.com/denoland/rusty_v8
vesche··on Hire me and pay what you want, just give me interesting work
Pie in the sky. Any realistic employer reading this plea should be turned off fairly quickly. Typically, it's a red flag when an employee gives an employer ultimatums while already in their employ (e.g., give me a raise of x amount or I will quit). This post is an example of a potential employee giving ultimatums to a future employer before they have even been given a job.
vesche··on Google Blocking Web Privacy Proposals at W3C (2019)
First of all, I'll say that I _obviously_ don't want to live in some sort of Orwellian, Ministry of Truth, 1984-esque dystopia. However, I think there's an unnecessary amount of fearmongering going on currently about organizations pushing back against disinformation. There certainly is a disinformation problem and from a U.S. perspective it is quite obviously a foreign adversary and malicious actor problem.

It seems that this Mozilla article is too vague, open-ended, and short to be processed correctly. I personally interpreted the article differently than you did, which doesn't mean either of us interpreted it incorrectly.

vesche··on Google Blocking Web Privacy Proposals at W3C (2019)
You hadn't mentioned your first point, so not sure how I would have known that.

I will indeed test both browsers, if Brave is objectively better obviously I want to use it... However, I wish there was just stats on both browsers we could see side by side.

I did find this, https://www.mozilla.org/en-US/firefox/browsers/compare/brave...

Obviously biased because it's from Mozilla, however- I think this argument is moot. They're both better than what else is out there.

vesche··on Google Blocking Web Privacy Proposals at W3C (2019)
Well so far you've given me a political article you misinterpreted based on a headline and I did try googling the EFF Panopticlick study on browsers- and there's an article from 2017 but no data or stats I can find? You haven't told me why you disagree with the company / business decisions so I have nothing to go off there...

I'm not being harsh, you just haven't presented anything beyond empty words.

vesche··on Google Blocking Web Privacy Proposals at W3C (2019)
I initially responded to this thread with being legitimately "genuinely curious" as to why you think Brave > Firefox, as it seems a lot of people have that same thought. However, every time I get into a dialogue like this there isn't any proof in the pudding. I'm sure Brave is a decent browser, but there doesn't seem to be any real reason to switch. I've been using Firefox for more than a decade, it's open-source, from a non-profit, great community, frequently updated, on-par with Chrome in-terms of performance/speed.

Everything I hear is just hollow words- "I just disagree with some of Mozilla's business decisions" / "it's more privacy-focused than Mozilla Firefox" / "it's less politically focused than Mozilla Firefox" / "Brave seems to be a little bit better in some aspects"

vesche··on Google Blocking Web Privacy Proposals at W3C (2019)
This comment chain is seriously confusing, did you or any of these other people even read the article: https://blog.mozilla.org/blog/2021/01/08/we-need-more-than-d...

The article is perhaps poorly titled, and the modern age headline-skimmers will take it at face value. The article isn't calling for more extreme action or censorship... It's saying that deplatforming isn't the solution and what we should do is have transparency of advertisers & algorithms and support / fund research into studies on disinformation. I'm not sure how anyone can disagree with the substance of the article.

Ok, so no political issues... Still waiting on the privacy argument.

vesche··on Google Blocking Web Privacy Proposals at W3C (2019)
Genuinely curious, how is Brave "more privacy-focused and less politics-focused" than Mozilla Firefox?
vesche··on SolarWinds leaked FTP credentials through a public GitHub repo since 2018
I discussed this in a video I made on the SolarWinds compromise if anyone is interested - https://youtu.be/ONd0ERCUy0k?t=760

Original Tweet came from @vinodsparrow - https://twitter.com/vinodsparrow/status/1338431183588188160

Keep in mind the binary files that contained the backdoor were digitally signed by SolarWinds after being tampered with. So this FTP credential leak might be part of the supply chain compromise, but is not the whole enchilada.

vesche··on Chrome Is Bad
The author went so far as to create a domain for this rant, and yet didn't even do any performance metrics or basic forensic analysis at all. I'm not saying the author is wrong, but there's a lot of questions here. How does Keystone hide itself from the Activity Monitor? Is there a Keystone process if you run `ps aux`? Did you run dtruss/strace? What is it doing when Chrome isn't running that causes it to degrade performance?
vesche··on A CIA Officer Visits Moscow, Returns with Mysterious, Crippling Headaches
I'm reminded of Daniel J. Bernstein's post "My trip to Russia / Maybe jail isn't such a bad option" from 2000: https://cr.yp.to/conferences/russia.html

He woke up in the middle of the night not able to breathe with some sort of toxic gas permeating his hotel room.

vesche··on New Features in the Fish Shell
I've been using fish as my default shell for ~3 years now. The faint gray history auto-complete / search that appears when typing commands alone is a killer feature. urxvt + fish + ranger + sauce code pro font = me loving my terminal experience a ton. Thanks fish devs!
vesche··on Statement Regarding the Zen Programming Language
Are you blind to the fact that you're causing damage & frustration to one of the coolest open-source projects to pop-up over the past 5 years?
vesche··on Former Uber executive charged with paying 'hush money' to conceal breach
From reading the article it doesn't sound like this was ransomware:

> "During this time, two hackers contacted Sullivan by email and demanded a six-figure payment in exchange for silence. The hackers ultimately revealed that they had accessed and downloaded an Uber database containing personally identifying information, or PII, associated with approximately 57 million Uber users and drivers."

The hackers were demanding a ransom from Uber to keep silent about a data breach. Which is a whole lot different than paying a ransom to decrypt valuable, internal data. If a company has been breached, while it will almost certainly cause damage fiscally & to their reputation- they have a responsibility to notify users/customers. I'm unfamiliar with the law on this, but it should be illegal for a company to pay a ransom for malicious actors to keep silent about data they stole.

vesche··on Python malware on the rise
Author here. Thanks for reading & the feedback. I'll try to unpack some of this.

> A lot of exploits are two-stage. Stage one is usually the vulnerability, usually written in C given the low-level and tightly controlled instructions required. The exploit breaks security to run an executable or otherwise gain control. Stage two is usually downloading a python executable to grab the goods.

This seems like a gross oversimplification & commonly incorrect. Often times a "stage one" vulnerability to gain initial access would be network code written in a high level language such as Python or Ruby (see Metasploit). And an executable payload to interact with the system would be generally written in a compiled language like C or C++. My article is detailing the uncommon rise of interpreted languages (especially Python) being used over the past ~5 years as malware dropped on an endpoint in an attack.

> Just seems like a minor observation, rather than some doom trend.

I wouldn't say this is a minor observation or a "doom trend." I'd say it's a very interesting and insightful observation that is worth keeping an eye on. Malicious actors are no longer operating in a world of slow endpoints and lack of resources. They instead are operating in a world of high-speed internet, very fast endpoints, and have a rich ecosystem of open-source tools at their disposal.

I find it highly interesting that malicious code written in interpreted languages, bundled with their interpreters into an executable, are finding their way into the arsenal of high-tier malicious threat actors over the past few years. Just as the web browser is slowly eating away at the operating system, interpreted languages are slowly eating away at compiled languages in a variety of domains- including malware.

vesche··on Python malware on the rise
Author here. Wasn't my intention to mislead, but I also don't think the article is mistitled. What would have been a better name? This article is about actual Python malware that would affect an endpoint like a remote access trojan (RAT). If the article was about malware within the Python package index, I would have named it "Malicious Python packages within PyPI on the rise!" It could also be a confusing professional domain interlap, as I exist typically within the security world.
vesche··on Python malware on the rise
Author here: I've seen your guides before, they're really great! I'd say my article looks at the difficulties, but also the great benefits malware authors have by writing in Python.

> Packaging with PyInstaller to create a single (but large) executable is easy and helps avoiding detection as the interpreter is embedded in the PE

If you look down further in the article it explores detecting PyInstaller generated executable using simple YARA rules. So, I'd disagree a bit there. I personally think that Nuitka (talked about in the article) in conjunction with a packer would be the best compilation method to use in-order to evade detection. It's actually quite surprising to me that limited malware samples have been seen in the wild using Nuitka, but as the title of the articles states- it's on the rise.

vesche··on Python malware on the rise
They can get really large, especially if it's a dependency that has many dependencies itself! Glad you enjoyed it, thanks so much for reading.
vesche··on Python malware on the rise
“What I cannot create, I do not understand." -Richard Feynman

I do hope that those reading this will use this knowledge to do good.

← PreviousPage 2 of 6Next →