HNHacker News
TopNewBestAskShowJobs

vngzs

2,583 karma · joined October 2, 2018

https://github.com/vngzs https://keybase.io/vngzs

[ my public key: https://keybase.io/vngzs; my proof: https://keybase.io/vngzs/sigs/JW88RqiRCJqnuZ_59waFsjWNKkHQ8c9ejTJR4JXX_mE ]

Comments are my opinion and not intended to represent the viewpoint of my employer (past or present).

submissionscomments
vngzs··on Amazon used algorithm to test how much it could raise prices: FTC
Cory Doctorow disagrees (1) that the consumer welfare theory of monopolies is valid and (2) that monopolies which dominate industries are economically desirable [0]. I found it interesting to realize that most modern antitrust theory - that consumer harm is the only reasonable basis for government intervention in monopolies - appears to lack historical basis in the law. For instance, the consumer welfare standard severely downplays the importance of free and fair competition among businesses as a means for class advancement.

> This is the “consumer welfare” standard, a theory as economically bankrupt as it is historically unsupportable. Let’s be clear here: The plain language of America’s antitrust laws make it very clear that Congress wanted to block monopolies because it worried about the concentration of corporate power, not just the abuse of that power. This is inarguable: Think of John Sherman stalking the floor of the Senate, railing against autocrats of trade, declaiming that “we should not endure a King over the production, transportation, and sale of the necessaries of life.” These are not the statements of a man who liked most monopolies and merely sought to restrain the occasional monopolist who lost sight of his duty to make life better for the public.

[0]: https://archive.ph/aTv47

vngzs··on 0-days exploited by commercial surveillance vendor in Egypt
I don't see GP claiming CAs should be checking reputability for domain issuance certificates. But the thread originator mentioned subverting CAs! Something to remember about even the most advanced attackers is that they value the continued effectiveness of their tactics, tools and procedures. Even nation-states in possession of CA subversion abilities won't burn their malicious CA on someone if they can conduct the attack with a legitimately-issued certificate, and they won't bother with a legitimately-issued cert if they can conduct the attack without even involving a CA.
vngzs··on 0-days exploited by commercial surveillance vendor in Egypt
That's just the delivery method, not the exploit.
vngzs··on Keystroke timing obfuscation added to ssh(1)
So Tor with a blockchain, and you have to pay for it?

> Users pay a fee in NYM to send their data through the mixnet.

vngzs··on SeaGlass: City-Wide IMSI-Catcher Detection (2017)
That's a question shared by several US senators [0]. Ron Wyden sent a similar letter in 2018, which received a response from an assistant attorney general, not the FCC [1].

[0]: https://www.eff.org/files/2016/10/06/senate_letter_to_fcc_on...

[1]: https://docs.fcc.gov/public/attachments/DOC-355228A2.pdf

vngzs··on Once hailed for decriminalizing drugs, Portugal is now having doubts
Indeed. They slashed funding to successful parts of the strategy and now claim the strategy failed. A convenient narrative for politicians, but hardly truth.
vngzs··on What if your Pods need to trust self-signed certificates?
If you want good integrity controls, treating the CA bundles as secrets (e.g., storing them in k8s secrets or something like Vault) can help there. We don't actually care much about confidentiality controls, but any secret manager worth its salt is going to have integrity controls as well. This gives you easy updates and lets you reuse containers across environments while remaining defensive against attackers adding their own CA to the store.
vngzs··on Moog sells its business to InMusic
See the movie Blackberry[0] for a dramatic telling of this.

[0]: https://www.rottentomatoes.com/m/blackberry

vngzs··on FTC sues Amazon over ‘deceptive’ Prime sign-up and cancellation process
Thank you for sharing this! This is super egregious and should be in the article.
vngzs··on AI camera with no lens
This should link to the original post, not link to a blog post about a Twitter thread that contains a link to the original post.

https://bjoernkarmann.dk/project/paragraphica

The author's site is currently struggling to load, so here is an archive link:

https://archive.is/mvfq2

vngzs··on The teens behind the Mirai botnet
"Outdated" is a reasonable moniker for devices that accept cleartext telnet over the open Internet. That you can retrofit security onto telnet by running it over a TLS tunnel is not especially relevant, nor does it make telnet less outdated; secure devices are better off just using SSH.

What makes a protocol outdated? I would argue that outdated protocols "bake in" outdated assumptions. The telnet protocol has a builtin assumption that the network is secure, while newer protocols for remote administration lack this assumption and assume an actively malicious network.

vngzs··on “Rewrite It in Rust” Considered Harmful? [pdf]
The only publication that might take this paper without changes is POC||GTFO. Did you read the abstract?
vngzs··on Advertise on DuckDuckGo Search
Sure as a general rule, but that doesn't render those experts free from criticism when they make mistakes. That low confidence scientific hypotheses were treated as high confidence scientific results is a valid critique of expert interaction with the general public, as it led to search engine censorship of objectively true information.
vngzs··on US adds a solid 253,000 jobs despite Fed's rate hikes
You seem to misunderstand the statement. "Upward pressure on wages" implies an increase in wages.

In other words, people make more money in robust job markets and can spend more money on goods and services.

vngzs··on White House Unveils Initiatives to Reduce Risks of A.I
https://archive.is/JgpNM
vngzs··on Finding and exploiting vulnerabilities in H.264 decoders [pdf]
> now fuzzers are being written in rust, as if that translates to better quality bugs being found.

I'm not sure if you're being facetious, but this is a classic straw man fallacy[0]: you've constructed a nonsensical motivation for the authors' use of Rust, then argued against that motivation.

There is superficial similarity between (1) "the authors wrote the fuzzer in Rust" and (2) "the authors wrote the fuzzer in Rust because it translates to better-quality bug findings", but the paper's authors did not claim (2), nor would any reasonable person claim (2).

More likely is that Rust is a useful language for authoring fuzzers because it is fast and supports modern abstractions while eliminating multiple troublesome categories of bugs. Fast performance, zero-cost abstractions, automatic memory management, and concurrency safety are useful language properties regardless of their relevance to security bugs.

[0]: https://en.wikipedia.org/wiki/Straw_man

vngzs··on The ThinkPad X1 Carbon Gen 10 as a Linux Laptop
I have this laptop. The connection between the charger and the battery died, roughly 13 months in.

I met another tech worker who had this laptop. Also ran Linux on it, like me. They complained that the connection between the charger and the battery failed and the laptop is now bricked.

The laptop was a dream before that. But the battery->charger connection (which is just USB3) is painfully unreliable - buyer beware.

vngzs··on A eulogy for Dark Sky, a data visualization masterpiece
To find it, you need to know that tapping on the hourly weather view gives you the temperature graph. Then you need to click the thermostat icon and switch it to precipitation. Only then is the information displayed. Once it's onscreen, the precipitation graph in the Apple Weather app centers on the full day view (with the current time in the middle) rather than just the future, which is what most users care about.

That's not the same as putting it front-and-center. Yes, the information is there, but the interface design is garbage.

vngzs··on The Astonishing Transformation of Austin
https://archive.is/eiMzk
vngzs··on Show HN: boxxy – Control where Linux programs put files, without symlinks

    $ du -sch ~/.config/Slack
    846M $HOME/.config/Slack
    846M total
... this is on a two day old machine. WTF, Slack? Junk cached data belongs in ~/.local/share ($XDG_DATA_HOME), not ~/.config.
vngzs··on GitHub to lay off 10% and close all offices
The last few years were marked by a truly outrageous hiring spree fueled by near-zero interest rates and, by extension, tons of cheap VC money. Because of greed or mismanagement, tech companies over-hired during the pandemic expecting record growth to continue indefinitely. These layoffs are a sign that pandemic-era business growth plans were brittle, unable to tolerate even temporarily raised interest rates and the ceasing flow of cheap cash.
vngzs··on Yes, Crypto Is All a Scam
Good point, I've had one hell of a time making down payments on cars or first/last month's rent with cashier's checks when my bank doesn't have physical branches in my area.

If I could have paid with, say, a dollar-backed stablecoin from a reputable institution, I could have made the payment digitally and closed the sale/rental without waiting days for a bank to mail me a check. In the apartment rental case, I might not have gotten passed up because someone else arrived check-in-hand ready to close the deal.

vngzs··on Surveillance Footage of Tesla Crash on SF’s Bay Bridge
It is exceedingly abnormal to come to a complete stop in the far left lane.
vngzs··on FTX’s Sam Bankman-Fried cashed out $300M during funding spree
In Europe there are rules that work out to: if you have 50 employees or assets over EUR ~5 million, you must disclose audited financial statements publicly (this is not strictly true, but it is true to a first order approximation).

It wouldn't be crazy sounding to require that companies worth over $10 billion USD disclose financial statements audited by reputable firms.

vngzs··on Xterm code execution via font ops

    -- $XTermId: README,v 1.3 2007/05/24 19:49:19 tom Exp $
    -- Below is the original README for xterm from 1991, for your amusement.
    -- For a better overview, see http://invisible-island.net/xterm/

                        Abandon All Hope, Ye Who Enter Here


    This is undoubtedly the most ugly program in the distribution.  It was one of
    the first "serious" programs ported, and still has a lot of historical baggage.
    Ideally, there would be a general tty widget and then vt102 and tek4014
    subwidgets so that they could be used in other programs.  We are trying to
    clean things up as we go, but there is still a lot of work to do.

    If you are porting this to a machine that has problems with overlapping
    bcopy's, watch out!

    There are two documents on xterm: the man page, xterm.man, which describes
    how to use it, and ctlseqs.ms, which describes the control sequences it
    understands.
vngzs··on Making an SSH client the hard way
Sounds like about "as good as this gets" if you happen to want to do this in browsers. Good job.
vngzs··on Writing systemd units that stop gracefully before shutdown
Thanks. I ripped it from a colleague, and now I have some bugs to report.
vngzs··on Making an SSH client the hard way
This is really cool and fun, but is this a safe way to run SSH clients?

If, say, the adblock Chrome extension you're using gets bought by a malware operator and backdoored[0], now it also has SSH and VPN access.

[0]: https://www.wired.co.uk/article/fake-chrome-extensions-malwa...

vngzs··on Writing systemd units that stop gracefully before shutdown
I have the following unit file saved for that purpose:

    [Unit]
    # https://stackoverflow.com/questions/36729207/trigger-event-on-aws-ec2-instance-stop-terminate
    Description=unlink agent from remote server
    Before=shutdown.target
    [Service]
    Type=oneshot
    EnvironmentFile=-/etc/environment
    KillMode=none
    ExecStart=/bin/true
    ExecStop=/opt/service-name/shutdown-unlink
    RemainAfterExit=yes
    User=root
    [Install]
    WantedBy=multi-user.target
If I recall correctly, the KillMode=none is important as it causes the shutdown-unlink binary to escape systemd process supervision. Without it, you may deal with systemd immediately halting your shutdown unit (and killing the process) when it hits the shutdown target.
vngzs··on Staff Engineer Archetypes (2020)
This post is a draft version of the released version at [0].

[0]: https://staffeng.com/guides/staff-archetypes

← PreviousPage 2 of 10Next →