HNHacker News
TopNewBestAskShowJobs

willscott

583 karma · joined June 6, 2010

willscott@gmail.com

[ my public key: https://keybase.io/willscott; my proof: https://keybase.io/willscott/sigs/PZ8NuMrWgqNFjPVMgRH_vyDZ0MeRBUzm86niZH5JK2w ]

submissionscomments
willscott··on Notes on Red Star OS 3.0
Great to see this getting played with. In addition to these notes, there's apparently a custom kernel module doing security stuff that was found on twitter.

I mostly find this interesting for how much work went into it. Priorities can be really weird sometimes.

I posted the slides from my CCC talk: https://wills.co.tt/bitbucket/dprk/#/ I'm also happy to answer questions about redstar & related technology.

willscott··on Notes on Red Star OS 3.0
I was running it on a super low powered chromebook, which was the main problem.
willscott··on North Korea's Official Statement
An interesting takeaway from this, perhaps, is how willing this statement is to defend and mark the 'defenders of peace' group as supporters of the regime.

If an anonymous hacker attacked a cause that you supported but you didn't know what they were going to do next, would you publicly support them?

willscott··on US Senate Report on CIA Detention and Interrogation Program
The saving grace is that we have a country that was able to admit that it did this. For me, that's hope that we're still in a position to learn from our wrongs, and that the checks-and-balances are still somewhat in-tact.
willscott··on Even with 2FA, Google accounts can be hacked with just a phone number
This is a good reminder that your phone may not be as secure as you think. In many countries governments are able to get access or ask for this type of change to be made from the national telco's.

The reactions you can take at the moment are to use a mobile App, (or preferably a security key!) rather than SMS backup, and if You're feeling especially uncharitable to your phone company, change the backup number google makes you enter to a google voice number rather than that of your actual phone - creating a circular situation where it can't really be used as a method for account recovery / hijacking.

willscott··on Is uProxy dead?
There's significant incentive for us to wait until we feel all the security pieces we have been working on are relatively stable before releasing.

Even if we don't advertise, we really want to have multiple security audits, and to know that it's pretty hard to mess up with the software before it gets in the hands of anyone who could get in trouble for using it.

It's a hard balance to strike, but we're getting pretty close :)

The github link has most of the source public, it's really just the front end UX that's kept private until we're ready to open up a public beta.

willscott··on Cross domain requests to every resource on the web
Consider supporting HTTPS, since a lot of the un-cors'ed javascript this service enables involve credentials.
willscott··on Ask HN: Does Google rummage through the Gmail account of job-seekers?
no
willscott··on Google Domain Name Exploit
This is exactly what happened with the first era of URL shorteners, and has the detrimental effect of scattering dead links around the web when your service closes. (termed link rot)

ArchiveTeam has a project scraping URL shorterners to attempt to archive exactly these things. Their tagline is "url shortening was a fucking awful idea".

http://archiveteam.org/index.php?title=URLTeam

My takeaway from this is that having a whitelist is fine, but keep the original URL visible so that if your service isn't available the original content is still visible (although potentially requiring manual user effort) is a good thing.

willscott··on How do you get a job in North Korea?
The campus has internet access for professors and graduate students. There is an egyptian joint venture company in pyongyang that provides both wired and cell internet access.
willscott··on How do you get a job in North Korea?
I'm an american currently teaching Undergrad level CS in pyongyang.

Most of the students here know that they want to work at one of the two government research labs: Korean Computing Center, or Pyongyang Information Center. One of the Seniors told me he thinks he has an 80% chance of getting a job where he has access to the internet and an email address for communication.

Many of the anecdotes in the article fit with what I've seen here. I've been told that the going rate to get in to the top high school in pyongyang is about $5000US. One of the government liaisons working at the university studied Malaysian in college, and got told that there were too many Malaysian speakers when he graduated and was assigned to our university instead.

I think the main takeaway is that everything here is based on connections and who you know.

willscott··on Ambient Backscatter: Wireless Communication Out of Thin Air [pdf]
The basic thought here is that there's a ton of energy in our environment, specifically in the form of high-amplitude RF waves from TV broadcasts, and we should be able to use that energy to do work.

This project is trying to figure out what the equivalent of an rfid tag looks like with that power model. They come up with a scheme of being able to absorb versus reflect the ambient signal to communicate between unpowered tags. Maybe the most productive way to think about this is as a step into the larger research area of how to effectively harvest energy and do useful stuff with devices that don't need batteries.

willscott··on Show HN: Transfer files between computers using WebRTC
Firefox is currently ahead on the data channel, right? They support sending blobs / arrayBuffers directly, while Chrome doesn't yet have a reliable transport or binary data support.

Your example translates the file into a base64 string to send over the unreliable channel, which ends up being a pretty big performance hit compared to a native binary transport.

All of this is to say: WebRTC is getting there, but it's still going to be several months before it's ready for more than demos like this.

willscott··on The Pirate Bay is now hosted in North Korea
I wouldn't be surprised if some of the ICMP responses are forged - It seems disadvantageous for the site to have such a long path, since each hop has the potential for attack.

http://www.thoughtcrime.org/software/fakeroute/ can be seen as previous work that it is practical to do something like this.

willscott··on Mathics - A free, light-weight alternative to Mathematica
I am an avid Mathematica user. Not because I need to evaluate that much math, but because I really like its wysiwyg notebook structure for note-taking. It's great for keeping up with lectures and including decent looking equations and tables when they come up (which is fairly often in technical classes). The export to latex is a nice added bonus.

As far as I know, there aren't great alternatives to the Mathematica front end - I'd love to be proven wrong, through.

willscott··on Ask HN: What are the cons of the Seattle area?
There's a reasonably high earthquake risk, more likely to happen in your lifetime than a volcano.

On the social side, Seattle tends to be somewhat slower paced than SF or NY. You might not see the same level of high intensity and fast paced tech development that you find elsewhere, and might feel like you're moving slower than you want. There is an oft-noted 'seattle freeze', where people are polite, but reluctant to form close friendships - meaning that you might have more trouble finding the same strong friendships and communities that you can elsewhere.

willscott··on Javascript Cryptography Considered Harmful
Are there many examples of websites using client-side javascript cryptography?
willscott··on Airpost.io - A RESTful API that unifies cloud storage for developers
This looks somewhat similar to Unhosted's Remotestorage[1] specification.

[1] https://unhosted.org/

willscott··on Eric Schmidt heading on mystery mission to North Korea
I'm sure many US companies would love to see North Korea become more hospitable to the west.

A plausible near term goal might be running fiber over land between South Korea & China, which would probably be much cheaper than undersea cables.

Longer term, political capital in DPRK gives companies more bargaining power in the region. If North Korea opens up to Google searches, think how bad it would make China look. Since North Korea is smaller and more volatile, change can potentially happen there faster. If there is a power shift or change in policy, the guy running IT isn't necessarily out of power as well - so it doesn't hurt to have him advocating your position.

willscott··on Will Google+ Ever Get A Full Read/Write API?
Google has indicated that writing will be provided through a history api: https://developers.google.com/+/history/

History sources can be set to default to public, and will show up on a user's profile when that happens (like +1's do today) - but they won't show up in other peoples feeds unless the user explicitly shares the moment within G+.

willscott··on Websites Vary Prices, Deals Based on Users' Information
There was an academic paper on this published in the fall by Telefonica in Spain: http://conferences.sigcomm.org/hotnets/2012/papers/hotnets12...

Abstract:

  Price discrimination, setting the price of a given product
  for each customer individually according to his valuation
  for it, can benefit from extensive information collected
  online on the customers and thus contribute to the
  profitability of e-commerce services. Another way to
  discriminate among customers with different willingness to
  pay is to steer them towards different sets of products
  when they search within a product category (i.e., search
  discrimination). Our main contribution in this paper is to
  empirically demonstrate the existence of signs of both
  price and search discrimination on the Internet, and to
  uncover the information vectors used to facilitate them.
  Supported by our findings, we outline the design of a
  large-scale, distributed watchdog system that allows users
  to detect discriminatory practices.
The paper only has preliminary results (hotnets targets fairly early ideas), but so far has only detected discrimination based on location and search terms.
willscott··on Chrome extension for end-to-end email encryption
There have been several attempts at chrome extensions. (example: https://github.com/Mononofu/CryptoChrome)

It seems pretty clear that the issue is that both sides need to buy into a solution for it to work. How are you going to verify the other sides identity so that you can encrypt for them in a useful, but unobtrusive way?

willscott··on I’m writing my own OS
There are a bunch of teaching OSes which are a great place to start for this stuff.

The actively developed ones we chose between when teaching the OS class at UW this fall were:

JOS (mit) https://github.com/guanqun/mit-jos

Pintos (stanford) http://www.stanford.edu/class/cs140/projects/

OS161 (harvard) http://www.eecs.harvard.edu/~syrah/os161/

willscott··on Pixelhead - the ultimate in anonymous?
The artist's page: http://www.martinbackes.com/pixelhead-limited-edition/

He sells them for 158 euro.

It's also worth looking at CV Dazzle if you find this interesting. It looks at ways to beat current face detection mechanisms while not looking like that's your only intention: http://cvdazzle.com/

willscott··on PGP for Gmail
A similar project hooks up GPG and Gmail: https://github.com/Mononofu/CryptoChrome
willscott··on "Do Not Track" HTTP header supported by IE, Opera, FF, Safari but not Chrome
I still haven't heard a cogent explanation of what this is supposed to do.

"Do Not Track" sounds nice, but seems no easier to scope than the initial problem of excessive information collection. I think it's safe to say that I want companies to 'track' me in order to keep me logged in for a session. Likewise, I hope that my bank keeps logs of visitors, so that it can respond to abuse / hacking attempts. Is this aimed only at behavioral advertising, or is it meant to have a broader scope?

It seems like the technical execution is almost misguided without having the policy discussion first and figuring out what it is we disagree with. Without that, I don't feel like this is going to draw a strong enough line to separate people abusing tracking from the legitimate uses.

willscott··on Chrome supports TCP & UDP sockets
It's worth noting that while this is becoming available in chrome now, the WebRTC APIs that both Chrome and Firefox are working on (and will likely start showing up in the 3-6 month time frame) is also likely to provide p2p message passing support.

There's a group of people beginning work on porting some of the traditional p2p constructs like DHTs into the browser, for those interested: http://joincollage.com/webp2p

willscott··on Google Reader API? Does It Exist?
what are you trying to do with the api?

RSS is a consumable format directly, and reader does export a (user-private) combined atom feed.

willscott··on Google Drive SDK
It seems like a better candidate for a linux FUSE client would be the existing document list API. It works with oauth, and lets you interact with documents.

The Drive API is a way to integrate new editor types into google docs.

willscott··on Idea: keep clientside js in localStorage
Why would this be preferable to an application cache manifest?

http://www.html5rocks.com/en/tutorials/appcache/beginner/

← PreviousPage 2 of 4Next →