HNHacker News
TopNewBestAskShowJobs

yetfeo

108 karma · joined December 23, 2013

submissionscomments
yetfeo··on R beats Python, R beats Julia, Anyone else wanna challenge R?
The way I speak and the way I write are different. Avoiding slang like 'wanna' when writing is good.
yetfeo··on R beats Python, R beats Julia, Anyone else wanna challenge R?
This is a pet peeve of mine but...is 'wanna' a commonly used word in the USA? It grates whenever I read it as it's rarely used where I am.
yetfeo··on The next version of DuckDuckGo
As I mention in a previous comment, if you are using the TOR hidden service (3g2upl4pq6kufc4m.onion/) the redirect goes over a TOR exit node without https. Ideally it should use the hidden service so no exit node is involved, or at the least use HTTPS.
yetfeo··on The next version of DuckDuckGo
One thing that would be nice to fix in the new interface:

If I use the DDG TOR hidden service, 3g2upl4pq6kufc4m.onion, do a search and click on a search result the link goes via a DDG redirect from r.duckduckgo.com. This should be using the hidden service domain, not the duckduckgo.com domain. As it is the redirect goes over a tor exit node rather than directly via the hidden service.

yetfeo··on Announcing ClearCrypt: a new transport encryption library
It would be nice if some of the items in the pre-commit checklist from [1] could be checked at compile time somehow.

[1] https://github.com/clearcrypt/clearcrypt/pull/3#issue-327877...

yetfeo··on Announcing ClearCrypt: a new transport encryption library
> Emphasis will be placed on simplicity, clarity, and audibility.

Most projects start with this as an implicit goal. Unfortunately they tend to grow out of control as the code base gets larger.

yetfeo··on The Nix project – Atomic upgrades, rollbacks and multi-user package management
Nix has a number of nice things going for it.

You can have multiple different versions of packages installed and other packages can depend on the different versions. The management of the 'shared library hell' is done behind the scenes using symbolic links in a GNU Stow like manner.

You can create 'environments' that are collections of installed packages and switch between them so tools needed for one task don't pollute the namespace for other tasks. For example, I create an environment for working on Firefox. It uses specific GCC versions and libraries. Only that environment sees them. I then switch to another environment when working on another project which uses clang - that environment can't see the library versions from the firefox environment, etc.

You can build package from source or download from a binary cache. You can modify configure flags and other build settings and the correct packages will rebuild - or download from cache if they are built with the same flags.

It installs easily on top of other Linux distros.

yetfeo··on The Nix project – Atomic upgrades, rollbacks and multi-user package management
Do you have any tips on managing a nixpkgs clone vs using channels? How do you set it up to default to your clone for example?
yetfeo··on Duktape: an embeddable JavaScript engine
I wouldn't describe JavaScript's OOP as bolted on. It's just a different kind of OOP - prototype based rather than class based. You could argue that Lua is more "bolted on OOP" since there are quite a few different libraries that build OOP for it.
yetfeo··on Frozen Funds
As long as you hold the private keys yourself and don't keep them on third party websites your holdings are safe. Safer than cash since you can encrypt and back up the keys.
yetfeo··on Frozen Funds
Exchanges usually charge a withdrawal fee to cover transaction fees. BTC-e also charge a fee for example. Bitcoin software doesn't provide (an easy if possible at all) means to compute the fee up front to pass on to the receiver. So exchanges charge a fee that to cover the average cost per transaction.
yetfeo··on Frozen Funds
Wouldn't multisig on an exchange prevent the use of cold wallets? It wouldn't be possible to move funds to/from hot and cold without a signature from the depositor.

It would also make trades a little more difficult in that users that are slow in signing off a transaction slows the trade down. The buyer has to wait until the seller has performed an action. Could you DoS an exchange with multiple buy/sells that you don't release?

yetfeo··on Frozen Funds
At the time bitcoin wasn't worth so much so trading out might have been more reasonable. The large increase in price has made the debt much more significant.

It's unfortunate that those that have deposited since then have subsidised those that withdrew after the hacks.

yetfeo··on Mt. Gox's Bitcoins are being sold on Bitstamp?
blockchain.info has a method of tainting and tracking coins:

https://blockchain.info/tags?form_type=1

Taint is viewable using "Related tags" and "Taint Analysis" on address pages.

yetfeo··on The Neo900 project is still alive and steadily progressing
The Geeksphone Revolution could be an interesting choice. Comes with Android pre-rooted installed with menu options to install other ROM's including Mozilla's Boot to Gecko as a supported option. You could run the latter with the Mozilla open source RIL implementation if you're concerned about that. I do like the hardware keyboard on the N900/Neo900 though.
yetfeo··on Mozilla's New Multi-Core Browser and the Open Source Language That Powers It
It might not be a goal for Mozilla for it to be a production browser but it does seem to be for other people working on it and this is affecting what is being worked on:

https://groups.google.com/d/msg/mozilla.dev.servo/-dmlVwMknJ...

yetfeo··on Firefox OS 1.3
Trunk builds of Firefox OS (version 1.4ish) work fine on my ZTE Open. I doubt they'll see consumer release though. I hope they do but I'm not confident in carriers pushing it.
yetfeo··on GnuTLS certificate verification vulnerability announced (CVE-2014-0092)
Mercury is used in production with PrinceXML [1] and ODASE [2]. ATS is used in production in the implementation of a bitcoin mining pool [3]. OCaml is heavily used by Jane St [4]. SML (via the MLton implementation) is used in industry [5]. Rust is not ready for production, I agree, but is being used to develop Servo by Mozilla and Samsung [6].

That said I'd hope that systems like ATS, Mercury, MLTon and OCaml being open source make it easier to contribute to the implementation for issues that come up and this would offset any 'not enough real world' problems that they have. If you don't like those languages, pick another (eg. Haskell).

[1] http://en.wikipedia.org/wiki/Prince_XML

[2] http://www.missioncriticalit.com/technology.html

[3] http://mmpool.bitparking.com/pool

[4] https://blogs.janestreet.com/category/ocaml/

[5] http://mlton.org/Users

[6] https://blog.mozilla.org/blog/2013/04/03/mozilla-and-samsung...

yetfeo··on GnuTLS certificate verification vulnerability announced (CVE-2014-0092)
> IMO, C is no longer suitable as a systems programming language.

Neither is C++. People writing new systems level code should seriously consider safer languages. ATS, Rust, Mercury, OCaml, SML, and many others.

yetfeo··on Reddit to Give 10% of Its 2014 Ad Revenue to Non-Profits Picked by Its Users
I agree but Flattr does provide an interesting approach. With them you set aside a set amount per month you want to donate. Then when you tip a site it gets a proportion of that amount based on the number of tips you made in the month. This way you cap your total spend per month. You could do this manually of course. Maybe sites could start a system of including a bitcoin address in a file at a common location in the URL space.
yetfeo··on Reddit to Give 10% of Its 2014 Ad Revenue to Non-Profits Picked by Its Users
Does Flattr do what you want with regards to enabling tipping small amounts to a website?
yetfeo··on Bitcoin mining the hard way: the algorithms, protocols, and bytes
GHash.io and BTC Guild own >50% between them though: http://blockorigin.pfoe.be/top.php

Eligius have some mining rules which one could regard as not acting in good faith (rejecting gambling site transactions, etc) depending on your point of view. This can prevent some from using them and limits their hashrate somewhat.

If you look at the top pools list compared to 6 months ago that landscape has changed quite a bit. The pools outside of the top 5 have less market share and there are less pools. Mining power is slowly centralizing: https://web.archive.org/web/20130215040845/http://blockorigi...

yetfeo··on Do you trust the Bitcoin Foundation?
The question is not "Do you trust bitcoin", it's "Do you trust the Bitcoin Foundation". The latter is an organization set up recently and is not involved with the original bitcoin creator.
yetfeo··on Don’t Use Mozilla Persona to Secure High-Value Data
Now that Firefox Accounts is being used in Mozilla properties rather than Persona I'd expect more downplaying of Persona to come from Mozilla, including employees like OP. Is Persona still being developed at Mozilla?
yetfeo··on Bitcoin Exchanges Under ‘Massive and Concerted Attack’
Unfortunately it does not fail completely safely. The change transaction seems to still be available for coin selection and causes sends to fail. The getbalance command shows an incorrect balance due to counting the change address twice - once in the double spend and once in the accepted. The accounts system also has balances messed up which some merchant sites rely on.

It is not "lose money" exploitable (unless combined with social engineering) but is definitely "lose time, lose effort" exploitable.

yetfeo··on Bitcoin withdrawal processing suspended
It depends. There's a small issue with the reference client that is also causing chains of double spent transactions in merchant wallets: http://www.reddit.com/r/Bitcoin/comments/1xm49o/due_to_activ...

I would be more inclined to believe that the majority of sites use the reference client and this is why issues are appearing.

yetfeo··on Bitcoin withdrawal processing suspended
This is not true. It does not handle malleability in one case. See http://www.reddit.com/r/Bitcoin/comments/1xm49o/due_to_activ...

This is why many sites are having issues. It is in fact a problem with the reference client.

yetfeo··on Bitcoin Exchanges Under ‘Massive and Concerted Attack’
The reason why exchanges and other software are having trouble with malleable transactions is not due to bad software using transaction ids. It's an edge case with the reference bitcoin client. See: http://www.reddit.com/r/Bitcoin/comments/1xm49o/due_to_activ...

Basically the reference client allows an edge case where it allows spending an unconfirmed output if that output was generated by the wallet itself as change. This can form a chain of unconfirmed transactions. When the malleable bot modifies the original one they all become invalid. The reference client does not handle this case well, it gets balances wrong, and clogs the wallet up.

It's unfortunate that Mt Gox got a lot of heat for calling out the issue from the foundation and core developers saying that malleability was known and wasn't a bit issue. in fact it is an issue due to this edge case in the reference client.

yetfeo··on Bitcoin Exchanges Under ‘Massive and Concerted Attack’
> It's a non-issue in so far as it does not prevent bitcoin from working as it should if you do implement things as the original client does it

This is not correct. The original client gets one edge case wrong and it is this that is causing the issue with most of the exchanges that use it: http://www.reddit.com/r/Bitcoin/comments/1xm49o/due_to_activ...

yetfeo··on Bitcoin Exchanges Under ‘Massive and Concerted Attack’
It is not poorly coded exchanges that are causing the issue. It's actually an issue with the reference bitcoin client and those that use the same behaviour: http://www.reddit.com/r/Bitcoin/comments/1xm49o/due_to_activ...

Spending unconfirmed outputs in the presence of malleable transactions is unsafe. The reference client allows spending unconfirmed change outputs as they used to be considered safe. But if the original transactions is modified then the chain of unconfirmed transactions becomes double spent and the reference client gets confused about balances.

Page 1 of 2Next →