HNHacker News
TopNewBestAskShowJobs

znep

222 karma · joined May 31, 2013

submissionscomments
znep··on Starlink User Terminal Teardown
I wonder who would be best equipped to see if any of those keys are traceable to individuals involved in special government affairs lately? There have been some good leaks...
znep··on Researchers confirm what we already knew: Google results are getting worse
Users and (at least before the last run through the meat grinder) moderators.
znep··on Threads, an Instagram app
Does anyone have any insight into if this a respin of the same Threads app from 2019 or just the same name? https://www.androidpolice.com/2019/10/03/threads-instagram-f...
znep··on Tell HN: Messages from Another Azure Customer Are Appearing in My Queue
That doesn't make any sense technically and sounds a lot like victim blaming.

It is far from certain that any application has such a "steady state", most of the ones I've worked on sure don't. There are obviously ways to analyze things and correlate enqueued and dequeues, but it is far from as simple and black and white as you suggest, especially with truly distributed systems and unknown cause of the reported behavior.

Heck, we don't even know if the messages are being "dropped" or just duplicated.

znep··on Specs of Inexpensive 2023 Amazon Fire HD 10 Tablet Leaked: NFC and GPS
Generally somewhere between terrible and non-existent if you stick with Fire OS. They will drop occasional small patch releases with broken links to non-existent release notes.
znep··on Justice Department says Google destroyed evidence related to antitrust lawsuit
True, now they are just used against you in the press when they get released one way or another, legally or not.

Then, the entire point for some lawsuits existing is to set the stage for that information to come out for no good legal reason.

You can think of it as legal hacking.

I regret writing that last sentence.

znep··on Justice Department says Google destroyed evidence related to antitrust lawsuit
Even Google can't solve all the downsides of things being in the cloud.
znep··on HP bricking printers remotely if the client's credit card expires [video]
Or they at least want you to think that.
znep··on Does the Tank Have a Future?
Indeed. I am sure there are lots of things under development, I have little knowledge in the area but I ran across this video the other day which suggests refueling and rearming via drone: https://www.youtube.com/watch?v=hNLCa6isqJA

No idea how far between concept and reality that is and obviously this is a whole different class of vehicle than a tank.

znep··on Dokku – Free Heroku Alternative
Not any more. https://aws.amazon.com/about-aws/whats-new/2022/03/amazon-ec... In theory. But yes, sometimes detaching resources can take a long time on a degraded host.
znep··on Psychic Signatures in Java
Spring4Shell is entirely a flaw in Spring, however is somewhat understandable because it was only exploitable due to a new feature in Java (modules) that added new methods to java.lang.Class, which is a very significant change. You could argue the very existence and nature of Java object serialization deserves blame as well, but that gets nuanced quickly.

Modules are also part of the reason why so many folks got "stuck" on java 8.

It is definitely an interesting study in the challenges of trying to make advances in a platform when a lot of the ecosystem is very much in maintenance mode and may not have a lot of eyes on the combination of existing libraries vs new versions of Java.

znep··on Spring Core on JDK9 is vulnerable to remote code execution
Ahh, your comment is the first one that made it clear why this is only in 9 and later, because it was actually "introduced" by the introduction of modules in Java 9. That added https://docs.oracle.com/javase/9/docs/api/java/lang/Class.ht... to java.lang.Class.

It looks like the Spring code, when written, did properly filter out existing unsafe methods in java.lang.Class deliberately. Obviously not in a defensive enough way to avoid this, but adding methods to java.lang.Class is a very rare event.

znep··on OpenSSL security advisory: Infinite loop reachable when parsing certificates
I'm not sure what they are using right now, but they currently have the "AWS-LC Cryptographic Module" listed as being in process for validation which may be sufficient for s2n.

I know there are other AWS features/services that are lined up behind that validation for FIPS support.

znep··on Postgres Auditing in 150 lines of SQL
For even more fun, try "SELECT pg_cancel_backend(pid) from pg_stat_activity".

(DON'T ACTUALLY DO THIS on anything other than a personal test db as it will kill all the connections it has permission to kill)

Related, postgres has a number of different volatility options for functions so you can declare if there are side effects: https://www.postgresql.org/docs/14/xfunc-volatility.html These can become very important in some cases to let the optimizer have the freedom to shine.

znep··on Twitter misses ad revenue and user growth estimates
...and almost every time I end up on a mobile link to a tweet in a web browser I have to refresh the page to get anything but an error. Which has been going on for years, or at least seems like it.
znep··on Roblox October Outage Postmortem
This is very true, the costs and performance impacts can be significant if your architecture isn't designed to account for it. And sometimes even if it is.

In addition, unless you can cleanly survive an AZ going down, which can take a bunch more work in some cases, then being multi-AZ can actually reduce your availability by giving more things to fail.

AZs are a powerful tool but are not a no-brainer for applications at scale that are not designed for them, it is literally spreading your workload across multiple nearby data centers with a bit (or a lot) more tooling and services to help than if you were doing it in your own data centers.

znep··on Ask HN: How did my LastPass master password get leaked?
That is concerning and directly contradicts the docs:

"You can revert to your previous master password only if the change had taken place within the last 30 days."

I guess it is possible it is another UX issue and would fail if you tried, but that still isn't very reassuring.

znep··on Ask HN: How did my LastPass master password get leaked?
One other thing to note is that by default lastpass allows reverting to your previous password for 30(?) days. The option is in account settings -> advanced -> "Allow master password changes to be reverted".

To be safe you would probably want to disable that then change your password again. Just don't lose your new password as you then can't revert.

See https://support.logmeininc.com/lastpass/help/recover-your-lo...

znep··on Log4Shell update: second Log4j vulnerability published
Exactly. eg. https://github.com/frohoff/ysoserial#usage

Note the classes aren't at fault or doing anything wrong (even though you could imagine other mitigations they could use), they are just conveniently there to use if you have a vulnerability that lets you de-serialize untrusted data.

znep··on Log4j RCE Found
While the specific exploit may not be possible in 8u191 and later, I am not convinced they are safe from all RCEs using this vulnerability. It does make it harder to exploit, and hit or miss depending on what is available in the classpath.

See https://www.veracode.com/blog/research/exploiting-jndi-injec...

znep··on Log4j RCE Found
Yes, you can specify a port.
znep··on Common Infrastructure Errors I've Made
Interesting example given you can no longer do that with the latest (v2) version of the AWS CLI, since it isn't published to PyPI due to how big of a nightmare AWS found supporting that to be.

There is a very nice comment talking through some of the reasoning here that is worth a read: https://github.com/aws/aws-cli/issues/4947#issuecomment-5860...

I am quite annoyed v2 isn't in PyPI as it makes updating to v2 a sizable project in some cases and v1 does not support all services, but also quite understand their reasoning.

Granted the tradeoffs may be weigh out differently for an internal tool as the post describes, or if distributing the tool to a more constrained audience.

znep··on An early look at Postgres 14: Performance and monitoring Improvements
I agree this is a great addition, but FWIW it isn't normal for ^C to not work in psql. Perhaps you are using some other client that doesn't support aborting queries properly, or have something on the network between you and the server behaving poorly and dropping connections?
znep··on Amazon S3 Object Lambda
No, Athena is built on Presto as AWS documents in numerous places. eg. https://aws.amazon.com/big-data/what-is-presto/
znep··on Don't trust default timeouts
That isn't due to a missing timeout, that is due to not properly communicating aborted requests down the stack which, admittedly, isn't always easy and some clients/languages/etc. are very bad at. A hardcoded timeout, while a fine workaround in some applications, is not a good default and not the proper fix for that.

Default timeouts in the database layers are hidden time bombs that turn operations that just legitimately take a bit longer than some value the library author set that you didn't even know existed into failures that get retried over and over causing even more load than just doing the thing once. Don't get me wrong there are lots of uses for setting strict timeouts and being able to do so is very important, but as a default no thanks.

znep··on Ask HN: What website, from your early days on the net, do you miss?
Ahh Silicon Investor. Powered by MS SQL Server stored procedures that essentially returned the entire HTML page. Real fast. Real hard to maintain.
znep··on What happens to Google Maps when tectonic plates move?
Yes, in the US (and presumably some other countries, I don't know of any offhand).

Many other countries such as Canada use Lowest Astronomical Tide. The difference is actually important to know at times when boating between the countries.

See https://en.wikipedia.org/wiki/Chart_datum#Choice_of_tidal_ph...

znep··on Using Bash to Automate Rubocop Fixes
rubocop is so over the top in pendantics that writing any ruby code that gets nit picked by it is so painful that it makes more sense to just switch languages.
znep··on Java's URL.equals() Performs DNS Resolution
I might be wrong, it was a long time ago, but IIRC a different DNS rebinding attack was actually part of the reason this behavior was introduced to the URL class, to help protect against such attacks in Java Applets.
znep··on Generating a Java program with 90% less code
TL;DR - "Here is a lot of boilerplate code that doesn't seem necessary for what you are doing in this case..."

...

"Hey look another tool that can generate a lot of boilerplate code you then have to deal with and makes the easy stuff easier and the hard stuff almost impossible!"

Page 1 of 3Next →