HNHacker News
TopNewBestAskShowJobs

zwp

601 karma · joined March 24, 2011

submissionscomments
zwp··on Confident Code
> can't make a Ruby object falsy

You can override ! (see http://www.rubyinside.com/rubys-unary-operators-and-how-to-r... from earlier this week) so !!obj can evaluate to false. But there is still this to solve:

    ruby-1.9.3-p0 :008 > obj ? true : false
     => true 
    ruby-1.9.3-p0 :009 > 
If only there was a #to_bool to override...

(For the record: yuck).

zwp··on 65k Open TCP Ports

    getent services 79
(Advantage is that getent will follow your nsswitch.conf configuration to find your actual service database).
zwp··on What is your favourite C programming trick?
It's to stop lint(1) complaining that you're not checking the return value from printf().

I see you're an old-timer here but maybe you missed out on lint: http://en.wikipedia.org/wiki/Lint_(software)

That page says it dates from the late seventies; I was still using it mid-nineties. I don't remember the last time that I linted but today Ubuntu is lint-unaware. These days the compiler will pick up most of the things that lint used to.

zwp··on Ayende posts a job applicant's crappy code
http://codereview.stackexchange.com/

http://refactormycode.com/

zwp··on Ask HN: Has anybody here ever successfully started a videogame company?
I apologize for the slightly tangential response but your post merits more than a POU (Plain Old Upvote).

30 years ago a C64 was My First Computer, a birthday present. Llamasoft's Attack of the Mutant Camels was my first game, swiftly followed by the insanely fast Gridrunner.

I cut my teeth on Commodore v2 BASIC and 6502 assembler. I turned down an early teens New Year's party (girls and everything...) to hack on an assembler monitor from Y64 magazine.

And I don't regret it.

Recognizing by chance something better in a local computer store I bought a copy of the Zeus assembler. The proprietor warned me "You know this isn't a game, right?".

I welded dodgy hardware into the underpowered expansion port, using telco engineer Dad's overpowered soldering gear. Despite the cost of the thing, nobody questioned that I might break it. A gift truly given.

I still have my copy of the C64 Programmer's Reference Guide (on the shelf behind me, next to Dad's copy of the KDF9 Algol Reference). I still have the 6502 opcodes in my head (LDA $A9). I'm saddened by the fact that I stupidly gave away my C64 many years ago. I'd love to see again the awful software that I wrote (transliterated from "Numerical Recipes") to help me with my high school physics homework :)

And I'd really like to see some pro code from that time.

> Sign up at www.yakyak.org

Done! Hard to quantify how much effect these guys' work has had on my life but it's certainly non-negligible. Hack on :)

/now playing: Rat's Monty Mole theme tune

zwp··on “C#, it’s just not portable”
That's interesting. Why do you do this?
zwp··on Introducing Bitcoinica API (The first RESTful Bitcoin Trading API)
I like the way the API allows us to see how much business your site is doing.
zwp··on Life on the Command Line
"It's all text!", https://addons.mozilla.org/en-US/firefox/addon/its-all-text/
zwp··on Designing command-line interfaces
Also tedious:

    $ ls -Q
    ls: illegal option -- Q
    usage: ls -aAbBcCdeEfFghHiklLmnopqrRsStuUwxvV1@/[c | v]%[atime | crtime | ctime | mtime | all] [files]
It's succinct but that second line is almost completely useless.
zwp··on Why God Hates German Words
As I said in my first post this particular example seemed so stridently wrong that I thought I'd missed something, that there was a level of irony in the article that apparently doesn't exist.

> "locate" rather than "find"

As it happens... I disagree this example is any better. To locate is to "discover the position" of something; to find is to "meet with or discover by chance" (that's my emphasis, but both are primary definitions from Collins English).

Could be it's just hard to meaningfully extrapolate those class-based connotations forwards 1000 years in an enjoyable pop-sci article.

zwp··on Why God Hates German Words
This was indeed my interpretation. I read this (second clause) as a linear chronology:

"Old english smeortan; related to Old High German smerzan, Latin mordere to bite, Greek smerdnos terrible"

Thank you for the correction.

zwp··on Why God Hates German Words
Yes! Thank you. Exactly (was later than I thought).

http://www.mtholyoke.edu/acad/intrel/orwell46.htm

"Bad writers, and especially scientific, political, and sociological writers, are nearly always haunted by the notion that Latin or Greek words are grander than Saxon ones..."

zwp··on Why God Hates German Words
Hello!

I like the hypothesis, I'm sure there must be some research on this.

There is a writing style guide written by a well-known English author, Victorian era, that suggests using saxon over romance words for clarity. I feel this is valid (also more concise, more punchy (more consonants)). I thought it was Kipling but perhaps not... somebody help me out?

zwp··on Why God Hates German Words
I enjoyed this article although I suspect its factual veracity (oops, err, truth).

For one thing LEOs don't say "individual" because they're romance language kowtowers but rather because it's an instance of the largest valid superclass of man/child/woman/girl/boy/teenager/infant/...

Similarly, it's not "Sir, please get out of the Porsche 911" but "Sir, please get out of the vehicle". "Vehicle" is factually correct whatever the beliefs of the other party ("this is not just a car!").

Perhaps I'm not smart enough to catch all of the nuances in the article. For example the very first sentence's "grandmother" is splendidly etymologically ambiguous (grossmutter/grandmere), is this intentional?

Similarly "smart" (allegedly dumb German word) is derived via German smerzan, Latin mordere, Greek smerdnos (according to my dictionary).

zwp··on Every language fixes something - a DiGraph - just for fun
> way to return a list of four arguments from a method

p, q, r, s = * method_that_returns_array_of_4_things

* aka "splat operator"

zwp··on Ruxum: Wall Street-Level Security Comes to Bitcoin
> They have an XSS

Oh dear.

The (short) audio clips on their site are... interesting. Trust Guard's emphasis/value appears to be sales conversions, not security per se.

https://www.trust-guard.com/category-s/3.htm

First sentences from the two co-founders:

"We really really try to help our customers increase their conversion rate"

"People spend a lot of time and a lot of money getting people to their site then they don't do the things that increase conversion"

zwp··on LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census
I understand your point (it is potentially true for more than just the security domain of application development) but I think your premise in this case is false. SQLI (XSS, CSRF, ...) attacks are neither sophisticated nor new. SQLI has been known since at least 1998 (Phrack 54).

SQLI protection at least should be abstracted away from the developer's concerns by use of default parametrized queries. Technical difficulty is not the problem here.

zwp··on Trusted certificate authority Certigna leaks its private key
"a lot of "real" certificates depend on this CA"

How many? did you estimate from sequential serial number allocation?

I am surprised (even if it turns out this is "just" an encrypted webserver key) that they aren't using hardware keys: (a) it's their core business (b) they appear competent (CTO posts to technical mailing lists) (c) they have a /29 so aren't just a single IP on an inaccessible low-end VPS.

ssllabs.com gives them a C rating.

zwp··on How to get shell access with a .htaccess file
Palliative: AllowOverride None

As jerf (+1, great answer), stepping back a little... it has been ~fifteen years since we started noticing problems with htaccess. It filled a niche when webserver configuration was hard and when CRUD admin interfaces were significant work. Htaccess (and friends) should go now. I don't just mean "use the palliative above": I mean any time a remote client can potentially download or overwrite the ACL then the design is probably broken. (Apache is not alone here).

With the myriad of possible use cases and massive deployed base apache is probably stuck with htaccess until extinction. Forever more, we will see this comment in httpd.conf:

    # The following lines prevent .htaccess and .htpasswd
    # files from being viewed by Web clients. 
Security is seldom well served by agile's "simplest thing that could possibly work".

Worse, there is certainly other "best of breed" security stuff that we are doing right now that will be incontestably bad from a future viewpoint. What is that stuff?

zwp··on G8 agenda calls for "civilized Internet": monitored, governed, controlled, taxed
> I've never heard of Windows being compromised via the serial port!

As a point of order: serial port exploits exist for other OSes (Linux, Juniper, Cisco, APC...) and also for windows virtual com ports so whilst probably not trivial it's not entirely infeasible either.

zwp··on Secure your Linux server - HowTo by the NSA
Nessus is probably (still) the best for Linux in this field (certainly in the "free for home use" category): http://www.tenable.com/products/nessus

Lots of vendors have offerings in this area. The quality is ... variable. If you are thinking of getting into this market, then the hard part is not the scanning engine per se. The more difficult parts are:

* Keeping the policy rule set in sync with reality (changing business policy, attack and vulnerability landscape)

* Maintaining the rule set (are DSLs for non-specialists feasible? service model?)

* Interpreting and actioning the results in a timely fashion (eg http://measurablesecurity.mitre.org for some background)

* Intrusiveness (intrusive validation of a test platform requires careful change control -- is test identical to production? intrusive validation of production may lead to shot feet)

* Application, domain-related and physical security (as opposed to system security captured by this document). These things are harder to scan for automatically.

zwp··on Java.next() - Clojure: The Return of the Lispers
Stuart Holloway uses something close to this in one of the presentations at infoq.com. He uses a method from Apache Commons stringUtils as an example of battle-tested enterprise java.

Whether or not that is truly representative of java code is perhaps another question but there is certainly a body of similar accepted code out there eg http://commons.apache.org/lang/api-2.5/src-html/org/apache/c....

zwp··on Show HN: My embeddable C/C++ webserver
Cool.

> only the ones that have been modified by the application code

Sounds good (after a quick skim again I still can't see that but I'll take your word for it!).

I've had two attempts to build and test but unfortunately failed: currently can't build (src/unix/Client.cc:242: error: cannot convert ‘sockaddr_in’ to ‘const sockaddr’) and hello_world.c dumped core on me this time yesterday (Ubuntu 10.10).

"Work in progress" as you say... but it may just scratch an itch. I will come back again in a couple of months :) Thanks.

zwp··on Show HN: My embeddable C/C++ webserver
Bigger potatoes: output sanitization?

Eg only whitespace is trimmed from cookies, then in webserver.Outgoing.cc:

    Socket << "\r\nSet-Cookie: " << Current->Key << "=" << Current->Value;
Lacewing splits input lines on "\r\n" but browsers often happily accept "\n" as a line delimiter (see 19.3 of RFC 2616 for Postel-esque tolerance discussion). So the client can send a request header like:

  Cookie: foo=bar\n<naughty stuff>\r\n
to manipulate the server response, cf "response splitting attack".

This is not discussed in the 37 pages(!) of the new cookie RFC 6265 :-/

zwp··on Show HN: My embeddable C/C++ webserver
No, it will hit the NULL terminator and short circuit.
zwp··on Show HN: My embeddable C/C++ webserver
Small potatoes but this:

        for(char * i = this->URL; *i; ++ i)
        {
            if(i[0] == '.' && i[1] == '.' && (i[2] == '/' || i[2] == '\\'))
misses the case where the double dot is not followed by a slash (eg http://example.com/foo/..). Currently you're almost certainly okay (read(2) will _generally_ (OpenGroup says "implementation specific") return EISDIR) but beware if you should implement a mod_autoindex-alike.

ps. Somebody else said it already but: nice read :)

zwp··on [dead]
> what you mean by "beware the clipboard"

It's not that long ago that certain browsers would give up your clipboard to any site that asked for it.

IE: http://www.securiteam.com/windowsntfocus/5CP0C1F61O.html

Similar (attacks paste), for FF: http://www.digitaltrends.com/computing/firefox-clipboard-hac...

zwp··on [dead]
I avoid browser-integrated password stores.

The attack surface is larger than a standalone app; your browser is a popular (and historically ripe) target; your browser sees lots of untrusted input from third parties; you manipulate sensitive data with your browser.

zwp··on [dead]
Actually Schneier wrote one: http://www.schneier.com/passsafe.html (now OSS)

I use one (actually three) but it's not a good solution for everybody (what is?). Mostly the pros/cons are obvious but two less obvious risks: * Beware the clipboard * Don't forget the vault passphrase...

zwp··on Rails Hotline (live phone help with RoR)
Neat idea.

What do you suggest for non-US volunteers (and callers, although I suspect that is harder to solve, at least for free)?

← PreviousPage 6 of 7Next →