HNHacker News
TopNewBestAskShowJobs

zxcvgm

784 karma · joined April 3, 2012

occasional thoughts and project write-ups at irq5.io
submissionscomments
zxcvgm··on “I just chose words carefully”
I sometimes use abbreviations like wd/ht. Should be understood with surrounding context.
zxcvgm··on Visopsys: OS maintained by a single developer since 1997
Ahh this OS is small enough that a university professor used it as the basis for his class assignments: write a device driver for it, or a pipe implementation, if I recall correctly. I thought it was pretty genius at the time, and it was certainly quite a challenge for the students too.
zxcvgm··on Power over Ethernet (PoE) basics and beyond
I use the FDMQ8205. It's an old part, a little pricey, but keeps the board footprint low. It also has a sufficiently high UVLO, so it acts like regular diodes during the classification phase and you don't need to factor those in to the Rcls values.
zxcvgm··on Samsung Removes Bootloader Unlocking with One UI 8
Xiaomi apparently have also stopped unlocking their bootloaders, so the "workaround" was to go to an official store and ask them perform a downgrade, and before the staff can relock the bootloader, grab the phone and run:

https://x.com/kobe_koto/status/1949154478298456531

Absolutely hilarious.

zxcvgm··on GTK Krell Monitors
Aahh this brings back memories. I first started out using Linux on my desktop and I found this fancy system monitor that made my desktop look cool. There's a section which displays filesystem usage with a button that allows mounting/unmounting with a click. I used it to mount floppy disks but it wasn't working for me, so I read the source to figure out what was wrong, then emailed Bill to contribute a patch to fix it.

It was one of my first open source contributions, and it was then that I understood the value of open source - being able to read the code, debug and then fix it yourself (and for others).

zxcvgm··on Show HN: Undetectag, track stolen items with AirTag
Probably. Or something like the TPL5110 might actually suffice, purpose-built timer for power gating at 35nA, but only goes up to 2hr at max.
zxcvgm··on Linkwarden: FOSS self-hostable bookmarking with AI-tagging and page archival
Cool, looks like text highlighting is a new addition in 2.10. There aren't any examples in the demo site of this, but can it capture the highlighted text snippets and show them in the link details page? That would help me recall quickly why I saved the link, without opening the original link and re-reading the page. I haven't really seen this in other tools (or maybe I just haven't looked hard enough), except Memex.
zxcvgm··on Apple pulls data protection tool after UK government security row
Well, WhatsApp backups claim they are E2E encrypted, but there’s a flow that uses their HSM for the encryption key, which still feels like some escrow system.

https://engineering.fb.com/2021/09/10/security/whatsapp-e2ee...

zxcvgm··on De-smarting the Marshall Uxbridge
I have the same thoughts about the approach, and I'm actually working (on the back burner) a similar thing. It's a harman kardon "smart" speaker with a similar design where the brains are on a separate daughterboard and that's now fried.

I've already figured out the control signals and have designed a new daugterboard with an ESP32 to drive the I2S output. I just need to figure out how to downmix the audio to mono and to DSP the L/R channels into tweeter/bass outputs, or to find some code already out there that does this. Any help/pointers here would be appreciated!

zxcvgm··on JSON parsers that can accept comments
I’m surprised HuJSON wasn’t mentioned in the list. Tailscale uses it for their config files. I did a hacky workaround by preprocessing my JSON config with regex, but found HuJSON later.

https://github.com/tailscale/hujson

zxcvgm··on EUCLEAK Side-Channel Attack on the YubiKey 5 Series
Yeah. That's what I came here to say too.

Previously when their Yubikey 4's were found to be suceptible to the ROCA vulnerability [0], they issued replacements [1] for any customers who had affected devices. I had a few of those devices and they were replaced for free.

I guess that's a disadvantage of having a non-upgradable firmware. They can't fix these devices that are already out in the field.

[0] https://en.wikipedia.org/wiki/ROCA_vulnerability

[1] https://support.yubico.com/hc/en-us/articles/360021803580-In...

zxcvgm··on How the Totem Compass Works
When I initially watched the demo video, I was wondering how the devices might locate each other. I thought it was using ultra wide band (UWB) like iPhones but now I see it’s just GPS. I’m not sure how many of these events are indoors vs outdoors, but it definitely won’t work indoors. Wonder how they might try to make it work indoors if there’s no additional hardware onboard.
zxcvgm··on The Luckfox Pico Mini B – Linux in a Thumbnail
I think the Luckfox Pico series is the lowest cost ARM-based board you can buy (that runs Linux) at the moment. Even the Pi Zero is $10. Prior to this, it was a board based on the Allwinner F1C100, but I don't think anyone made and sold a dev board except for a DIY business card [0].

[0] https://www.thirtythreeforty.net/posts/2019/12/my-business-c...

zxcvgm··on SSH agent extensions as an arbitrary RPC mechanism
Doesn't look like it, but the author uses the Go SSH agent library [1] which _does_ have some example code there and looks pretty straightforward, based on what was described in the post.

[1] https://pkg.go.dev/golang.org/x/crypto/ssh/agent

zxcvgm··on LPCAMM2 is a modular, repairable, upgradeable memory standard for laptops
I remember when Dell was the first to introduce [1] these Compression Attached Memory Modules in their laptops in an attempt to move away from soldered-on RAM. Glad this is now being more widely adopted and standardized.

[1] https://www.pcworld.com/article/693366/dell-defends-its-cont...

zxcvgm··on Google is feeling pretty pumped about a new way of showing you ads on YouTube
This sounds like what Roku had patented, except it injects ads when it detects that a HDMI-connected device has paused: https://www.theregister.com/2024/04/17/roku_tv_ad_patent/
zxcvgm··on Server-side sandboxing: Containers and seccomp
It's pretty easy to apply seccomp to a process using systemd by adding SystemCallFilter= in its unit file. There's a reasonable set of permitted syscalls for general system processes, aptly called `@system-service`, but you can tweak that to suit your needs [1]. I generally use this, among other settings, to further lock down system services [2].

[1] https://www.freedesktop.org/software/systemd/man/latest/syst...

[2] https://www.redhat.com/sysadmin/mastering-systemd

zxcvgm··on Raspberry Pi 5
Interestingly the Pi 5 has moved most I/O like Ethernet, USB, MIPI and GPIO into a custom I/O controller chip called the RP1. It talks to the main CPU over 4-lane PCIe. They also have a custom PMIC (Dialog DA9091) with a built-in RTC and support for external backup battery. Everything else seems pretty standard.
zxcvgm··on iPhone 15 and iPhone 15 Plus
It is available on Windows too, in iTunes. You need to connect the cable once to enable it. I’m using this to sync my music and backup my iPhone.
zxcvgm··on System76 Open Firmware
I'm impressed to see this paragraph in the README:

> System76 customers may request board schematics for their system by sending an email to firmware@system76.com with the subject line "Schematics for model", where model is one of the supported models listed above.

> Please include the serial number of your system for verification.

This means that you can actually troubleshoot and repair the board yourself, if you're so inclined.

zxcvgm··on Drag and Drop from Terminal
I usually use “start .” on Windows to achieve the same.
zxcvgm··on Making unphishable 2FA phishable
I guess this is what Heroku was pushing for [1] when client tokens were leaked. They wanted GitHub to adopt RFC 8075 [2], that combines mutual TLS auth with the tokens, so that the tokens can only be used by authorized clients, not just anyone that had possession of the tokens.

[1] https://blog.heroku.com/april-2022-incident-review

[2] https://datatracker.ietf.org/doc/html/rfc8705

zxcvgm··on The Hummingbird Clock: date videos by background mains hum
Tom Scott did a video about this topic in 2021: https://www.youtube.com/watch?v=e0elNU0iOMY
zxcvgm··on Apple’s Killing the Password. Here’s Everything You Need to Know
The passkeys are only synced across Apple devices, via iCloud keychain. Trying to sign in on another device (e.g. Windows laptop, Android phone) will require scanning a QR code. The devices then establish a secure channel using FIDO caBLE v2 (introduced by Google/Chrome, I believe) to perform the authentication. This ensures the passkeys never leave your Apple device, but can still be used on other devices.

You can see the sign-in user experience here, when they use a non-Apple device: https://developer.apple.com/videos/play/wwdc2022/10092/

zxcvgm··on Our screwdriver took three years [video]
Not an apples-to-apples comparison, but I just wanted to see the price positioning for this screwdriver. It goes for $69.99 [0] and Megapro ratcheting screwdrivers (which they mentioned in their video) goes from ~$50 to $59.99, depending on what bits it comes with.

[0] https://www.lttstore.com/products/screwdriver

[1] https://megaprotools.com/collections/ratcheting-drivers

zxcvgm··on Google declined to review an extension because they can’t find a Kindle to test
For context, his next tweet [0] in the thread was:

> But for an extension (with the exact same functionality) from a Big Corp, they magically found a way to test it

> https://chrome.google.com/webstore/detail/send-to-kindle-for...

[0] https://twitter.com/daniel_nguyenx/status/155516779079696793...

zxcvgm··on Apple Passkey
This is based on the open standards WebAuthn and FIDO2, where the credentials (“passkeys”) are synced via iCloud Keychain. Currently you need remember to register at least 2 security keys, in case one is lost/misplaced. The syncing of passkeys in iCloud solves this backup problem.

https://fidoalliance.org/apple-google-and-microsoft-commit-t...

zxcvgm··on My Unholy Battle with a Rock64
I have a Rock64 and I don't remember it being that difficult to setup. Maybe I was just using it as a headless machine, but to get a working Linux install shouldn't have been this hard.

I typically use Arch Linux because it's very barebones, and Arch Linux ARM has a working setup [0] for the Rock64. You do need to write various parts like U-Boot bootloader onto the SD card manually, but everything has been pre-compiled. If you prefer an image that you can directly flash onto an SD card like Raspbian, then maybe you can try Armbian [1].

These should get you a working Linux install rather quickly, bringing you to up to the "sixth circle" as written by the author.

[0] https://archlinuxarm.org/platforms/armv8/rockchip/rock64#ins...

[1] https://www.armbian.com/rock64/

zxcvgm··on Home Made TPM2.0 Module
It depends on how the TPM is being used by the OS and its apps. If it’s purely being used for the crypto key storage and crypto operations, then you can probably use something like the MS reference implementation [0]. If the OS requires attestation and endorsement, there is a manufacturer key pair that is embedded into the chip that you can use to attest and verify that the TPM you are interacting with is indeed from a particular manufacturer. That aspect would not be doable for an emulated DIY TPM.

[0] https://github.com/microsoft/ms-tpm-20-ref

zxcvgm··on Melting KiCad
The author has also made a video about it recently: https://www.youtube.com/watch?v=euJgtLcWWyo

It reminds me of Boldport, who made project kits that were also works of art [0]. The funky PCB traces and shapes were all hand-drawn, I believe, rather than drawn up in a regular EDA program.

[0] https://boldport.com/shop?category=Soldering+projects

Page 1 of 4Next →