HN user

CodeAndCuffs

624 karma
Posts0
Comments70
View on HN
No posts found.

That doesn't really explain why there is a bunch of GitHub repos created as well.

If I remember correctly from Shai-Hulud 2, the attacker extricated creds by posting them in public github repos with minor easily reversible encryption. I believe it was double b64 last time.

I'm assuming the logic there is that every security researcher and company is going to pull and scan those creds for their stuff and their clients' stuff. So the attacker is just 1 of N people downloading it. As opposed to trying to send it to their own machine directly.

Ive used fp-ts, mainly for Either, Option, and Pipe. I tried out Effect for a new project, and have loved it. The initial hurdle was a little intimidating but I was productive with it within 2 days, and it's paid dividends. It's discord community was surprisingly great, and helped me turn an okay module into an amazing one.

Effect is huge, and does seemingly everything, but it probably does the specific thing you want to do now, with the ability to extend to the other stuff as you need/want

That defeats the entire point of this arrangement, which allows them to investigate in situations where the legal requirements for obtaining a warrant are not met. (Which is the elephant in the room: the entire premise of this system is to bypass established legal thresholds).

This is just 100% false. If im pulling a prescription from a pharmacy its because Doctor Adams told me "I never wrote a prescription for Bill Barnes for percocet, but this state maintained record says that he filled a prescription for percocet at CVS #12345 on main street". That statement alone is enough to get a warrant for said pharmacy records.

Nope. Invading privacy is invading privacy. Just because something is happening today does not make it okay and acceptable

Thats not what I was trying to say. My point was that the state already has this data, and I've already seen it before I get a copy of the data from the pharmacy. If you're concerned about the privacy of the data, you should consider the root issue of warrantless access to the PMP by investigators. Anything I get from the pharmacy is just a piece of paper that says the same thing that I already had from that

Here is a wild idea: we have tjis thing called the internet and this other wild thing called PKI. Give the doctor a certificate pair and they digitally sign every prescription. You don't ever need to talk to the doctor, you just need to pull their public certs.

This is a great idea in theory, but currently has some problems. Some of them probably could and should be addressed, some not.

- Old people who dont want to learn. The PMP lets doctors get a list of every prescription filled in their name in a spreadsheet. You can sort and filter by where it was filled, patient name, type of medication, etc. Of the doctors Ive dealt with, maybe 10% knew about this and used it. A few learned about it from me, got excited, figured it out, and used it to its fullest extent. Most just went "yeah okay" and ignored it because spreadsheets are too complicated.

- Where are we storing this? Can only the doctor do it? From only one computer? Can his receptionist call in the prescription? Can anyone else access that computer? Basically is there any way at all for fraud to happen? What if its the doctor whos the one doing it? Ive seen pharmacists say "Were getting a lot of suspicious prescriptons from this one doctor" who was just flat out selling them to people who had no problems. E-scripts are a thing, and ive seen cases where nurses and receptionists hop onto the system to write illegal scripts.

Since we're doing privacy, give the chumps that need the prescription a cert pair and encrypt their shit

My mom thinks opening chrome dev tools is going to get her arrested for hacking a website. Please dont put the onus of key pair encryption on her in any way

+ make it a crime to store any of their PII at pharmacy level Im not sure if its a legal/regulatory requirement, or just a moral thing, but Pharmacists are highly trained, with a Doctorate in what they do, and they catch things. Whether its a Doctor wrote the wrong script, or a potentially lethal contraindication between meds. Them having records of what else a person is on is a legitimate medical use case. There may be ways to keep this sort of data without PII, but it would be another concern to address.

You omitted the end of my sentence in your quote, which is operative in this case.

My apologies. I've re-added it with an edit note.

I think its a reach to say 'the system' was created to exploit 4th amendment loopholes, especially in this case. Again, the patients privacy isn't compromised by the pharmacies at all here. The state has its claim of a vested interest in prescription activity, much like with drivers licenses and vehicle registration, and has a database of said data, much like with licenses and vehicle registration.

If I start running tags to see where someone lives to stalk them, thats bad, and illegal. If I start running prescription data for someone to see what they're on and stalk them, thats bad and illegal.

If a car dealer says "These VINs on the car dont match, we think something was stolen" we can investigate it by accessing the state database. We will likely see some personal information of someone who isnt guilty of anything in the process of this investigation. If a doctor says "This person filled a prescription under my name that I didnt write" we can investigate it by accessing the state database. We will likely see some personal information of someone who isnt guilty of anything in the process of this investigation.

My assertion here isnt "Everything is fine, change nothing". Its "If you're concerned about privacy here, you are looking at the wrong target". Warrant requirements could be reasonable. Whether we get them or not, I think a good start would be auto-redacting Prescription Monitoring Program reports. If Doctor Adams says Bill filled a fraudulent script, because Adams doesnt write for percocet, I shouldnt see every name for every prescription on Adams' report. That should be redacted. Then if I see a script for percocet, which we've established is fraudulent, we then un-redact the "patient" name.

Again, CVS handing me a copy of a prescription that I already know is fake is the least significant issue at hand.

Now consider states make it illegal to get birth control pills and retroactively go after anyone who has them prescribed. It's according to the law, ain't it?

Are we discussing legality, morality, what should be legal, or what should be moral? I agree that would be bad morally, and shouldn't be legal, and currently isn't. My original comment was regarding how the process currently works, and why. It was also to explain that any concern of privacy regarding prescriptions comes more from the department of health/board of pharmacies than it does from 3rd partys providing documents, as the documents arent invading privacy anymore than what already happens.

The states should keep their noses out of this and in effect all drugs should be made legal.

The whole "your right to swing your fist ends where someones face begins" thing applies here. The problem with some heavier drugs, and their addictive nature, comes in how it effects others. When something is so addictive that a person would sell their own child to acquire more of it, maybe we should limit access to that thing. Ive known a lot of addicts professionally and personally. They come in various degrees of wanting help. Some are in denial, some would do anything to kick the addiction. Some don't care at all and would fight to refuse any help under any circumstance. Its a super complicated issue, "Just legalize all of it", and "Just criminalize and punish all of it" are both equally shortsighted solutions.

we should make it trivially easy to get help I agree 100%

it should be trivially easy for a pharmacy to check if a doctor did indeed prescribe something without raping the privacy of everyone involved

It is, and they do. They call the doctor, he says "I didnt write this". Then he gives me a list of people who filled prescriptions he didnt write. The biggest invasion of privacy of unaffected people is when we have a confirmed suspect, we see what other doctors he filled a prescription for, and then go through that list with the new doctor to see what is and isnt legit.

So yeah, at some point in a table of a few hundred people I probably saw some names of people who were a doctors patient, and that they have a prescription from him. I've been inside their privacy just as much as the receptionist at the doctor's office and the pharmacy tech at the CVS

how normalized the process for violating the 4th Amendment and patients' privacy is.

Well thats the rub, isn't it? Right now the courts don't see this as a violating of the 4th amendment. I can see the argument for requiring a warrant. Im not necessarily against the requirement, but this isn't normalizing a 4th amendment violation any more than license checkpoint (which the courts have also ruled isn't a violation)

[Edited to add the rest of the quote]

Yeah, it could. People can also lie on affidavits for warrants, but it does leave more of a paper trail to catch the guy. Honestly I don't think I'd be against a warrant requirement, but I also think we need a way to speed up the warrant process a _lot_. Right now it often involves a 1 hour + drive to a magistrates office, 30-45 minutes of filling out paperwork by hand, plus the hearing, getting the actual warrant printed+signed+logged, then 1 hour + drive back to where you need to be. I think you'd see less pushback of warrants in general if it leveraged the technology we have. We should absolutely be able to file an affidavit electronically, facetime a magistrate, and get a warrant approved/denied that way.

But again, getting records from the pharmacy isn't really the issue. The government already has the records of the doctor that "wrote" the prescription. All the pharmacy is giving you is the physical copy of the record + data of who picked it up.

I used to work in Drug Diversion investigations, which is basically any time a prescription medication gets used from something other than intended bona fide medical use. Sometimes its doctors selling prescription drugs for non-medical use, sometimes its medical staff stealing.

The biggest thing we covered was prescription fraud. People stealing or forging doctor's prescriptions. Some were more subtle about it. Sometimes you'd see a patient filling a 30mg Oxycodone, 90 count.

Leads would come from either the Doctor, or the pharmacy. 30mg Oxycodone/90 is generally a "You are in massive pain and probably dying" prescription. So when a health 20 something year old walks in and has it filled for themself, it raises some eyebrows. They'd either call the Doctor to verify, who'd call us to investigate, or theyd call us and then we'd call the doctor.

But the state already has access to this information. All prescriptions are logged in the Prescription Monitoring Program, which I believe all states how now. Any Doctor can get a spreadsheet of all prescriptions filled in their name over the last N days, who it was prescribed to, what for, and when. It was an invaluable tool. Doctor Adams tells us he never wrote this prescription for Bill. We lookup Bill and see he has filled similar suspicious prescriptions from Doctor Charles and Doctor Daniels. We talk to Charles and Daniels and they tell us that Bill isnt their patient either. We encourage Charles and Daniels to check their PMP report, and they uncover 4 or 5 more suspicious prescriptions, and we just keep pulling at this thread uncovering more and more.

Of course there is potential for abuse and neglect, but we werent (and couldnt, legally) just go into a pharmacy and ask for random documents, or lookup random names on the PMP. We had to have an initial lead, usually a doctor, or a pharmacist, who saw something suspicious. From there, its just checking state records, verifying what we saw with doctors, and getting paper evidence of the stuff we already knew was false. I had maybe 3 cases where we had a red flag, called the doc, and they doc said "Yeah thats legit" and that was the end of the conversation. I don't need to know why this patient is on this narcotic, I just needed to know if it was a fraudulent. If its not, then thats between the doc and the patient.

State law gave us authority to request pharmacy records, i.e. prescriptions and pickup logs, without a warrant. Most pharmacists did it with no hesitation. A few would want to make sure it wasn't a HIPPA violation (it wasnt) and that it was legal (it was).

Concerningly, I did have a_couple instances where I asked for documents and the employee started to provide them before I had a chance to identify myself.

In summary, if we were to blindly look at someones medical history or records without a bona fide articulable suspicion of a crime, it'd be massively illegal. If we did have a reason to look at the records, its because someone in the medical field saw something suspicious and reported it. From there we were mainly looking at records the government already had, and then finally getting medical records from the pharmacy that was just paper evidence of records we already had.

I mean we can see a demonstrable and quantifiable MASSIVE decrease in meth usage and overdose circa 2005 when the Combat Methamphetamine Epidemic Act went into effect.

Also, it's still available without a prescription, last I checked, it was just behind the counter/required an ID to track if you're grabbing a pack from every Walgreens in a 50 mile radius in a single night

Are you asserting that the caution against shaking babies was intentionally constructed for the sole purpose of the state kidnapping children? For what motivation, to what end? How orchestrated? Who is "the state"? Do they have a hand picked squad of CPS investigators to kidnap children from their targets, or do they just use any CPS investigator? Are the investigators in on it, or are they just thinking they're helping kids? Can you cite references for any of the answers to any of these questions?

Part of the testimony was that there is widespread detection. The claim is that UAPs are often a part of briefings and debriefs. Its also been claimed during the recent UAP related testimonies that a large number of military and civilian pilots have seen stuff, but either had no clear path to report it, reported it and were ignored, or reported and were harassed, or chose to not report it out of fear of harassment.

What does that even mean?! Will this take the Christian path of forgiving our enemies, turning the other cheek, and giving our shirts to people who steal our cloaks?

Is he saying that military AI should specifically target Philistines and the uncircumcised? Will the military AI enslave people but give them the option of freedom or permanent servitude after 7 years?

You can't base something on Judeo-Christian ethics because both the Hebrew bible and new testament are a giant compendium of people disagreeing with G-d and each other on proper ethics.

Fp-ts is one of like, 4 things in life I feel the need to shill for. It's docs are a little rough coming into it for the first time, and I think some of gcanti's tutorials are a little to complex. But I've slipped it into 3 or 4 moderate sized projects. Every time someone goes to touch it there's initial confusion, a 5 minute explanation of Either, 5 minutes of Q and A, and then they love it.

Ok, so I'm not the only one who's noticed the wrestler walk? Like, something in their posture or their gait. Idk what it is, but you can just eyeball a dude and be like, "yeah he knows what a Granby roll is"

IMO this is one of the beautiful things about Judo/BJJ. I'm bad at BJJ. I know that. Yeah I can manhandle a dude my size who's day 1 no experience. Anything more than that is me trying my best and then going easy on me. I passed that purple belts guard but he could've stopped it if he wanred to bad enough.

Then you roll with a legit seasoned black belt, and realize you are even worse than you thought.

And it's not because of the team, or the gear, or someone cheating or lag in a videogame. It's just him being better.

And you either let that beat you up, or you look forward to how high the scale goes, and keep on growing

The biggest utility I can see would be some already proposed with prototypes. I.e. military boarding a boat, and high angle search and rescue. We've seen tech demos for both. I have no expertise in mountain climbing or EMS, so I can't speak for how far off we are from that being practical or useful.

For things like boat boardings, it seems like it could (eventually) be the best solution to an awful situation. If bad guys with guns are on a boat and you need to get on said boat (whether to repossess the boat, or save people on the boat) boarding it is a tactical nightmare. Your options are basically:

1. Ride a small boat up to it, hope they don't see you, and climb into bad guy boat. If the bad guys did see you and start shooting you, hopefully your friends from another boat or helicopter can shoot them first.

2. Fly a noisy helicopter above said bad guy boat and fast rope down, hoping they don't shoot you or the helicopter before you get into a fighting position

3. I dont know, maybe parachute onto it? Options 1 and 2 are outside of, but adjacent to, my expertise. This is a whole other level. The military has proposed, tried, and done crazier things though.

Option 4, Jetpacks, would be nice. To be able to go from good guy boat to bad guy boat within like, 30 seconds, is still a rough approach but probably the least awful.

Fortunately, for society (unfortunately for the Jetpack industry) maritime hostage rescue is a pretty small market surface

Circa 2017 when IE8 compatibility was still a thing, I saw a metric that said more people use screen readers and/or have poor enough vision to need some sort of UI accomodation than there were IE8 users

Some very brief googling suggests about 3% of Americans are visually disabled. Having a team ensure your product is available to an extra 3% of people seems like a potentially reasonable investment.

Fp-ts adds some amazing functional tools. Io-ts, which is built off of it, adds great run time type validation.

I can define types using io-ts, infer a true typescript type from that to put in my d.ts files to get full ts type checking, and also have run time type checks, all from the same single definition.

The initial learning curve is admittedly a little steep, but once you have it down it's a breeze to use, and delightful.

Its a choice that effects others. When you get ejected from the crash and hit someone else's car. When we have to shut down the interstate north and south bound for 3 hours to do a full reconstruction. When we have to do a death notification.

Dealing with a dead body isnt a big deal. Your mind kinda puts it in the pile of "just evidence". Working the fatality is easy. The hard part is the death notification. Having to find the family member, either waking them up at 2 am or knocking on the door in the middle of an otherwise normal afternoon. Its not like brain surgery gone bad. There was 0 warning of this happening. Noones prepaered for it.

Death notification is a full day of training in our academy. Noone deserves to learn their loved one died on the news or thru a rumor or over the phone. You have to tell them in person.

And you have to be blunt. Anything less just makes it harder to cope. "There was a crash, he didn't make it" leaves their mind to fabricate a weak lie, like maybe he didn't make avoiding the crash, and he's just hurt. This just makes the pain last that much longer

"Sir, I'm sorry to tell you that your son was killed in a motor vehicle crash".

If you want to make dumb decisions, that's fine, but don't try to justify it with this isolated "well it's my choice" nonsense. Your choice effects others, and I can still remember the reaction of every single death notification I've done. The viet nam vet trying to pass a tractor trailer on his motorcycle, and the way his wife screamed. Having to tell a Dad who's son was touring a college, that his sone was the only one in the car not in a seat belt. Having to wake a mother up at 2 in the morning to tell her her son is dead, and not having an answer to "How do I tell his little sister"

Individual choices generally effect more than the individual

I was a cop for several years. I worked hundreds of crashes, and a few fatalities.

If cars had a max speed limit of 85 mph, and required the seatbelt to be engaged to work, we'd cut our fatality rate in half.

Most nations' DUI laws consider a 0.05 BAC as illegal. In most US states 0.08 is presumed under the influence, 0.06 - 0.079 is considered no presumption either way, and under .06 is considered not under the influence. My alcohol tolerance is fairly average, but after some off the cuff experiments with whiskey and a preliminary breathalyzer, I shouldn't drive at a .055. My wife shouldn't drive at a .03

Something like 80% of fatal crashes involve either alcohol, no seatbelt, or excessive speed, but not wearing a seatbelt is like a 50 dollar ticket, and a secondary offense, in many jurisdictions.

The AP isnt saying that assault rifles dont exist. They are saying the term has a definition that doesnt apply to most situations, and when it does is still vague. AR-15s aren't, by Wikipedias definition[1], an assault rifle.

Rifles have a definition. In the U.S. they have a very specific one regarding cartridge size, barrel length, and rifling of said barrel (which differentiates them from muskets, which have smooth bores)

The issue isn't that the term Assault Rifle is too specific, its that its too inaccurate. A fully automatic machine gun in a high powered cartridge isn't an assault rifle. An AR-15 that shoots semi-auto is not an assault rifle. A fully automatic 9mm is not an assault rifle. To call them such is like saying a moped is a motorcycle, a hang glider is a plane, or an M1 Arbams is a truck

Very few shootings in the US have happened with assault rifles. Most people already cant access (legally or otherwise) assault rifles. Semi automatic rifles or sporting rifles are largely available, and generally just as dangerous.

Most lay people wouldn't consider a Ruger Mini-14[2] an assault rifle, and it isn't. However it is a rifle that comes with a 20 round magazine that fires the same cartridges as an AR 15 at similar ranges, and is of similar size. Its a dangerous weapon, its a rifle, but its not an assault rifle by any widely accepted definition. The same applies to the AR-15

[1]https://en.wikipedia.org/wiki/Assault_rifle [2]https://www.ruger.com/products/mini14RanchRifle/specSheets/5...

Per Wikipedia, "An assault rifle is a selective fire rifle that uses an intermediate cartridge and a detachable magazine"

Selective fire means it has a fire mode other than semi-automatic(one trigger pull fires 1 round), such as 2 or 3 round burst, or fully automatic.

The Assault Weapons Ban of 94 basically scored weapons based off of sometimes irrelevant features (e.g. pistol grips, bayonet mounts, telescoping stocks)

One popular work around these days is "AR-15 pistols", which have an AR-15 style lower and upper, but instead of buffer tube assembly being placed in the stock, it sticks out the read of the weapon. Some manufacturers make "arm braces" to "attach it to your forearm" that look a lot like stocks, but aren't, because that would make this a short barreled rifle.

As a cop, I had a Colt AR-15. This was not an assault rifle, as it was semi-auto only. If someone has an m2 50 caliber machine gun, that would not be an assault rifle, as the .50 is not considered an "intermediate cartridge". In the 90s, Colt made what appeared to be a smaller fully automatic M-16, which fired 9mm rounds. This was also not an assault rifle, because it fired pistol rounds, not considered intermediate cartridge. This weapon would be an assault carbine or a submachinegun.

The media use of the term 'Assault Rifle' has been a meme among firearms owners for years. This was a good call by the AP