HN user

Pharaoh2

220 karma

[ my public key: https://keybase.io/akshetpandey; my proof: https://keybase.io/akshetpandey/sigs/AcLwTDYvWbR9A4BYlBh0nfwxDxnj3RII_jTajYx_3wY ]

Posts0
Comments128
View on HN
No posts found.
[GET] "/api/user/Pharaoh2/stories?hitsPerPage=30&page=0": 500 Failed to fetch user stories
[dead] 4 years ago

This isn't real. This is a scam video for crypto.

This scams are very common and fairly easy to detected even without contacting the person.

I have been looking at apartments since november and finally found a place in January, and this is the third apartment I have rented in SF over the last 5 years. I believe this one would have been caught by point 2.

Detecting a SF craigslist rental scam:

1. Is it too good to be true? Its a scam. What's too good to be true you ask? Check other listings, especially on something like rentSFnow, or the many other property management company to get a baseline price range.

2. Reverse image search the images and if it comes from a house listing on redfin or some other website to buy/sell houses, its a scam.

3. Does it mention a management company? Check their website, if the apartment is not listed there, its a scam. If they don't have a website, its a scam. Does the building/apartment's google maps or yelp not link to the management company website? Its a scam.

4. Are the pictures really good/professional looking? It MAY be a scam.

5. Does the listing provide no/very little info about the apartment/roommates? Its a scam.

6. Look for listings for the same apartment on alternate sites like apartments.com/hotpad/zillow/trulia. Don't find another listing for the same place? Its a scam, with a minor chance that the owner may not be technically adept, in which case look at the pictures, if they are good, its a scam.

7. Are there multiple postings on the same day/close by with different titles but same content? Its a scam.

If it passes all of these, it may still be a scam, reach out and proceed with caution.

If after reaching out, they ask for deposit before seeing the place, its a scam. If they ask you to sign up on any website, it may be a scam. If the sign up requires credit card/bank account or sensitive personal info, its DEFINITELY A SCAM.

Ignore most things they tell you, the only thing you should care about is actually checking the place out and making sure it works for you in person.

Even if they let you see the place, IT MAY BE A SCAM. Proceed with caution and make sure the person actually own the place/has the right to rent the apartment.

Its mostly higher bandwidth from being closer to source. Latency is definitely improved but so is bandwidth if you are in peered in the same exchange. Peek bandwidth is going to be much higher, especially if you are pulling/pushing north of 10G.

Basing this solely as a person from India and not some research background,

In the small minority of hacker rank study set, I would say that women are just as much encouraged or frankly expected to be in STEM as men. Although I am fairly certain that this observation will quickly disappear and will be heavily male dominated on a larger percentage of the population.

Really, looking at the actual hacker rank source, it seems like their sample set is really tiny and heavily biased.

Presumably because the gap exists in the current system, and the current system is optimized for the current scoring function. Changing the scoring function will cause the system to rebalance into a new steady state.

Although, there is no clear reason why the new steady state would not be female dominant or evenly split, but if I were to take a bet, I would bet that the new scoring function will still hold existing bias because the problem starts much earlier.

That just the fire stick, or the netflix firestick app or your network. That isn't netflix's infrastructure problem. Netflix is the most reliable of netflix/hulu/hbo.

Try a higher end streaming devices that wired to your router

What is 1e100.net? 8 years ago

Its the domain name they use for their servers. Its generally a good practice to have a dns name that maps to a particular server apart form the website its supposed to be serving for administrative purposes.

Try this:

dig google.com

;; ANSWER SECTION:

google.com. 299 IN A 172.217.164.110

nslookup 172.217.164.110

Non-authoritative answer:

110.164.217.172.in-addr.arpa name = sfo03s18-in-f14.1e100.net.

Because this way you have a public ledger that can't be mutated without notifying the public. Not everything that blockchain gives is for the trust distributed use case. For that fact, proof of work is the only thing that is purely there because bitcoin's blockchain needs a distributed trust system.

5 mins on amazon will find you what you are looking for. There are a whole bunch of feature phone and basic carrier/prepaid phones out there. Some of them will also do usb tethering but its a bit difficult to actually set up since it needs obscure drivers. You can also go for the higher end blackberry which still keeps physical keys and runs full blown android.

Even sold by Amazon: Blackberry: https://www.amazon.com/dp/B00DGYW83E TracPhone: https://www.amazon.com/dp/B01M3VI4Q6 TracPhone: https://smile.amazon.com/dp/B01L2DE1G2

What is he supposed to do?

His initial reaction when he thought he was under attack was fine and the second reaction was immature and lacked empathy but he was likely facing an unexpected problem that he couldn't figure out how to handle but very soon got on the right track.

Those servers and bandwidth aren't free. Bandwidth to tier three countries is actually more expensive.

Advertising revenue is basically non-existent for tier three countries, conversion rates and LTV is super low, ltv for the group of user that are using his service for whatsapp will be in the range of 1-5 Rs, ~(1-8 cents).

He will eventually have to block these countries again if he can't figure out a way to indirectly monetize these users. Or he will run out of money and the servers go down.

The best thing for these users would be if he can figure out a way to make it sustainable, and that means to monetize these users.

Some researchers had independently create and demonstrated working PoC based on the linux patches they saw which read kernel memory from user space. At that point it was already public.

After that its all about PR and getting people prepared for the magnitude and impact early.

Also to let people know that patches that were already available can be used (restarting GCP/AWS instances, SPI on chrome).

4,5 and 6 don't need to time the attack.

I am not really sure how/if zero copy may/may not solve this problem.

If this bug only allows reading kernel pages, zero copy may actually help if the unprivileged user can't read your pages, but from the small amount of available description it looks like it can read any page, but kernel pages are more interesting because thats a ring lower and which is why all the focus is on that.

I am fairly certain there is more protection against being able to read memory owned by process on a lower ring level so zero copy may be a bad idea for security critical data.

And based on the disclosure that google published, looks like any memory can be read

I can think of a few ways to get privilege escalation if you already have rce as unprivileged user:

1. Read the root ssh private key from the openssh deamons kernel pages maintaining the crypto context and ssh into the system

2. Read a sudo auth key generated for someone using sudo and then use that to run code as a root user

3. Read the users password's whenever a session manager asks the users to reauth

4. If running in AWS/GCP inside a container/vm meant to run untrusted code, read the cloud provider private keys and get control on account

5. RCE to ROP powered privilege escalation exploit seems reasonable...

6. Rowhammer a known kernel address (since you can now read kernel memory) to flip some bits to give you root

Also remember running JS is basically RCE if you can read outside the browser sandbox, ads just became much more dangerous...

Conversion on android has gone up, along with users on high-end android devices. At the same time CPI on iOS has gone up.

Speculation: iOS users may be running into app fatigue and just don't want to install new apps anymore.

Sorry should have clarified, I am taking about freemium apps , both subscriptions and IAPs. Don't have data on paid apps.

Also I am talking about app that are well monetized and advertised so you have an level comparison instead of chart positions giving and sustaining a significant lead on one platform just by some fluke.

Hard part in this case is not the actual build code or even the CI runners, its actually maintaining a mac server farm for your builds. None of the major cloud providers have mac hardware options.

Buddybuild and very few other CI systems have iOS and Android support.

Not a reasonable replacement as maintaining your own mac servers is non-trivial and all the major cloud providers don't have mac as hardware options.

Not a reasonable replacement as maintaining your own mac servers is non-trivial and all the major cloud providers don't have mac as hardware options.