HN user

__jf__

147 karma
Posts7
Comments57
View on HN

Gay Talese starts "The Kidnapping of Joe Bonanno" (Esquire, August 1971) with this:

Knowing that it is possible to see too much, most doormen in New York have developed an extraordinary sense of selective vision: they know what to see and what to ignore, when to be curious and when to be indolent—they are most often standing indoors, unaware, when there are accidents or arguments in front of their buildings, and they are usually in the street seeking taxicabs when burglars are escaping through the lobby. Although a doorman may disapprove of bribery and adultery, his back is invariably turned when the superintendent is handing money to the fire inspector or when a tenant whose wife is away escorts a young woman into the elevator—which is not to accuse the doorman of hypocrisy or cowardice but merely to suggest that his instinct for uninvolvement is very strong, and to speculate that doormen have perhaps learned through experience that nothing is to be gained by serving as a material witness to life’s unseemly sights or to the madness of the city. This being so, it was not surprising that on the night when the reputed Mafia chief, Joseph Bonanno, was grabbed by two gunmen in front of a luxury apartment house on Park Avenue near Thirty-sixth Street, shortly after midnight on a rainy Tuesday in October, the doorman was standing in the lobby talking to the elevator man and saw nothing.

Paul Strassmann wrote a book in 1990 called "Business Value of Computers" that showed that it matters where money on computers is spent. Only firms that spent it on their core business processes showed increased revenues whereas the ones that spent it on peripheral business processes didn't.

For vector generation I started using Meta-LLama-3-8B in april 2024 with Python and Transformers for each text chunk on an RTX-A6000. Wow that thing was fast but noisy and also burns 500W. So a year ago I switched to an M1 Ultra and only had to replace Transformers with Apple's MLX python library. Approximately the same speed but less heat and noise. The Llama model has 4k dimensions so at fp16 thats 8 kilobyte per chunk, which I store in a BLOB column in SQLite via numpy.save(). Between running on the RTX and M1 there is a very small difference in vector output but not enough for me to change retrieval results, regenerate the vectors or change to another LLM.

For retrieval I load all the vectors from the SQlite database into a numpy.array and hand it to FAISS. Faiss-gpu was impressively fast on the RTX6000 and faiss-cpu is slower on the M1 Ultra but still fast enough for my purposes (I'm firing a few queries per day, not per minute). For 5 million chunks memory usage is around 40 GB which both fit into the A6000 and easily fits into the 128GB of the M1 Ultra. It works, I'm happy.

Tom Uren and grugq did a podcast on this recently in Risky Business News [0] I think the main point was that these attacks are physical, don't scale very well, and are untargeted because they depend on luck, so an adversary probably would use more efficient techniques. Unless of course these USB charging points happen to magically cluster around important secret carrying government buildings or other points of interest.

[0] https://risky.biz/BTN46/

I was primarily struck by the awesomeness of this whole autonomous glucose regulation thing. My last meal is usually around 18:30 in the evening and during the night glucose would fluctuate around 4.5 mmol/l between 4.0 and 5.0 in 1 hour periods, like a crappy PID controller that needs a firmware update. Other nights it would be flat instead of fluctuating, but unfortunately two weeks were too short for a controlled experiment, meal repeats and figuring out what caused the difference. Some nights it would show a couple of hypo's where glucose would drop to 3.5, quickly to be countered by an increase. I didn't notice a thing.

Additionally every morning before my alarm went off, I could see my glucose increasing, most likely preparing for wakeup, all by itself. Amazing!

It gave me a new-found respect for these otherwise invisible processes happening in this fleshy vessel on autopilot with closed cockpit doors. I only got to peek through a small window during 2 weeks.

1968 interview: https://scrapsfromtheloft.com/books/truman-capote-playboy-in...

Playboy: How do you react to those critics who deride the form of documentary crime writing employed in In Cold Blood as inferior to the novel?

Capote: What can I say, except that I think they’re ignorant? If they can’t comprehend that journalism is really the most avant-garde form of writing existent today, then their heads are in the sand. These critics seem unable to realize, or accept, that creative fiction writing has gone as far as it can experimentally. It reached its peak in the Twenties and hasn’t budged since. Of course, we have writers like William Burroughs, whose brand of verbal surface trivia is amusing and occasionally fascinating, but there’s no base for moving forward in that area—whereas journalism is actually the last great unexplored literary frontier.

Playboy: The gulf between someone of your background and two such brutal criminals would seem impossible to bridge. But you’ve said, “Hickock and Smith became very, very good friends of mine—perhaps the closest friends I’ve ever had in my life.” How did you establish rapport with them?

Capote: I treated them as men, not as murderers. To most people, a man loses his humanity the minute they learn he’s a murderer; they could be talking with him one moment and then the next someone would whisper, “Do you know he killed five people?” and from that moment on, the man would become unreal to them, an uncomfortable abstraction. But I find it relatively easy to establish rapport with murderers; in the past few years, I’ve interviewed more than 30 of them in all parts of the country. Before I began In Cold Blood, I knew nothing about crime and wasn’t interested in it; but once the book was under way, I began interviewing murderers—or homicidal minds, as I call them—in order to have a basis of comparison for Smith and Hickock; and I met many more recently while doing a television documentary on capital punishment. The second we begin talking, I find that they are ordinary men with extraordinary problems, set apart only by their ability to kill; in some it’s a total lack of conscience, in others a passionate destructive drive. But I have found a certain pattern. One common denominator, for example, is their fetish for tattoos. I have seldom met a murderer who wasn’t tattooed. Of course, the reason is rather clear; most murderers are extremely weak men who are sexually undecided and quite frequently impotent. Thus the tattoo, with all its obvious masculine symbolism. Another common denominator is that murderers almost always laugh when they’re discussing their crimes. I’ve met few killers who didn’t start laughing when I finally managed to force them to discuss the murder—which isn’t easy. When Perry Smith started to tell me about the murder of the Clutter family, for example, he said, “I know this isn’t funny, but I can’t help laughing about it.” Just a while ago, I interviewed a 21-year-old boy named Bassett in the San Quentin death house who is extremely intelligent. He’s a slight, thin boy, with a delicate face and figure, a college student, and he writes poetry and short stories. He murdered his mother and father when he was 18; he’d been planning to do it since he was 10 years old. And when he started telling me about how he killed his parents, he began laughing and cracking little jokes, just as though he was telling me the most humorous story. They’re mostly like that; they’ll tell you how they cut someone’s throat and it’s as if they were watching a clown slip on a banana peel.

Playboy: You don’t agree, then, with the adage that it’s better for a dozen guilty men to go free than for one innocent man to be unjustly convicted?

Capote: It’s a charming sentiment, but more apropos in the halcyon days of yore, when our cities had not yet been turned into jungles and a citizen could still stroll the streets in safety. I’m afraid that today, for the very self-protection of our society, it’s better that one innocent man be punished than that a dozen guilty men go free. It’s unfortunate, but that’s the harsh reality we face.

Are there any perfectionists around here that have experience with Acceptance and Commitment Therapy (ACT)? It sounds like perfectionism-induced procrastination: it's better to give up than to play because playing may mean losing, and the chance of losing is unacceptable.

Near the end of “Understanding Michael Porter”, there is a Q&A with him that touches on this subject:

Q: “How do you do a five forces analysis if you’re an entrepreneur starting a new business in a completely new market space? Is strategy even relevant when there’s no existing industry or when conditions are still so fluid that there is no discernible industry structure and no direct competitors?”

Porter: “Strategy is relevant for any organization at any point in its trajectory. How to develop and sustain a competitive advantage is the core question that every organization has to answer if it’s to be successful and to prosper. In emerging industries there’s a lot of experimentation. What will the product ultimately look like? What will the distribution system look like? Will the product or service scope produce a stand-alone industry, or will this new idea become part of a larger or existing industry? There’s more uncertainty about the shape of things, but the five forces exercise is fundamentally the same with one big exception: instead of analyzing what already exists, you’re forecasting. And you probably know quite a lot about all of the five forces but one. You know the customers you’re targeting. Are they likely to be price sensitive? You know who your suppliers are or who they are likely to be. How powerful will they become? You know the substitutes and can identify the likely entry barriers. What you don’t have yet are actual rivals. That’s where you need to think through who those might be. Will the rivals most likely come from adjacent industries? Or from companies that already exist in other countries? Or will the likely rivals be new start-ups? How would each of these rivals be likely to compete? So even when you’re inventing new market market space, you probably already know more about the five forces than you realize. Doing such analysis is important because if you’re creating something that’s truly valuable, don’t kid yourself that no one will follow you. There is no such thing as a market where competition is irrelevant, as nice as that might sound. The idea that innovation allows you to ignore competition is a fairy tale. So you have to have a hypothesis for how the industry might take shape once there is an industry. Early on, there are many paths the evolution can take, many choices you can make that will have an important impact on how attractive the industry will become. Decisions you and others make over time will begin to lock in the basic economics, making industry structure less fluid. So it’s crucial to see different paths for how the industry might evolve, and to ask the basic questions about the five forces, so that you can make choices that will put the industry on the best possible path.“

You can look at:

- A collection of public threat intel reports [0]. Lots of reading though. I did some Splunking on it last year and at least 50% uses phishing for initial access. You could call that a structural vulnerability.

- Exploiting vulnerable public facing stuff is another initial access technique. Here someone collected all the CVEs used by ransomware crews [1].

- VERIS community database [2]. Collection of 8894 security incidents. If you look in the JSON there are some fields describing the vector and the actor.

[0] https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_C...

[1] https://twitter.com/uuallan/status/1437068825636265985

[2] https://github.com/vz-risk/VCDB

They responded by asserting the contract couldn't be exploitative b/c top lawyers in the industry wrote it and b/c other devs have signed it. The fact that they still easily sign devs on this is a poor reflection on the industry, not a vote in favour of the practice.

A long time ago, we had an expensive lawyer at a prestigious law firm draft a contract for a vital deal we were trying to close. We were in our early twenties and were very impressed by all the risks this contract transferred to the other party or mitigated in our favor. The other party reacted by asking if we had some junior draft the contract because it was so one-sided. They said: "If you want people to sign a contract, this is not the way to go." They proceeded to explain that our dog-eat-dog approach is not a promising start to a business relationship. They went bankrupt a year later.

The most surprising thing I discovered was that it took me 3 months to lose a jittery “I.SHOULD.DO.SOMETHING.NOW” feeling. Only after 3 months did I feel truly relaxed to pursue whatever interest-driven nerding project and at the same time letting go of a sense of achievement or progress. 2021 was supposed to be a “me” year until an interesting project came along. I said yes. Taking time off is hard.

Covid lockdowns and WFH had a surprisingly large influence on self-service threat modeling facilitation I did for a client.

Pre-covid we would facilitate workshops interactively around a whiteboard. It turns out that starting with an empty one was essential for successfully thinking about risk.

During lockdowns whiteboarding was difficult so we often discussed the application stack in a virtual meeting using some Powerpoint or Visio diagram provided by the team. Without fail this diagram was huge and included lots of detail. This didn’t help group discussion because basically only the author would understand it enough. After a number of these unsatisfying attempts we started having separate virtual meetings to create high-level diagrams to abstract away initial detail overload. This often resulted in teams discovering their CI/CD pipeline and have a healthy discussion about scope.

We all know what "have a show in Chelsea" looks like today. The distribution model changed radically, but the personal drivers didn't. Surprisingly, the rise of new platforms only temporarily affected the old way's economics if you look at the number of photobooks published in the Netherlands. Until the first peak in 2005, these increased linearly, plateaued until 2012, and reached a new peak in 2017. While the supply of digital photography expanded, apparently so did the supply of physical photography books.

Most of the compliance paperwork I’ve seen does leave room for custom risk assessments, threat modeling or other wordings that invite a business team to do more. However in their rush to go live or otherwise get it over with this security work is done after all other things. It isn’t integrated, in an SDLC for example.

So minimum standards become maximum standards. It’s hard work convincing teams to do better, but at least the compliance docs give permission to develop your own, often better, understanding if the data classification is high enough. It doesn’t happen often but I havent abandoned all hope yet.

In 2017 I got a second hand Cisco ASA just to play with the shadowbrokers tools. EXTRABACON was the codename for the SNMP exploit using a buffer overflow.

This was an interesting excercise because there were NO logs of this happening on the Cisco ASA, not even when ramping every loglevel to debug. Well only on the console port. Exception in readline() or something like it. Doing stuff for security monitoring in daily life this ehm was alarming, but not unexpected. Fixing “No logs” is often a challenge for blue teams.

Anyway it was alarming enough to find and read through the Common Criteria EAL4+ certification docs for the Cisco ASA only to find that SNMP was excluded from certification scope. I still have the idea in the back of my head to explore scope exclusions in other certification docs for other unfortunate exclusions.

Also the lack of mitigations like stack canaries, ASLR or others was quite surprising for a certified black box security device on the network perimeter.

Trust boundaries make most sense when used in a data flow diagram, where for every flow between processes you ask yourself: “what could go wrong here?”

That question deserves additional attention if these flows reach processes controlled by different people, or are running under different privileges. That’s when they cross a trust boundary.

So a db server with local storage: single trust boundary around db and storage. But! But! What about the kernel!?

At this point it becomes important ask to another question: does the current abstraction level of the model help you think better about risk? It depends. Perhaps not if the db is part of a larger infrastructure with a global CDN, loadbalancers, webservers and some in memory caching layer.

I like the fact that malware authors also seem to have trouble setting up a (secure) software development lifecycle. On the other hand if they were to threat model it, expoiting weaknesses in the agent does not cross a trust boundery so why bother. Imagine this would be different for their command and control infrastructure.