HN user

a904guy

530 karma

Andy Hawkins

destructive criticism need not apply

http://a904guy.com/

                         S.;@88888X%..%8                     
                    X:t%@8888@XS%t;. .:tSX88S                
                 %.tX888888@S%t;:. .;;%%X@8888S%             
              @.;X8@8888@XStt;...:;t%SX@8888888%.;           
            %.t88@888@@SStt;. .;tSX@88888888@@XS%:t8S        
          S.%8@8888@XSS%t;.S@        X8S;;ttS%t;:. ;88:      
         .t8@8888@XXSS:                    .S%:. .:ttSt      
       ;t@8888@@SXSt                         :88%t%SX@@ t    
      .S8888@XSSSt                              S%S88888t8   
     %@88@@X%%%tS           888XSS                 @8888S88  
    S888XSSt;;.         @88@@@X%t:.%@% t88@X%t; : X%@88@X.@  
   ;88XS%t;:.:        8888888XX%t;:.:@88X%XX888;8  8XXXS%t:; 
   8@St;:. .%       8@888@@XS%t;:  ::;%SS@8888%@    8.%;:. : 
  %@t;:. .;%       @X888XXSt;:. .:;t%SX@888@88%8    S;:. .:%.
  St:  :;tS       SS8@@S%t;: %X@XS%S@8888@888X8@    %. :;t%X@
 %; .:;t%88      ;t@XS%t;. @8S    S .8888888@ @     S;.t%SXS8
 ..:ttSX@8X     ; %St;:. ;8@        %%8888@S%t%     tX:X@88:@
 ;%%SX@888      ; t;:. .t8S          8.@XS%t.:%     %8%8888.t
 X@@88888S     ;S:...:;tSS           8;%%;:...      8@88888.:
 8888888X.     S@ .:;t%S;.           @.;:. :;%     .8S8888X. 
 888888@%:;    88;;%SX@@ ;          St. .:;:Xt     @.888@St% 
 8%@88XStS%    @8%SX@888.S         %: .:;t%.8     ;;X@XSt%X  
  .tS%t;:S8    :%X@888888t8      8: ::ttSX@:8    .:SS%t;%88  
  .;t;:..;8.    .;8888888@ SXSt:. .;t%SX888%@. ;..%%t;:t8@   
   @; .:;tSS     t:8888@S%t;:...:tt%X@::8888%::;%%;;..%8@    
   @8:;t%XX;.     8tXXS%t;:...;t%SX@X;88%88@@SSt;:. ;88      
    8XSX@888.%     8X ;:. .:;t%SX@%:@S :;:SS%t;: :%@88       
     tt8888@8%8      %: . ..:: ;%8@      Xt%XX@8888          
      ..88888@;88       t tSXXt:                             
       XtX8@SSt:;:%                                          
        88 %t;:. . ttt                         @tS           
          X:.  :;t%%:t88S.             S@8X%; ;S%%           
           S...t%XX88888S;:..:;tSSX@@St:.;%@888888           
             .XS @8888888@SSt;;. .:;t%S@@8888888888          
                @8;t@8@@S%t;:. ::ttSX@8888888888@88          
                   ;. ;t%%t:..:;%%SX@@8888888888%.S          
                        @8@@88X%t: .;.;...:

YW5keUBhOTA0Z3V5LmNvbQ==

[ my public key: https://keybase.io/a904guy; my proof: https://keybase.io/a904guy/sigs/B_EBJ3huUPfFzzPnMTBF9GHCw4zac9O4GzbcfCjvZV8 ]

Posts23
Comments55
View on HN
github.com 11mo ago

Show HN: Multi-hop WireGuard chaining, speed-tested and API-controlled

a904guy
2pts0
github.com 11mo ago

Smart Segments: Krita plugin that adds Segment Anything V2 object selection

a904guy
2pts1
gist.github.com 8y ago

Show HN: Script to install recent python versions. Verified on .deb based OSs

a904guy
1pts0
github.com 9y ago

Show HN: CryptoCurrencies Market, Poloniex. Supports Streaming, and REST API

a904guy
30pts1
github.com 12y ago

Show HN: Hack Lang Minimal RESTful Router

a904guy
3pts0
github.com 12y ago

A fast and simple Hack Lang HHVM Router

a904guy
2pts0
www.bonanza.com 12y ago

Automatically Remove Backgrounds From Images.

a904guy
1pts0
www.dealsofscale.com 12y ago

Show HN: Deals Of Scale. Coupons that scale with interest.

a904guy
1pts1
blog.mediafederation.com 13y ago

CSS3 Working Boxee Box Remote.

a904guy
2pts0
lifehacker.com 14y ago

Don't like the idea of iPhone apps accessing your address book?

a904guy
1pts0
yro.slashdot.org 15y ago

Telstra Fears LulzSec Attacks, Hesitates On Internet Filter

a904guy
118pts44
blog.mediafederation.com 15y ago

Ubuntu Headless x11vnc VESA 800x600 Resolution Issue Fix

a904guy
1pts0
www.lehnerstudios.com 15y ago

Chat with people in Apple Stores (iChat | AIM)

a904guy
35pts7
wefoundland.com 15y ago

Command-Line Coda Script for Panic's Coda. Open files from command line in Coda.

a904guy
1pts0
blog.mediafederation.com 15y ago

SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys

a904guy
45pts19
blog.mediafederation.com 15y ago

Complete Hacker Tutorial to getting Time Machine over NFS to work.

a904guy
56pts28
blog.mediafederation.com 15y ago

Show HN: Fireworks Mobile iPhone Prototyping Suite

a904guy
38pts1
blog.mediafederation.com 15y ago

Show HN: EDW, quantitative analytics, machine learning.

a904guy
70pts18
www.linkedin.com 15y ago

BackTrack 5 on the horizon

a904guy
1pts0
blog.mediafederation.com 15y ago

Getting TA-LIB to work with Python 2.6 SWIG interface.

a904guy
1pts0
news.ycombinator.com 15y ago

T-Mobile rate limits your data connection

a904guy
2pts0
mingle2.com 15y ago

ZombieHarmony - One of the Best Free Dating Sites for Zombies

a904guy
3pts0
news.ycombinator.com 15y ago

Youtube Live Epic Failure (Plaintext DB Password Exposed)

a904guy
96pts23

I wasn't. I indeed find the site to be fun, and fits the author's own words.

“So thank you to everybody who writes and publishes text-only webpages.”

The site is 100% text.

Guilty on the splash. Regardless the entire site is clean text, fast loads, no images, and no blockers.

In the author's own words:

“So thank you to everybody who writes and publishes text-only webpages.”

I built a Krita plugin called Smart Segments that lets you easily select objects using Meta’s Segment Anything Model (SAM v2). Just run the tool, and it automatically finds everything on the current layer. You can click or shift-click to choose one or more segments, and it converts them into a selection. No more struggling with the magic wand or cutting stuff out by hand. It supports GPU and CPU, works on Windows, macOS, and Linux, and sets everything up on first run without needing to install anything manually.

ArXiv vs snarXiv 13 years ago

Oops: Was going for the high score...

OperationalError: (1203, "User #### already has more than 'max_user_connections' active connections")

ArXiv vs snarXiv 13 years ago

Nobel Prize Winner ( aka Ed ) goes to:

$("a:contains("+arxiv['title']+")").click();

#1: Not really impossible, just requires additional maintaining of a monitor, methods within the script, or custom triggers to handle the switch.

Looks great.

Two things,

#1: If you modify the attribute checked of the input, the state doesn't change.

#2: I don't see a programmatic way of changing the state from your source without re-initializing all the elements?

A (extremely) large number of usual local network IP ranges are issued to the DOD. Including my local subnet as well. 11.1.11.0/24, if I ran a whois on that IP as well, it would return DOD, but that doesn't mean the DOD is snooping my network, it just means my router has all the routes for 11.1.11.0/24 associated with it and doesn't actually attempt to send traffic over the wire to that IP. I assume your Android phone is listening locally on that address for the VOIP communication, which would in return mean the DOD is NOT snooping on your phone. Much similar to apache or (insert other socket application) listening to 127.0.0.1:80 for local only traffic.

As far as I can tell from the demo there is no server side validation on this captcha. Everything is handled on the client side. So really all your doing is making an annoyance for your honest target users. And allowing a spam bot to just totally ignore this 'captcha' to submit their POST regardless....

I've seen hundreds of these 'alternative' captchas. 'slide to unlock', 'sort images' ect. None yet have proven to be as effective at stopping a simple curl script.

Real captchas will store the value of the image or verification method on the first fetch in a session, and when the form is finally filled out the server will verify that the session value matches the submitted value. Without this component, the alternative captchas are pointless and just an annoyance to your real users.

Spam bots are not built on top of web browsers...

... well. Since we are going deep down the rabbit hole. So your machines other users are potentially a threat. Considering that the folder and contents are chmod 600. Only the owning user and root can see them. The key pass is pointless without the key files.

While we are on the subject. Lets dig deeper on this situation. Whats stopping your rouge user on the same box (that can dump the proc table while ssh-keygen is executing in ms) from dumping the ram to extract the stdin password typed out by keyboard then?

If you already have fear of a user INSIDE your box. SSH keys should be the least of your concerns.

When you run ssh-keygen it creates the two keys, public and private, neither contain the 'plaintext' passphrase in your home directory like you mentioned. The only concern may be bash history, I'll include a wipe for that. Secondly, even while being transmitted using SSH they are NOT in plain-text. As the SSH connection itself is encrypted, so while executed in plaintext, the password is NOT stored in plain text, or transmitted in plaintext as identified by those commands.

Finally, the remote_password being blank is by design, passwordless keys are less of a security threat than any weak user supplied password. They serve their purpose in the real world amongst private networks.

EDIT for 'and in the command line.': Reviewing the command history doesn't show the libssh2 or php5 commands being executed on either BSD or debian.

EDIT for your comment 'in the config file': If your suggesting that the software is insecure by the fact that the user leaves the config file after usage, then perhaps that user should be allowed in the environment to begin with.

The language doesn't really matter, especially considering its a single use app. It can be done via any LibSSH2 binding, or even with a more complex expect binding.

The reason for php is simple, I had already wrote the libssh2 code for what I needed. I submitted it, in hopes it saves someone else the time.

For your comment that was edited stating: "the script was storing passwords in plain-text in the user home folder", There is no plaintext passphrases stored anywhere... and you can use different passwords per each device per the config file. This script follows the exact procedure for ssh-keys defined by OpenSSHD in general, ssh-keys are more secure than logging in using a password in general. As for the reverse connections, I have a version that utilizes the reverse key in the config array that keeps them from distributing across server, only to and from the localhost. I took it out to roll this version out as I still haven't tested it fully.

It works out great for me. I work primarily on a Ubuntu Desktop but for my Mac Air, all my files are on other servers, so really I only have locally Xcode and my development tools.

I assume everyones situation is different, I wouldn't be attempting to use TimeCode on a couple TB drives of a MacPro tower.

The restore works just like any other Time Machine restore. In critical data loss when the machine has to be formatted. You will be able to restore the system completely from the Time Machine. Just remount the NFS on the new OS and run to command so Time Machine will see NFS mounts and click Restore.

~@