HN user

ago

154 karma

[ my public key: https://keybase.io/ichundes; my proof: https://keybase.io/ichundes/sigs/uM4Zn-7Nsj6pHqq8b80GsI0PCI3753XTXVIiDi872Yo ]

Posts0
Comments30
View on HN
No posts found.

I tried it a few months ago and ReFS ate my data. No indication of why in event logs or SMART data. It had IsPowerProtected set because I have a UPS and I had a unclean restart, I would expect it to lose data, but not to corrupt the filesystem metadata. I had a backup of the data but wanted some recent changes. Refsutil (the official Microsoft tool) didn't help because it has not been updated for the newest ReFS version. I couldn't read most files because I had integrity enable and files failed the check. Hetman's Data Recovery was able to recover most of the data. In later testing I found out that IsPowerProtected is just very unsafe. I have since put some time into testing and sometimes fixing https://github.com/openzfsonwindows/openzfs , it is not ready for use yet, but it is making great progress.

They are bad, but it is better than nothing. I think if you are completely deaf they probably are not good enough. For myself, I have some hearing damage from working with fire alarms without hearing protection which makes it sometimes hard to understand speech with some background noise, it also doesn't help that English is not my native language. These subtitles make some videos that are hard for me to understand much better than without, because I am able to combine the hearing that I got with the subtitles to figure out what is being said. So yea, I hope they could improve them, but without them my experience is definitely worse.

BCH for small transactions with 0-conf is not slow as hell. When you require confirmations a system like Bitcoin has a quite random time between blocks, but 10 minutes on average.

IOTA has an absolutely unprofessional development team, doing things like saying critical security vulnerabilities are there on purpose so they can point it out when someone forks or saying that the network being unusable due to a DOS attack is fine because they can use it for testing. Don't forget the time they turned off the network for 2 days without any prior notice (yes, they can do that). I'm all for new technology, but Bitcoin is 9 year old proven technology at this point, while IOTA and RaiBlocks are both new and unproven. Let them mature a bit before suggesting people rely on them. Would be quite bad if someone turned off IOTA when you need your money, wouldn't it?

How is it a scam to keep it working like it was intended to work? I did not buy into Bitcoin to hold it forever, I bought it to use it as cash. Therefore I do feel defrauded by the current developers, until just yesterday they advertised one thing on their website but delivered something different.

I have kind of mixed feelings about removing ASIC boost. I do feel it is everyones right to innovate and get an advantage, then patent that advantage. It takes money to do that R&D, so it should be protected. Others can do so as well, or operate from countries where these patents are not respected. On the other hand, others have so far been unable to get their own advantages, so maybe it is time to hardfork (yes, hardfork, SegWit does not fix it, not until > 90% of transactions are using SegWit) to prevent getting this advantage.

Transaction malleability has nothing to do with the security properties of zero conf, it only allows you to change the signature of a transaction, not the contents. So if you malleated a transaction, you would still end up with a transaction paying the merchant, in no way vanishing like you describe. What does affect the security is if miners violate the first seen rule, which is not a consensus rule, to include transactions that were seen later but have higher fees into their blocks. This allows you to essentially replace a transaction by bribing a miner with a higher fee. Generally the risk of this is seen as low, generally lower than the risk of credit card fraud, so for low value transactions it is generally fine. Malleability breaking the withdrawals of an exchange is a problem with that exchange, not with Bitcoin Cash.

As for developers removing the malleability fix (SegWit) to break the LN, that is just a plain lie. First, SegWit was removed because it is just an hack that can be achieved in much better ways. SegWit is such technical debt because it did in a soft fork what should have been done in a hard fork. Second, you can see on the development mailing list that fixing it has been discussed well, and a fix for third party malleability is actually already active. You can also see that nobody is against 2nd layer systems like Lightning Network, and it will be supported if and when it is actually useful.

The EDA that was in place in the first 3 months was indeed a big mistake and has since been replaced with a well performing fast acting DAA, but it is not the reason people push for 0-conf. 0-conf was a pretty well used and working feature of BTC before the blocks first became full. It is only logical to use it again on a chain that does not intend to let its blocks become full.

Se­cu­rity Keys 9 years ago

That was my problem first too, but you can make it require the token on mobile too. I have it set up that way and I need to tap my Yubikey NEO to authenticate using NFC on Android. Works great.

I think the multi tab selection is not part of the extension, but is integrated in Chrome itself. I recently discovered it by accident and found it to be super helpful to do things like splitting a group of tabs into a new window.

Qt 5.6.0 released 10 years ago

Wow, finally being able to resize dock widgets. I've been searching for this forever, always thinking I was doing something wrong. At least now I know it wasn't really possible. This finally allows me to get my last major UI task out of my todo list :)

Same here, I only use it because I have to make my applications work on OS-X and to me it is the worst operating system that I've ever had the opportunity to try. I took my time to learn how to do things the OS-X way, but I prefer Linux or Windows a lot. There are things like about it though, like the self-contained application packages, although you can have them on Linux as well, just not as unified.

I agree that Opera the browser is not as competitive as they once were, but for the ads point you could say the same about Chrome since Google makes its money from advertising, not from the browser. I haven't seen any ads outside of the web content in Chrome or Opera (at least since version 8.5).

You're completely right. The police were nice to me, probably because I was very cooperative. The team was about 15 people from the LKA, including the head of the cybercrime unit. I did cause a bit of a scare when I reached for the kitchen knife to cut some bread, but they quickly realized I didnt want to stab anyone. Of course I knew that I was far better off being in Germany than anywhere else, so I wasn't worried much. Overall I'm quite satisfied with how it went for me, even though it would be 4 years until the trial where I had to report to the police 3 times a week. I had the opportunity to turn my life around and get a good job. If I got put into jail neither me nor society would have been better off considering I paid a lot of taxes in the meantime and haven't done anything criminal since.

I worked programming fire alarm systems for a while, embedded device programming and test automation. Now I started doing realtime graphics in Bejing. Working on using the Kinect to do gesture input on presentations on really big screens. Like Powerpoint on steroids.

I agree that what I did was bad, but to say that it takes no talent is just wrong. In fact some of the things were more challenging than anything I've come accross at any of my jobs (programming embedded device firmware, test automation and realtime graphics) in the last 10 years. And no, I couldn't find even a "boring" programming job where I lived. Of course I tried, I tried a lot. Really, you have no idea what kind of shithole the place I grew up at was for programmers. Still, that doesn't excuse what I did, and I'm sorry for it.

I am a convicted malware coder (Agobot/Gaobot/Phatbot/etc...) and it all started because of a chat I had with a botmaster.

Back then I needed a key for Warcraft III, which just came out, so I tried some keygen I found on the net, without any antivirus. When the keygen did not work I knew something was wrong, so I checked for suspicious network traffic and saw some IRC connection, quickly found the process responsible for causing the traffic and fired up a disassembler. After UPX unpacking I had the assembler code to the program and was able to determine the IRC server, the bot password (they didn't use password hashes or hostmasks back then) and I got a command reference for the specific bot (SDBOT). I joined the channel disguised as one of the bots, logged in and sent the remove command. This kills the botnet. The bot herder was pissed, but I started talking to him and I got interested in malware to get CD keys, which I couldn't afford at the time.

I started modifying SDBOT for my usage, writing scanners and fixing bugs in the IRC connection code. After I while I felt limited by the codebase and started my own called Agobot. Agobot quickly grew into one of the most capable trojans at the time, with thousands of variants. I also quickly got a team of at peak ~15 people together who helped with testing and coding. Coding was mostly done by me and at most 3 other coders. We were having really cool stuff, like wormride which was a tool to make other malware/worms spread Agobot instead of itself. It also contained an exploit that I wrote for the LSASS hole that Sasser used only a few days after the advisory. My LSASS exploit did not crash the target, which let it spread a few days without being noticed. ISC noticed it after a while and raised the threat level to orange.

There was also a variant of the bot that used the waste network to communicate and the gnutella network to find themselves. It made the DHS shit their pants and release an advisory :)

First I hosted the bots on public IRC, but after being detected very quickly I got to talk with some IRC opers that offered me a private server to run the botnet in exchange for usage rights. These were powerful servers, holding around 50k bots at peak. Basically this all got busted by the FBI, which caused the Foonet/CIT shutdown. For more infos, check these URLs:

http://www.theregister.co.uk/2004/08/27/ddos_mafia_busted/

http://regmedia.co.uk/2008/10/03/03116720232.pdf

http://www.securityfocus.com/news/9411

http://newssocket.com/foonet/

http://www.techimo.com/forum/imo-community/100728-your-isp-n...

Anyway, they caught me because I accidentally let a bot start a short scan from the linux host where we hosted the SVN repository and IRC. The company running the datacenter detected the scan and decided to investigate the server (illegaly) and found all the stuff (I didn't even think about encrypting all that). I got 2 years probation for this as well as hacking Valve Software.

Hers some more info:

http://en.wikipedia.org/wiki/Agobot

http://www.honeynet.org/node/55

http://www.infectionvectors.com/vectors/kitchensink.htm

http://web.archive.org/web/20070423182932/http://www.lurhq.c...