HN user

aleks224

113 karma
Posts10
Comments27
View on HN

So this would be the first stack overflow after the Morris' fingerd one (well, first one that's widely publicized):

https://seclists.org/bugtraq/1995/Feb/109

we've installed the NCSA HTTPD 1.3 on our WWW server (HP9000/720, HP-UX 9.01) and I've found, that it can be tricked into executing shell commands. Actually, this bug is similar to the bug in fingerd exploited by the internet worm. The HTTPD reads a maximum of 8192 characters when accepting a request from port 80.

This was great to read. Related: Morris also discovered the predictable TCP sequence number bug and described it in his paper in 1985 http://nil.lcs.mit.edu/rtm/papers/117.pdf. Kevin Mitnick describes how he met some Israeli hackers with a working exploit only in only in 1994 (9 years later) in his book "Ghost in the Wires" (chapter 33). I tried to chronicle the events here (including the Jon Postel's RFC that did not specify how the sequence number should be chosen) https://akircanski.github.io/tcp-spoofing

This blog post exposes the badness of SMS-based recovery. I think other recovery options such as Yubikey aren't ideal either, as a Yubikey may simply stop working and you're completely locked out. The specific situation the author of the blog post isn't dramatic - he can't receive SMS - personal decision to avoid roaming charges.

But in all seriousness, if there's an authentication recovery standard, it should serve all people including those who are in seriously difficult circumstances (e.g. homeless or ill). The question then is what should recovery look like in those cases.

To me it looks like good old recovery code on paper is the best solution, as it doesn't depend on ever-changing device ports, or hardware malfunction due to lack of use long-term (such as 10-15 years).

I wonder whether authentication apps nowdays address that aspect and make and I kinda doubt so (i.e. can you print out a QR code with all account information in your typical TOTP app?).

For a set of primitive operations (such as those in Turing machine), how can you be sure that it spans all possible computations? It sounds that's one of the challenges Turing had - so he went at lengths to show that by various "soft arguments", e.g. that it's possible to build a VM (Turing machine that runs other Turing machines IIRC). Later on, it was shown that the Turing machine is equivalent to machines other folks came up with (Goedel's recursive functions, lambda calculus, etc) and a consensus emerged that they are all describing a full set of computations.

The only way to mitigate this is to use computer-readable proofs, which can be verified by algorithms to ensure correctness.

This seems like a strong overstatement. We got by for more than 2000 years without computer-readable proofs, relying on intuition and validation.

Very interesting! My understanding is that you're thinking about this more in terms of an 'application environment for power-users' than in terms of a 'multi-faceted IDE with lensing'.

To clarify, the specificity of Emacs is that it fully exposes it's internal function sets to the world. This could be done by other applications in an organized way. For example, in the picture-editing app example, it would amount to allowing scripting over the features that the app exposes. The scripting feature would come from the environment, not from anything specific the app itself does (apart from being built in that environment). The previously mentioned IDE could then be thought of simply the multi-tasking environment in which such generic applications are running.

Does this roughly correspond to what the project is about?

A trisector is a person who has, he thinks, succeeded in dividing any angle in three equal parts using straightedge and compass alone. He comes when he sends you his trisection in the mail and asks your opinion, or (worse) calls you to discuss his work, or (worse still) shows up in person.

The question is, how do you select for those whose research will ever amount to something truly interesting

You can't, as "truly interesting" is context dependent, changes over time and something that everyone deems as futile may become interesting - that's the point of research. You just increase the bar of entry to get people who work very hard and leave it to them to decide.

I believe the culprit is the assumption the grants/tenure-track systems make about applicants/assistant professors. That assumption is negative, as if new hires will try _not to do research_. It's also about the number of grad school offerings, it just seems so huge at the moment, which again forces introducing such metrics on what is considered "success" in academia.

Richard stallman himself got repetitive strain injury from emacs

Is this really true? Some notes at https://stallman.org/stallman-computing.html indicate it was a different type of strain injury, unrelated to ctrl/meta key:

In the mid 90s I had bad hand pain, so bad that most of the day I could only type with one finger. The FSF hired typists for me part of the day, and part of the day I tolerated the pain. After a few years I found out that this was due to the hard keys of my keyboard. I switched to a keyboard with lighter key pressure and the problem mostly went away.

My problem was not carpal tunnel syndrome: I avoid that by keeping my wrists pretty straight as I type. There are several kinds of hand injuries that can be caused by repetitive stress; don't assume you have the one you heard of.

Our financial regulatory system still hasn’t fully figured out how to address the risks of the derivatives, securitizations, and money market mutual funds that comprised Shadow Banking 1.0, but we’re already facing the prospect of Shadow Banking 2.0 in the form of decentralized finance, or “DeFi.”

The stakes are much higher when money is involved, and if DeFi is permitted to develop without any regulatory intervention, it will magnify the tendencies towards heightened leverage, rigidity, and runs that characterized Shadow Banking 1.0.

An "elite controller" is a person living with HIV who is able to maintain undetectable viral loads for at least 12 months despite not having started antiretroviral therapy (ART) . Elite controllers are rare: for every two hundred people living with HIV, approximately one may be an elite controller (0.5%).

It is not entirely understood why some patients are able to achieve undetectable viral loads without ART.

https://www.aidsmap.com/about-hiv/faq/what-elite-controller

http://www0.mi.infn.it/~calcolo/OpenVMS/ssb71/6489/6489p009....

Each person engaged in the conversation has a viewport on the screen. Phone can display as many as six viewports at a time. The viewport contains information regarding the user's name, the text of the conversation, and various status indicators, such as who is on hold. User names of people that you have on hold can be temporarily eliminated from the screen to make room for new participants.

   ANSWER      Answers the phone when you receive a call.
   DIAL        Places a call to another user.
   DIRECTORY   Displays a list of the users you can call.
   EXIT        Exits from the Phone utility.
   FACSIMILE   Includes the contents of a file in your conversation.
   HANGUP      Cancels the current phone call.
   HELP        Displays information on how to use the Phone utility.
   HOLD        Places the other users in a call on hold.
   MAIL        Sends a message to another user.
   PHONE       Places a call to another user.
   REJECT      Rejects a call from another user.
   UNHOLD      Reverses the previous HOLD command.

I'm thinking of doing this with my kids for programming exploration + imagination development. Anyone has ideas how to quickly generate pictures/graphics, such as, draw them by hand and make them super small PNGs? It seems that drawing them by an image editor would be super tedious.

Founded in 2008, Sky ECC surged in popularity after messages sent via another encrypted messaging service, EncroChat, were intercepted and decoded in a French and Dutch-led operation in mid-2020, leading to the arrest of over 800 people Europe-wide and the seizure of drugs, guns and large sums of suspect cash

French authorities had been investigating EncroChat since 2017, stepping up efforts in 2019 and secretly installing an implant on all EncroChat devices disguised as a system update. The implant caused the device to transmit all data that had not been erased to a French police server and to Europol and collected data created after the device had been compromised

For Balkan clients, there were three websites promoting the app in languages of the region – skyecceurope.com, skyeccbalkan.com, skyeccserbia.com.

Related: https://news.ycombinator.com/item?id=26468437

Some web application hacking in action in this medical paper:

.. none of the deleted sequencing runs could be accessed through the SRA’s web interface. In addition, none of the runs could be accessed using the command-line tools of the SRA Toolkit. For instance, running fastq-dump SRR11313485 orvdb-dump SRR11313485 returned the message “err: query unauthorized while resolving query within virtual file system module - failed to resolve accession ’SRR11313485’“.

However, the SRA has begun storing all data on the Google and Amazon clouds. While inspecting the SRA’s web interface for other sequencing accessions, I noticed that SRA files are often available from links the other cloud such as https://storage.googleapis.com/nih-sequence-read-archive/run....

I interpolated the cloud URLs for the deleted accessions and tested if they still yielded the SRA files. This strategy was successful; for instance, as of June 3, 2021, going to https://storage.googleapis.com/nih-sequence-read-archive/run... downloads the SRA file for accession SRR1131348

Speaking of unhinged mushroom hunting behavior, it's interesting to look at the New York Mycological Society (NYMS) Newsletter from 2017: https://www.newyorkmyc.org/newsletters/NYMS_17_2E.pdf

On May 15th last year, we took an early trip to our family cabin in the central Adirondacks to see if we could catch the beginning of morel season there.

We walked down a dirt road for a mile until we came to numerous splits in the road.

While taking a closer look through a loupe, Riitta, who was a few steps ahead, squealed with delight. She had found something special! But it was not a Morchella americana. She knew it as the choice edible Korvasieni (Finnish for “ear mushroom”). We knew it as the deadly poisonous Gyromitra esculenta, the false morel.

We knew that these were potentially deadly poisonous, but that some people do eat them when prepared properly.

However, according to Wikipedia “although it is still commonly parboiled before preparation, evidence suggests that even this procedure may not make Gyromitra escu-lenta entirely safe for consumption, thus raising concerns of risk even when prepared properly. When consumed, the principal active agent, gyromitrin, is hydrolyzed into the toxic compound monomethylhydrazine (MMH - a com-ponent of rocket fuel). The toxin affects the liver, central nervous system, and sometimes the kidneys. Symptoms of poisoning involve vomiting and diarrhea several hours after consumption, followed by dizziness, lethargy and head-ache. Severe cases may lead to delirium, coma and death after 5-7 days.” Yikes!

Rinse the mushrooms thoroughly in plenty of running cold water. Repeat once more the boiling and rinsing of the mushrooms. Drain the mushrooms and use for cooking like any edible mushroom.After doing this with all the windows open in our kitchen, trying our best to avoid inhaling the poisonous fumes, and cautiously boiling twice for 11 minutes, we cooked up the false morels in lots of butter and onions.

The article mentions Teams E2EE in the context of password sharing between employees.

Also E2EE will be an opt-in thing, but a company may enable it by default for all 1:1 calls.

Sounds like this is mostly about companies believing to be more secure if their employees share passwords only with E2EE enabled.