HN user

aspensmonster

1,604 karma

Electrical Engineering student. Currently working as support staff for a web hosting company. edit: Nope. Full-time student now.

edit2: Graduating in May of 2014. Finally.

edit3: Yeah. Finally graduated. Now about those student loans...

edit4(2021-01-03): Loans long done. Haven't been here in... six or seven years?

http://aspensmonster.com

aspensmonster@riseup.net ; public key on keys.openpgp.org (a Verifying Key Server (VKS)).

[ my public key: https://keybase.io/aspensmonster; my proof: https://keybase.io/aspensmonster/sigs/bqotMpja1fdMryld2TzXlGiEXPE73DVxIM2znHtLHWc ]

This is an OpenPGP proof that connects my OpenPGP key to this Hackernews account. For details check out https://docs.keyoxide.org/advanced/openpgp-proofs/

Keyoxide: https://keyoxide.org/79895B2E0F87503F1DDE80B649765D7F0DDD9BD5

Posts3
Comments396
View on HN

Very true, but again, the RFC describes a completely different threat model with much stronger guarantees. The Kagi threat model: >- Does not provide Issuer-Client unlinkability >- Does not provide Attester-Origin unlinkability

If the Client, Attester, and Origin are all a single party (Kagi), then it follows from that threat model that Kagi does not provide Kagi-Client unlinkability, no?

Further, this is not what Kagi has advertised in the blog post:

What guarantees does Privacy Pass offer? >As used by Kagi, Privacy Pass tokens offer various security properties (§ 3.3, of [2]).

Kagi are explicitly stating that they provide the guarantees of § 3.3. They even use more plain language:

Generation-redemption unlinkability: Kagi cannot link the tokens presented during token redemption (i.e. during search) with any specific token generation phase. *This means that Kagi will not be able to tell who it is serving search results to*, only that it is someone who presented a valid Privacy Pass token. >Redemption-redemption unlinkability: Kagi cannot link the tokens presented during two different token redemptions. This means that *Kagi will not be able to tell from tokens alone whether two searches are being performed by the same user*.

As it stands, Kagi cannot meaningfully guarantee those things, because the starting point is the client providing a unique identifier to Kagi.

That said, I will point out that this Issuer-Client unlinkability issue can be solved by introducing a 3rd-party service or when Kagi starts accepting Monero payments.

Sure, but at that point, there is no need for any of the Privacy Pass infrastructure in the first place.

Also completely valid, but also not something Kagi claims to guarantee.

I disagree. Their marketing here is "we can't link your searches to your identity, because cryptography."

They believe the extension should be responsible for guarding attainer issuance partitioning. I don't think it's implemented currently but it shouldn't be too hard, especially since they currently use only 1 keypair.

If Kagi is going to insist on being the attester and on requiring uniquely identifiable information as the basis for issuing tokens, then yes, the only way to even try to confirm that they're not acting maliciously is to keep track not only of distinct keypairs, but also of public and private metadata blocks within the tokens, and to share all of that data (in a trustworthy manner, of course) with other confirmed Kagi users. And if a user doesn't understand all of the nuances that would entail, or all of the nuances just discussed here, and instead just trusts the Kagi-written client implicitly? Then it's all just privacy theater.

3. CLIENT uses it's identity to request token from ISSUER/ATTESTER

The ISSUER and ATTESTER are different roles. As previously quoted, "Clients explicitly trust Attesters to perform attestation correctly and in a way that does not violate their privacy." The RFC is explicit that, when all of the roles are held by the same entity, the attestation should not rely on unique identifiers. But that's exactly what a session cookie is.

You can see how the ISSUER/ATTESTER can identify the client as the source of the "anonymous request" to the ORIGIN because the ISSUER, ATTESTER and ORIGIN are the same entity, and therefore it can use a timing attack to correlate the request to the ORIGIN (1.) with the request to the ISSUER/ATTESTER (3.).

No timing or spacing attack is needed here. If I have to provide Kagi with a valid session cookie in order to get the tokens, then they already have a unique identifier for me. There is no guarantee that Kagi is not keeping a 1-to-1 mapping of session cookies to ISSUER keypairs, or that Kagi could not, if compelled, establish distinct ISSUER keypairs for specific session cookies.

Seeing as I'm not getting any traction in the fediverse (https://tenforward.social/@aspensmonster/113999217587309328), maybe I can ask here instead.

=================================

From their blog:

As standardized in [2 - 4], the Privacy Pass protocol is able to accommodate many “architectures.” Our deployment model follows the original architecture presented by Davidson et al. [1], called “Shared Origin, Attester, Issuer” in § 4 of [2].

From [2] RFC 9576 § 3.3 "Privacy Goals and Threat Model" :

Clients explicitly trust Attesters to perform attestation correctly and in a way that does not violate their privacy. In particular, this means that Attesters that may be privy to private information about Clients are trusted to not disclose this information to non-colluding parties. Colluding parties are assumed to have access to the same information; see Section 4 for more about different deployment models and non-collusion assumptions. However, Clients assume that Issuers and Origins are malicious.

And From [2] RFC 9576 § 4.1 "Shared Origin, Attester, Issuer" :

As a result, attestation mechanisms that can uniquely identify a Client, e.g., requiring that Clients authenticate with some type of application-layer account, are not appropriate, as they could lead to unlinkability violations.

Womp womp :(

This is not genuinely private in any meaningful sense of the term. Kagi plays the role of all three parties, and even relies on the very thing section 4.1 says is not appropriate: to use mechanisms that can uniquely identify a client. They utilize a client's session token: "In the case of Kagi’s users, this can be done by presenting their Kagi session cookie to the server."

Frankly, that blog post is disingenuous at best, and malicious at worst.

=================================

I want to be wrong here. Where am I wrong? What am I missing?

The signatures on the Actas are digital, not ink.

Yes, each acta has a digital signature, gathered ahead of time. It is there to compare against the inked signatures signed by the members of the mesa, after confirmation that the sampled ballots converge toward the computer's results. The ballots are the source of truth here, not what the computer receipt says. And the link between the ballots and the receipt are the inked signatures (or fingerprints) of the members of the mesa.

What's more likely, that the opposition forged tens of thousands of receipts in less than a day, or a dictator reported fake results to remain in power?

The opposition need not have been the one to hack the machines. A third party could have done that. And again, the opposition haven't released "forged" receipts, merely receipts that have not actually been certified. How they have obtained those receipts is an open question at this point.

Receipts, mind you, copies of which are given to each witness from the top-three political parties, at any point now could have been called into question but not a single counter example has been shown.

90% of their receipts lack any inked certification from the presidents, secretaries, members, witnesses, or operators of the mesas on the ground. That should be garnering an enormous amount of skepticism from a crowd that is normally adamant about not trusting computers during elections.

Long time no see, HN! As a techie-turned-communist I'm vested in this story, so I decided to follow along:

https://x.com/aspensmonster/status/1818859550516129814

I was able to follow their guide to scrape the resultadosconvzla.com website, and ended up with ~22,000 JPGs of receipts. A random sampling of them shows that, for the most part, they contain no actual inked signatures and/or fingerprints that would be present on the receipts signed by the poll workers. Some of the receipts do have signatures and/or fingerprints, but not most of them. Most of them look like this:

https://octodon.social/deck/@aspensmonster/11288491762219446...

I.e., it looks like they asked a voting machine to print out a receipt, and it did. Then, they scanned the receipt in and put it online. The important part though, where individual poll workers scattered across hundreds of stations all over the country all sign their receipts in ink, for comparison against the computerized signatures gathered beforehand, does not appear to have happened for most of the receipts that the opposition has in possession.

I'm frustrated that the Maduro government has released highly improbable numbers. And I'm frustrated that it (certainly appears that) the opposition doesn't have nearly as much validated data as they claim to have. My gut tells me that the CNE got hacked, that the results are thus untrustworthy, and that they'll need to re-run the election, preferably by pen and paper. But the Maduro administration didn't want to face up to that fact and so, made up numbers instead -__-

I come back a few weeks or months later, and find that HN is still silently killing NSA stories. This was near the top of the front page, until I refreshed and it disappeared, ranked 25 among the new stories despite 13 points and 2 comments.

Stay classy, mods. Signing off now :D

Edit: Currently ranked #72, probably well on its way to the fourth or fifth page. At least on https://lobste.rs, I might be able to see a modlog explanation if it gets removed there too.

An hour at the helpdesk can help you discover great product ideas, feedback and suggestions - a gold mine when you're chasing product-market fit.

An hour with your front line support --or bothering to read through or even solicit their thoughts-- can do just as much for you, multiplied by however many support members you have. If anyone knows the flaws of your product, it's the guys and gals on the front lines that have to make excuses for it every day.

A support rep can only go so far. Support agents often don't have the visibility in an organization to go back and fix bigger process problems. Only you can.

Speaking as someone who has done support before, and will likely continue to do so in the future in one way or another: you've got this all backwards. If anyone knows how screwed up a process is in your organization, or how broken your product is, it's the poor saps like us that are tasked with carrying those processes out and supporting those crappy products. Support agents don't lack "visibility." They lack authority and autonomy to handle issues on their own without fear of reprisal for not using the proper openers and closers and not keeping all calls under 12 minutes so they hit that magic 5 calls and 10 chats an hour marker. For all the talk of "horizontal" and "flat" organizations, most support shops have a very clearly defined hierarchy and strict control over lateral movement that blows up the very "gold mine" you're chasing after.

When employees see their CEO on Support, they realize it's absolutely essential for them to go above and beyond call of duty to make sure their customers are more than just satisfied.

If you want "above and beyond," be prepared to compensate for it: more-than-COL raises, PTO, TOIL, year-end bonuses, above-average salaries/wages. You're the CEO. You'll go above and beyond because at the end of the day your compensation is tied directly to how well the business does financially. Front line support? We get paid the same amount no matter how easy or rough the day was, no matter how "above and beyond" we went. If anything, going "above and beyond" just means "this call will take me an hour," which means "my metrics are totally fucked for the rest of the day and possibly the week." And that could mean losing your job. Or it could just be justification for denying a raise or promotion.

===================================

Overall, I don't think you'll really get the experience you're looking for as a CEO. Unless you insist that your support manager treat you like any other front-line support tech, with all of the same metrics, and expectations, and "rough" customers, and "in-house" problems, and hours, and compensation, and fear of reprisal, you're going to miss things by simple virtue of the fact that what you're experiencing simply isn't what actually occurs on a day-to-day basis.

As of starting to write this comment, there are more comments on this submission bickering about Tesla's PR than there are about the actual merit of the matter:

  * "Aren't people starting to get tired of Tesla's constant defensiveness?"

  * "something about the tactics they use seem... off."

  * "It's almost like they're bullying people they don't like..."

  * "But. What happens in 5 years when Tesla is 10x bigger than it is now..."

  * "this blog entry leaves a sour taste with me."

  * "Yeah, this does not feel good to me. I get the PR angle but this feels not right to me."

  * "Thank you HN for hosting another Tesla public service announcement."
I think the amount of flak Tesla gets on a constant basis from numerous entities that want to see Tesla dead more than justifies their aggressive public stance on these kinds of matters. The lawyer involved is apparently a self-proclaimed "Lemon Law King," which should raise a red flag all by itself. Litigious opportunism isn't usually celebrated by the HN crowd and I don't see why an exception should be made here. HN user yock has also pointed out that the lawyer involved in this suit is making a claim that the lack of franchised dealerships strengthens his justifications for opening a case, in that a lack of a dealerships for Tesla vehicles makes invoking Lemon Laws harder for consumers. Given Tesla's recent battles with states over having to sell their vehicles through middle men, I agree with yock's assessment that this is the real motivation for the suit --to add ammo to the case that Tesla must submit to the dealership franchise model-- rather than a genuine concern for a customer's rights under Lemon Laws to reverse a purchase of a vehicle.

But if none of that is enough, there's these gems:

Ultimately, Tesla service applied non-tamper tape to the fuse switch. From that point on, the fuse performed flawlessly.

After investigating, they determined that the car's front trunk had been opened immediately before the fuse failure on each of the three occasions.

I'm all for stomping on double-speaking weasel-wording bullshit. It's not OK when the NSA does it, or the State Department does it, or anyone else does it. That goes for Tesla too. But for some reason it seems a good chunk of the readers here are stomping on what is absolutely the wrong target. Tesla is speaking truth to power and attempting to disrupt a dinosaur of a market that is pulling out all of the stops in a truly glorious effort to kill Tesla off. Could we all drop the pseudo-skepticism act and take note of the plain truth as it is?

Between Squirrelmail, Horde, and Roundcube, I always liked Roundcube the most. It was more polished than the others, at least, and was far easier to support end-users with. Glad to see the project is still alive :D

I'd say Google has its own share of responsibility for the lack of adoption of APNGs. Chromium doesn't support them out of the box.

Glad to see this finally making it on the front page. I'm particularly impressed with the actors' ability to capture the subtle facial expressions and other mannerisms that the various characters tend to make in real life under various situations.

Direct YT link: https://www.youtube.com/watch?v=BKorP55Aqvg

============================================================

My favorite bit...

PHB: "That's it. Now you've confused everyone. So what exactly is stopping us from doing this?"

Anderson the Engineer: "Geometry."

Client: "Just ignore it."

PHB: "We have a task. Seven red lines. It's not 20. It's just seven! Anderson I understand you're a specialist of a narrow field; you don't see the overall picture. But surely it's not a difficult task to draw some seven lines."

Walter the PM: "Exactly! Suggest a solution. Now, any fool can criticize --no offense-- but, you're an expert. You should know better."

2048 As A Service 12 years ago

Edit: It's missing a snarky game over message. Something like "you pivoted too late" would be perfect for a game like this, don't you think?

"Unstoppable! You are the next Rap Genius!"

"Growth Hacker Extraordinaire! You are the next Optimizely!"

I like it more than the other offers that April Fools has provided thus far. Somewhat reminiscent of this thread: http://chan.installgentoo.com/g/thread/38087806

Question for kasey_junk, seeing as s/he is taking questions :D

Lewis: "This form of front running is legal. It's legalized front running. It is crazy that it's legal for some people to get advance news on prices and other --[information on] what other investors are doing. It's just nuts. It shouldn't happen."

Do you agree or disagree with Lewis' assessment of the state of HFT?

It sounds like that's exactly what the market needs though. That there is a "serious bias" against it, that exchanges don't want to have to explain the math to traders --surely the traders would get it?-- is at once understandable and irrelevant.

I'm pretty sure HN keeps an eye out for upvote and downvote behaviour like that. We don't know for sure, of course, because moderation is a complete black box and I don't believe there is any surefire way to guarantee just what code is actually getting executed server side. And of course there are the design choices to consider, like

"only those with X karma get to downvote,"

and

"everyone with less than X karma gets their comments pended first,"

and

"anyone above the pending threshold that is too liberal with their approval of pending comments will have their approval privileges revoked,"

and

"only those with X karma get to flag,"

and

"anyone above the flagging threshold that uses the function 'incorrectly' will lose the privilege,"

etc etc ad nauseam.

And we think ourselves so superior to other internet cultures.

Still, enjoy the handful of upvotes you got from me :D And feel free to downvote my comments once you hit the threshold (last I checked, it was 500 karma). I'm actually curious to see how long it would take to fall back down to 0. Mentioning reddit is a good way to get downvotes (as you can see) especially if you highlight this community's insistence on just how much better it is than reddit. Using "low/no-content" comments is another good way. That's how we distinguish our memes from everyone else's: everyone else's "don't contribute to the discussion." As if our own memes were somehow high art and reddit's the lowest of brows.

Of course, my account is more than a year old. So, according to The Rules, it seems I can "submit comments saying that HN is turning into Reddit," but certainly cannot submit comments stating otherwise.

But do feel free to downvote this as well. I am, after all, "[baiting] other users by inviting them to downmod [me]" and "complaining about being downmodded."

Wow! I've managed to infuriate someone enough to downvote my OTHER comments too! That seems strangely reminiscent of behaviour I see on those other, filthy casual websites.

Fuck all y'all. I consider this mission an 11/10 success.