HN user

castillar76

546 karma
Posts0
Comments219
View on HN
No posts found.
GTFOBins 3 months ago

The former happens a lot when people try to block specific commands for sudo, instead of taking a "permit these only" approach. If your sudoers file says you can access "all these commands but not cat", the site points out that you can still use base64 to accomplish the same ends. The effective solution is to start from "you can run exactly these commands and no others", which at least allows you to reason about what the user can and can't do.

I doubt we'll see it, but one thing I'd really like is for them to release cleaner drivers or specs for the hardware in Intel Macs. Now that they're committed to removing Intel support from the OS, it would be really nice not to consign all of that functional, high-performing hardware to the bin.

At the moment, I have a 2018 Mac Mini with a 12-core i7 and 64GB of RAM that is more limited in OS choice and hardware support than the 2012 Mac Mini sitting next to it, because the inner workings of the T2 chipset in particular and various other components have to be reverse-engineered bit by bit.

Yep, I concur: this explains a bizarre behavior I’ve noted in my Mac laptops for ages now. I have a tendency to just suspend them without rebooting for ages, especially the work one that doesn’t leave my office as frequently. Periodically, I’d come in to find the system bizarrely frozen just as they describe: TCP stack blocked up, but everything else on it behaving normally. (Well, mostly: some apps would block starting and bounce eternally, but I suspect that’s because they’re trying to make a network call while starting up and it’s blocking.) The only fix was a reboot.

It’s not a disaster, but very annoying. At least now I can just schedule a reboot every 30 days at minimum to keep things running.

The point of communication between engineers is usually to establish a mutual understanding...

I tried to let this pass in the discussion, I really did, but since it came up in various other replies I felt like I just couldn't. We need to get the hell over ourselves as a profession: the fact that someone is an "engineer" says nothing about their communications styles, needs, or preferences as a person.

There is absolutely nothing intrinsically different about two engineers discussing a software codebase and two doctors discussing a surgical plan. Or two artists discussing a mural design. Or two musicians discussing a score. Or two stone masons discussing an arch design. Two professionals are discussing a professional issue as peers, and they are both people, which means they will have preferences about their communication styles and needs and none of that is dictated or predictable based on their choice of profession. I have worked with engineers who valued social interaction buffering comments about their code; I have met musicians who valued just being told what to do better in the next run-through.

If you[0], as a person, value directness, bully for you. Express that need to your peers, ask them to respect it, be prepared to be annoyed when they don't. But don't assume or expect them to assume that that's your communication style — or that it should be your communication style — because you are an engineer.

[0] The reader of this comment, not directed specifically at the person who posted this.

Many companies miss how important this is, too: they get caught up in "but if they buy it second-hand, they're not buying our new stuff!". When people buy the stuff second-hand, though, they become Bose fans — that means when the second-hand Bose stuff dies, they're more likely to replace it with new Bose stuff. That's particularly true with audio equipment, where people become attached not only to how something works but how it sounds. If they like Bose's rather particular audio signature, they'll keep buying more.

Between that and the good-will they're getting from this move, this is making a ton of life-long Bose fans out of a lot of audio geeks. And if there's a community well-known for creating religions out of their hardware preferences...

Agreed, and it’s not just the hardware keyboard (on which I could comfortably have written an entire novel) that I miss. It had just enough access to email that I could reply to things when necessary, even if it required a bit of typing (something very uncomfortable on a screen keyboard), and later on it had access to maps and enough web browsing to be able to look something up quickly. But the lack of an enormous app ecosystem and limited Internet access meant it didn’t become a doom-scrolling device to nearly the extent my current smartphone has, so I was more inclined to either pick up a laptop and do something deliberate or put it down and go do something useful like reading.

Side note that not remembering it has nothing to do with memory deterioration. Neurons that fire together wire together: if you haven’t used that particular piece of information in a while, your brain gradually clears out links to it to make room for stuff you are currently referencing. So not remembering it is really more a demonstration of how much ICQ use has deteriorated. :)

(That's usually used to justify 'And that's why I don't need to spend time looking into the actual details and just give up')

Just FWIW, giving up wasn't my point at all. I'm just not particularly optimistic that putting anything in front of the current SCOTUS bench will result in a lot of welcome rulings. That doesn't mean we don't seek legal remedies; it just means we need to plan for them to not work out and act accordingly. I'm heartened by the amount of work people are putting in at the state level and getting appropriately creative with bending the rules — for instance, the recent effort to redefine corporate powers at the state level in order to obviate _Citizens United_.

Yeah, call me overly cynical but I'm waiting for this cycle to play out:

- CA bans face-masks for law-enforcement

- White House issues executive order requiring face-mask use for all federal law enforcement

- Both are placed on hold pending litigation, allowing the status quo (face-masks) to continue

- Litigation eventually winds up at the Supreme Court

- Supreme Court once again confirms White House can do whatever the hell it wants, Constitution be damned.

I really hate this timeline. Like, a lot.

Interestingly, it has held up quite well, too: outside of the occasional bit of old tech sticking out here and there, the whole thing could be set in 2025 with a minimum of updating. The problem the MacGuffin solves, the methods for conducting their various heists, even the inclusion of the post-Soviet Russians as a player are all still valid today.

sigh Is it that time of the year again that we start publishing these? Boy, how time flies...

Too frequently, what people (and clearly the author of this piece) mean when they say "tougher grading" is just a return to forcible bell-curve application and faculty who take out their personal insecurities and annoyance over being required to teach classes on their students. That's not making academics more challenging, it's just torturing statistics and arbitrarily modifying the race-course in order to satisfy other agendas. If you have a good teacher and a good course and more than half the class does well, you should consider making the next iteration more challenging, but you should not feel obliged to fail 10% of them because "there's always a bell-curve", nor should you be using grading as a means to "humble" your students.

I emphasized the word "consider" up there because not every course needs to be a slog up Everest, either — an "intro to X" course might well be a class in which many people do well. Some percentage of them will be people looking to make that their major, so they'll already know enough to be ahead of the curve in an "intro" course. Others will be bright people who learn well and adapt to the material. As someone who teaches classes regularly at the college/grad-school level, I try to make the content interesting and challenging, but if most of my students turn in work that exceeds standards and are coming out with a good understanding of the content, I feel like I've accomplished my goals — academia is supposed to be about learning after all, and they're displaying that they've correctly learned the content I wanted to communicate to them. I do spend time trying to re-work the course regularly (something I'm forced to do much more since the explosion of sites like Chegg...), but past a certain point if something is clearly working, why am I obliged to break it?

Note that Quakers never rejected the possibility of being killed for their beliefs, just the choice of killing others for them. Pacifism does not equate to passivism, after all: it simply means that they reject the notion of visiting violence on others.

It's also important to note that pacifism has been a divisive issue for Quakers from very early times. The play 'Sword of Peace' that's performed throughout the year in Snow Camp, NC, is about Meetings in the US struggling with the question of pacifism vs. the desire to aid their nascent country during the American Revolution. It was a debate for Friends during the US Civil War, both World Wars, Korea, Vietnam, and onwards – one of the tenets of Quakerism is the need to wrestle with those issues by listening to the 'still small voice within' rather than blindly accepting the dictates of others. For many Friends, the threat posed by British colonial rule, the Confederacy, or Nazi Germany simply outweighed the demands of their conscience not to bear arms.

Friends often refer to the anecdote of William Penn asking George Fox (one of the founders of Quakerism) whether Penn should stop wearing his sword because he was now a Quaker. Fox told him, 'wear thy sword as long as thee is able' — meaning he should give it up because his conscience dictated it, not because he was a Quaker.

That Friend speaks my mind. :)

In seriousness, I agree — it's always odd to see Quakerism discussed in other contexts, as well as running into other Quakers in other contexts outside of things like /r/quakerism or such. I do wish it were a more widespread practice, as I feel like it's such a good anodyne to the modern "I got mine, forget you" approach endorsed by so many megachurches.

I was puzzled by that, too: I'm always mystified when people share their entire screen on a Zoom call instead of just the one window they need to show me. Zoom even makes it easy to change out what you're sharing (add / subtract) any time.

Having seen a giant work meltdown stemming from a colleague's Slack DM accidentally broadcast over a Zoom call, I'm always paranoid about it.

The only place I'm insistent about source-code is things like this that need access to a ton of my data at all times. An app that only has access to the data I choose to share with it, I'm more willing to give-and-take on the show-me-the-code front.

As far as subscriptions go, a lot of devs have moved to a subscription-train model, which I really like: you pay for the subscription (which funds development and pays for support), but at any time you can _stop_ paying the subscription cost and keep the version you're currently running without further updates. That's a good trade-off to me, since I can choose to end my subscription without it becoming a catastrophic migration event that has to be carefully planned and executed fully before opting to stop paying.

I'm aware this is old-man-shakes-fist-at-cloud territory, but I don't want an AI-based AI browser with AI integration to AI the AI in all the AIs. I want a freaking browser. If I want to leverage AI features, I'll use a site for them. I don't want to chat with my browser — I want to tell it what site to open and it opens that site. I don't understand the use case for AI in the browser itself at all, and I'm really frustrated to lose a useful tool to another finance-bro-driven relentless drive to AI all the things with AI.

I'm experimenting with moving to Zen, but finding it frustrating. I think I can get around the containers-vs-workspaces-as-separate-things shift, but the last time I tried it I found it really opinionated and you lose a lot of the customization benefits of something like Firefox because it's so different.

It's seriously annoying because Arc has been just perfect for the kind of "keep each hat separate" workflows I have going. SigmaOS is the closest other thing I've used to it, but its reliance on a weird amalgam of the Safari and Chromium engines makes it behave really oddly with plugins like 1Password.

I was genuinely taken aback by visiting a restaurant website last night that was only served over HTTP. (Attempting to hit it with HTTPS generated a cert error because their shared provider didn't have a cert for it.) These days, I'd gotten so used to things just being over HTTPS all the time that the warnings in the browser _actually worked_ to grab my attention.

It's a restaurant that's been here with the same menu since the 1970s, and their website does absolutely nothing besides pass out information (phone number, menu, directions), so they probably put it up in 2002 and haven't changed it since. It was just a startling reminder of how ubiquitous HTTPS has gotten.

You're not wrong: there's definitely evidence, for instance, of savvy attackers watching the CT logs for things like newly-instantiated WordPress servers and then attacking them before the admins have set the initial password on them. (Which is really a WP problem, but I digress.) So there's benefit in not having the internals of your infrastructure writ large in public CT logs.

My problem is with the selected solution: wildcard certificates are a huge compromise waiting to happen. They give an attacker the ability to impersonate _anything_ in my infrastructure for as long as the cert is valid (and even a week is _long_ time for that). Worse, if I'm then distributing the wildcard to everything on my internal network that needs to do anything over HTTPS, that's a lot of potential attack points. (If it's just one TLS-terminating bastion host that's very tightly secured, then...maybe. _Maybe_. But it almost never stays that way.)

To me, it's a much better security tradeoff to accept the hostname problem (or run my own CA internally for stuff that doesn't need a public cert) and avoid wildcards entirely.

They’ve been making it harder and harder to serve things over HTTP-only for a while now. Steps like marking HTTP with big “NOT SECURE” labels and trying to auto-push to HTTP have been pretty effective. (With the exception of certain contexts, I think this is a generally good trend, FWIW.)

Having my ACME client munge my webserver configs to obtain a cert was one of the supreme annoyances about using them — it felt severely constraining on how I structured my configs, and even though it’s a blip, I hated the double restart required to fetch a cert (restart with new config, restart with new cert).

Then I discovered the web-root approach people mention here and it made a huge difference. Now I have the HTTP snippet in my server set to serve up ACME challenges from a static directory and push everything else to HTTPS, and the ACME client just needs write permission to that directory. I can dynamically include that snippet in all of the sites my server handles and be done.

If I really felt like it, I could even write a wrapper function so the ACME client doesn’t even need restart permissions on the web-server (for me, probably too much to bother with, but for someone like Rachel perhaps worthwhile).

You can also permanently change your default to LE — acme.sh actually has instructions for doing so in their wiki.

I rather liked using ZeroSSL for a long time (perhaps just out of knee-jerk resistance to the “Just drink the Koolaid^W^W^Wuse Let’s Encrypt! C’mon man, everyone’s doing it!” nature of LE usage), but of late ZeroSSL has gotten so unreliable that I’ve rolled my eyes and started swapping things back to LE.

Whoof — this brought back memories of endlessly typing things like...

kkk kik kik k,k k,k jjj juj juj jmj jmj hhh hyh hyh hnh hnh

...on a lovely, bangy, ink-scented IBM Selectric in typing class. Which at the time felt like a meaningless exercise, but absolutely strengthened the ability of my fingers to find the right keys in a hurry without looking at the keyboard.

This is a fascinating finding! As someone with a neurodivergent brain (and kids with it as well), I'm wondering if this has something to do with the greater degree of anxiety in neurodivergent brains, which often have trouble processing dopamine the same way neurotypical brains do.

Milk Kanban 1 year ago

Yep! And indeed, this is Who Gives A Crap. I've been really impressed with their product. I do still intend to buy bidets for the house to cut down on TP use overall, but theirs is pretty darn environmentally friendly for the product that it is, and the subscription has been just the right amount that we're not having to buy extra at the grocery to cover shortages nor winding up with stacks and stacks like a doomsday prepper.