Yes. And the malware could be polymorphic. Or there could be multiple versions of the same "core" out there. It's not clear to me how sophisticated virus (malware) scanners for OS X are with dealing with that.
HN user
clinton_sf
Is there any diagnostic tool out there to determine if you've been infected?
From what I can tell, they posted the SHA256 of the offending binary under the IOCs section of that web page. So you should be able to do this in the root of your home directory to detect if such a file exists:
# find . -type f -print0 | xargs -0 shasum -a 256 | grep 664e0a048f61a76145b55d1f1a5714606953d69edccec5228017eb546049dc8c
Thought experiment: let's say that Apple doesn't know what the suspect in a law enforcement investigation is suspected of. If the request is between revealing the identity of a user from a particular IP address (which is probably easy for them to determine), or giving away (essentially) a master key to decrypt all iPhones, which would it comply with? I think it would have complied with revealing the identity of a user pretty much every time, even if the suspect was a terrorist, but not necessarily to give away the master key for all iPhones even if the suspect was an intellectual property pirate.
Maybe it is a coincidence being posted on HN 7 months after the article was written, but the NY Post article is a great commentary on what is in the news these days:
https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...
Duplicate of https://news.ycombinator.com/item?id=11275505
Take a look at Jocelyn Goldfein's software engineering career ladder chart:
https://medium.com/@jocelyngoldfein/a-very-very-rough-approx...
I actually don't see a problem with Apple's MFi program. Back in 2013, a woman in China was electrocuted by her iPhone 4 due to a non-OEM charger:
http://www.scmp.com/news/china/article/1283818/woman-electro...
To quote from the article: “Knockoff chargers sometimes cut corners,” Xiang said. “The quality of the capacitor and circuit protector may not be good, and this may lead to the capacitor breaking down and sending 220 volts of electricity directly into the cell phone battery.”
Apple trying to enforce its quality standards on the charging system seems completely reasonable -- yes, even if it means that the end-user has to pay for the quality. Most Apple customers are actually looking for that quality and willing to pay for it.
There is a great teardown analysis of Apple and knock-off chargers at Ken Shirriff's blog:
http://www.righto.com/2014/05/a-look-inside-ipad-chargers-pr...
http://www.righto.com/2012/05/apple-iphone-charger-teardown-...
This approach solves a few problems:
1. Apps in the Mac App Store can't ship their own kernel extensions along with the app. With the framework, it may not be necessary for virtualization products to do that -- enabling them to ship in the Mac App Store.
2. Compatibility breaks between OS version updates. Every time the kernel interface changes, someone shipping a kernel extension will need to ship an update as well. With this approach, it's possible to keep compatibility and let the implementation of the framework do all the heavy lifting.
3. If virtualization products are going to be in the kernel in order to run, it would be better for the host OS vendor to supply official supported interfaces instead.
Just as Intel is making it easier to do virtualization on their chips with VT-x and VT-d, Apple is making it easier to implement virtualization with Mac OS X as a host with this framework.
While it may not be covered under FDIC, Federal Regulation E might come into play here, according to this research paper:
Is Everything We Know About Password-Stealing Wrong? http://research.microsoft.com/pubs/161829/EverythingWeKnow.p...
"Federal Reserve Regulation E guarantees that US consumers are made whole when their bank passwords are stolen. The implications lead us to several interesting conclusions. First, emptying accounts is extremely hard: transferring money in a way that is irreversible can generally only be done in a way that cannot later be repudiated. Since password-enabled transfers can always be repudiated this explains the importance of mules, who accept bad transfers and initiate good ones. This suggests that it is the mule accounts rather than those of victims that are pillaged. We argue that passwords are not the bottle-neck, and are but one, and by no means the most important, ingredient in the cybercrime value chain. We show that, in spite of appearances, password-stealing is a bad business proposition."
I don't think this is Apple trying to be difficult: SSD TRIM is buggy between all the different vendors (today even Ubuntu enables it only for Samsung and Intel SSDs by default), they want to guarantee that it works by whitelisting what they ship with, and the mandatory driver signing seems like a security improvement. If some third party wants to ship a signed kernel extension that works with their specific SSD (or generic ones, even) and supports TRIM, that should be possible.
FWIW, there is a third party SSD drive that works with Apple's default drivers for TRIM support; I suspect they're doing some sort of identifier spoof to fool the whitelisting code: http://www.angelbird.com/en/prod/ssd-wrk-for-mac-929/
Take a look at http://www.broadbandmap.gov/ and plug in your address to see what your options are.
I'd suggest Monkey Brains ISP: https://www.monkeybrains.net/wireless.html
It's not on the national broadband list, but they claim SOMA is on their coverage map.
Or also try WebPass, based in SOMA: http://webpass.net/residential
I didn't give this article much weight -- Bennett called up Christensen on the telephone and got an emotional, ad-hoc response. This isn't a well thought out, polished, official response from Christensen. Hopefully we'll see one later on.
I had to step back and think of examples that would qualify for what Christensen is talking about. I think I found a few, so I can't take Lepore's piece at face value.
If that's what you're trying to do, you might want to explore cross compiling Mac apps on Linux:
http://stackoverflow.com/questions/2786240/how-to-compile-in...
See also Mozilla Bug 921040 - Cross-compile Firefox for Mac on Linux. https://bugzilla.mozilla.org/show_bug.cgi?id=921040
That's nice for a fanless i5. But a fanless i7 is already out there with some great specs, though it's pretty expensive.
http://www.tinygreenpc.com/microsvr.aspx
Power: 8W – 35W (Depend on system configuration and load)
What graphics card does Mac OS X think it's using when running in QEMU/KVM as you describe? Are you able to get different (more than 1200x800) resolutions? One of the major shortcomings of most of the "Mac OS X in a guest" efforts is that 3D hardware acceleration is disabled (unimplemented) in the guest video driver, which the Quartz compositing engine assumes will always be there. This results in weird video behavior, like certain things not showing up or for FLV video to not render in a web browser. Are you able to view web video with this Mac guest?
he's actively asking people to send money to him in a way that skirts the lien the irs has filed against him. if the irs notices this and gets pissed, it absolutely puts his 'helpers' in harm's way.
I'm not sure that's actually true. Is it? If you donate money[1] or buy something from him, you're giving him property; whether he is properly reporting that property and paying any necessary tax on that is his issue -- he's not asking you to enter into a conspiracy to hide anything.
At the very least, he could use cash donations to pay off whatever lien is against him. And according to [1] below, the recipient of the donation isn't the one paying taxes on the donation amount.
[1] The gift tax doesn't apply for amounts under $14k or so per year, according to Wikipedia: http://en.wikipedia.org/wiki/Gift_tax_in_the_United_States
It's breathtaking to see such a blunder: a Forune 100 company telling nearly 20% [1] of its installed user base, it's second largest desktop OS customer base, to stop and make a financial decision about what to do, instead of giving them a low-cost, path of least resistance option to continue in some way similar to the status quo. For many people still on XP, the users are not technical enough to understand how to do an OS upgrade or how to migrate user data to a new machine, let alone understand why they would want to when the current system appears to work fine.
I'm surprised that they're not trying to monetize their current XP user base with some sort of "XP extended support" fee-based subscription so they don't force users to look elsewhere for a desktop OS -- between Windows 8's blunders and a Mac, I suspect many of those XP users will consider a Mac. Or simply by offering a ~$40 upgrader app to get to Windows 7 "lite" for XP users that works on the same hardware and drivers...
[1] http://techcrunch.com/2014/04/02/discontinued-windowsxp-stil...
StartCom/StartSSL thwarted a recent hack attack, according to: http://www.informationweek.com/attacks/how-startcom-foiled-c...
Their due diligence on verifying who is requesting the cert probably helped; but I've seen some people complain that it's not a quick/easy process: http://danconnor.com/post/50f65364a0fd5fd1f7000001/avoid_sta...
I don't see this as a "youth" problem. To reframe the discussion, this is about the ever present cycle of innovators that become incumbents and innovators that disrupt incumbents. If you haven't heard of Clayton Christensen's book, The Innovator's Dilemma, it's a good read.
While some of the people mentioned in the article are young (Bicket and Miswas of Meraki are in their 20s/early 30s), other entrepreneurs in the news today are not: Acton and Koum of WhatsApp (recently bought by Facebook for $19B) are in their late 30s/early 40s.
Google's founders, Larry and Sergey, are 40.
Twitter: Jack Dorsey is 38. Biz Stone is 40. Evan Williams? 42.
Steve Jobs' best work at Apple was when he was in his late 40s/early 50s. Arguably, the success of Apple today is due to Steve's leadership, not due to the company being saved by some young person who breathed new life into the company as this quote from the NYT article suggests: "The most innovative and effective companies are old-guard companies that have managed to reach out to the new guard, like Apple". (If you disagree with this, look at Apple between 1985-1997 and 2011-present, where plenty of young (and old) people worked at Apple)
To simplify the claim here: there are those who know how to adapt to the current situation and those that don't (or can, but don't care). Some of those who know how to adapt are "old guard" and some are "new guard" -- it's not the age that is the determining factor.
As for other items in the article, like the lack of young people "help[ing] cure cancer or fix healthcare.gov", there are plenty of old (older) people who don't want to work on those problems too.
As for the claim that startups are the bastion of youth, that's not true either. I see plenty of 40-something founders and startup employees. While young startup people can easily afford to do a startup because their financial commitments are low (e.g., no mortgage or family to support), the older folks tend to do a startup for a similar reason: they've earned and saved a chunk of money where they're no longer worried about money and they can take on more risk.
The journalist spin on this is misleading, especially the part about "speculatively shipped to a physical address".
It's common in supply chain management to optimize the ordering and placement of items before they are "consumed". If you store everything in one central location, there's an increased cost to quickly move it to the final destination. If you distribute some items to regional hubs, there's a (wasted) cost to doing that too, especially if you ship more or less than is actually needed. They try to estimate what items go where based on their historical data: what people buy where and how often. They could speculatively do this with "people who buy this will often buy that" data too.
In this case, they look at the cost of returning an excess item from a regional hub to an upstream distribution center and try to recoup the cost by selling to someone near it's current location at a discount that is less than the cost of moving it around further.
From what I understand, the mechanisms for this law are already in place and aren't much of a problem; any Apple customer already has this with the "Activation Lock" feature, and any carrier can already deny service based on a blacklisted ESN. The proposed law, at least in spirit, would require carriers and phone makers to honor your request to make your device unusable when you report it as stolen. It isn't so much that the government is going to be making technology and forcing everyone else to use it -- it'll let the private tech industry do whatever it needs to do to comply with the proposed "please brick my stolen phone" law.
I can understand how handset vendors other than Apple would have a problem with this. For example, where is the "activation lock" setting stored and who controls it? The handset vendor (Samsung, LG, etc)? Google (since it's an Android phone)? The carrier? Who deals with the customer when the device is stolen? That level of coordination would be a mess to deal with if you don't already control most of the stack and user experience like Apple does.
As a side note, Apple already does this with Mac hardware too: https://discussions.apple.com/message/19010713 .
Send you résumé over to jobs@quakelabs.com and reference Hacker News. I'll take a look. We're based in Mountain View.
From an earlier Hacker News post: The money is in the Bitcoin protocol https://news.ycombinator.com/item?id=6823394
pasted below: Alternative chain examples
1. Peer-to-peer, social trading of “normal” (government-backed) currencies without the need of a centralised clearing house. Called a ripple exchange, it is based on a design loosely inspired by the Ripple monetary system.
2. A decentralised, open DNS (Domain Name System) using the .bit Top Level Domain. This is an alternative DNS root based on Namecoin and outside the official DNS root administered by ICANN. Early work in this area included discussion on BitDNS.
3. A service called Proof of Existence which is a sort of notary public service on the Internet. It easily and cheaply (0.005 BTC) allows people to verify ownership, integrity, and that a document existed at a certain point in time.
Building on the Bitcoin protocol examples
1. Bitmessage for encrypted peer-to-peer communications, including hiding metadata like the identity of the sender and receiver, from eavesdroppers. The message transfer mechanism is similar to Bitcoin’s transaction and block transfer system, requiring a ‘proof of work’ for each message.
2. Zerocoin that augments the Bitcoin protocol to allow for fully anonymous currency transactions by placing anonymity technology into the Bitcoin network itself. Zerocoin uses Bitcoin as a “distributed, online, append-only transaction store.”
3. Gliph adds secure mobile communications to the Bitcoin landscape. It edges into controlling digital identity “that shares as many (or as few) facets of yourself as you want to.”
but actual market decisions that drives such profits is the real source of truth.
Right. Cue up the 2008 financial crisis.
may be it isn't profitable enough because the other problems they chose to focus on is more "important" in the eyes of society.
Back to my original comment that this is a self-correcting problem: https://news.ycombinator.com/item?id=6771657
But I doubt that society at large evaluated that certain things (that are currently very profitable) are more valuable than avoiding the situation of running out of effective antibiotics. I posit that there's so much information overload, this problem is simply overlooked by the masses (due to human nature) until it's too late.
Most things in the world eventually self-correct. But before that happens, many people will be hurt and die in the process.
Yes, I understand that, but my point is that this isn't some apocalyptic end to the world as we know it, and it helps to take the long view of how it will unfold and prepare accordingly. As insensitive as it sounds, it's more productive to look at why something bad happened and what we can do about it rather than lamenting that bad things happen in the first place.
Sadly, when you look at large groups of people, it's human nature to ignore problems that don't have short term profitable solutions.
People have known about this problem for decades and are unable to persuade the decision-makers to proactively prevent this scenario from happening; it'll be interesting to see how it unfolds as an emergency (probably not very well), and what will be done differently after the emergency is handled.
Perhaps non-profit groups like the Gates Foundation will work on antibiotic drugs in the future, simply because for-profit pharmaceutical companies aren't going to touch it because it isn't profitable enough. Or perhaps an international group will try to tackle this problem, similar to how they try to tackle other global problems (which isn't promising: look at how we're globally handling environmental issues).
As for looking at this problem now, it may be profitable for people to pick up the dropped research in gram-negative antibiotics. The Hacker News crowd would most likely be interested in the bioinformatic aspect of this problem, modeling gram-negative bacteria and its interaction with various compounds.
I suspect this problem will self-correct. It's not that we've run out of choices: it's partially that pharmaceutical companies had the narrow view that developing new antibiotic drugs is less profitable than developing drugs for chronic illness (e.g., to control cholesterol); once catastrophe hits due to bacteria being resistant to all current drugs, it will be extremely profitable to work on this class of drugs again. Take a look at this interview with Dr. John Rex M.D., (V.P., Clinical Research, AstraZeneca) [1]
"Dr. JOHN REX: If you need an antibiotic, you need it only briefly. Indeed, that’s the— that’s the correct way to use an antibiotic. You use it only briefly.
And from an economic standpoint of a developer, that means you’re not— you’re not getting the return on the investment you’ve made because you’ve spent between $600 million and a billion dollars to bring that new antibiotic to market."
[1] http://www.pbs.org/wgbh/pages/frontline/health-science-techn...
For what it's worth, journalists can and do talk to subject experts. Whether they quote their sources in a casual non-scientific article for Wired magazine is another thing.
For more info (e.g., of a journalist talking to doctors and such), take a look at: http://www.pbs.org/wgbh/pages/frontline/hunting-the-nightmar...
It depends what you value more: best or cheap.
For cheap, there are plenty of options: the San Francisco public library has many branches, is clean, quiet, and does not restrict what protocols you use on their wifi. (e.g., ssh is allowed) If you're willing to pay for a coffee, the Capital One 360 Café at 101 Post St also has wifi with unrestricted protocols, as well as any Philz coffee location.
For something that resembles an office, try NextSpace, which is $25 for a day-pass, at 28 2nd Street near Market Street.
The answer to this is complicated and I'm not going to try to cover all the angles of it, so I'll simplify the answer with this: it depends on what you value and what you're willing to pay a premium for; if you care deeply about the optimal ratio of commodity functionality versus price, then the iPhone 5s (or most any Apple product) is probably not for you. That is NOT meant to be a snobbish, classist, elitist jab and I mean that respectfully.
In a similar vein, yes you could do similar things on a $500 Lenovo laptop compared to a $3000 Retina Macbook Pro; driving a Tata Nano or Honda Civic will get you to your destination just as fast (within reason) as a nicer car. Buying the cheapest food possible will get you calories just like more expensive food... the list goes on and on with other things (clothes, coffee/tea/wine, jewelry, etc).
So ask yourself: what did Apple value when they designed and manufactured the iPhone 5s, which are different than the values used to produce competing products? If those values are similar to your values, then it's worth every penny.