HN user

danielvf

9,770 karma

daniel at leancoder dot com

Long time builder: - Web applications - Embedded firmware - Blockchain applications and security.

Posts34
Comments1,385
View on HN
www.nature.com 1y ago

Thermal infrared directs host-seeking behaviour in mosquitoes

danielvf
3pts1
dps.alaska.gov 2y ago

Alaska Highway Patrol Roadkill Program

danielvf
2pts1
acoup.blog 3y ago

How to Polis

danielvf
4pts0
aviflax.com 3y ago

Avi Flax – Resume

danielvf
3pts0
blog.mro.name 3y ago

Have I Been Pwned? – DIY style

danielvf
1pts0
www.youtube.com 3y ago

GPUs to Mars: Full-Scale Simulation of SpaceX's Mars Rocket Engine (2015)

danielvf
1pts0
braino.org 4y ago

The Rise of the Stupid Terrorist

danielvf
3pts0
github.com 4y ago

Vat.sol – 9.3B dollars, 3 and 4 letter variable names only

danielvf
2pts2
twitter.com 4y ago

The dark side of Crypto Bug Bounties

danielvf
3pts0
news.ycombinator.com 4y ago

Ask HN: Software to edit code in many vertical strips?

danielvf
1pts3
laputan.org 4y ago

Big Ball of Mud Pattern

danielvf
4pts0
github.com 5y ago

Darts – Python time series forecasting library

danielvf
4pts0
github.com 5y ago

Merlin Finance Hack

danielvf
1pts0
www.damninteresting.com 5y ago

The Heroes of SARS (2008)

danielvf
2pts0
braino.org 5y ago

Why are there so many people in prison in America? (2017)

danielvf
73pts162
medium.com 6y ago

Diving into Ethereum Gas Prices

danielvf
1pts0
medium.com 6y ago

Diving into Ethereum Gas Prices

danielvf
2pts0
www.nytimes.com 7y ago

Full lunar eclipse tonight

danielvf
1pts0
oceaninfinity.com 7y ago

Ocean Infinity – Commercial Undersea Drone Swarms

danielvf
4pts1
www.astronomerstelegram.org 8y ago

X-ray Flare from Galactic Center Detected by Swift

danielvf
2pts0
upload.wikimedia.org 8y ago

Falcon Heavy Delays as a Burndown Chart

danielvf
12pts6
www.sv1afn.com 8y ago

PCB ruler

danielvf
3pts0
www.youtube.com 9y ago

Learning to Fly by Crashing

danielvf
1pts1
symas.com 9y ago

Lightning Memory Mapped Database

danielvf
4pts0
www.youtube.com 9y ago

Indistinguishable from Magic – CPU manufacturing

danielvf
1pts0
www.kickstarter.com 9y ago

Subform – User Interface Prototyping

danielvf
1pts0
www.revisionism.nl 9y ago

The Moon Does Not Exist

danielvf
2pts0
m.reddit.com 9y ago

Blue Origin Software Team AMA

danielvf
1pts0
waldo.jaquith.org 10y ago

Term Limiting the Non-Profit

danielvf
1pts0
bounty.github.com 10y ago

GitHub Security – Cash Bounties

danielvf
2pts0

The report to the government about a more than 50% fraud rate was from six years ago. The Minnesota government was not serious about dealing with problem. Most businesses would not last that long with a 50% customer fraud rate.

Yes, there were some investigations and convictions, but nothing to on a scale that would deal with problem, nor any systematic change to a level paying huge amounts of money to scammers.

Similarly, it drives me up the wall with people posting black and white "historical photographs" of history happenings, that are AI slop, and from the wrong era.

Just yesterday someone posted a "photo" of a 1921 where a submarine lost power, and built sails out of bedsheets to get home.

But the photo posted looked like a post WWII two submarine, rigged like a clipper ship, rather than the real life janky 1920's bed sheet rig and characters everywhere.

Actual incident (with actual photo): https://en.wikipedia.org/wiki/USS_R-14

In the software development / security world, someone reporting a vulnerability to you is one of the greatest things one human can do for another.

I've been burned in the long past when trying to be helpful to an activist. The accuracy of information provided was never a consideration.

So the important bit here is that the guns failed drop testing. And that's bad.

The rest of the article seems to misunderstand FMEA style "write down every conceivable bad scenario in the universe, how bad it is, and then what you have done to stop it", and then spins this as "look at all these horrible known issues they knew about". I hope a jury doesn't view it the same way, because it would be an epic bad for safety everywhere if engineers writing down a list of bad things to avoid and mitigate was forbidden by company lawyers.

As others have pointed out, this is primarily due to the American Civil War when the Medal of Honors was given out much more freely than today.

Here's the breakdown on more recent conflicts:

WWII, 625 total recipients, 13 Irish, 2.1%.

In the Korean War, there were 152 Medal of Honors, 3 given to Irish, or 1.9%.

In the Vietnam War, there were 271 Medal of Honors, 13 given to Irish, or 4.8%.

There were 36 Medal of Honor medals given out in the wars in Iraq and Afganistan. Of these, 3 are marked as Irish on that page, or 10.7%.

As almost every other commenter here has said, this is just a bad article in practically every way. It's quite possible that the problem isn't smart phones, but this article completely fails to show this.

Even the suicide data that they decide is the proper measure of mental health, and according to them proves that teens don't have a problem, shows a 2x increase in teen girl suicide.

I'm going to so something I almost never do, and flag, since this is just bait. I would love to read a case for this with a better argument however.

I handle reports for a one million dollar bug bounty program.

AI spam is bad. We've also never had a valid report from an by an LLM (that we could tell).

People using them will take any being told why a bug report is not valid, questions, or asks for clarification and run them back through the same confused LLM. The second pass through generates even deeper nonsense.

It's making even responding with anything but "closed as spam" not worth the time.

I believe that one day there will be great code examining security tools. But people believe in their hearts that that day is today, and that they are riding the backs of fire breathing hack dragons. It's the people that concern me. They cannot tell the difference between truth and garbage.

And how sure are you these weren't random hackers or trolls, but actual NK agents?

"Agents" is way too big of a word. Just cogs in a corporate theft machine.

There's a lot of reasons I'm sure, but the biggest is because before a hack they asked for help doing something simple with a crypto address that was later used to test run the 50 million dollar theft that was North Korea. And also trying to drop North Korean linked malware is another data point.

This also hits my point about both dangerous and amateurs. They pulled off pretty sophisticated heist but, had to ask for help, asked for help using a crypto address tied to the theft, and blew the cover on an identity they had been building up for a year.

Here's a twitter thread I put together of both my conversation and others with this particular account:

https://x.com/danielvf/status/1905642180749775189

I am saying they are both a credible threat and many are amateurs. Those are not mutually exclusive.

You are talking about North Korea attackers from a theoretical point of view. For many people dealing with them is just a normal part of work. It's not an unknown that needs to be worked out logically from an armchair.

I'm saying this as someone who personally chatted with a North Korea persona that later tried to drop exploits on people, and the persona belonged to hacking group with at least one 50 million dollar heist. I've also seen the screenshots on many chats with North Koreans.

These aren't spies first. They are often children of well to do, high loyalty group North Koreans. It's just a privileged job.

The skill and IQ level varies widely, from super smart to super unskilled. And these roughly get sorted out into different groups with different MO's. North Koreans aren't some uniformly skilled group. You could be targeted by a team of world class bytecode exploit geniuses who rehearses every move, or by the equivalent of Milton from Office Space.

Dissing Kim is something that is not currently widely permitted in NK. Just isn't worth personally.

Not saying no one from NK never will, but so far almost everyone will immediately stop the conversation at this point. There are plenty of crypto people who have monthly or weekly encounters with NK job applicants.

North Korea's efforts have been evolving.

In the past, they just tried to break into bank computers, then into crypto company's computers. For the last two years, they've been working on getting people into crypto companies.

But now they appear to have enough people to spare than they also have groups working on "honest" employment as remote workers, who may not even have theft as the first thing on their mind.

Here's a federal case where a US woman was convicted of helping North Korea steal the identities of 70 people, and then remote in as them, to do remote work:

https://www.justice.gov/usao-dc/pr/arizona-woman-pleads-guil...

It's buried deep in the article, but what made PC Connection amazing was the shipping.

You could phone call a human in the wee hours of the morning, and have it show up later that same day. Or pay only a little and have it into two days. Compared to every other mail-order retailer in the universe at the time, it was insane, to have such selection and speed.

In this case the only person espousing the idea of "code is law" is the hacker. Neither the blockchain's builders, nor the hacked protocol, nor the users are saying that.

"code is law" is a meme that primarily lives on hacker news. Only a tiny fraction of crypto people believe it or say it.

My favorite is one of the text files on the attacker's computer:

A file labeled "Decisions and Mistakes," in which he wrote, "Going On the run / Yes / Chance of getting caught<Payoff for not getting caught / (NA) / Risk is typically underpriced in modern world.

The camera shows night in the Wild West.

A masked man creeps through the shadows of a sleeping town.

He looks both ways, then uses a knife to unlatch a door from the outside. He slips into near pitch blackness. He moves confidently in the darkness - he's worked for this bank before, checking on their security from theft.

Out comes his lock picking tools - the bank president's office door opens with a quick rake. Cheap lock.

Inside, with no windows to betray him, he lights a candle. There in the corner stands the safe. He knows it inside and out, and has been practicing. Five minutes later, the lock is picked, and he loads up the gold, cash, and bonds inside.

He puts the candle out, slips back outside, and returns to his room at the lodging house, climbing in through the window.

The next morning, with the discovery of missing gold, the town looks like someone kicked over a fire ants nest. It only takes 30 minutes before people start wondering about "bank security expert" who had just been in the bank every day.

A crowd heads over the boarding house, growing in size as it goes.

"Did you steal our money?", they ask?

"ABSOLUTELY NOT," he replies, "I merely used my immense mental powers to out hink several flawed physical security measures, breaking no laws of physics, in such a way that the gold, cash, and bonds previously belong to you are now in my possession, and now belong to me. No theft has taken place, only the movement of certain levers, of which anyone who knew how could move, and the movement of afterwords of certain goods."

"So you stole our money!!", the town shouted.

"No, no, I just interacted with the universe according to its very own publicly available rules. No theft has occurred!"

An old cowhand, covering him with double barrel, spoke up, "Walll, guess he's right. We deserved to lose all that money. He did nothing wrong at all."

Everyone left, impressed with his genius.