HN user

firebacon

338 karma
Posts5
Comments99
View on HN

Interesting to consider the total complexity of that approach though.

An iterative fibonacci solution runs in linear time. Calculating the N'th fibonacci number requires O(N) serial operations.

A fully parallel, recursive solution without memoization requires that each value in the sequence is computed more than once. Consider the example of fib(4):

   fib(4) = fib(3) + fib(2)
   fib(3) = fib(2) + fib(1)
   fib(2) = fib(1) + fib(0)
You can see, that if we run this in parallel, the value of fib(1) has to be calculated twice. As the tree of operation branches out, more and more duplicate calculations are required.

A quick google suggests that the time complexity of the recursive approach is O(2^N).

You don't need any specific instructions. The hex encoded double contains the final binary representation of the floating point number. So no conversion is required to load it, except maybe for swapping around bytes on some architectures. Conceptually:

    double v;
    memcpy(&v, "\x00\x00\x00\x00\x00\xe4\x94\x40", sizeof(v)); // LE

Does the chance of seeing a vaccine-defeating mutation increase after injecting parts of the population with a less-effective vaccine (compared to the baseline scenario of no vaccinations at all)? What mechanism is responsible for that?

The answer is only obvious to me if both the original virus variant and the mutation compete for some kind of shared resource. But that shouldn't be the case here, right?

Unless I'm misinterpreting the tweet, she suggests that a partial vaccination campaign will somehow lead to a higher rate of mutations?

As a non-biologist, it's not immediately obvious why that would be the case. What's the mechanism that increases the chance of mutations in vaccinated hosts?

Well you're right, I misremembered. Also I just looked it up and I think it was actually a Panda and not a Punto (only owned it for a short time around 2009 and it was already close to worthless when I bought it). Still, I think it doesn't change the point much: at 500kg you're closer to a small car than to the lightweight moped for which these exceptions were made...

Some (maybe only slightly related or relevant) background:

In Germany, there is a pretty serious problem with dangerous driving and street racing: In the last ten or so years, there has been long string of downtown races that have killed numerous innocent bystanders in all major German cities.

This went so far that recently the German law has been changed and killing somebody while participating in a street race is now treated as "first degree murder". This year, the first conviction under this law was upheld by the German "supreme court". Still, street racing is on the rise.

Now, the uncomfortable truth is that the demographics of the offenders skew towards young German men that do not consider themselves to be culturally German or even European.

I am not trying to enter a debate on the how much value different cultures place on life.

What I am trying to do is to point out that when you consider how the human mind works, it is almost inevitable that these issues are starting to appear to be interlinked. What you have here is a very hot debate on road safety, which is already a topic that is very emotionally charged for a lot of people. Considering that there does actually seem to be a cultural correlation, it is somewhat predictable, if sad, that the public debate around here is now slowly starting to turn into an cultural/ethnic argument.

My personal opinion is that we need a massive crackdown on street racing and dangerous driving to prevent this topic from turning into yet another ethnic fault line in Germany.

Pyrrhic Victory 6 years ago

Unemployment in Germany didn't go up much because they reclassified the "unemployed" as "furloughed". The end result is the same though, recipients are living entirely off government assistance.

7.3 million germans are currently fourloughed. That is 21% of the workforce!

I also feel like the project recommendations on Github have become really... stale.

At some point, the sidebar would display a new set of projects almost every time you hit refresh. Now, there hardly seems to be any rotation at all; I've been seeing the same projects for weeks. Somebody should check if the cron job for updating the list has crashed :)

In Germany there are, as far as I know, also a number of ways to get an exception. The normal way to attend Uni if you did not get the right Abitur from your high school however is to simply repeat high school from age 18 to ~21. This is called "Zweiter Bildungsweg" (Second Path to Education).

There is the colloquium doctum in the Netherlands, but you're still at a relative disadvantage if you're not put on the right track (VWO) as a child. So while the Dutch do a lot of things much better than the Germans, I think this one is only marginally improved.

Also cost of living in the Netherlands is far from cheap and as far as I know the Uni doesn't really help with that. So I'm still not sure how one would go about completing five or six years of full-time studies here without any financial assistance, either from their parents or by taking out a loan?

At the end of the day, it's always possible to go to Uni somehow, even if you had the bad luck to get sorted into the wrong bucket as a child. But it obviously takes much more effort than would have been required if you were placed in the right high school from the start. And even once you are admitted to Uni, not having a steady stream of passive income puts you at a huge disadvantage compared to most of the other students that do have it.

So my point is that, even in Europe, having wealthy and well-educated parents still puts you at a huge advantage when it comes to education. It's not exactly a solved problem here either.

The other difference of course is that in Germany, only a fairly small proportion of high school students is even allowed to go to Uni.

People that were not placed into Gymnasium at age 8 are set on a course where, once they turn 18, do not get to go free Uni; they simply are not allowed to go to Uni at all!

Also the problem of cost of living while studying isn't exactly trivial. Accommodation, food and participating in general student life all are things that cost a lot of money. You will need at least 1k-1.5k EUR net per month, which means earning 2k or more gross. That's not exactly easy to do on the side, since most degree programmes are full-time only; you are expected to put your 40 hours a week towards the degree and not some other job to finance yourself.

When polled, 87% of students answered that they were dependent on financial support from their parents and 12% received state-sponsored loans [1].

So let's not kid ourselves. The question of whether you will go to Uni or not, in Germany, also depends to a very large degree on who and how wealthy your parents are.

Statistically speaking, your chance to go to Uni is 27% if your parents are blue collar workers. It is 79% if your parents also hold academic degrees. If your parents have no professional training at all, the probability is 12%. [2]

So maybe we should focus on our own issues first ;)

[1] https://www.sueddeutsche.de/bildung/studienfinanzierung-so-k...

[2] https://www.forschung-und-lehre.de/lehre/nichtakademiker-kna...

[dead] 6 years ago

Not that long ago someone decided that it is not a problem to ignore humiliated people who came back home from battle fields of I World War straight into poverty, however there was a certain Austrian painter, who managed to attract them very skillfully. The rest of the history is well known.

That is exactly why there is so much outrage. People have been predicting that history ryhmes for a long time, but now it is actually starting to happen. The CDU's decision to rather cooperate with the AFD than supporting a socialist coalition is a paradigm shift. Yesterday's decision has shown that the nazis are back as a bona fide political power.

[dead] 6 years ago

Maybe I should have added that I actually hold a german passport. I realize that posting a hitler quote here looks really weird, but before instantly writing it off as a case of Godwin's law, do your research and check out what the AFD actually stands for. Sadly, the quote is extremely relevant to what has happened in Thueringen yesterday: It reminds us that this is how it all started before. That is why even conservative german media outlets have picked up on it.

The quote is from 1930, which is still at the beginning of Hitler's rise to power. In it, he reckons that the NSDAP had now become a major political force since the established parties in the state of Thueringen were, for the first time, unable to stand up a government without the votes of the NSDAP. This is pretty much exactly what has happened yesterday.

What's worse is that the "christian" conservative party, which is the largest centrist force in Germany, has basically given their tacit approval to all of this. They were the ones who teamed up with the nazis to put a center-right candidate into power. Without the votes of the nazis, he would have lost the election. Mind you, they did this after years and years of political campaigns claiming that they'd never cooperate with the AFD. That promise aged like milk.

To put it into perspective, it's a bit like the GOP of South Carolina teaming up with the local KKK to put a new senator into office because the KKK controls over 20% of the votes in the state. Imagine that for a second. It's scary...

[dead] 6 years ago

Things are starting to look pretty scary in Germany with the CDU coming out and defending their decision on this. The fascists have gained enough political control that the major conservative party is now starting to depend on their votes in parliament. There's a pertinent quote that made the rounds in german media yesterday:

"Den größten Erfolg erzielten wir in Thüringen. Dort sind wir heute wirklich die ausschlaggebende Partei. [...] Die Parteien in Thüringen, die bisher die Regierung bildeten, vermögen ohne unsere Mitwirkung keine Majorität aufzubringen." A. Hitler, 02.02.1930

operation will just panic at runtime if the array is too short

Exactly, rust doesn't provide a good solution to this problem at all. Panics in rust are an escape hatch used to ensure the language stays "safe" in situations where the compiler can not prove a given behaviour at compile time, but where it would have made the language too ugly if you had to wire through Result types for all the trivial operations like adding two numbers.

In my experience, panics in rust have been a major source of pain. In contrast to an exception, which you can catch, a panic behaves more like an abort. At least it has been that way in the past. Now, with a lot of libraries using panics to signalize runtime errors, coding in rust has at some times felt like I was using a bunch of badly written C libraries that internally call "abort()" and kill the process when something goes wrong that would have been totally handle-able without killing the whole process. That's the benefit of using a safe language, right?

I think lately the rust "community" has become aware of this issue and IMO the way things are going is that that panics, as they are designed, should basically not be used. But, without proper exceptions, that brings you back to the situation where an operation as trivial as adding two numbers either produces a return code that must be explicitly checked or may silently fail and produce an "undefined" result in some cases.

Indications of a net change - not sure, but individual examples, yes. For example, some parts of Eastern Germany have seen a trend reversal in recent years. Also a number of previously poor ("cheap") regions in southern Europe are experiencing a massive investment and tourism fueled boom. Portugal seems like a good example for that.

True. Still, one alternative model to consider is one where the recent trend of opportunity concentrating in a few big cities could reverse. Either due to market forces (cheaper everything outside of the big cities), remote work becoming more prevalent, or both.

Though this is contingent on arithmetic bugs in caller code elsewhere in the hypothetical program

That was my point. The article claims to show how easy it is to introduce such a bug in the second snippet, but that isn't true. You need to introduce more bugs to get a security vulnerability.

This depends, obviously, on the code calling allocatebufs

That was my point. The article claims to introduce a backdoor with the tiny change in the second example, i.e. "commit the change from the second example an you're in". But that just isn't true without assuming some other vulnerable code at the callsite.

And arguably, the assumed bug is a bug of the assumed callsite and not a bug of the allocatebufs method!

"See how easy it is to introduce a backdoor into C code which just one small change that looks completely harmless" might generally be true (debatable), but claiming that the change shown in the article (on it's own) is an example of this is incorrect and looks a bit like fearmongering.

I don't think that what you are saying is correct.

If you ask the method to allocate a negative number of bytes and the method returns a buffer which is greater than zero, that doesn't seem like a backdoor in the allocation method!

Saying you can get a return buffer that is smaller than whatever amount of bytes you requested is wrong I think. Can you give an input to the second method that will result in a buffer smaller than the input value?

But that is not what happens in the code shown in TFA.

Passing a large value into the method shown in the article will do nothing nefarious (assuming sizeof(size_t) >= sizeof(int)). It will either return a large allocation, or, more likely, fail because the amount of requested memory is too large.

If you have a narrowing/casting bug somewhere else in your program, which BTW would produce an obvious warning, that would of course cause trouble as you have described.

And while mixing signed and unsigned arithmetic for buffer sizes is, of course, a recipe for desaster, I think it's incorrect to claim that the allocatebufs method shown in TFA has a "backdoor" because of this. I feel that is a bit like saying memcpy has a backdoor because you might get your pointer arithmetic wrong when calling it.

This makes sense, but it also implies that there is no actual backdoor in TFA. The code as shown in the article is not exploitable without assuming more (actually exploitable) bugs somwhere else in the callsite (which the article doesn't mention). Or maybe we haven't figured out the actual vulnerability yet...