HN user

hyper_reality

1,219 karma

Co-founder of CryptoHack.org

[ my public key: https://keybase.io/hyperreality; my proof: https://keybase.io/hyperreality/sigs/UP-XDCQUL1Z4L1T9KfF14x0Jpy_WxPs5UEyAPkIKPRs ]

Posts11
Comments122
View on HN

There are definitely a lot of reckless cyclists, but it's worth keeping things in perspective.

According to the Department for Transport's report, there were 41 pedestrians and 7 cyclists killed in traffic collisions in Greater London in 2022. Pedal cyclists were listed as the "other vehicle" involved in fatal collisions 0 times, while cars were listed 39 times, and goods vehicles 23 times. As stated "other vehicles" does not directly describe who is to blame for a collision, but it's a proxy measure for it. https://content.tfl.gov.uk/casualties-in-greater-london-2022...

This map looks cool but it doesn't tell us a lot about the safe and unsafe places to cycle in London. Because it's based on collision data by location, but we don't know how many people cycle on each road per year, so can't normalise for that.

To compare two examples, you can pick out Richmond Park in south-west London due to the low number of collisions in it. But this is actually a highly popular location to cycle. The relatively low amount of vehicles, 20mph speed limit, ban on large vehicles, high visibility, and few junctions, makes it a great place to cycle.

There are also a low number of collisions in the boroughs of Bromley and Bexley in south-east London. But this is not because they're safe, but because very few people cycle there. There are loads of fast roads in these boroughs and little cycle infrastructure, and more of an hostile attitude from drivers compared to many other places in London.

Thanks for mentioning CryptoHack!

Yes while some challenges overlap, we also explore more deeply the mathematics of cryptography, as well as its practical use in protocols like TLS. We recently added challenges on lattice-based post-quantum cryptography. In this way it makes a great complement to CryptoPals.

But it's not all harder, our introductory section gradually introduces concepts like base64 encoding and the modulo operator one challenge at a time.

- higher lifeforms are more valuable than lower ones (cat vs lobsters)

Choosing between preserving the life of one cat vs one lobster seems straightforward enough. But the trolley problem was asking whether one cat was more valuable than five lobsters. According to the stats, many people agreed, but how about one cat vs a million lobsters? Or one cat vs all the lobsters on earth? Most people would think that making lobsters extinct would be very bad (unless they really hate lobsters).

The difficulty is when we can no longer rely on intuition and have to come up with a precise exchange rate of when one being's life is more valuable than another's, which, like you say, is impossible to do in the complicated world we live in and our limited understanding of consciousness and neuroscience. In absence of that, deferring to the first law "whenever possible, do no harm" seems sensible.

To pick an extreme but well-known thought experiment. You are walking past a pond, and see a child drowning in it. You glance around and there is nobody else nearby. You could easily jump in and save the child. It will certainly die if you do not.

If you choose to do nothing and ignore the drowning child, are you really not morally responsible in any way for the child's death?

I'm curious, why do you think that these requirements won't spread to the rest of the internet

I didn't say that, I only said that we currently have two Internets, but that there has been a shift towards the walled gardens of identified accounts over time. The proponents of the law probably would end up creating loop holes just because their main beef is with the big tech firms, and it would be challenging for a single country to enforce legislation on the rest of Internet.

Verified accounts, as I understand them, on the social platforms are only for people who publicly want to build a brand around their identity. While people have to use a "real name" on Facebook and Google, there's nothing requiring to get verified.

We may be getting mixed up with the meaning of "verified", I'm talking about accounts where the platform has associated you with your RL identity through some method, not just the process to get a public blue tick.

And, while there may be nothing formal requiring verification, there are many reports of people suddenly getting locked out of their accounts and being required to provide ID or at least a phone number shortly after registration. In fact a phone number is a pretty widespread requirement and it's getting harder to obtain a phone number that's not linked to your identity in some way. I don't see the contradiction in what I wrote, I have simply pointed out trends, not absolutes.

I think it’s pretty clear at this point that the notion of the web as a self protecting organism that naturally rejects misinformation and stops bad actors is completely wrong.

It's an interesting question, but the point isn't as clear to me. First of all I believe most people are able to see through misinformation. The biggest blame should be laid on algorithmic feeds that optimise for engagement, and are therefore designed to lead people into self-reinforcing loops where their ideas never get challenged. That's the main bad "innovation" that social media platforms brought; the arguments about dangerous ideas, censorship, and bad actors echo all the way back to the dawn of the printing press.

But I also think you can’t ignore that misinformation from anonymous actors has pushed democracy to the brink of collapse, and “that wasn’t the original idea of the web” isn’t the best rebuttal.

I think this is overstating the role of "anonymous actors" - plenty of misinformation comes from well-known politicians and simply normal people. Are you referring to FB's concept of "coordinated inauthentic behaviour" and troll-farms in authoritarian countries? This is definitely a problem which platforms have to tackle, but again I don't think it's as huge a factor as people make it out to be and certainly has not pushed democracy to collapse on its own.

I still remember the days when almost everyone on Internet forums used pseudonyms and closely guarded their identities. It was even taught in schools not to reveal who you are online.

Google, FB and other tech giants changed the norms around this completely for most Internet users. Once these platforms realised it was easier to monetise their users, and control abuse when dealing with real identities, they pushed hard for verified accounts (e.g. Google Plus) even though this is antithetical to the founding ideas of cyberspace.

Today we have two Internets, one where anonymity is still possible but you can reveal your true name if you want (e.g. HN), and another of walled gardens with verified identities. The UK government is proposing to enshrine the fully identified concept of the Internet into law. While this will prevent some abuse it's a sad reflection on how some of the early values of cyberspace have been lost, where people could be who they wanted to be, and freely discuss topics they might not wish to have associated with their real names forever. Politicians whose main interaction with the Internet is through their Twitter accounts just don't get that.

This is fascinating and a great bit of work by Stefan Marsiske. Loved the technical writeup in PoC||GTFO too. This quote from the TFA really shows just how difficult it was for the public to access decent cryptography at the time:

In her book Operatie Vula, Conny Braam explains how one of her people met a guy, by the name of Floris, in a pub in Amsterdam, who allegedly had developed the PX-1000 [5]. From him they learned that the device had been taken off the market as its encryption was too strong. It had been replaced by a calculator but he suggested to find the older version with built-in crypto.

In all I would say it was a pretty good backdoor for the early 80s, showing how far ahead the NSA's internal understanding of cryptography was. I wonder if they would have anticipated the world we live in today where state-of-the-art cryptography is available and used by everyone on the Internet.

Absolutely right, the essay writes from a comfortable UK perspective and ignores large amounts of the world where well-regulated, trustworthy financial institutions aren't available. And even UK banks aren't immune from failure or just mistakes which can freeze people's savings and put them in terrible situations that take months to resolve.

To add to your counterpoint, the OP's praise of going cashless as opposed to the problems of cash is another fine example. It's certainly more convenient to use your card everywhere, but if everyone did it then just a handful of payment processors would gain immense power, with the ability to track, monitor, and censor all transactions. Plenty of dystopian fiction like The Handmaid's Tale covers what can happen when this infrastructure is abused. Cash may have problems but it plays an important role in an open society, and redundancy when a major payment network goes down (as Visa did across Europe on 1st June 2018, causing retail chaos). But many vendors no longer accept cash and this will only accelerate as more people never use it. In praising going cashless as protecting ourselves from being our own banks, the OP misses the forest for the trees.

Leaving Debian 5 years ago

Inspiring interview, as the interviewer says there's a zen about Joey where he's dedicated himself to producing great open source software (git-annex, debhelper, ikiwiki) instead of trying to make millions.

Surely he can look back over the last few decades and feel proud of his work and the benefit it has brought to so many users. The tech treadmill can cause us to lose focus on the things that really matter or that really inspired us to begin with, so this is a refreshing perspective.

Transhumanist philosopher David Pearce has a fascinating piece arguing along these lines. The dystopic Brave New World "has come to serve as the false symbol for any regime of universal happiness", and Island offers a counterpoint, however hardly anybody has read it compared to Brave New World: https://www.huxley.net/

PostgreSQL 14 5 years ago

PostgreSQL is one of the most powerful and reliable pieces of software I've seen run at large scale, major kudos to all the maintainers for the improvements that keep being added.

PostgreSQL 14 extends its performance gains to the vacuuming system, including optimizations for reducing overhead from B-Trees. This release also adds a vacuum "emergency mode" that is designed to prevent transaction ID wraparound

Dealing with transaction ID wraparounds in Postgres was one of the most daunting but fun experiences for me as a young SRE. Each time a transaction modifies rows in a PG database, it increments the transaction ID counter. This counter is stored as a 32-bit integer and it's critical to the MVCC transaction semantics - a transaction with a higher ID should not be visible to a transaction with a lower ID. If the value hits 2 billion and wraps around, disaster strikes as past transactions now appear to be in the future. If PG detects it is reaching that point, it complains loudly and eventually stops further writes to the database to prevent data loss.

Postgres avoids getting anywhere close to this situation in almost all deployments by performing routine "auto-vacuums" which mark old row versions as "frozen" so they are no longer using up transaction ID slots. However, there are a couple situations where vacuum will not be able to clean up enough row versions. In our case, this was due to long-running transactions that consumed IDs but never finished. Also it is possible but highly inadvisable to disable auto-vacuums. Here is a postmortem from Sentry who had to deal with this leading to downtime: https://blog.sentry.io/2015/07/23/transaction-id-wraparound-...

It looks like the new vacuum "emergency mode" functionality starts vacuuming more aggressively when getting closer to the wraparound event, and as with every PG feature highly granular settings are exposed to tweak this behaviour (https://www.postgresql.org/about/featurematrix/detail/360/)

Bombs vs. Bugs 5 years ago

Here's an example of purple prose that has nothing to do with the complexity of cybersecurity, from his first post on Substack (https://edwardsnowden.substack.com/p/lifting-the-mask):

Though my relationship to time fluctuates, the gravamen of my disclosures remains constant. In the past eight years, the depredations of surveillance have merely become more entrenched, with the capabilities that used to be the province of governments now in the hands of private companies, too, which employ them to track and tether us and attenuate our freedoms.

Fastly Outage 5 years ago

I recommend reading about "blameless postmortems" [1]. Our natural tendency is to look for who is responsible for an incident and point the finger of blame. Over time this leads to a cover-your-ass culture, whether you like it or not. Therefore such a tendency needs to be actively fought against to keep the focus on quality engineering and not politics.

"An atmosphere of blame risks creating a culture in which incidents and issues are swept under the rug, leading to greater risk for the organization."

[1] https://sre.google/sre-book/postmortem-culture/

This is an interesting exploration of the incarceration statistics, but it doesn't go one step further and explain why American prison sentences are so long.

I've seen numerous explanations for this, one being that there is a strong incentive for US politicians to look "tough on crime", a greater emphasis on retribution than rehabilitation, historic racial injustice, and a sizeable for-profit private prison industry. But other developed countries also have these factors to some extent, for example the UK's private prisons house 18% of prisoners compared to the USA's housing 8%.

In my view, understanding the cause of why these long sentences are considered normal is essential to preventing a lot of pain and suffering. There are several examples of harmless people given life sentences for marijuana possession under three strikes laws, but that's just the tip of the iceberg. A society that is obsessed with freedom yet incarcerates more of its citizens than Cuba or Russia, and hands down disproportionately severe sentences for transgressions that would be viewed much less seriously in other countries, is a bizarre phenomenon with a huge human cost.

One big difference is explained in the article. The fact that code going into the kernel is not as secure as we might hope is already known to the open source community. Maintainers are overworked and none would be surprised if you told them that it would be possible to smuggle in backdoors. This is not a "bug", but an issue with time and resources, and because the researchers attempted to add bugs to demonstrate it just makes it worse.

On the other hand, security researchers are finding vulnerabilities that weren't previously known. They've discovered specific exploitable bugs, rather than introducing new ones. Following disclosure, the company can patch the vulnerabilities and users will be safer. Which makes that a laudable thing to do.

This is an excellent tool to have as a security consultant, and it just keeps getting better and better. When approaching a large codebase, it enables you to write custom rules that match on certain antipatterns you've spotted that may be unique to the codebase. That's the real value of the tool, but the repository of per-language rules is also convenient for quickly finding low-hanging fruit (like every use of a potentially injectable function such as exec,system,etc. in PHP).

For example, a webapp may have been designed such that authorisation needs to be explicitly added with a line or two to each controller. A semgrep rule can be written to match all the controllers which are missing this line. Then these controllers can be manually reviewed to assess whether unauthorised access should be allowed. Depending on what you are trying to match, this is something that may be very complex or even impossible to implement accurately in plain grep. Some languages like Ruby have powerful static analysis tools (Brakeman) that can also do this, but the benefit of Semgrep is the flexibility across multiple languages and how readable the rulesets are. [1]

[1] https://blog.includesecurity.com/2021/01/custom-static-analy...

Java Is Underhyped 5 years ago

This is funny and I would love to hear your personifications of other languages. I imagine Python and Perl offer a lot of material.

Great and clear guide to this thorny topic. However, even this article gets a little confused in its wording at one point:

In such cases, we want our API to set the Access-Control-Allow-Origin header to our website’s URL. That will make sure browsers never send requests to our API from other pages.

If users or other websites try to cram data in our analytics API, the Access-Control-Allow-Origin headers set on the resources of our API won’t let the request to go through.

The ACAO header only performs a controlled relaxation of cross-origin restrictions. It is the browser that is ensuring that by default other pages can't send requests to the API. Just a nitpick as I feel the rest of the article illustrates this well.

True, but less than half of world countries are covered by street view and it's possible for a human to learn the distinctive metadata features of every single one, together with all the common roadside features like poles, road markings, and vegetation. So I don't know if the level of granularity where statistical variations are noticed is required to succeed at least in determining the country.

But in terms of picking the closest point within a country, perhaps with a large enough dataset the AI would be able to distinguish based on local weather conditions when the Google car was driving through certain regions. And this would trump the player's ability to read place names and signage.

Interesting post, but I disagree with the conclusion that with a bit of work AI could take down the best Geoguessrs. The best players already take into account all the metadata like camera quality and distinctive features of the Google car. Furthermore, they would surely have an edge in urban locations where proximate locations are visible in street-signs. I could be proven wrong though, and it would be super interesting to reverse engineer AI guesses that turn out to be surprisingly correct based off little info.

To see just how good the top players are at instantly recognising a country using these clues, then check out https://www.youtube.com/watch?v=zEmoAYpTJuA . Or maybe don't if you don't want the game spoiled!

This is being discussed in CryptoHack Discord. We are struggling to understand the paper, it is written in a very dense style and the difficulty is compounded by the fact that lattice problems can be a challenging topic even for cryptographers.

Either way, we think that the title "this destroys the RSA cryptosystem" is sensationalistic and probably incorrect. It is presumably based on the fact that the paper claims to reduce some forms of integer factorisation to a lattice problem which can be solved in polynomial time. However, whether this technique applies in the general case to RSA moduli is not argued here and the claim seems to be premature.