Yeah, you can look in the contributors' dashboard, they stopped around 2019. As any documentation, its fate is to wither and fall into decay. But hey, he got a book out of it.
HN user
ivancho
[ my public key: https://keybase.io/ivancho; my proof: https://keybase.io/ivancho/sigs/3C6HaZKd1uSVQiqL0ly24b0RG753TlHr3E7393X3V3I ]
So we'll have expensive artisanal software for rich people? Self-assembly takes a whole new meaning for the rest of us.
That's a pretty narrow view of software too. The nature of building software systems is not always towards being able to mass-produce them. What would be the point of copying and distributing 10K copies of my script that runs migrations for one legacy database in a very specific way?
It's complete nonsense. "The total number of moves in the game is equal to the number of stones initially in the pile, which is 5000."
Similarly on the Martian question "If we transform 1 red and 1 green Martian, we get 4 blue Martians. This changes the parity of red and green Martians from even to odd, and the parity of blue Martians from even to odd." - is complete nonsense too.
"the sum of the digits of a number k modulo 2 is equivalent to k mod 2" - 12?
Basically all "solutions" are regurgitated techniques from math competitions which are used completely incorrectly but with a lot of confidence
So, "it is really mostly a matter of luck", and just do so much work that they decide to fire someone else... sigh. If only there was some way for the workers to negotiate collectively for working terms that avoid mass layoffs whenever the interest rates go the wrong way.
I think the anecdote highlights that there's no incremental way to approach gRPC, it's not a low risk small footprint prototype project that can be introduced slowly and integrated with existing systems and environments. Which, well, it is a bit of a fault of gRPC.
My model was not to demonstrate that utility doesn't go down ever, it was to show that it can do that extremely slowly, which makes the utility argument about why we discourage it societally a bit weak - we're clearly not very good at discouraging any other behaviors resulting in long-term bad outcomes (for society or the planet), and we reward all sorts of risk-taking.
I think the simpler explanation is that gambling is seen as addictive and destructive on an individual level, and there is no need for total utility to explain why that's undesirable
This is a bit of a stretch from what I said - 1% drop after the entire population has gambled through 10x their net worth is not meaningful. I also pointed out other speculative activities which we encourage, presumably because they compensate by growing the economy. Insurance might preserve or increase equality, but it also might extract so much rent that the overall utility is lower. There is simply no cut and dry explanation - for some parameter choices things work the way you say, and for some they don't
Ok, take 100 people, with $100 each, and have one round of $1 coin flips between each 2. A significant number of bets overall, 4950. Each person has wagered 1% of their net worth 99 times, something that we all agree sounds quite scary. And yet there will be no busted people, most will likely be between $80 and $120. Repeat this 10 times, a ridiculous amount of gambling - still most likely no bankruptcies, and the total utility, if we assume log, has barely dropped by 1%.
I simply do not believe that we are making such a subtle societal optimization by frowning upon gambling while encouraging all kinds of other risk taking, like investments and properties.
And the other scenario where insurance just acts as a drain on the overall system seems to indicate that it is not inherently positive for utility either
You haven't demonstrated most of these assertions. For example, if everyone gambled against everyone else every second, then that system has a pretty good chance of staying close to equilibrium for a long time, whereas your model indicates that the total utility would be depleted almost immediately. Whereas if everyone was fully insured for absolutely every risk in their life and immediately received a replacement of the exact same value on any loss, then the overall system would just steadily trend to all the money ending at the insurer, which doesn't seem like increased total utility
Ah, a brilliant idea, design all languages so people who only know C can make small changes to existing Ruby code without getting confused. Definitely don't want to enable different abstractions or models of computation. Are these core principles in codebases you mentioned mostly "how to write stuff using C paradigms"? After all, "the Real Programmer can write FORTRAN in any language"
Even more so then. Simplify, simplify, simplify!
What is your certainty that that statement is true? What if it was a calculation which takes decades on a supercomputer?
I'm not gatekeeping proofs here, and I'm glad you got math pizza :) If proofwiki had exhaustively printed all possible arrangements, or the decision tree of constructing them, or if they had even included the code that would do the checking (like, say, https://www.richard-towers.com/2023/03/11/typescripting-the-...), then I would agree it counts. But without even a rough ballpark estimate of possible arrangements to check, asserting "brute force" does not make a proof. If I incorporate understanding of the problem, I can see that at most we need to check 8!, which is reasonable. But if the constraints were not so simple, then we might be dealing with 64-choose-8 cases instead, which is heading into not-reasonable.
They can add the same sentence under every finite fact in their wiki, but then it won't be a proof wiki, it would be a list of numeric facts they checked by brute force and we can either trust them, or check ourselves.
Their "proof" that there are only 12 solutions to 8 Mutually Non-Attacking Queens on Chessboard is just "That there are only these 12 can be proved by brute force." :/
There is extensive research on key finding attacks. Often they only need 30% of the bits. Things can be sped up by exploiting entropy - keys are really random, unlike most of the rest of your memory, so that filters things down, and as you said, an incorrect key produces total garbage on decrypt, which is easy to detect, so you can automate testing and discarding key candidates. Lastly, if you have knowledge of the applications or algorithms involved, you often get some extra data structure around the keys, which makes searching the memory dump trivial.
All that is to say, yes, this is a viable attack vector, even if some or many of the bits are flipped
I think the dunk is funny, and at the same time recognize that glibc is invaluable. At least here the attackers had to do some memory tricks - in other (apparently safer) languages they just get arbitrary code execution directly implemented in the logger!
You can't simultaneously have that key strength is maintained as long as they don't know how many bits are flipped, or where in memory the key was, but also that leaking any number of bits is catastrophic. If your memory dump creates a different distribution on the space of possible keys, it has already compromised the cryptographic security of the key, it's just a question of how much, and the answer here is a lot - even if we had GBs of garbage data, that is still tiny compared to the whole space and can be sifted extremely quickly
The original comment said "One bit flip and it's game over". Which is clear nonsense, I don't have to specify that there's exactly one bit flip, I just need to know that the key is in that general neighborhood and its security is already compromised.
I think this needs its own cognitive term, it's not a survivorship or selection bias, it's just skipping the selection entirely and just focusing on the sample. So here people go "This plane is an outlier, there must be something special about it", as opposed to "We would just be talking about another missing plane instead". Or in the immortal words of Tim Minchin "If I didn't have you, someone else would do"
What the hell are we doing as an industry? We have 20 cores per CPU and enough RAM to fit the entire human civilization's knowledge in text form in everyone's pocket, but we can't scroll a webpage with animations without stuttering?
I have not conceded anything. Many crimes would be perfectly unsolvable if everyone did everything perfectly, and yet.. You are again using "logically impossible" while insisting on a very specific condition, "not knowing all inputs into the laundry", which is very much solvable to a high degree of certainty - CM mixes so hard that their addresses are all connected to each other - I just need to send them a single transfer, watch it tumble, then connect the dots, and then list all transactions leading into that giant hairball of connections. Just read the Justice Dept complaint against CM - it has an extensive inventory of specific customers and crime proceeds, using "Company A [..] tracking approximately 118,500 bitcoin addresses associated with ChipMixer". Now how would they do that if it was so logically impossible?
And why would having a private key to an output address that no one else has touched be an evidence to a crime? They probably only delete them after the user has transferred the funds out, if they even bother.
I don't know why you are so bought into Bitcoin privacy specifically, but it holds as much water as the privacy statements in the App Store - anyone with sufficient motivation and data analysis skills can poke right through it. Monero is likely stronger, but if it can't be cracked, then as soon as it becomes big enough it will get blocked.
But we don't have to search for those keys in all of the deposits that CM ever made - only in the ones that stopped churning and mixing. Maybe they try to control the dynamics of their lots to be statistically indistinguishable from the withdrawals - but that requires a vastly larger pool of capital and continuous operational effort, and I have a hunch they do not in fact do that.
Furthermore, if you are a client, how long are you willing to keep your money in private keys that you know CM also has? Even if you don't mistrust them, you still need to worry about the exact scenario that happened - they get busted and all their private keys get seized. So chances are those amounts leave the CM network of addresses pretty quickly, even if they don't get added up in a single address. So now all that combinatorial explosion drops down to a pretty tractable k-NN classification problem.
I would advise against making strong statements like "logically impossible" about things that seem to require a lot of very narrow conditions like perfect actor behavior and strong stationarity in order to be true.
I disagree with pretty much every point here, wow. ChipMixer provided a little bit of disconnect, but there was a research paper a while back that ran something like 5 transfers through it and managed to identify their mixing transactions with 90% precision. Law enforcement is most likely constantly tracking those, similar to how the NSA runs some significant percentage of Tor entry/exit nodes. Second, recognize the enormous amount of trust required here - that the mixer will actually do proper randomization, that there will be a large number of participants, that they won't keep the logs, that they won't just up and leave with all the money. There's plenty of examples of somewhat established mixers that fail on some or all of these, and you're telling me that instead people will just send their money to be mixed by anyone that can setup a network connection and a bit of code?
Except with packet switching networks I can immediately point to the problem they are solving and can also make a guess how things will change when we create 000s of bigger and better ones. And the timeline is definitely not what you are making up here - the 70s had immense development of networks and protocols, every telco was building new networks across the country, it was most certainly not hobby stuff, there just weren't that many computers until the 80s.
What problem are we solving with decentralized consensus? How will things improve if we have a giant one? Say every mobile phone was a part of the consensus mechanism, churning Turing-complete smart contracts. Billions of nodes. What do we get out of that?
I meet some people in crypto occasionally, and it's hilarious that most of them no longer talk about technologies, projects, applications - all they discuss is sentiment. "Oh, there's a wave of positive outlook", or "new patterns of participation are emerging". At least it's honest, I guess, instead of pretending that we are changing the world with DAOs or whatever, they are just sizing up the next bubble.
MtGox thieves evaded prosecution because no one was doing tracing back then. Chainalysis got started specifically to link all their activity and is now a giant graph connecting all the "pseudonymous" addresses. And the thieves laundered most of their stolen coin through exchanges, not chain transactions, strange how they didn't want that very strong privacy. There's none of that left on Bitcoin, it's been indexed, clustered and mapped.
Obviously there are technologies which enable complete privacy - and like tumblers, any that prove popular will be shut down, there's just too many negative externalities.
a zip bomb will only serve to hinder teenage/kid 'hackers'
And that is literally what the blog post says - it will mess with script kiddies who don't change their user agent. Author acknowledges that it is not an actual methodology to protect their server, so pointing out that it's a flawed methodology is a weird flex. I have not seen anyone suggest using zip bombs instead of hardening the server.
You are very insistent that people are doing "defending" wrong, and I can see how someone could read victim blaming into it, the industry does have a bad habit of loud hindsight bias. But it's also entirely beside the point, since no one here is claiming that this is real security, it's just a small nostalgic hack, and it comes off a bit grumpy to be so adamantly against it.
No one is really worried, and no time is wasted when the outcome is occasional fun. There's no security holes to fix, there's just a bunch gnats poking at your server and you shoo them away, that's all.