HN user

kw71

1,175 karma

I built things that you probably see and use every day, and changed the world a little.

Posts31
Comments456
View on HN
gizmodo.com 7y ago

We Finally Know How Wombats Produce Their Distinctly Cube-Shaped Poop

kw71
3pts1
www.usatoday.com 7y ago

Cleveland man locked in Cadillac for 14 hours

kw71
4pts1
en.wikipedia.org 7y ago

PARRY: Early Chatbot with Mental Illness

kw71
1pts0
en.wikipedia.org 7y ago

Trout Tickling

kw71
66pts25
en.wikipedia.org 8y ago

Pumpable Ice Technology

kw71
48pts30
www.aisec.fraunhofer.de 8y ago

Shedding Too Much Light on a Microcontroller's Firmware Protection (2017)

kw71
189pts23
en.wikipedia.org 8y ago

Chicken Gun

kw71
2pts0
www.bleepingcomputer.com 8y ago

Long Prison Sentence for Man Who Hacked Jail Computer System to Bust Out Friend

kw71
2pts0
www.fresnobee.com 8y ago

Women enslaved as sex workers in Fresno

kw71
2pts0
www.amsat.org 8y ago

US Air Force FalconSAT-3 Begins New Mission: Ham Radio BBS in Orbit

kw71
2pts0
www.arrl.org 8y ago

American Red Cross Asks for Ham Radio Operators for Puerto Rico Relief Effort

kw71
346pts151
www.nytimes.com 8y ago

In Kenya, Selling or Importing Plastic Bags Will Cost You $19,000 – Or Jail

kw71
2pts1
38north.org 9y ago

North Korea Nuclear EMP Attack: An Existential Threat

kw71
1pts0
www.reuters.com 9y ago

Chinese state media says U.S. should take some blame for cyber attack

kw71
2pts0
motherboard.vice.com 9y ago

Apple Forces Recyclers to Shred All iPhones and MacBooks

kw71
4pts0
motherboard.vice.com 9y ago

The Man Who Broke Ticketmaster

kw71
4pts0
www.reuters.com 9y ago

U.S. court blocks FCC bid to expand public broadband

kw71
2pts0
jezebel.com 10y ago

Why Do We Destroy Our Barbie Dolls? (2009)

kw71
1pts0
techcrunch.com 10y ago

Security researcher gets threats over Amazon review

kw71
210pts84
en.wikipedia.org 10y ago

1925 serum run to Nome

kw71
2pts0
en.wikipedia.org 10y ago

Caning of Charles Sumner

kw71
1pts0
www.hindustantimes.com 10y ago

Bitcoin [mtgox] CEO spent embezzled funds on prostitutes

kw71
1pts0
theintercept.com 10y ago

The Pentagon's Missionary Spies

kw71
3pts0
www.j-display.com 10y ago

World's First Standard Monitor Size 17.3-inch 8K4K LCD Module

kw71
2pts0
entrepreneurship.org 10y ago

Lessons from Failure: Borrowing Tools from Your Neighbors

kw71
14pts1
www.itworld.com 11y ago

The US Navy's warfare systems command just paid millions to stay on Windows XP

kw71
2pts1
news.nationalgeographic.com 11y ago

Stem cell injections prolonged lives of rapidly aging mice

kw71
2pts0
www.bbc.co.uk 11y ago

Dog mess DNA test to launch in Barking and Dagenham

kw71
1pts0
www.eff.org 11y ago

Automated Vehicle Occupancy Detection

kw71
7pts0
www.cnet.com 11y ago

ESPN Sues Verizon to Stop New Sports-Free TV Bundles

kw71
2pts1

It depends on the confinement, the overcrowding of industrial production may be unadaptable. There are still enough instincts programmed that unfamiliar males would rather avoid each other.

I do not beleive that industrial breeding is selecting for anything that makes such prison life tolerable. Birds in production generally aren't reproducing, so nothing in the henhouse is affecting evolution.

while open source keeps adapting and changing

In these places, this is a great thing to avoid. Old software is well known. You do not want to be the one to be affected by a bug that stops production or changes data.

mainframes have remained stagnant in features

Having a well known universe without any beta software, and not being disrupted by new stuff that you don't need anyway, is a damn good feature.

Writing off all the big computer shop stuff as irrelevant means you throw away all the experience and best practices and will be repeating the mistakes people made 50 years ago. And maybe reinvent some wheels too.

A computer center is your best resource for observing and learning how to build computer services, deploy them, and keep them available. And for knowing what experienced computing people and their customers expect.

And some of the stuff you do today is descended from here:

You probably wrote this comment in a program that displays forms, and allows you to fill in forms and call up other forms. This is how the 3270 terminal worked.

Maybe you have some hypervisor running somewhere. Welcome to 1970s IBM. We don't want to rewrite our 360 stuff so we will emulate the 360 in its own sandbox.

Saddest part of these things, when they come into general awareness one way or another, they are so out of tune with the universe that the public hail them as new "technology." The ideas are old, it's only some new implementation or circumstance that's novel.

In the US, yea, inspections aren't universal, but the only inspection program I know of that has been scrapped was Florida's. I think there are more operating inspection regimes than defunct ones, even if you can cheat some of them. This also seems to be an anomaly among developed countries.

Rust that's more than superficial can lead to structural failure, and improper crash repairs can cause this. These are definitely situations that leave the vehicle in a lesser state of crashworthiness.

A compromised exhaust frequently leads to more exhaust entering the cabin.

This gets into the roots of my socialist beliefs as caring for our injured comrades brings us all down. There are always better things to send effort and resources to than dealing with the loss of productivity, the costs to deal with whatever damage, and misery of loved ones.

It seems Tesla is deliberately ignoring or trying to squash the aftermarket/custom-car culture

This culture ("F your emissions controls," "I the lay blue collar know better than the committes of degreed engineers who designed the thing") has never cared about safety, nor has the aftermarket ("fitness for purpose, engineering, warranty... to hell with all that, the only requirement for our product is that some idiot should buy it")

Improperly repaired and modified cars are a detriment to the safety of others on the road, but wishing the problem away like Tesla is doing is not going to help anything, they need to publish and make accessible the documentation like the real car makers do.

Ford has been doing this for decades (I think I saw it mentioned in the docs for EEC IV.) It turns off fuel for a cylinder here and there intending to pump heat out of the engine (a cylinder with no fuel is an air pump.)

It doesn't really let you operate with no coolant. Might get you farther before you die if you push it.

The Caviar Con 7 years ago

When I lived in Russia (2000s) it was quite abundant and seemed to be cheap, it was part of nearly every breakfast that I didn't prepare for myself whether or not there was anything luxurious about the situation.

The foie gras that GP mentioned, is inherently labor intensive to produce and not abundant anywhere.

Last quarter I quit my job at one of the world's largest automakers and for twelve years I've had a small business on the side that serves specialist mechanics of all kinds, so I talk to dealership and indy mechanics all the time. I think you need a lot more experience with automobiles before you are qualified to say such things.

I have a 22 year old 3 and a 26 year old 5. Neither have ever been in the shop for anything but tires. It's not fair or accurate to lump this in the same bucket as vw or mbz. I have bought quite a few parts from the dealer that cost less than $1, like plastic rivets or clips that I broke in the process of getting to something else. Toyota and VW want almost ten bucks for these sometimes. GM won't sell them to you. But my coolant is cheapest at the mbz dealer.

Unlike japanese makes, for anything that people have a need to replace, the original parts are sold on the aftermarket at fair prices. For my toyota, if I want a ball joint, I have to pay three times what it should cost at the dealer parts desk, or deal with junk from the aftermarket - and it's all junk. Datsuns, honda, same boat. Mazda, you're lucky if they even support your car anymore.

Okay, I am in the habit of using pulls, and even some micros have pulls that can be switched in. That may be pointless when there is only one slave on the SPI, as it probably is in the attacked system, as the /CE is probably strapped active so the device will never switch that pin to high Z.

I don't think there is any deception with that, but if he said he did not have a power supply arranged for it then I missed it.

The demo shown in the talk was in an emulator, I have no doubt that he actually added his script into the filesystem in the emulation.

I think I found some flaws with this, now I think I am rather experienced but I haven't seen everything.

1) He didn't demonstrate it in real hardware without outside power and ground, while he says an arm core is very small, capacitors are large unless you change the laws of physics. Also I never saw a reliable clock generator the size of a 0402 (or even 1208 now that I think about it) passive. Like I said I haven't seen everything, if there are answers to these I'd love to see them.

2) He faked in some addition to unprogrammed memory, he theorizes the change can only work one way (change a high to low) so an obvious countermeasure is to fill empty memory with random bit patterns.

3) IIRC he intercepts an spi flash in series on the data (MISO) wire. Not only does this assume the spi clock is regular, I think it's totally wrong because he says he turns high to low. Usually the quiescent state of a net like this is high, due to pullup on one or both sides to Vdd (high state.) The mark on the data wire is a short to ground against this pullup to get a low state. Now I haven't seen everything, nor have I looked at any datasheets of parts used in any real system, of course the pullup can be anywhere along the wire, or in one or many integrated circuits along the net, but it really strikes me as incomplete because he says he turns high to low and I didn't notice him mentioning anything about any pullup and how to deal with it.

So until I see something better than this talk I am writing this off as feeding the FUD.

Not the c++, the functions they give for simple things, so you don't have to read the manual to find out for instance the name of the GPIO port register (a very small step) or learn the boolean operations to diddle only one bit (another very small step). This is fine for an educational toy but arduino libs (and even the boards, ha) are showing up as part of finished products in the market, that's really sad.

Is my personal opinion that c++ doesn't belong on an 8 bit anyway.

Thank you for replying, despite my shitty abrasive attitude.

No the normies don't know anything, that's why they are buying garbage like cars without keys, "connected" door locks, and burglar alarms that some talk radio host tells them is "safe". You can't teach them, and if you have something better to sell with meritable security they won't choose it.

I don't know if you were surprised to find what you found. At any rate, you knew that this stuff is garbage as soon as you found it. And so has anyone who has attacked just about anything. From consumer junk to military toys, there is very little out there that has actually incorporated much thought to attack resistance... the only examples I can think of right now are pay television and some game consoles... really, the most frivolous things.

I think it was the late 90s when I checked into a hotel and was slightly surprised to get a magcard instead of the swiss cheese looking ving stuff I was used to. I am sure that I am not the first or only one who thought, well this is shit. The card probably only encodes a site code and an id for the individual lock. I was impressed to learn that when the next guest gets a card then mine won't work anymore. But whether we had the capacity to realize how stupid the implementation must be, we all had some reassurance in that there was at least a level of sophistication required to put me at risk there. Whether that's a shitty night clerk disclosing the password for that card writing device, or someone who took apart the lock to figure out how to throw the bolt, there was something more required than a dickhead reading the internet to do it. And for like fifteen years "it was acceptable" because nobody gave a how-to to everyone.

So what were we supposed to do when the details - not the idea - were disclosed? Not travel anymore? You did make the attack a lot easier than necessary to make your point. Explaining an overview, the idea, still carries some risk - there are so many people in the world that nobody has any novel skill and someone's bound to replicate the rest of your work - but all these details lowered the bar unreasonably.

Man, what if I had published the party trick that lets you start a toyota without any keys or fob? I know I'm not the only one and doubt I was the first. But it's not that people could lose their property, it's possible that people who would not normally have access to "that car" would do something extremely shitty with this possibly lethal weapon. Another attacker without travel experience, grown up in the usa, might not realize that in other places you can get away with car theft simply by driving east. I wouldn't have thought about this when I was young but now I sure as hell don't want anything like this on me.

What were you thinking would happen? That you'd simply become the envy of magazine-reading normies and nerd conference attendees?

Anyone who's pirated software knows that electronic locky things are about as worthy as masking tape. But you gave all the work away such that it took all the brains of a jailbird methhead life-winner to rig up a formidable burglary tool with an arduino (which i've always derided as baby-talk-programming-for-potheads, how about that) Normally there would be some secretive jackass in the middle like those developing and selling the auto theft tools to the guys who manage car thieves... but you changed the world! Congrats.

It depends on where you were, because before the breakup there were still regional operating companies with their own management. In the 70s and 80s we had service from C&P Telephone, and did not have any of the problems that customers of Pacific Bell or New York Telephone were so familiar with. The good times lasted until the dawn of local competition (Bell Atlantic wouldn't install a line the next day because they weren't allowed to do it faster than a clec.) Then when Bell Atlantic bought NYNEX we started seeing all the terrible service problems that New Yorkers held so dear.

My understanding is that these treaties are not so cut and dry. Treaty extraditions to the US have been refused on grounds of human rights, probable cause and documentation issues and I've never known of retaliation for failure to act. The US trend of "The World is My Jurisdiction" is sketchy and arguable enough for a country to refuse.

In his official actions Trump has shown that he does not know what the law even is so expecting him to respect it is like a pipe dream. And what has come out about some of his personal actions in the past doesn't give much hope either.

(I'm an American so when I speak about "our" I mean US)

Nobody sane ever expected China to be a 'rule of law' country in the Western sense though. I don't know enough about Chinese law to judge whether changing a law should have been allowed. But that law is changed, by whatever mechanism, and that is a bit different to acting in contravention of a law.

None of this 'How China Works' is new to anyone. Canada should have considered it when deciding to get involved.

While the majority of US Federal prosecutions are honest, FBI agents and US attorneys do get involved in misapplication of the law and reckless prosecution for political or personal reasons.

And our president respecting rule of law or being better than Xi on any measure except successful criminal behavior is a real tough sell. It would be easier to sell sand in the desert.