HN user

logicrime

9 karma

hack'n ur feelings

Posts0
Comments46
View on HN
No posts found.

What was the best case scenario (in your opinion) for this message?

My mission is to speak the truth, ONLY the truth.

I don't mind ruffling feathers along the way, especially in regards to JGC, who is actively taking steps to destroy the FOSS principles of the LuaJIT project.

I'd sooner see myself banned than retract or apologize for a single character of anything I've said thus far, or plan to say soon.

The qualms I have with this dialogue are the same as before, because CloudFlare has little to no idea how they are going to handle this. JGC tweeted me about how 'Oh, we get so much benefit from LuaJIT being FOSS" but here we have CloudFlare walling LuaJIT into it's own entity on GitHub where I predict commit bits will be few and far between.

More than that, I don't think there has been enough narrative between Mike and the 'new LuaJIT crew' (CF) to determine how the project should be structured. In this thread, agentzh had a fantastic idea to vet somebody through Mike, someone the community knows can be trusted and also is somewhat familiar with the LuaJIT internals, and that person could serve as a canary between the project and CF.

I write a fair bit of Lua for game scripting, and I've even made a few bucks here and there helping folks with their custom plugin ideas etc, but I've never touched C before. Well, when the previous announcement was made, I immediately Amazon'd some C books, which I plan to devour in my free time. At which point I'll be learning Rust, and reimplementing LuaJIT in Rust, and hopefully convince Mozilla to host the git, such that it will be protected from FOSS corruption.

My worst fear is CF taking this project into the shadows, developing it closed-source (which they absolutely have a right to do) and not sharing their insights with the community.

I think everybody with any kind of invested interest in LuaJIT needs to be gearing up right now, such that we can do our parts to keep this project alive.

I kinda hate these papers that just humble-brag clusterized setups without providing any abstract insights. This doesn't bring me any closer to understanding graph data any better, but I'm now ready to begin installation of a multi-million-dollar cluster of machines and storage.

The bit about k-means was interesting, but the rest was an irrelevant bore.

I use a unique password and even a burner email, and a phone number that I update every 8 weeks for my banking website.

It's taken blood, sweat and tears to save up 20k (a lot for me) and even though I have a secure authentication scheme for the website, I worry about it getting hacked all the time.

"...there is absolutely no risk"

You have no idea! There's little practical risk in people getting access to my (fictional) ProjectEuler account, but there is absolutely some risk into returning to the same scam twice. Say they exploit PE again and are able to extract more than just password and email, maybe they find a way to get more info about the user's browser, or cookies, or SOMETHING. Anybody foolish enough to continue to navigate to projecteuler.net will suffer the consequences. They'd be better off never returning.

I know the response to this will be, "Oh, you can't possibly expect people to just abandon services that are compromised once" but I absolutely don't expect people to do that. I do it, because my security is worth it to me. Others don't, and this is the sort of thing that happens.

We've no way to really isolate what happened to projecteuler, and no way to now what kind of nasty code got injected into the pages.

Haven't they been wrecked once before this most recent incident?

I find it concerning that folks are so eager to rush back into a warzone when they know it's not safe. Piling onto a recovering website after a cyberattack is akin to running back into a field where landmines were found. Maybe somebody was able to remove a landmine or two, but wouldn't it be wiser to just walk around it?

Somebody else in this thread was talking about BLAKE2, which I cast a cursory glance at. It seems pretty cool, claims to evade the length-extension 'issues' that SHA-1 has.

Wikipedia indicates that there has been at least some progress as far as cryptanalysis goes, but even with that being said, there's always that lingering 'but what if' about anything NSA-related.

I gotcha, that makes sense to do it that way, such that if the foundation of SHA-2 is compromised, SHA-3 can be deployed safely where it's needed.

What is Ethereum? 11 years ago

This convinced me to not waste another second on Ethereum. It serves a self-defeating purpose, and I think it's diametric to the hacker ethos. Bitcoin is neat because it can't be controlled, nobody can tax it or pose fees on it. It's free market at it's very best. The bitcoin protocol is weak, but luckily developers are strengthening it all the time.

Laws as a general concept are diametric to human nature, and they should be avoided whenever possible, especially in regards to social realms like bartering and contracting and the like.

Have you stopped drinking altogether? Did you consider yourself someone with a 'problem' when you did your experiment? Did your findings change the ferocity with which you drink? Given that it was one of your original expectations of the experiment, do you think that social friction plays a major role when it comes to the frequency with which you drink?

I find the idea of that type of experiment fascinating, perhaps you documented it in more detail....?

Lua. Computercraft is a very mature platform for playing around with, and is powered by Lua scripts. Lua is a very simple language to learn, and Minecraft is a great platform that kids seem to love, and the tangibility of seeing the world they create be molded by the code that they wrote really has a profound effect on kids.

At least in my experience anyways. Semantics first, concepts later, this is why Lua is easier to learn than JS.

Yeah but a lot of the moderation tools that the administrators use is behind closed doors.

It's like running a chatroom and doing moderation through a bot with a little DSL built-in. The bot itself might be FOSS'd, but all the little scripts that make it actually useful are shut away on someone's drive.

That's basically how reddit is. Automoderator is kinda neat, but it's not even CLOSE to being FOSS™

I know you don't understand. I don't call police names just like I don't call any other group of people names. They're still human beings.

People should be smart enough to defend themselves and their physical safety. Weak people who call the cops over a bump in the night are digging their grave, handing over their security to the state.

You think that the world would be ruled by the violent? Open your eyes, guy. It already is. I'm talking about equalizing the playing field. The weak won't get stronger unless someone is there to show them how to be strong.

That picture looks like a mugshot. When that link opened up I thought, "Gee, you'd think they'd mention that he was in prison!"

That's really cool. I don't think that just because a person doesn't use a word regularly, that they don't 'deserve' the word or can't play the word on the board. There's THOUSANDS of words, nobody uses all of them.

I hate this attitude towards people who play games over time, and they start showing signs of game theory during play, and suddenly it's 'not about the game anymore', but it's always BEEN about the game. The goal is to win!

I really, REALLY want the cops to be at fault here, but I just don't know about this one. The sound seems to be mostly intact, unless there is some kind of offset because it does crackle and spit at one point. A lot goes on between the suspect and officer ON camera and I wonder what could've possible happened off camera bad enough to warrant being hidden when what's on the camera is already there. I mean, this guy pulled her out of her car and threw her on the sidewalk because she got a bit snarky over a ticket.

Another concern is the absence of a timestamp. This I'm not as worried about because they probably cropped it out. It's definitely understandable, especially for public-facing video to crop out some of more sensitive metadata like time, officer info, car info, etc. It's not nearly as concerning as the video itself.

Then there is the case of the actual jumps themselves. What makes me doubt is that they aren't just jump cuts, there's some stutter and back and forth motion for each cut, and there's also some video artifacts for each one.

I despise the police, I really do. The very idea of police is repulsive and disturbing, in my opinion. That being said, I think LA Times is definitely suspect here for such a bait-y headline over what looks to be an actual video issue. I mean: "arrest video has continuit problems, anomalies"? No shit, the video is messed up. It also has the entire dialogue between the two leading up to the arrest, it even has a whole other stop from another time!

I just don't see the possibility that they are hiding something, when there is so much on tape already.

Holy crap! I've been keeping up with the hype, yet having never used Docker and never needed it yet I can't help but become more skeptical now that I know that it's features aren't more complex than a little bit of bash.

People give bash a hard time, but things like this really give me that warm, fuzzy feeling.

esac4lyfe

Yet, Kevin Mitnick (yeah really) endorses them to people who answer his question "Would you spend $300 to amp up your security"

I don't pipe sensitive data through the Google cloud, but as far as hardware prices go, the Chromebook has ABSOLUTELY got Apple beat.

Furthermore, Google makes efforts to fight back against NSL's, and even have canaries implemented.

I don't use Google products when there is something better, obviously but refusing to use something of a superior quality for some reason you can't actually articulate seems ridiculous to me.

I have no sympathy who are afraid to use things because someone might be watching, especially not when that person can't be bothered to consider just using something else for sensitive data, but instead whine and moan about how SuccessfulCorp is ruining everything, blah blah, etc.

Too many 'anons' are obsessed with security, yet oftentimes they are the most security-ignorant demographic on the market.

I know the knee-jerk reaction is to assume foul play, but I knew him a little bit and he was as healthy as an ox. Or at least he was several months ago the last time I saw him.

I don't know, but it would shock me to the bone if someone could truly get angry enough at a man like him, to try and hurt him. He knew like we all knew, Grooveshark was never going to last, but it reinforced the point that Napster proved and I think that was always one of the major goals of the project.

That being said, I wish all the best to the Grooveshark family. It's never easy to lose someone like that, it always is hard.