HN user

phkn1

89 karma

[ my public key: https://keybase.io/phkn; my proof: https://keybase.io/phkn/sigs/1X6UR9uC4N8XD0dzrOY3OKr6TmY_txot4scZznojrDk ]

Posts2
Comments28
View on HN

Under this interpretation, wouldn't (say) a collection of Facebook photos with statues, in aggregate, constitute a database and therefore become illegal? At what point does the size and structure of a collection become sufficient to cross the legal line? Would an individual Facebook user therefore be liable? Would Facebook as whole? etc.

It seems that the law has created the unintended consequence that the organization of the depictions in question matter more than the actual depictions themselves. Or in other words, of imputing commercial intent to any such collection of copyrighted works, whether intentional or otherwise.

Depending on the system you use to view the text, many of the characters are actually printed using non-Roman lookalike characters that still render as the "usual" ones.

In OSX / Firefox I see the usual text in the web view, but in source view there's a variation in shading between characters, in what should be an unadorned monospaced font. Viewing the same source in Chrome shows the trick for what it is...

https://www.dropbox.com/s/oj9cqlh3kh90zep/Screenshot%202016-...

Subtle and not always visible due to differences in display normalization in various libraries? Way out of my depth for system fonts / encoding issues. But hopefully the above shows what I'm talking about. Could there be some data hidden in the lookalike string values?

http://www.lookout.net/2012/04/generating-confusable-lookali...

Did anyone else notice the weird GNU/Linux screed on line 803? In particular, the "Additional Comments" content is actually written with a large amount of look-alike Unicode. Playing around with this data in Excel somehow byte-shifted it into garbage. I noticed that other folks thought it would be funny to put things like =SUM(G1:G1000) in other cells, but this seems a little bit more sinister for some reason. Anyone savvy enough in UTF-8 to deduce what's going on there?

I've done a whole lot of individual research in the last two months, consulted with two dentists and an endo, gotten opinions from friends and family etc... seeing that any procedure is irreversible, it seems prudent to take the least drastic option first. I don't have a particular concern about recurrent infection in this case, because my diagnosis is about trauma, not decay. What concerns do you have?

Assuming for a minute that bottled air is a viable solution to smog, it's only the prestige of "exotic Canadian air" that necessitates the long shipping distance. Bottling filtered air from a relatively local source might work... but only if your factory could generate net negative emissions.

And anyhow, to have a health impact, we're talking about large quantity concentrators for those lug-around supplemental oxygen machines. These look awfully small to have any impact long term:

http://vitalityair.com/products/bottled-goodness.html

Anecdotal: I once tried purchasing a similar Oxygen can at a high-altitude ski resort as a sort of "stamina inhaler" on a heavy powder day. A good puff would return one's breath to normal pretty quickly, but the can ran out after a few hours of occasional use. So, at best these can be used as an ersatz, non-medical inhaler.

On the other hand, the market for air filters is still booming.

In particular, this summary graphic is telling:

http://img3.auto-motor-und-sport.de/Abgastest-Wertung-fotosh... (blurry, sorry)

At the top of the NOx scale we have a VW TDI engine (albeit in an Audi Quatro application).

Near the bottom of the NOx scale we have... a VW TDI engine.

In other words, VW already had the capability to eliminate the emissions through design, but chose to cheat the tests instead. That is rather damning evidence, and serves as a rebuttal for those who think that VW is somehow being unfairly targeted.

Clearly, many other companies also need to lower their emissions, and regulators need to adopt meaningful tests. But to cheat the tests that do exist, and for no clear need (except possibly profit margins) is inexcusable.

Safari on Yosemite also shows power usage per tab which is great for identifying rogue websites.

Also... TIL that some sites take more power to render than a 1080p stream!

This also of reinforces the argument for installing an ad blocker -- less elements to process on each page means less power used. µBlock is particularly promising as it's very lightweight.

Hotel melancholia 11 years ago

An interesting take on the experience of occupying a transient and impersonal space, but also a reflection of the author's perspective on travel. The two are not the same.

Being disconnected from friends and family, being too narrowly focused on work, or actively avoiding human entanglements as the author admits, is a perfect framing device for melancholy. Whether this takes place in a home or in a hotel is simply a matter of setting.

Having held a travel-intensive consulting position in an earlier part of my career, I absolutely identify to the melancholy of constant dislocation. However, now that I work primarily at home, I do miss the occasional changes of scenery and am looking forward to my upcoming vacation overseas.

The moral of the story is that balance matters, as does context. Too much constant motion produces alienation. Too little produces boredom. And it's much easier to look forward to a personal trip than a business trip, because the former is much more directly rewarding. As important as it is to travel, it's just as important to have a sense of homecoming when it's over.

Because you don't own any of those things. If you own your own plane and have a pilot's license, you are more than welcome to fly it yourself and to disengage the autopilot should the situation demand it.

I wouldn't mind an autonomous car-share service. Just saying that Musk's futurist vision of mandatory self-driving vehicles is incompatible with personal control of personal technology, and practically, politically infeasible in the US anytime soon.

‘In the distant future people may outlaw driver cars. You can’t have a person operating a two-ton death machine!’

I don't care how good the design is, people will always require a way to take control when they wish. The trick will probably be to make the UX (passenger experience - PX?) so much easier than driving that nobody will want to.

But outlaw them? Nah...

Here we see the other side of the "responsible disclosure" coin -- if the ethical white-hat security researcher is required to withhold publication of a critical vulnerability for a set amount of time, is there a corresponding deadline for timely publication as well? And if that deadline is not met by meaningful attempts at remediation or disclosure, is the researcher not compelled to publish the findings independently?

Obviously these companies failed miserably to meet any reasonable person's timeline of disclosure. One question is whether the extra time researching this malware reasonably would have produced additional worthwhile intelligence about its function and targets. If so, then the delay was "worthwhile". Another question is whether it's not better to simply release an incomplete picture to the security community (perhaps selectively) and let the larger hive mind go to work on finding and corroborating additional clues.

It seems like the firms chose the former; many HN readers would advocate the latter. So finally, the question remains whether such a forced disclosure would be perceived as an irresponsible "leak" based only upon the disagreement in methodology and interpretation of "responsible"? Would its withholding be considered likewise irresponsible? Can a single firm, a collection of firms, or the security research community at large meaningfully stay ahead of a dedicated state-funded attacker? (Probably, Probably, Probably not).

If a nation-state is producing malware, it logically will also be monitoring the channels of disclosure for evidence of its release and detection in the wild. But that's no reason to limit the resources being dedicated to protecting the public; it's egotism at best and collusion at worst.

If you can mitm the dns or ip you can still do this even with https.

Strictly speaking you'd need a compromised DNS and a compromised CA (possibly with a wildcard certificate). Certificates provide assurance of identity as well as encryption (that's why public key encryption works). No matter where the connection comes from. (EDIT: If I compromise DNS for an SSL secured site I only get half an attack.)

does the app allow "upgrading" to a lower version number automatically?

I'm not as familiar with the app update mechanisms in respect to enforcing monotonic version numbers. I don't have proof it enforces this, however.

the app enforces signed updates, no?

The author says it best here:

http://httpshaming.tumblr.com/post/95160721901/but-its-signe...

Right you are. Fixed the title. The the app does sync the notes themselves over SSL.

But this is still a risk, as the link to the app that does the syncing could be blocked to maintain a vulnerability, downgraded to a vulnerable version, or potentially compromised...

I'm fairly certain that this would be a clear application of Double Jeopardy clause of the 5th Amendment for at least the majority of charges; in short, this is true because whether or not the case had merit, the prosecution definitely screwed up the proceeding.

There may have been a case for CFAA violation (right or wrong), but the prosecutors improperly chose New Jersey as the venue of proceedings. This was a calculated move that had the effect of producing additional state charges, which then resulted in an increased Federal charge for CFAA + State Law violations. That sort of willful "venue shopping" cuts both ways, then; as soon as they try for additional charges, prosecutors now had to conclusively prove that the location of venue was material to the crime at hand, as well as the actions committed.

Since Weev &co were not in NJ at the time the act occurred, and neither were the machines they accessed, and there's no conclusive proof of NJ residents being harmed, then the venue of crime committed was incorrect and thus so were the additional charges hung on it. And that is the prosecutorial misstep which was overturned on this appeal, which is subject to jeopardy limitations.

http://criminal.findlaw.com/criminal-rights/when-double-jeop...

Glad to see she has belatedly grown a sense of moral indignation about overreach by intelligence agencies. Once can only hope that this debacle will add credence to the idea that the US clandestine apparatus is in dire need of meaningful reform.

Emacs, naked 13 years ago

Why go to all that trouble? There's always "emacs -nw" to get pretty minimal in an xterm...

[dead] 13 years ago

Likewise, though my specific concerns were around a suspiciously large volume of inbound traffic that appeared to be maliciously probing for open services, and in particular a lack of any sort of upstream mitigation (to paraphrase their response, "can't help you, try Cloudflare".

Of course, Digital Ocean has had its own problems lately with not properly scrubbing decommissioned VPS containers... so to some degree, data security is not a Linode specific problem. And for that matter it is not just because someone is recycling passwords (bad), but because it is by nature one of the most fundamental and pervasive security challenges with any VPS hosting. Your AWS node might be perfectly secure, but it might be sharing a physical rack with a Russian botnet and you'd have no way to know.

Bottom line, if you are using a shared environment there is always some risk of having bad neighbors, experiencing disruption at the supervisory layer or of your data bleeding over into an untrusted location. Your application security design should be planned accordingly, and the choice of VPS host is only one part of that equation.

Source: CS major with 10 years experience in enterprise development, support and systems architecture consulting.

While it's always possible to be a development autodidact, and in fact to be quite productive this way, there's a reason why the theory and practice underpinning good software have been codified in the study of algorithms. Shortly said they are knowing your tools, knowing when to use them, knowing why to use them, and recognizing their strengths and weaknesses. And finally knowing these things instinctively, not just casually, so you can diganose complex issues in terms of understanding their larger moving parts, and not just the low level details.

Knowing your tools: Anyone who has debugged code where some critical component is based on nested arrays or other representation with similarly poor scaling characteristics, and banged their head on the desk on reading the code, will understand this one. If you aren't even aware of a possible range of workable, if not optimal, solutions for a given problem space, then you are unlikely to come up with a stable and high performing solution.

Knowing when to use them: On a practical level, it's important to know the proper use of the tools available to you (and how to recognize when one is not well suited to the task at hand). Having a clear picture of the applications where X versus Y representation or approach will perform better is critical to being able to accomplish the 'big picture" task effectively (whatever that may be). Recall that nearly all mathematical and CS proofs will refer to other, more well-known concepts in establishing newer concepts; in the general case the proof of any given algorithm's workability can be expressed in terms of its reduction to another well known, well understood solution. The same is true of your code using a well known library that implements any one of these.

Knowing why: Similar to "when", but a little more nuanced. On a philosophical level, it's useful to separate the problem-solving aspect of the job from the creative aspect, and avoiding re-inventing-the-wheel when it's not needed to solve your unique problem (hint: it's probably not that unique). In other words, if you have a finite budget of mental effort to expend upon a given programming task, you'd be better served by ensuring you meet the low level requirements of its implementation with an algorithm that you understand intimately, than laboring through a hand made solution for a problem whose details you might not know anyhow. (Of course, see also "if your only tool is a hammer" -- laziness is useful, but only to a point.)

Instinct: Experience goes further than simple knowledge, because the units in which you "think" are constantly changing. In the same way that a chess master sees more possibilities and nuances in the opening moves of a chess game than a novice can see in individual pieces, a novice or even skilled autodidact can not bring to bear the same skills as an experienced programmer with intimate working knowledge (if not extreme detail) of a wide range of possible approaches to a given solution.

Finally, consider that nothing I've written above precludes "creativity" -- it simply provides you a tool kit that moves the bulk of mental effort to a higher level of execution.