HN user

simondedalus

285 karma

Full of hope and all delighted. . .

But alas, 'twas idle dreaming. . . .

Posts0
Comments95
View on HN
No posts found.

You would have a point if the exploit were more serious, and looked harder to fix than it does.

As is, this is a phishing type variant that it’s not at all clear gatekeeper was even designed to stop. However, the default behavior described (especially making symlinks to NFS shares without any sort of warning or special graphic when following them in Finder) seems sufficient for forceful language when complaining about it to Apple / giving a disclosure deadline then publishing.

[dead] 7 years ago

Good thing, since America has had a variety of socialist policies in place since before anyone currently alive was born and continues to.

Socrates “knows that he knows nothing” and spends his time trying to refute that. He looks for knowledge earnestly but usually doesn’t find it. Socrates is less devil’s advocate, more “how can we be sure of X when Y? If not Y because Z, doesn’t Z also make X problematic because of (blablabla)?”

Sure, he gets people RAGEing like a great troll, but at least ostensibly he’s doing more the 2nd type of argument described in the article, but with kind of a backdrop that precise intellectual beliefs are really hard to specify or maintain. It’s like dialectic but it’s not Hegelian; he wants to return to some central question and doesn’t necessarily see that thesis/antithesis climb as crucial, he just finds problems with the premises and wants to find better ones (Hegel’s whole thing was a bit more nuanced than that).

Re: article, trolling initially meant trying to get a rise out of people. It’s not so much you won’t admit you’re wrong or you’re eristically tearing everything down, it’s that you’re pretending to play the argument game (or some other game, like “art criticism” or “testimonial”) but in fact you’re fucking with people of varying levels of specificity.

it is of course just a matter of time for either of the companies you mentioned to "be hacked" (obviously it's happened countless times with Microsoft, both the OS and their cloud services like O365, and there was a recent high profile revelation that the google apps suite APIs exposed user info to developers). the difference is incident response and layered security.

as long as you're using software somewhere in the stack that isn't like maturity level 5, AND you don't have constant audits looking for novel attacks on working-as-intended systems, you're pretty much guaranteed to inherit (or create) a vulnerability at some point, and if you're important enough it will get exploited. the reason that doesn't mean we should start modeling computer systems as "living organisms that eventually get old and die" and should keep modeling security like war is that when you get hit, you can respond. all the layers matter, and insofar as Microsoft or Google do it right, they primarily do it right by having a mature process for monitoring, patching, isolating, etc.

as for docker hub though, yeah i'm totally with you. i'm just saying we shouldn't overestimate the preventive capacity of anyone, honestly. if you're doing anything important over the internet at all, you're making some compromises somewhere.

here are 2 links to things i handwaved at above, for example's sake:

https://www.wired.com/story/microsoft-email-hack-outlook-hot...

https://www.forbes.com/sites/kateoflahertyuk/2018/10/09/goog...

as i replied in the comment below, the goal isn't "absolute porn free paradise," it's "keep our current control working." sound shortsighted to you? it is. it's also the easiest thing, and frees everyone up to do other, more important work than impressing people who are aghast that an organization would uninstall 1 of 2 browsers b/c it bypasses some control of theirs.

as for once chrome implements DOH, they'd cross that bridge when they came to it. it's an uphill battle, because really content filtering, of course, should not be done through browser settings (remotely managed or otherwise), nor solely through DNS. if whoever tells IT what to do in that school district is hellbent on it being impossible to browse to pornhub, they'll ultimately need a layer 7 firewall. but again, when you're on the budget, you do fastest / cheapest / most effective.

(and if we return to pure hypothetical, i would argue that dns filtering really is the best way in their case, because anyone who could bypass that--besides just using firefox--will be able to bypass better chrome config, or your firefox config change, etc, since they can just edit host file, etc etc etc)

this is getting really boring and repetitive, but you didn't give a "cheaper" solution, you gave an administratively more expensive solution (change files on machines rather than bulk remove an app which is out of the box functionality for many products IT like this would use), along with moving the goal posts; the goal is "keep my DNS filtering working," not "make sure no one ever gets to the porn site."

of course, you would need to do more in chrome (and windows/osx/ubuntu generally) to stop traffic to a site if a student knows what they're doing. that's not the point. the point is: we have this control in place. we've agreed it's working well enough. people can bypass the control simply by using firefox. to avoid adding overhead, we ditch firefox (for now). it's that simple.

as for future-proofing, that's a luxury. ...and part of why it's a luxury is that some goals ("make all traffic to any porn sites impossible on our school network") just aren't going to be met by budget IT.

re: BYOD, for that i go over to the armchair tech purist side i'm afraid, and just say "well, you allow that, so you need to get over that they can use VPNs and stuff. you're not DOJ or some wealthy corporation with important IP assets and equally 'important' VIP execs that insist on bringing their OSX 10.6 MBP to work. you don't get to have all the cool controls that might allow BYOD. sorry."

the DNS filtering works on chrome. yes, people can bypass it, but it doesn't even work on firefox, so they remove firefox. this isn't rocket science, and you're being foolishly contrarian instead of trying to understand what the original commenter's actual situation is. this leads me to believe that you are hypothesizing about work you don't do, but feel perfectly qualified to talk about "half assing" things.

of course it's possible to do so. but DNS filtering works for most users, and is much easier to centrally manage on a budget (in terms of time / people / money) than browser settings.

i'm belaboring this point now, but people who actually do this stuff know that you can't just throw up a GPO to fiddle with chrome settings and expect everything to work. this culture of "power users" thinking they know the best course of action for every situation in IT (and it's always "that thing i Put In The Work to do when i was tailoring my own system") is really silly.

firefox messes up their DNS filtering, chrome doesn't. so they remove firefox and enforce chrome. if you see that as a slippery slope, you're imagining it. they probably 1) have a decent app like ninite to remove and install apps, 2) don't have anything but their production environment, 3) don't have a homogenous environment in terms of patching (maybe they do), 4) don't have people to go around and make sure the config changes they push (however they would push them) took, worked, etc. so they block the app. maybe eventually they reinstall it. welcome to IT.

...which reinforces my point about how people actually doing this and people speculating about it tend to respond to issues like this.

no, using the nuclear option of removing the browser outright when others work is the smart, efficient option that someone who actually works in IT with limited resources would (and should) use.

this stuff about finding all the right config files during "basic hardening" and having it just work is the stuff of armchair commenters and people who do IT/security on a well funded, sufficiently redundant team. assuming the latter would be the people in charge of school IT is hopelessly naive.

"Don't do that. A job interview is a structured process designed to let you consistently evaluate multiple candidates. If you are asking each candidate different questions, that's not a fair test."

if this is the thing you're responding to, you're misunderstanding the post entirely. "fair test" here is not about morals, it's about results. if i want to evaluate 2 candidates, i want the test to be as "fair" as possible so that i have the most relevant, fine grained information as possible. i want to render the candidates commensurable so i can make a better decision for my own purposes.

"life's not fair" in this context sounds like some kind of systems pessimism. it sounds like you're saying "stuff doesn't work." but of course it does. of course asking this question and not that question gives me more relevant hiring information. it's totally insane to think otherwise.

i gave you the benefit of the doubt when i read your earlier comment, but this doubledown shows you're extremely naive / have no experience with the space. you realize there are entire industries (plural) premised off the fact that you can't just throw up "any firewall" and detect this kind of thing, no?

can you imagine how it would go down if a major corporation like apple experienced a hardware hacking based infrastructure breach, contracted a cybersecurity company, and the tech heading their case asked them like "well were you making sure to check which ports were open?"

IT or cybersecurity both benefit from CS (cybersecurity especially, since that's basically just CS/IT + read the news / some sec feeds + basic risk assessment and management).

the good thing about IT for you in particular is that scripting is so important to it that it might sharpen your programming skills enough to incline you back toward software engineering. sysadmin scripting is obviously less theoretically demanding than most software engineering tasks, but you can get the satisfaction of solving real problems (relatively) quickly using code--and knowing basic CS principles will only help, as long as you're open to learning the practical realities of IT, which often strain to breaking the idealistic assumptions many CS people have about how systems work and where/why they fail.

nature of consciousness is the biggest one IMO, precisely because it doesn't appear to be captured by "nature of existence." we have good physical/mathematical models on hand re: causation, such that we can at least start hypothesizing about what change is, where the universe came from, what if anything differentiates life from other motion, etc.

but consciousness is so categorically different that we can't even start. "well, brains are made up of cells and further of particles, and electricity works this way and here's some results from information theory and [UTTER MAGICAL WALL / ABYSSAL GAP] then there's the subjective experience of consciousness and will. and damnit we don't have anything like a logical or explanatory connection between these two sides, but for 'well, if i destroy 'someone else's' (??? what's this possessive in our fundamental terms???) body in the right way, it stops acting as if it's conscious like me, and also my own consciousness (which i can't describe with any specificity) changes when i do weird physical things involving drugs, injury, nutrition, um... and attitudes seem to matter, and there's definitely a subconscious, i guess, and...'..."

there's also of course the possibility that uber violated the CFAA if someone exfiltrated data from waymo, though the distinctions re: access without autorization and access that exceeds authorization are quite nuanced.

if "uber-spy" had authorized access to many secrets, intended all along to steal it and bring it to uber, dumped a ton of data, then left and carried out their plans to give the data to uber, case law says "uber-spy" didn't violate any clauses of the CFAA, whether they signed an NDA or not ("contract based restrictions" are rarely if ever considered unauthorized access per the CFAA). however, there are many gotchas that can hook that data into access in excess of authorization (exfiltrating it on company property, even printed pages for example).

once you have a nexus to get a CFAA violation in, you can start bringing in intent and monetary gain and such and potentially even get into easy to prove strict liability offenses.

given the description of their anonymous server, secret phone team, there's a pretty good chance that stuff alone will open them up to CFAA based prosecution, which could go very badly. who knows though.

if you're interested in this sort of stuff, which may be tangential to uber/waymo (i'm not sure / don't care) , orin kerr is the person to read.

in what fantasy world is chess.com more "serious" than the ICC? the one where attracting a couple super GMs to play promotional tournaments is more "serious" than having thousands of titled players online? not to mention the superior autopairing system.

serious: ICC, for the competition. casual: lichess, for the dramatically superior UI and value than any other site edit: the personal analytics alone make lichess superior to chess.com and other long time inferior sites like chesscube.

playchess and chess.com are relics, though chess.com survives on promos and articles and such.

best way to learn vim:

(optional) first, go thru vimtutor (just type vimtutor in your shell and press enter).

second, get a vim cheat sheet (google).

finally (most important), code a few things using vim. keep google at the ready to look up "how do (etc)?" to speed up things you're actually doing.

once comfortable with that, maybe watch a few vim tips videos.

after all that, you will probably find vim much more comfortable than gedit, textedit, notepad, etc, just for the power. if you favor ides, you'll probably need to do a lot of tweaking to love raw vim, though or course some ides offer vim keymapping anyway.

(: these aren't the droids you're looking for. taking down the internet (or specific pockets of it) via BGP is not a question of method, it's a question of access. BGP hijacking can be easily done by computer science grad students... state actors would not need to test a "cyberweapon" that messes with BGP routes.

edit: the point being, how to do it is not an issue. they're not in the position to do it. ...but if you were thinking of censorship or outright disruptive terrorism via BGP, you'd be looking for infiltrating network operator jobs, not developing an attack. the attacks themselves are trivial, well-documented, and often happen accidentally.

edit2: "sorry we broke the internet" http://seclists.org/nanog/1997/Apr/444

not to put too fine a point of it, but there's a world of difference between creating a ledger that creates a "distributed" SQL database whose integrity is guaranteed among non-trusted nodes through a blockchain, and using smart contracts to "put a functioning SQL database on the blockchain."

"get used to blockchain when all you know is SQL" - cool.

"guarantee all us non-trusted nodes have the same SQL database" - ...sure, but for any project such that i want this, i'm pretty sure i don't need a blockchain. (but of course, your project doubtless has uses i haven't thought of)

"i want a trustless SQL database so i'm going to use EVM and solidity and put it on The Blockchain because i'm awesome" - very bad.

"i'm starting a new project, so naturally i need to use a blockchain" - extremely bad.

not only would it be hard, but using a blockchain (a type of database) to represent a functional SQL database using smart contracts is a mind-numbingly bad idea.

(insert "should i use a blockchain" infographic, which is amusingly impossible to google image search for, because this question evidently does not often occur to people...)

and the virtue of allowing a single point of 2FA.

the seed is just the seed, and will always be the seed. the master password can change and be supplemented by 2FA / other enhancement schemes.

this film is pretty great. i got it on video from a catalogue in the 90s (heard of it because one of the stars was in kurosawa's "ran").

if you like this, you would probably like shuuji terayama (of emperor tomato ketchup fame), those his work isn't the easiest to get in the USA outside of an academic context.

more available is nagisa oshima, a lot of whose work is on the excellent streaming service filmstruck, but it's a bit headier than bara no soretsu.

yeah, i recently downloaded intellij idea for the first time (i generally eschew IDEs) to try my hand at kotlin, and when the "use vim keybindings? " option popped up during setup i was like "(very satisfied and refreshed) ahhhh..." works well too for a slim .vimrc user like myself.