HN user

udev

909 karma
Posts8
Comments202
View on HN

You answered your question.

Making a CPU requires exactly "photographic plates and film, exposed and developed, other than motion-picture film", i.e lithography and more and more extreme wavelengths.

Fuzzing is not a magic trick, in the same way as invariants are not, and unit tests are not, and debugging is not.

All these techniques have degrees of mastery, and if applied carefully, and in combination, can save you a lot of grief.

Dumb fuzzing will not get you anywhere, same as dumb unit testing, and dumb debugging.

In this case, iMessage is particularly well suited for some smart fuzzing because all the attack vectors seem to involve smallish malicious attachment files.

What code auditing? Are you claiming NSO has access to iMessage and iOS source code?

NSO seems to be finding more and more bugs by poking a black-box alone, while Apple cannot seem to be able to fix by looking at the source code with all the fuzzing and verification tools, and much more $$$ at their disposal.

I don't understand Apple here.

Just put an army of people on fuzzing the shit out of iMessage and all its possible file attachments.

You tried and failed? Fire the bozo who lead the effort. Try again.

You did not even try? Fire the c-level bozo who failed to see it coming and failed to approve such an effort.

But cynically, more and more it feels like some bugs have to stay unfixed, for NSA use, just that NSO is also getting on the game.

From information perspective we are looking at two pieces of information: the request itself, and the answer.

The answer contains just 1 bit of information, yes or no.

The request carries much more information. Did you chose me specifically from all my colleagues for this request? This informs me about you and how you operate. Did you wait until a specific moment to make this request? This informs me about you and how you operate. Did you attach special conditions to your request? Did you formulate it like it's nothing, when in fact it is a big deal? Etc.

The Askers think there is no information in the request itself and its specific formulation, and just care about the 1 bit of information in the answer. They also believe that the request-answer is a stateless transaction, i.e. that nothing gets memorized, or changes the environment going forward.

The Guessers are the opposite, are very careful with what the information disclosed in the request itself can do to the environment, the people, and the relationship going forward.

"You could've just said no" is what Askers say when they want to say: please ignore all the information in my request.

Example:

You are a friend who often scratches/dings his car, has occasional accident, etc. and you ask me to loan you my car, which I saved a lot for, restored old model, etc.

I will say, NO.

But I also learned something about you, that besides being careless you are also not self-aware, so I will take that into consideration going forward.

This reminds of Richard Feyman's observation how some people count visually while others do it by sound.

You might be one of those people that can do math purely symbolically, by parsing and manipulating expressions, a bit like regular language and you don't need your brain to build a mental image for the things you work with.

I am intuition-first kind of person, and let me tell you, intuition is not a crutch, it can do things where symbol manipulations would take orders of magnitude more effort.

It is actually possible to imagine and manipulate highly-complex, multi-dimensional things that don't have equivalents in nature.

Imagination is a muscle used a lot when thinking intuitively, some of us have it developed to a ridiculous degree.

I also speak the same four languages plus one more.

I do consider there are advantages to speaking several languages.

I learned from English that you can be very precise, but also economical in exposition of complex matter.

I learned from Russian how incredibly powerful and nuanced a language can be (too bad it is currently used to scare people everywhere). I always say that "you can translate anything into Russian" and, if you have the skill, it will carry over the original style, atmosphere, and colour. Not sure how to explain this, but e.g., you can almost get a feel for the New-York accent reading a good translation into Russian. I heard from several people that Arabic has a similar power of expression.

I learned from French that there are way more words for expressing feelings than I was using before, and also a certain way of having no-pressure intellectual, exploratory conversations, exchanging ideas among peers. It has a certain rhythm and many turns of phrases that work very well for this.

In Romanian you can be incredibly sophisticated (via modern French influence), but also stay close to the agricultural and pastoral roots. The language just has this great dynamic range. Romanian literature has examples of great works that are essentially collaborative, and have hundreds maybe thousands of authors (some likely illiterate), and that were passed along in oral form with various modifications that were finally recorded and published less than two centuries ago, and are very much readable by modern speakers.

===

Bonus: More things that I learned from English are certain expressions that guide you into a (I think) pragmatic world view, e.g.:

  - thinking clearly about hidden assumptions, e.g. "don't make assumptions", is easy in English, but is convoluted and indirect in the rest of languages I speak.

  - what I call "scoped" phrases, e.g. "just because IDEA1 does not mean IDEA2", or "IDEA1, though IDEA2", where English language helps you to avoid exaggerating or generalizing too much, by making it easy to "scope" your statements, but also helps you to be explicit about the boundaries within which your statement is true: "Just because I refused your first request, does not mean I don't want you to try again."

In Canada, kids can write letters to:

Santa

H0H0H0

which is valid postal code, and used to be processed by volunteers around Christmas time.

I suspect you can just write H0H0H0 and it will work.

If I sense lack of clarity and focus in your question, I will tend to provide extra context with my answer just to make sure you are not about to make a mistake.

If I sense you come with a very pointed, clear, relevant question or request, and I have a history of clear communication with you, I can trust a short/tight answer is enough.

But I agree with you on one thing, all things being equal, people who think and speak more clearly tend to also write (code, documentation, emails) clearly.

A DRAM Failure 4 years ago

The 48 DIMMs problem is not so bad...

Remember those problems where you are given n gold coins (among which one is fake) and a balance, and the task is to find the minimal number of weighting operations to identify the fake coin.

So, you go binary search looking for the borked DIMM, load 24 DIMMs see if it crashes, if no crash -> the borked DIMM is in the other pile, rinse and repeat...

If everyone around, except you, sounds angry about something, it might just mean something is wrong.

Whether this goes against your comfy-in-my-relaxed-state attitude, or you are not ready to face the negative information, does not mean everything is fine.

I bet you read the title only, and not the article.

There is way-way more to it than the title. Nowhere did the author reduce the contribution of non-engineering roles.

An excellent read!

From the article "In summary, please take time to write strong recommendation letters for your best students."

"of course" and "obviously" it is not intended for students, but for professors writing recommendation letters for student that intend to go Cambridge.