Dr. Hax's avatar
Dr. Hax
Dr.Hax@hax0rbana.org
npub16v82...eqha
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu
Dr. Hax's avatar
Dr. Hax yesterday
It works over USB power, but not with a battery. I tried with a bare Nice!nano and LiPo battery, with nothing else soldered on, and was able to reproduce the issue. It's behaving as if the battery lines don't connect to the rest of the board. Seems unlikely that I have two defective boards. I checked the polarity so many times, it's maddening. I don't get it. Nobody on the internet seems to have ever run into this either. I can't even. View quoted note →
Dr. Hax's avatar
Dr. Hax yesterday
This is the sketchiest prototype I have ever soldered together. image #electronics #diy
Dr. Hax's avatar
Dr. Hax 5 days ago
We grew, picked, washed, *sliced*, triaged, and dried 2.438 kg of Blondköpfchen tomatoes (about 770 tomatoes). That dehydrated down to just 300g. Turned out to be a bit over a quart in volume. image It required a significant amount of work, equipment, and skills, but they are SO GOOD. They'll last at least a year in storage (if you can stop people from eating them for that long). Not for sale. There's a reason nobody sells dehydrated cherry tomatoes, let alone Blondköpfchen. Too much work. Only the wealthiest people would be able to afford them. #garden
Dr. Hax's avatar
Dr. Hax 1 week ago
Kinda disappointed to learn that neither Venmo or PayPal supports the lightning network. Getting people to sign up and go through KYC all over again is a big ask for someone to make a single payment.
Dr. Hax's avatar
Dr. Hax 1 week ago
"The first Docker images [of Core Lightning] tagged v26.06.7 reported the new version but did not contain the fixes." This is just one of many reasons to release the patch and the builds at the same time. It's much harder to verify the patch is in there when all the users are in the dark about what the issue was, and what the fix was. This type of embargo is indefensible. That doesn't apply to ALL types of vulnerability embargos, but it absolutely does here, and I've been consistently saying this since before the news of this latest fuck up broke. View quoted note →
Dr. Hax's avatar
Dr. Hax 1 week ago
And I understand the argument that what we've done in the past might not be appropriate now that anyone can pay a couple hundred bucks for a tool that finds vulnerabilities. If anything, this only strengthens the existing disclosure norms. Imagine how a binary-only release will affect attackers and defenders. Attackers learn there's a vuln in that project, and can go find it right away. Defenders get a false sense of security and some will fall for "the details won't be available for another week or two, I'll get to it later" trap. The fact of the matter is if you are running software on tbe internet, you are always one 0-day away from being compromised. The smart move is to think about what data is at risk and the impact. Maybe it's moving money, or signing releases or controlling cameras inside your house. If the potential impacts make you uncomfortable, you have some choices to make. This is true regardless of the project's disclosure practices. And I think the user who have money on the line are pretty good about this, generally speaking. That's why people invest in setting up and testing multi-sig systems, have hardware signing sevices (sometimes those are air-gapped), and take other precautions. Treat them like adults. Give them all the info so they can make an informed choice. And on a closing note, I'd totally be willing to forgive the developers who fsck up the disclosure process. And I'm a big softie at heart, so I don't even need an overt acknowledgement that they were wrong. Simply saying "this is how we're going to handle disclosure and patch releases going forward" would be sufficient. This isn't a "you're banned for life" thing. But if a project I use is a repeat offender, then yeah, I'm going to ditch them. View quoted note →
Dr. Hax's avatar
Dr. Hax 2 weeks ago
It's sad to see open source project shipping closed source binaries. 🤮 It goes against best practices because it prioritizes the attackers over the users. Attackers will reverse engineer an executable and bindiff it to find the patch, and possibly find code paths that the initial patch missed. The users will be left in the dark about what was wrong, what was fixed, and whether the patch really fully addresses the issue or not. With the exception of the full-disclosure crowd, the infosec industry agrees that it's best to keep the details under embargo until the patch is written and tested, then release the patch (binary and source) along with all of the details. The industry has been facing this problem since at least the 90s. It's extremely well understood and we have decades of evidence that led us to this conclusion. Some exceptionally critical software projects post a notice saying that a security update will be released at a given date and time (in UTC) along with how severe the vulns are that are being patched. OpenSSH does this. This allows users to be ready for when the patch drops. The outliers in the industry advocate for full disclosure before a patch is available, sometimes including an exploit to demonstate the issue is real and to allow people to test their mitigations and patches. Linux does this. Opinions vary about whether it's appropriate to publish an exploit at the same time as the patch (or at all). Opinions also vary about how long developers should get to fix the issues before the person who found the issue tells the users directly. It used to be 90 days and then the details drop whether there's a patch or not. There's been a push for shorten this to 30 days. If you are a developer in any open source projects, please do security disclosures properly. If you don't believe me saying this is how its done, just look at how the open source projects who power the majority of the internet handles these things. By hiding the details from the very users you're supposed to be serving, you're putting your project's reputation on the line. Vulnerabilities happen, nobody should fault you for that (unless they're happening non-stop...), but we will fault you for how you handle it after you find out about them. View quoted note →
Dr. Hax's avatar
Dr. Hax 2 weeks ago
Just had a drive fail which held the root partition on a hypervisor that was hosting at least a dozen production VMs. No downtime. No emergency. I plan for the long term, which assumes that this will inevitably happen. That's why it's in a mirrored ZFS pool. All VMs have been migrated and I can shut the machine down and replace the drive at my leisure. Once the drive has been replaced, it goes into the pool and we're redundant again.
Dr. Hax's avatar
Dr. Hax 2 weeks ago
"First we drink all the booze Then hack all the things Then backdoor the firmware On anything you bring" "Regardless of the hardware, service, or encoding Connect it to the internet And someone's gonna own it" If you are into technolgy, this is a song you should know. "All the things" by Dual Core And because there are so many references in there, here's a guide to help decode 'em:
Dr. Hax's avatar
Dr. Hax 2 weeks ago
It's coming together nicely. Local wifi access point Local DNS (so you can use hostnames) Landing page (to point to local resources) Local LLM access (Meshtastic or wifi) File/photo/calendar sharing (nextcloud) No more "invalid cert" warnings ...and more to come. But first: more testing to make sure what I've already done is absolutely bulletproof!
Dr. Hax's avatar
Dr. Hax 2 weeks ago
I think it might be helpful to the world if people would mix together victims of goverment violence. For example Ruby Ridge, Breonna Taylor, George Floyd, and Waco. It seems there are genuinely not many people who are aware of these stories. It's rare that people know about more than half of those examples. Yet, they have remarkable similaraties. Many people won't be interested in hearing about it, but if we could reach some people, it might inspire more empathy and chip away at the polarizing divide. Nothing is going to fix everything overnight. And maybe it is beyond fixing, especially if nobody puts in the effort to try.
Dr. Hax's avatar
Dr. Hax 3 weeks ago
Super disappointed that njalla doesn't support lightning network nor do they have any plans to ever do so. I though they'd be interested in the privacy aspect. If you run an open source project, or even a company, and you want to reach out to them, they seem like they'd be a good candidate to add lightning support. Maybe it's just getting ahold of the leadership team?
Dr. Hax's avatar
Dr. Hax 3 weeks ago
Do you know a good conac recipe that isn't a sidecar? Rules: 1. Don't suggest something you've never tried 2. If I wanted an answer from an LLM, I'd have asked one.
Dr. Hax's avatar
Dr. Hax 3 weeks ago
Do any of the LLM geeks know of a free tool that can take a bunch of text and spit out a stylish flier with graphics, a proper layout, and absolutely zero spelling errors or messed up looking characters? #AskNostr
Dr. Hax's avatar
Dr. Hax 3 weeks ago
I heard a ticking today. I almost decided that it wasn't important enough to interrupt my work to track down. Sure glad I didn't go that route. When I investigated further, it was dripping water from the basement ceiling. When I investigated further yet, half the machine shop in the next room over was flooded from this water dripping. Got the water shut off so it's not getting any worse, but we still haven't found the break in the line. Dry everywhere up top, but water somehow dripping from the plywood above the floor joists. Still working on it It's just turning out to be one of those days...
Dr. Hax's avatar
Dr. Hax 0 months ago
The #bitcoin mining space is going to get more interesting in the next couple years. Massive increases in using would-be curtailed electricity is going to be pointed at bitcoin. I wouldn't be surprised if the difficulty doubled. And that's going to squeeze out any companies why are using power that isn't going to be otherwise wasted. This has been happening in an increasing number of places around the world... Europe, Brazil, Africa... I'm an environmentalist and I like cheaper, more reliable power, so this is great for me. Replace fossil fuels with a flexible load? Yes please. Stablize the grid with a technology that is 1/3 the price of batteries? 100%! Give solar and wind farmers more money for their existing capital investment? More of that. As for mining companies who were built around the expectations that may no longer hold... probably not so good for them. As for more miner centralization, yeah, it'll probably mean consolidation... unless people start up more mining companies. If you have stranded power near you, now might be a good time to get the wheels in motion. Because when miners go under and liquidate their gear, you want to be able to jump on that. But if you REALLY want to contribute to decentralized mining, don't just start a mining company, plublish the blueprints on how to start one, mentor people who are trying to do so, sell your expertise, and put some skin in the game to align your interests with the other people who are starting these things. Scale it out so we have lots of smaller companies. Helping one another makes more sense than allowing big players to swueeze out the little guys. It does necessarially require a significan capital investment to get started, that much is true, but it doesn't have to be your capital. You could do the operational parts that funders don't want to deal with. You can be the one to connect the existing power suppliers with the people who can cause them to get the most of their investment. Being the connection-maker is very valuable to all parties involved, if you're actually doing a good job at it. If it results in a profit, it will be rewarded.