Dr. Hax's avatar
Dr. Hax
Dr.Hax@hax0rbana.org
npub16v82...eqha
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu
Dr. Hax's avatar
Dr. Hax 1 month ago
I feel for these folks who bought coldcards. Trust in that company has been completely shattered. People expected that buying a closed source hardware product would be run by people who would invest in audits of their firmware and the libraries on which they depend. That's a reasonable expectation, even if it is based on trust instead of verification. On the flip side, there's open hardware projects like seedsigner and trezor, where it's well known that they're not raking in the money needed to fund a serious audit. Because they are expensive. There aren't a lot of people who can say "yeah, the code looks good" and have that be taken as evidence that the code is vulnerability-free. Their time is valuable. There aren't any magic answers here. Sure, it's easy for armchair analysts with the benefit of hindsight to say now what people could have done differently. It's a different thing entirely to put in the work to change the game.
Dr. Hax's avatar
Dr. Hax 1 month ago
Someone I know requested that disappearing messages be turned off unless there's something secret I need to say and then just turn it on for that message. I found this interesting because this person is keenly aware of privacy and security. It got me thinking, why do I feel more comfortable having diappearing messages on, even with someone I know and trust? For me, I think it comes down to returning to the old ways (you know, like a couple decades ago). People would say things to one another and not have a record of what was said, how it was phrased, and so on. This was certainly a problem when it came to investigating a scandal where the relevant questions are who knew what, and when? I think it's appropriate to have a log of everything said in those contexts, but me messaging with a friend isn't that. I think the counter-argument is to have a detailed record to clear one's name, likely in some social context. To show the record and that, no, we did not talk about some topic or another. And perhaps this is what I don't like about having the complete record of (nearly) everything discussed. It comes with this idea that the other participant(s) might someday reveal all of our past conversations. And for what? With perfect forward secrecy, the whole transcript could be forged. So it reverts right back to what people claim was said. This means dropping the entire logs isn't likely to convince some 3rd party. It'd only be convincing if they captured them in some way that they're confident they can't be tampered with, and that's a creepy thought and is not what is motivating to have the full record. That benefits the attacker and is a detriment to the participants of the conversation. Obviously not a good motivation for us to want to disable disappearing messages. So if sharing chat logs with a 3rd party is of limited utility for proving anything, what does that leave for a motivation for resisting disappearing messages? In my mind, it leaves the ability for one of us to go back into conversations that happened months or years ago. This kind of digging would probably only ever be done if there was some kind of drama or serious event (e.g. suicide) where one of us might feel the need to pour over every message that was ever sent, viewing it in a new light. Were there warning signs that I missed? Should I have seen this coming? Did they ever say something to me that would have clued me in that they were a jerk? And I don't think that's healthy. Digging up the past and trying to reinterpret things in a new light, outside the context in which it was said... it seems like it'd be much more stressful than if no record existed. Because even with the entire written record, there still could have been something someone said in a voice call, or some other interaction that wasn't meticulously cataloged. There's seldom any good that will come of that. The record becomes a tormentor. I don't want that for anyone. In the end, there's always going to be unanswered questions, and people are going to have to deal with that. I say, let them do so in a natural way. Accept uncertainty. I still don't have a one-sentence answer to why I prefer to have disappearing messages enabled, but if I let this percolate fir a while, maybe I'll be able to articulate it concisely. #RandomThoughts
Dr. Hax's avatar
Dr. Hax 1 month ago
Remember: it's not aboit how many lines of code you can add in anday, it's about how many lines you can REMOVE. Smaller, leaner, more maintainable software. This is the way.
Dr. Hax's avatar
Dr. Hax 1 month ago
If you want to get people on boarded to environmentalism, as in, really taking action, not just posting memes about it on social media, you need to put in the work. First: practice what you preach Second: Lead with things you have in common. Some people think environmentalists are all nuts. Don't start with "I'm an environmentalists and let me tell you why you are wrong..." Stop & think for a moment. Do you really think that is the most effective approach? Maybe start with gas prices and using a bicycle to stick it to the oil companies making obscene profits off of us. Show them bikes are pretty easy to maintain. Help them do it. Spend the time & effort. Third: Meet people where they are. If getting them to give you aluminum cans that you recycle for scrap money is as far as they're willing to go. That's fine. It's more than they were doing previously. In fewer words: Be nice to people, have some empathy, and don't ask others to do something you are not willing to do yourself. Don't expect to get results without putting in dome real time & effort Pro tip: This doesn't just apply to environmentalism.
Dr. Hax's avatar
Dr. Hax 1 month ago
I'm alright Nobody worry 'bout me Why you got to gimme a fight? Can't you just let it be? #IYKYK
Dr. Hax's avatar
Dr. Hax 1 month ago
"Invaders Must Die" --The Prodigy This album rocks so fsckin hard. 🤘🫨🤘
Dr. Hax's avatar
Dr. Hax 1 month ago
Sundays are my day off, in the sense that I don't have anything scheduled and I don't feel obligated to do anything boyond taking care of the loving things that depend on me. Today, I kept moving forward with IT tasks. Unglamorious work, bit things that feel good when they're done. A bugfix to get backups on two machines working again. Completely deleting a couple VMs and re-building them from scratch (the process is automated). Making the off-site, secondary DNS server handle an additional domain Those kinds of things. I don't have anything to show for it. No new features or capabilities. No cool videos, screenshots or demos. But I gotta say, it feels good. And now it's time to relax. You know what that means. A glass of scotch, my favorite easy chair, and of course, a compact disc playing on my home stereo. I'm going endulge myself. Kick off my shoes, put my feet up. Lean back and just enjoy the melodies. After all, music soothes even the savage beast.
Dr. Hax's avatar
Dr. Hax 1 month ago
"People who think they know everything are a great annoyance to those of us who do." --Isaac Asimov
Dr. Hax's avatar
Dr. Hax 1 month ago
Troed uaing @ZEUS's NFC feature with Square. It failed saying something like invalid card. Is was the new model register with a customer-facing screen. Different establishment, but same model as I mentioned previously that people said it worked for them. There was a line behind me, so I just switched to cash. No sense in being that annoying person holding up the line to play with weord tech stuff. Not going to win any hearts & minds that way, that's for sure.
Dr. Hax's avatar
Dr. Hax 1 month ago
Imagine it's the year 1996. People are talking about these computer things and how they can use the phone line to dial up websites and get information from universities. You tell them that in the future, everyone's going to have a battery powered computer that they carry around with them everywhere they go. You claim that everyone, even department stores and fast food restraunt, will make custom software that you can install on your computer. You'd have sounded like the people preparing everyone for flying cars, vacations to the moon, irradiated food, and a world where robots do all the work and people enjoy leisure time with their friends and family.
Dr. Hax's avatar
Dr. Hax 1 month ago
I've semi-automated watering the raised garden beds. Off grid. Press one buttons and it'll top water the little plants, another and it'll flood the underground basin. Future work will be to automate those button presses, but first, I get the herb garden, garlic bed, rabbit bait, patio plants, sundial and possibly some others to put on easy mode. Lowering my time preference for weeding will be a much harder task. The best strategy we've found so far is to focus on a small area and let the native things grow there so they can outcompete the invasives. That keeps the maintence work to a dull roar. Then slowly expand outward.
Dr. Hax's avatar
Dr. Hax 1 month ago
There aren't many things the liberals and conservatives agree on, but on the topic of mass surveillance, there sure seems to be a lot of people who are pissed about it. View quoted note →
Dr. Hax's avatar
Dr. Hax 1 month ago
I just saw an attack in the wild. Fun! An exit node is hijacking SSH traffic to github. The host fingerprint didn't match, the SSH key failed, and then it prompted for a password, which presumably would be harvested. I didn't spend much time on it, so I don't know if they patched their version of sshd to accept any password and then tie it to the repo that was pushed. That'd be smart. And I'm sure a reply-guy is going to jump in and say this is only a risk for Tor users, ignoring the fact that your ISP, their peers, and maybe a CDN can all pull off the same thing. And anyone who compromised any of these entities can do likewise. This is alway a risk. It's why we have things like TLS for websites and host fingerprints to verify for SSH.
Dr. Hax's avatar
Dr. Hax 1 month ago
Anyone know how A CUSTOMER can pay with the lightning network with square? The UI just had a pointer of where to tap (NFC) and there to enter a credit card (chip). Tapping all over the screen did not have any effect. I just paid cash to not cause a scene. Does this mean they explicitly disabled lightning payments? If not, is there anything that *I* can press on the screen to pay via ln? Please don't reply suggesting that I "just have the shopkeep do xyz". They are not going to cooperate.
Dr. Hax's avatar
Dr. Hax 1 month ago
It's a white russian type of night image