Hacker Newsnew | past | comments | ask | show | jobs | submit | ufmace's commentslogin

I don't understand why it's so common for Europeans to act like they speak for the entire rest of the world outside of North America.

> key verification - I certainly don't see any of that in Google's "Messages" app!

I do! I have a old-ish but up-to-date and stock Pixel phone, and I see (what appears to be) full E2EE with several text contacts in Messages, with ability to verify keys (which admittedly I have not attempted to use yet). It only works if both devices / all of the devices in a group are fully compatible with the version that adds encryption or newer, but when they do, it just starts working automatically and transparently. AFAIK, that's primarily thanks to Google's work.

I think what we've learned from the rise and fate of current alternative messaging apps and services is that, if we actually want to get the majority of the world's population on modern-quality E2EE for all of their communication, it's going to have to be done gradually and transparently through the apps they already use. Getting everyone to switch to a different app is a pipe-dream that will never happen, at least not thanks to the work of any particular person or company.

Apple is pretty good at privacy and security for people playing within their ecosystem. They seem rather indifferent to any attempts to communicate or interact with anybody without an Apple device. Better than nothing, but not great IMO. Google has many faults in many areas, but I think they're doing awesome work at a difficult and thankless job as far as developing a standard for modern and fully encrypted communications that is actually possible for everyone to switch to transparently, and dragging everyone kicking and screaming into actually using it. Apple just rolled out support for it in beta 4 months ago. Very likely in the next year or so, we may see the majority of texts and group-chats between Android and iOS be actually E2EE without the users needing to do anything besides ordinary OS updates. That will be IMO 80% Google's doing, and 20% Apple's.


Part agreed (E2EE by default so broadly is a great achievement), part "I think this is likely a massive communications power-grab on Google's part and not all that altruistic". They control almost literally all of the servers and the only app nowadays (Samsung's is shutting down), globally, outside of Apple. Soon they will see a massive portion of the world's contact graph in near real time due to presence checking.

I am very glad to hear they're finally exposing some of those details though. Now they just need to open it up to third parties, like the original reference implementation did over a decade ago, so we don't need to blindly trust them as much.


I mostly agree. I think it's more of an imperfect world thing though.

I agree that I don't entirely trust Google with all of this power. The problem seems to me to be that every other relevant player in the industry has even less interest in setting up reliable universal secure messaging. Apple is mostly interested in keeping everybody inside their walled garden. The carriers are mostly interested in figuring out new revenue streams in an attempt to get themselves out of the "dumb commodity data pipes while also forced to spend big money on constantly updating nationwide infrastructure" role that the mobile tech world has forced them into. Mobile hardware providers are basically the same, except for hating the "dumb commodity hardware provider of the 13th black rectangle" role. Nobody else's opinion actually matters in this world.

I'd be happy to see them set up their own servers and an actual federated system, it just seems like none of the other players really want to do it.


It's a silly idea that's full of holes:

> Free use comes with responsibility: whoever occupies a home must keep it in excellent condition and cover its ongoing maintenance costs. If you can’t afford to properly maintain a particular home, you can’t occupy it

Exactly who decides what constitutes "excellent" condition? Exactly what do you do with people who fail to keep their home in what whatever authority figure considers to be "excellent" condition? If I really want a property somebody else has, can I trash it right before inspection day or pay off the inspector to declare it non-excellent? What do you do with the poor hard-working family who just doesn't have the time or money to keep their place in "excellent" condition? What do you do with the mentally ill person who trashes their place every other week and can't afford to fix it?

> For desirable homes or plots, anyone can apply during a fixed period. If demand exceeds supply, the new resident is chosen by lottery, regardless of income, wealth or status

Lottery? Riiiiight. There's just no chance a simple lottery system will be able to manage the issue of to what extent particular homes or areas are desirable. There's no way a lottery system massive enough to even attempt to address the issue will actually be free of influence by wealth and status.

> The country must always keep at least 10% of homes/plots available, creating real choice and mobility

Exactly how is this going to work in practice? Which "10%" is going to be kept available, and how do we make it available? If we have a desirable city center with under 10% free, do we have to kick some people out to keep that 10%, or do we kick some people out for a while to build denser/taller buildings? Or will our "10%" only be in the undesirable areas?

If I'm a rich person, can I pay off a poor person who happens to have a nicer house to move out to a somewhat less nice house so I can move in? What if I say, I'll pay you to voluntarily move out, or I'll pay someone else to trash the place or pay off the inspector to get you kicked out?

Nobody is smart enough to dream up a new system in 10 minutes that actually covers every possible use-case and situation more fairly than our current capitalistic system that has existed and had all of its rules in practice and iterated over for hundreds of years.


> Exactly who decides what constitutes "excellent" condition?

In my country, some people have decided that a Homeowner's Association (HOA) is the body that decides, and for those who don't want to live subject to an HOA, their city, county, and/or an AI make that decision. And of course the companies insuring the homes also have a say in the condition of the properties they insure.

Right now, for example, a city in my area has decided to place cameras on all the municipal and trash vehicles. Those cameras take pictures of everybody's house at least once a month, and AI flags any pictures that it decides appear to show a property to be in less than excellent condition. A human at city hall is allegedly tasked with reviewing all those flagged pictures, and notices and fines get sent to the homeowners that the human decides needs to be notified and fined for the condition of their property.

I suspect that someone will be able to chime in that insurance companies are buying overhead and satellite imagery of all the homes that they insure, and that they also have AI inspecting the properties they insure for roof damage, debris surrounding the property, and checking that branches aren't encroaching on roofs, and flagging any images that would indicate that the policy should be cancelled for non-compliance.

I imagine that this system or something resembling it would be carried over to ensure that the properties are kept in "excellent" condition.


Since everyone gets a "free" house, employers would immediately cut everyone's wages by about third to pay the taxes that would be necessary to implement this scheme. So your disposable income (less mortgage/rent) would stay the same and you'd be paying rent indirectly through taxes.


Your link doesn't really work right, but note that light bulbs are not at all planned obsolescence. It's been known for a long time that making the filament temperature of an incandescent bulb hotter makes it brighter, more efficient, and whiter, but also burn out faster, due to the tungsten sublimating. Anybody can make a super-long-lasting bulb that is really dim, inefficient, and dull just by making the filament temperature lower. Nobody will ever buy one to actually light their home, because it sucks compared to the competition, but it can run for a crazy long time in a museum or something. And the useless museum bulb will cause a bazillion news and blog articles to be written in support of a mostly-false narrative that we don't make things to last.


We still don't have much of a theoretical understanding of many things in medicine and healthcare, or have since learned that what we thought was a theoretical understanding is grossly wrong. Usually, the only way we can get any closer to such an understanding is by performing what are essentially experiments on people and seeing what happens, particularly people already suffering from horrific diseases and injuries. It may be disturbing and scary in some ways, but that's how things work.


I wish medicine were more like theoretical physics. I understand that it’d be difficult to come up with theories that could fully explain complex brain functions and diseases like Alzheimer’s. It’s also difficult to test those theories safely without crossing ethical boundaries. Being either overly cautious or overly optimistic could lead to bad outcomes. It seems like we need a reasonable balance.


Well clearly you'll need to stop using Google search too


We've been circling that since "thing reddit" became the most optimum search.


Kagi search allows you to block whole domains, which is pretty great.

Isn't there a browser plugin to do that for Google too?


I'd be more curious to know what these SSH scanner bots actually do if they manage to log in. Automated recon, install spambot/cryptominer/phishing site, something else?


I'm not sure about less targetted bots, but I gave a friend an account on my media server without locking off shell access (which she had no need for), and it turns out that she used the same password as she used for every other service. Something got hold of those (that something must have run on her machine while she was on my network as it was not an externally connectable service) found the account with that user+pass and got in.

I noticed PDQ because of a sudden and fairly constant flow of upstream data that was unusual from that machine, and finding the account & processes involved was easy. As well as installing something to run SSH scans (presumably for further propagation) and running what looked like a crypto-miner, it seemed to be forwarding HTTP(S) requests in a manner that suggested the machine had become part of a “residential proxy” network or similar. Maybe if it hadn't been so greedy I wouldn't have noticed so soon (it hadn't been able to, or hand't tried to, cover its traces, so I found the time of installation very easily as the account otherwise had no SSH activity).

Luckily there were no open root escalation attacks at the time (at least that it knew about) so I only needed to pave that account to get rid of everything, but combined with one of the LPE attacks that have been around over the years it could have caused me much more of a headache.


- Steal application credentials if posix perms or database privs are weak, attempt privilege escalation, install rootkit RATs Remote Access Trojans for persistence and hiding processes.

- Install Proxies, DDoS Agents, Bitcoin mining, proxy to SMTP servers, etc...

- If anything looks interesting on their console they will log in and poke around. The order of these events depends on the sophistication of the bot script. Most are very simple.

If you the target look like you have money they may install ransomware and encrypt some of your files. Now I want to watch the Beekeeper again as corny as it was, also a fun movie.


I presume that at least some of them just log the host as accessible and maybe some basic statistics into a list for an actual person to look at later on. That actual person would be the one to look more closely to see if there are any interesting credentials to steal or important data to steal or ransomware.


This was submitted 2 weeks ago https://news.ycombinator.com/item?id=48947548

Seems more entertaining than suitable for real analysis. At least I did not see any collected data. You can just watch what happens at this moment.

From watching it a while I came to the conclusion that adding a new authorized ssh key is a common first step.


The most common things I observe:-

- Installing a cryptominer or persistence tool

- Sending spam (smtp)

- Using pre-obtained credentials to log into various ecommerce/social media sites


Anonymizing network proxy.


Sorry, I forgot that this building only has 18 floors, it's on me that your elevator is now airborne.


Would you like to learn more? If you meant an aircraft elevator or a building elevator malfunction, tell me more so I can give you the right facts.


> The generalization and summary of this rant is: slack is good. Happiness lives in slack. There is such thing as optimizing too much. Also the small, isolated systems under optimization, are in reality neither small nor isolated.

Yeah there's a certain type of engineer mindset that loves the idea of optimizing things. But if you want to really optimize something, you have to carefully account for every single possible factor, situation, and use-case. Miss anything, and it's a much bigger disaster than saving 2% of whatever resource. It's rarely worth it.

Much better to treat the presumptions as a vague heuristic, make generous assumptions and add some slack, and call that good enough. Now there's probably enough slack to cover most of the edge cases you didn't think of, other things you based your original assumptions on changing under you, etc.


Ehhhh I think it'd be more accurate to say that in a small percentage of potential routes there are alternatives.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: