Hacker Newsnew | past | comments | ask | show | jobs | submit | binarytransform's commentslogin

Source?


I'm not sure if GP is talking about this https://en.wikipedia.org/wiki/Quantum_key_distribution#Troja... or not, but that's definitely an issue.


Yeah nature got us here, but "here" is a local optimum based on evolutionary selection forces. If you were to design things based on biomimicry rather than first principles, planes would flap their wings, cars would gallop, and computer vision sensors would only perceive visible light. These people are building solutions rather than solving the problem.


You are assuming that designers would be overly simplistic about their work. Planes don't use their wings for propulsion, so why would a designer try to make them flap? That action isn't solving the same problem, and any engineer would know that. Likewise, tires roll in response to propulsion, whereas galloping legs are providing power. Frankly, the pistons inside an engine ARE closer to a gallop than to a roll. (Well, maybe not in a Wankel rotary engine, but...)


Leonardo da Vinci, notable designer, and many other sophisticated people considered flapping wing aircraft. It’s easy to dismiss it as simplistic hundreds of years later once practical solutions already exist.


No, flapping wing aircraft simply are less efficent for size scales that can carry a person. That's why the larger a bird's wingspan, the less frequently they flap, such that condors, storks etc. are basically fixed wing gliders.

We in the artificial world do have our own local optima with quad copter drones. Flapping here would be more efficient. Consider seagulls that dive and change direction instantly, and can respond to gusts without missing a beat. We have nothing approaching that maneuverability. This is an active area of research.


What do you mean 'no'? It's an empirical fact that very talented designers considered flapping wing flying machines, before they had the information that we have now. They were not 'overly simplistic' except in deep hindsight.


We aren't done designing flying machines. Maybe it will turn out that when we have sophisticated enough control mechanisms and materials, flapping will turn out to be the way to go after all.

Of course natural evolution has found only local minima in the fitness landscape, but as a designer it's been running its algorithm a lot longer than humans have. Its local minima may well be better than ours, and so worth trying to imitate.


Refer to the grandparent post as to why large flapping machines are unlikely.

This thread is so weird.


I think a piston engine is just a different thing than a gallop.

A 1 cylinder engine works a lot better than a 1 legged gallop.


You seem to misunderstand what biomimicry even is. It’s about identifying root problems and seeing how nature has already solved the same problems we’re trying to solve. The whole concept of first principles is there. Remember when Speedo invented new swimsuits that led to swimmers breaking world records left and right? That was due to biomimicry. Because sharks are fast and shark skin is not smooth under the microscope but instead has lots of tiny protrusions that create micro-turbulence along the surface that leads to less overall drag. And then creating a similar material for swimsuits. That is biomimicry. Not making freaking airplane wings flap to achieve lift. But instead, discovering that the way a hummingbird sweeps it’s wings back and forth creates an area of lower pressure above the wing that virtually sucks the wing up. Interestingly enough airplane wings are shaped in such a way that the wind travels faster above the wing than below the wing, creating a similar pressure difference and achieving lift.


The human brain is the best pattern matcher in existence and we continue to learn from it. Think about that.


As a 12-year post-9/11 veteran with 7 years at a Tier 1 SOCOM unit and currently a successful BD guy at a Top 5 SV unicorn, your post is filled with misinformation, generalities, and is frankly offensive. Many of my brothers and sisters from the SOF world have successfully transitioned to the civilian world and are crushing it. Are there dark times - yes. But we either choose to let them define us or choose to rise above and move ahead with our goals.

Your comment about bankruptcies and poor credit is not even worth responding to.


The world under SOCOM is pretty big, and I've only experienced some of it, second hand via direct family as well as family friends. I may be painting with an overly broad brush, but I'm telling it how I experienced it.

The bankruptcy and credit problem may not be as relevant anymore due to technology, but it was absolutely relevant in the time my father was active. The technology we rely on to maintain our finances (automatic payments, mail, pervasive internet and phone communications) didn't exist, and if it did, it wasn't anywhere near the combat outposts where they would be deployed to for several months to train local militias. It is really hard to pay a bill if you can't be sent a bill, call to ask about a balance, send a check via mail, or have your bank take care of it for you.

I do know at least one former Ranger who was pretty successful in a civilian job (logistics at amazon), but I've known far more that couldn't hack anything out of the military (apart from security contractors that is). Maybe my sample is small and not representative, but that's just the way I've seen it. Sorry if I offended you by the generalization, it wasn't my intent at all.


I'm laughing my ass off at the fact you have actually posted your little resumé in a comment. The guys that do stuff usually aren't the ones to float what they've done in order to be taken seriously, especially a "Tier 1" guy.

But, there are absolutely dudes no matter how high up who are not smart in how they handle their personal finances. Didn't Matt Bissonette (aka Mark Owens) write a novel about his time in DEVGRU and what took place on the UBL mission because he didn't have any money?


What...is with that UI? Between the cut-off titles and the mouseover image spinning, I left in less than 10 seconds. Here's a better, non-seizure inducing list: https://github.com/mvillaloboz/open-source-cs-degree


My favorite of these kind of sites: https://teachyourselfcs.com/


Yet another curriculum, basic org-mode page that focuses on functional/parallel and verification https://functionalcs.github.io/curriculum/


There is also this : https://learn-anything.xyz/computer-science

If you're into mind maps.


This constant barrage of FUD from the cybersecurity community is exhausting. The real story here is that a combination of misconfigurations resulted in a system being exposed to remote exploitation. Until we in security move away from producing this noise about the latest clickbaity hack and start professionally addressing underlying hygiene, root causes, and config laziness at scale, we will never drive the conversation forward. But that doesn't get your talk accepted at Black Hat.


The point is not to deliver a measured and realistic view into the specific security threats, for the entertainment of experts. The point is to show the broad public what the logical extremes of vulnerability are, so that the public exerts some market pressure, and seeks out the help of third parties to insure that things within this realm do not happen in their cars.


We have to acknowledge that the underlying issues here won't ever be understood by the broader public. These kinds of "here's what happens when..." stories are among the most important ways that we can get your message across.


Many hardware manufacturers simply don't understand the danger of using software willy-nilly. You can tell them all day long about using sane defaults, but they won't listen.

Malfunctioning hardware that physically damages their customers' property, on the other hand, is something the significance of which they will understand immediately. A few lawsuits here and there, a few percents off of their stock price -- these are the language they speak, and we must learn to speak it too if we want to encourage them to do something.


Same issues as those faced in the field of scientific research, really. Pressure to put out something flashy coupled with sensational journalism adding even more fantastical hype over the top.

Question is, what did we used to have that drove research efforts in the more beneficial ways we used to see?


> Question is, what did we used to have that drove research efforts in the more beneficial ways we used to see?

I don’t know the answer to your question, but decoupling progress from profits would be a good idea.

An international body dedicated to knowledge and research for their own sake, funded by everyone, maybe?


Xerox PARC and Bell Labs?


Sure but I mean - What was the secret sauce that drove us to have PARC and Bell? What motivations were there then that have gone away now? Can we get them back?


Well, yes. But at the same time what other mechanism would you suggest to educate the large segment of the population that has absolutely no inkling of the mechanics of security? I don't see any and stories like this illustrate in a way that is accessible to all what the consequences of lax security could be. As such I think it serves a valid purpose, even if to those more knowledgeable like you it comes across as FUD.

And even within the security community there is a shift in the last couple of years with sexy names and bespoke websites for specific vulnerabilities. Apparently there is a need to get security out of the technical realm and into the public eye for reasons that transcend FUD.


If there is no scenario the public can understand the problems will just be waved away using arguments such as 'I don't care, I don't have anything to hide', 'Perfect security is impossible, it's good enough' etc.


This view is increasingly outdated. The public view/ed the internet as something harmless but the moment they are real world consequences they will inform and take things seriously very quickly. Self preservation is universal.


Another reason the IOS is a truly terrible concept. There is no need to have a toothbrush or car wash connected to a global network.


I suspect that many times it is not intentional.

It's just that when you have a computer connected to two networks, it takes every little for it to act as a router.


Even simple things like default passwords being the first few numbers of the products serial number wouldn't be that bad.


Only if the serial numbers were random and not, well, serial.


Given that the state of the situation now is often "learn one password, pwn the entire class of devices", a default that was vulnerable to literally any other vector of attack seems like a marked improvement. Its easier to protect against a brute force or dictionary attack on any individual device than it is to protect against a single magic default admin credential being discovered - rate limit password submissions, lock outs after subsequent failures, etc.

Sure, if someone can look at the sticker on the bottom of my router and see the serial number and learn the default password that way without having to attack it iteratively, thats still a problem. But a random default password would have to be communicated to the end user somewhere, too... and as with most things, by the time an attacker has physical device access you've already lost.


But serial serial numbers would turn one password into a small handful, not that much better of an improvement.

A lot of routers come with random, long passwords printed on them as the default. No reason this shouldn't be standard.


While i agree there's a lot of clickbait from cybersecurity that really has to stop because some of them are really ridiculous and causes the cry wolf syndrome. Like the ones where "Researchers can find out what you are thinking by just listening to scans of your brain from your wifi router!!1". Where they conveniently leave out the detail that they first require physical access to your wifi router to implant a special program, then a training set targeting exactly you built up over 10 years in a perfectly controlled environment, then the attack must be performed in this exact environment, they have just identified one type of thought and that they only managed to repeat the attack once where the result was more likely to be a fluke than deliberate.

But i don't think this looks one of them, they seem have a very easy and reproducible attack entry point open for everyone and the consequences are very tangible.


The rise of "cyber" nonsense and the army of certified cyber-warriors produces intense pressure to get CPEs and to get attention.


CVEs?


Continuing Professional Education


Yeah super. Let me scale that for my bank, car loan, house loan, credit cards, FB, IG, Twitter, Email, HN, Coursera, EdX, Udacity, Udemy, Concur, forums, Netflix, LinkedIn, Paypal, Slac, Spotify, Hulu, AppleID, Reddit, Amazon, health insurance, college alumni page, Digital Ocean, WSJ, GoDaddy, hotel points, and airline miles sites.


That's a lot of accounts and a lot of passwords. You'd probably want to use a password manager. These kinds of passwords still have the advantage of being easy to hold in short-term memory, so when your password manager is on a different device than the service you're trying to use, you can look it up once and type it in rather than having to look back and forth between the two for that 16-digit number.


I think that's his point. The strategy of memorable passwords is not viable. You still need a password manager. But I agree that spellable, pronounceable passwords are helpful when you need to type on in.


I finally started using KeePassX so I could keep track of the insanely long and randomized passwords it creates across the same plethora of sites you've listed. I love using it, but there's no way in hell I can quickly update so many different credentials conveniently(e.g. update your password every 6 months or so? Just kill me now)


I've used password managers for about 15 years now. I just counted I have ~400 passwords saved, most of which I'm obviously not using and a large number for services that do not even exist any more.

As I can't be bothered to even check which ones to delete, I will definitely not be updating any of those.


Except some you can outsource everything to a password manager.

I think I remember just these passwords: my 2 banks (that keep my savings), stock broker, primary email a/c, AppleID, personal VPS. For these too I keep very personal hints (no one else can guess) in KeePass (just in case).

Master passwords for LastPass and KeePass are quite difficult and I don't keep its hint or anything anywhere. It's a risk I decided to take. On the downside I have not changed these two passwords in a long time.

Rest goes to LastPass (100s of them).


Hmmm. Have you considered closing some of those and regressing away from your online presence in order to solve your evident frustration with managing so many pwds? If I signed up for all that cra..stuff, I would close some. :)


One thing that works is putting the name of the service into part of your password for each site.

So like, Abzysbej@10netflix and Abzysbej@10hulu


And then one leak in plaintext compromises all of your accounts because a targeted attacker is presumably smart enough to understand what you did...


To make it a bit less conspicuous, take the third character (or something) from the service name and put it as the fifth character (or something) in an otherwise long random string. This will look like a random password... until someone gets two or more passwords made with this strategy, then it's pretty easy to find out the strategy.


How is any of this easier than using a password manager??


You only have to remember one password, the strategy is the same for all passwords, replace the fifth character (for example):

google: mojko2if6bibe78

youtube: mojku2if6bibe78

yahoo: mojkh2if6bibe78

Note that I don't advocate this strategy for high-security applications, but for throwaway accounts that you might want to access when not having access to your password manager it might be useful.


I should clarify, there should only be a pattern like that for the many frivolous services, and a different password for financial medical etc.


>> selector

Found the former SIGINT guy.


My clue was their use of "SIGINT".


No. That simply results in a TCAS warning and a couple of irritated pilots.


No one is tracking a small drone on radar. There will be no TCAS warnings.


You clearly have no clue how the rest of government contracting works.


Yeah we should go back to following the jitney cab news.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: