7 ms·
I discovered a critical exploit in ZeroMQ with mostly pure luck
- FabHK 2y agoMeta comment on this (excellent) article: I liked the memes and the accessibility-friendly captions thereof.
- eddd-ddde 2y agoNow I'm really curious how blind people experience memes. Like if you read "cat at table meme" is it funny in it's own way?
- starttoaster 2y agoI imagine there's some amount of conditioning (for lack of a better word), and some amount of how well the meme author annotated it. Mostly just postulating, with a small amount of experience having been an assistant to a blind person for a short stint. But I imagine you're onto something, that as people who experience memes visually, we'd find the meme's description less funny than someone who relied on that description to experience the comedic effect of the meme; they might just use their imagination to fill in the gaps more naturally than we do. But there are of course limits to what details we can divine from our imagination, so I imagine there's a lot of memes where blind people are left contextless unfortunately. I don't know that everyone has one of these. But the professor I assisted for that aforementioned short stint also had a special braille printer, of course. I believe these printers have since advanced to the point of being able to render photos in a sort of limited fashion where the paper is indented to contour to lines. I believe there are also tactile tablets now for the visually disabled.
- theamk 2y agoI find any sort of animated pictures next to the text supremely annoying. I had to scroll the text to keep them out of the screen just so I could read in peace. And yet you liked it... I wonder if this is a generational thing (I was born in 1980's)? Or "I don't run adblocker" thing?
- arcanemachiner 2y agoWe should start a club. In the meantime, I just use an image blocker extension when I encounter those articles. My mobile browser (Cromite on Android, Chromium fork) also has a setting to toggle images, which is also good.
- fangpenlin 2y agoThanks for the feedbacks. The author here. Personally I found it more "fun" (well, I guess for everybody it's different) to have some meme in between of the articles, some people hate to read too much text all in once, but yeah, I get your point. So I was thinking maybe I should add a switch like "meme off" to hide all of those at the top of article so that people don't like it can feel better while reading it.
- partdavid 2y agoYou can probably set your browser to play animated gifs only once; that's what I did.
- kristopolous 2y agoIt's extremely distracting. It's a competently written article mixed with a bunch of childish animated nonsense
- cdelsolar 2y agoI was also born in the 1980s but am fairly immature, and liked the article layout a lot.
- teslabox 2y agoThis was not "pure luck". Reminded me of that quote about chance favoring the prepared: "Dans les champs de l'observation le hasard ne favorise que les esprits préparés." -Louis Pasteur In the fields of observation chance favours only the prepared mind. Variant translations of this or similar statements include: Chance favors the prepared mind. Fortune favors the prepared mind. In the field of observation, chance favors the prepared mind. Where observation is concerned, chance favors only the prepared mind. https://en.wikiquote.org/wiki/Louis_Pasteur#Quotes https://en.wikiquote.org/wiki/Louis_Pasteur#Quotes edit: "Louis Pasteur's quote "Chance favors the prepared mind" means that the better prepared and more knowledgeable you are, the more you'll be able to take advantage of any chance opportunities or observations. "If you are unaware of things that influence a situation or an event, you are very unlikely to be able to identify any opportunity or learn anything significantly new. By having insight, interest, and aptitude related to the situation, you put yourself in the position to capitalize upon any hidden "nuggets" buried at the moment." - https://asymmetric.pro/chance-favors-the-prepared-mind/ https://asymmetric.pro/chance-favors-the-prepared-mind/
- pstrateman 2y agoOne the bug is in curbezmq not zmq. Two do not expose zmq to untrusted networks. edit: lol their website doesn't even have a valid cert http://curvezmq.org/ http://curvezmq.org/
- lambdaxyzw 2y ago> Two do not expose zmq to untrusted networks one: Is this documented somewhere? I use zeromq for the (internal, but by design usually accessible on the public internet) API of my project two: what happened to zero trust? Every network is untrusted.
- deleted 2y ago[deleted]
- samtheprogram 2y ago> internal, but by design usually accessible on the public internet Your API can be accessible obviously, but put ZeroMQ behind a firewall so only the API server can reach it. If it’s running on the same server, at least block the port ZeroMQ is listening on from the outside world.
- fragmede 2y agoPeople make fun of Kubernetes or "resume driven development" for making things more complex than they need to be, but this is why you want mTLS via a sidecar with short auto renewed certificates on a mesh inside your distributed system of a operating stack, when the system is big enough to justify that complexity. Something the size of, like, Airbnb should have that.
- theamk 2y agoOr a wireguard VPN. Or even just socat with mTLS inside systemd. There are easier ways to achieve that than kubernetes with sidecar mesh.
- pstrateman 2y ago
- theogravity 2y agoThe Elliptic Curve Cryptography article (mentioned in the ZeroMQ article) the author wrote is really good: https://fangpenlin.com/posts/2019/10/07/elliptic-curve-cryptography-explained/ https://fangpenlin.com/posts/2019/10/07/elliptic-curve-crypt...
- chrisweekly 2y agoI love how they wanted to learn about ECC and decided to write the book they wished existed. What a perfect mindset.
- dev_0 2y ago[dead]
- fovc 2y ago> As a software engineer, I am lazy, so I always love to reuse existing tools as much as possible… That’s why I decided to take the chance to learn how Elliptic Curve Cryptography works. Imagine if they weren’t lazy!
- jakjak123 2y agoI have worked with non-lazy engineers too. The amount of convoluted barely working franken stuff they come up with is staggering. No obstacle will stop them from digging the hole deeper. Nah, they are alright. The real issue is they are so busy working, they never stop to really think about what they are building.
- kvmet 2y agoThis is why teams need both. Relentless, obsessive people are great for the things that need it. Most stuff is usually fine to just do the lazy way though and move on.
- bullfightonmars 2y agoDifferent definitions of lazy. * lazy - wants do as little work in the future as possible and so spends extra time now solving the problem the right way. * lazy - has no consideration for the future and takes a straight line path to solving the problem now. Spends all future time fixing problems created from this approach.
- jart 2y ago> Reading code is underrated, and many software engineers don’t understand how and why they should read it. Reading code is much harder than writing code because writing code translates your thoughts into code, and reading code is the opposite. That's like saying reading Hamlet is harder than writing it. What kind of garbage do you have to be filling your head with all day to hold such a dismal opinion of software?
- Zambyte 2y agoProprietary enterprise production code
- ok123456 2y agoThe modal programmer barely reads stack traces that tell them where exactly something is happening, even when it tells them exactly the mistake they're making. Digging into other people's code, reading it, and having enough education and context to understand why they did things a certain way is an even rarer skill.
- chrisweekly 2y agoFantastic post, I loved everything about it. Fang-Pen, I'm interested in your book but it's apparently only 16% complete, is that right? In any case nice find, thanks for sharing, and please keep writing! :)
- fangpenlin 2y agoThe author here. Thanks for the interest. Crazy things happened in life last year, so I barely find a time to write anything. Recently finally find a time to pick up writing again. Hopefully I can add more content to the book this year.
- tus666 2y ago> By reading the source code, I realized that the incoming data was put into a fixed-size static buffer in the stack, and the payload was decrypted into another fixed-size buffer. There’s no boundary or size check. This is not normal. It's amateurish in the extreme that leads to the only conclusion that whoever wrote this ZeroMQ thing is not a real software engineer. I.e. stay away at all costs.
- cjbprime 2y agoI have some really bad news for you about OpenSSL.
- CuriousCosmic 2y ago> This is not normal. It's amateurish in the extreme that leads to the only conclusion that whoever wrote this ZeroMQ thing is not a real software engineer. I.e. stay away at all costs. I don't think that's a remotely fair assessment. ZeroMQ is a very large and quite popular project but it's also getting close to two decades old if I remember correctly. Any large C or C++ project that is that old is going to have quite a bit of historical cruft. And looking at some of the code that said vulnerability touched, most of that code was over a decade old. Not to claim that it's any less severe but this is the nature of long lived projects. Unless they are massively privileged, they tend to have more code than eyes to look at said code and said code often was written in the bad old days.
- SPBS 2y ago> it's also getting close to two decades old if I remember correctly. Any large C or C++ project that is that old is going to have quite a bit of historical cruft. I don't think writing arbitrary data into fixed-size buffer without boundary checks is just an artifact of being historical cruft, it's a ridiculous mistake no matter which time period it was written in. Whoever wrote that code decades ago was incredibly amateurish.
- smsm42 2y agoThat assuming the code was written that way initially. More often than not in long running projects pieces get moved around, refactored, functionality added and removed, and silent assumptions that were true before aren't true anymore. Somebody coded functionality for fixed data buffer, somebody else extended it with variable sized data but was not aware fixed buffers are being used, that stuff happens. We live in a myriad of glass castles, don't be so quick to throw stones around.
- wenbin1991_sh 2y agothe most interesting part is the last one -> hire me..