Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joushou
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
joushou
10y ago
man xcode-select - It's right there in the manpage. /usr/bin/git is a "toolshim" that effectively calls "xcrun git" (it actually calls xcselect_invoke_xcrun, from /usr/lib/libxcselect.d
32.
▲
by
joushou
10y ago
Right, and you can do the same with C, using libraries providing this functionality wrapped as well. There's plenty of std::string and std::vector like containers, which handle the magic for you. But even then, you can work with struct
33.
▲
by
joushou
10y ago
I don't like Java, but don't underestimate the performance of the JVM. Unless you're a crazy perf wiz, then your average C code won't beat your average Java code. It's fast enough for short processes, and for long p
34.
▲
by
joushou
10y ago
As, yeah, stupid applications is hard to guard against, but stupid applications might/will have their own share of code execution bugs, which you also have to control. Everything sucks. As for the environment, that's the same for
35.
▲
by
joushou
10y ago
It doesn't hide anything related to git. The binary in /usr/bin is there to shat xcode-select works and points to /Application/Xcode.app/Contents/.../bin/git. It's not hidden, it's mere
36.
▲
by
joushou
10y ago
Well, you can, but it's inconvenient and requires manual intervention with each machine. I would argue, though, that if you have developers that intentionally circumvent the version of git you provided them with, despite being told tha
37.
▲
by
joushou
10y ago
This is indeed an issue. I would like to think that a person capable of using git would have enough of a critical mindset not to do what random people on the internet tell you to do, but... StackOverflow kinda proves the opposite. I don
38.
▲
by
joushou
10y ago
> You have the user's execution rights only; you don't have root access. That is also what I said - code execution. Like the git RCE gives you. But, it would be rather redundant to use code execution as a local user to obtain c
39.
▲
by
joushou
10y ago
A little, but you have enough to get started. Rather an old bash than no bash. First task on OS X is usually to use the bundled curl and ruby to get homebrew. :)
40.
▲
by
joushou
10y ago
No, the dev tool binaries are magic binaries that check if the "Command Line Tools" package is installed, and if not, asks you if you want to download it. They're protected by System Integrity Protection, so you have to tempo
41.
▲
by
joushou
10y ago
With the ability to modify .bashrc, you have execution right to the machine. If not before, to modify the file, then after, because you modified a shell script that is automatically run all the time. Thr machine is already pwned, and one pr
42.
▲
by
joushou
10y ago
I'd like to point out, however, that installing a new version of git is not in any way blocked by either Microsoft or Apple. If you install git with homebrew, you get the newest version, which will take precedence over the Xcode variet
43.
▲
by
joushou
10y ago
You're talking about naked char[]. You can just as easily make a struct{ int len; char* str; } in C, and combined with the "n" variants of string operations, would work just fine with common tools. Again, C++ does not make an
44.
▲
by
joushou
10y ago
A rewrite in C++ would not make it any safer. Rewriting it to make it easier to understand could make it safer, but you do not need a different language for that.
45.
▲
by
joushou
11y ago
You're not alone in your concerns. Dynamically generating static layouts seem rather silly to me.
46.
▲
by
joushou
11y ago
If you tied the local FW magic to a socks5 client, you'd be able to skip part of the magic, assuming you don't desperately need mDNS. SOCKS5 does UDP too, IIRC. I like tearing things apart, and I like making clean muggler solution
47.
▲
by
joushou
11y ago
It's also good to know that you completely ignored security advice from security professionals, making this a waste of time. You could say that up front as well: "I'm going to write a comment insulting you, but don't you
48.
▲
by
joushou
11y ago
Statically linked, but you can replace the entire application. You'd get one or two private key signa before the user disconnects and starts wondering what happened (remember that you need to have something to sign). Of course, without
49.
▲
by
joushou
11y ago
ssh -D (socks5 mode) doesn't require root, and can forward both udp and tcp traffic, doing what it appears that the client requires. socks5 is just a protocol that tells the server to connect to X on port Y using protocol Z, or to bind
50.
▲
by
joushou
11y ago
sshmux is a jump host that allows more user-control than you can with a ssh server. Unless you use the interactive mode with agent forward, you still need to configure your client to use one. I'm not sure I get what you're on abou
51.
▲
by
joushou
11y ago
I have to disagree with you. 1. The private key is not secure by default by putting it on a different host. 2. This still allows an evil user getting access to his original machine to SSH into any host requiring his private key. 1 should be
52.
▲
by
joushou
11y ago
> sshmux looks like an interesting project, and love the simplicity. Wonder if Userify might automate the ProxyCommand setup! Seems really useful. Yeah, ProxyCommand is a bit cumbersome for many setups, which is why the agent forwarding
53.
▲
by
joushou
11y ago
When I use SSH as VPN, it's usually because I want less flexible applications to use it, using socks5 configured as a system-level proxy. When doing more work on our corporate network, I usually SSH through the jump to my desktop and w
54.
▲
by
joushou
11y ago
I see why you might think that, but no. SSHProxy tries to move the private key from your computer to an external thing. SSHProxy doesn't have anything to do with sshmux. SSHProxy is a two part thing: 1. A server that, when connected to
55.
▲
by
joushou
11y ago
What authentication do you have from the jump host to the target? To me, it looks like it has been reduced to either none or keyboard-interactive (password) login, which is considered bad practice. I could very easily implement support for
56.
▲
by
joushou
11y ago
Hi CTO for Userify person! One thing is setup of jump hosts (basic version just being a box with sshd enabled + users with authorized_keys, which is beyond simple), but it's the limitation of hosts. I have 1 big network where a set of
57.
▲
by
joushou
11y ago
You need arbitrary read and write memory access to abuse it (how would you otherwise make the signing request? You can't just steal one, as they're unique for their purpose), not just read, which is much more than heartbleed w
58.
▲
by
joushou
11y ago
Landskrona, actually. Malmö would have been nicer, but the waiting list for an apartment is 2-3 years. It's actually quite common, especially in Malmö (Malmö<->Copenhagen takes about half an hour, Landskrona<->Copenhagen 1:
59.
▲
by
joushou
11y ago
Oooooooh, I missed that one. It would have been better if it wasn't an option, but default behaviour, but I guess we can't win every time...
60.
▲
by
joushou
11y ago
VPN's can be quite a pain, and is considerably more work than raw SSH. Depending on the VPN, the authentication strength is usually also quite a bit lower than that of SSH with RSA keys. There's also additional overhead. I have bo
More ›