Hacker Newsnew | past | comments | ask | show | jobs | submit | more vmfunction's commentslogin

>I think chrome has better security model, sandboxing...

It also worth to mention that Firefox is built with Rust, and Chrome mostly C/C++.


Isn't Firefox still mostly C++ as well?


Yes. And Chrome has made efforts to support Rust.


Many scientists/people only think about problem in the scope of the their discipline. Keep in mind this is the problem-solution knee jerk (treat the symptom) responses is how we got to our current situation in this world.

Oh we don't like horse dung, we going with cars now!

With bio-engineering such as this, many intergenerational horizontal studies need to be done before it even should be consider releasing in the wild.


Wow! When will beautiful doreena be ported? It is one of those software need to run quite old MacOS to work.


It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on?

Here is one on github:

https://github.com/NavyTitanium/Fake-Sandbox-Artifacts


I'd be willing to bet good money that 99% of malware authors won't adapt, since 99% (more like 99.999%) of the billions of worldwide windows users will not have this installed.

For the cat to care about the mouse it needs to at least be a good appetizer.


If I were to run a Windows computer, I wouldn't care what 99.999% of other people didn't do to make their computer safe. If it were something that I could do, then that's good enough for me. However, the best thing one can do to protect themselves from Windows malware is to not use Windows. This is the path I've chosen for myself


I think this is a same thing as betting on your own failure: "not enough people will use this for it to be an important consideration for hackers".


I've worked in companies with horrendous security, where someone with just a bit of SQL injection experience could have easily carried out the data. Yet, since this was a custom in-house application and your off-the-shelve-scanners did not work, this never happened; the only times the servers were hacked was when the company decided to host an (obviously never updated) grandfathered Joomla instance for a customer.

But even more simply, just setting your SSH port to something >10000 is enough to get away with a very mediocre password. It's mostly really not about being a hard target, not being the easiest one is likely quite sufficient :)


> But even more simply, just setting your SSH port to something >10000 is enough to get away with a very mediocre password.

Given how easy and free tools like Wireguard are to setup now (thanks Tailscale!), I really don't understand why folks feel the need to map SSH access to a publicly exposed port at all anymore for the most part, even for throw away side projects.


I say leave it at 22 and use public key authentication. If a hacker can crack that, they deserve my server!


I mostly agree, but even this leaves you exposed to new bugs found in SSH in the future etc if on an unpatched/forgotten server. I still think its best (and really, really easy now with tools like tailscale) to simply never expose the software to the wide world in the first place and only access over Wireguard.

Fundamentally, it makes no sense to expose low level server access mechanisms to anyone other than yourself/team - there is no need for this to sit listening on a public port, almost ever.


The really fun part is when malware authors add detections for "fake sandbox" and then real sandbox authors get to add those indicators.


Look into Windows NT source code that was leaked. The if-else/switch statements in there is just another level of string matching hell. Seems like software development just become "let's jerry rig it to just make it work and forget about it." Pretty sure management (without tech clue) have something to do behaviours like this.


> Pretty sure management (without tech clue) have something to do behaviours like this.

Always the same bullshit with you people here. Could never possibly someone built a sub-optimal system -- it HAD to be management fucking with our good intentions!


Lemme guess you're a manager.


Well yeah. Left to their own devices, people want to build good stuff. It's when some dumb turd with his metrics and clueless plan shows up that things get screwy.


Author of scarecrow here. Our thinking is that if malware starts to adapt and check if scarecrow is installed, we are doing something right. We can then look to update the app to make it more difficult to spot - but its then a cat and mouse game.


You had an answer canned for one part of the query. Why are you trying to release security software completely anonymously? This is insane - you want an incredible amount of trust from users but can’t even identify a company.

Simply, if users are as intelligent as you think, they’re too intelligent to use your product.


If you think that is what will make it a cat and mouse game instead of understanding it has been a cat and mouse game since the beginning of time, then you're not compelling me into thinking you're very experienced in this space.


Not just that - it only works on smart malware.

There is plenty of dumb malware.

Security folks seem to get overly focused at times on the most sophisticated attackers and forget about the unwashed hordes.


It's not a cat an mouse game; it's a diver and shark game. In SCUBA training we joked that you had the "buddy system" where you always dive in pairs, because that way if you encounter a shark you don't have to outswim the shark, you only have to outswim your buddy.

A low-effort activity that makes you not be the low-hanging fruit can often be worth it. For example, back in the '90s I moved my SSH port from 22 to ... not telling you! It's pretty easy to scan for SSH servers on alternate ports, but basically none of the worms do that.


What I've heard is: If you're running from a bear, you only have to be faster than the other guy.


If windows would have this built in, then it would make malware authors job much more difficult. I like that.


Some malware will catch on, some will not. It's a cost vs profit problem. Statistically, this will always decrease the number of possible malware samples that can be installed on the machine, but by what margin? Impossible to say.


>Command line interfaces don't fit modern application usage. We simply can't do everything with pure text. I'd like to pipe my Skype call to a video analysis service while I'm chatting, but I can't really run a video stream through awk or sed.


>Command line interfaces don't fit modern application usage.

I guess you and I have different use cases and definition of "modern application usage". I assume you spend most of your day in a GUI, while I spend most of mine in a terminal.

Pipes can handle binary data and sure you could pipe Skypes output through sed or awk... Though something like ffmpeg is more likely, and it will happily take stdin as input.


Either that or the OS need to provide an API to allow major languages to be able to interact with the system other than the GUI. sh can be an add on.


Not sure if this is what you meant, but I'd like to expand a little bit on it.

- This API should be programming language agnostic (like, with a well defined ABI). Ideally an IPC based one, with a well defined wire format and protocols.

- Not a singular API, but an “API system” with extensibility taken into account from the beginning (with things like versioning). It should be able to support arbitrary new API definitions so that other apps could consume, and also produce.

- Such an API system should be used by the OS itself too, of course. So the OS would have the resulting benefits and the whole system would be more uniform.


This not surprising at all. The stories of suicide in High Achieving School in Asia is common knowledge. Same can be said about "High Achieving Jobs" and "High Achieving ______"

Do we want to live or just be high achieving in life?


I'd say the good approach is to set high standards and then work towards achieving them in a supportive environment. Every the pursuit brings happiness.


To many people it's virtually the same thing, TBH...


We want status. Like, we want it so much.


Why not make some physical collage and letters with pics? Last longer. You can have a digital copy of it.


"Heroism doesn't scale"

You can pretty much replace Heroism with Leadership or whatever.

Question is do we really need it to scale?

Corporatism thrived off the back of the industrial revolution. It is not bad, it just has taken us as far as it can go.

Something more decentralised and organic should take place instead of corporatism for large scale human development and space exploration.


In that scenario, people still need a medium of exchange. Physical medium of exchange such as precious metal and paper currency will still be more reliable than crypto or anything digital. The countries who are enforcing digital currencies are just digging their own graves when a Carrington level of event (or EMP) hits.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: