from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Dennis Yurichev

Ideas, decisions, and lessons from the team.

yurichev.com (opens on the source site)
14Posts tracked
last weekLatest publication
1.2Posts / month over the last 12 months

Latest writing

14 of 14 posts

[Crypto] Communicating with TPM 2.0: the first step (opens on the source site)

tpm2_tools suite has a command to generate random data -- a PRNG in TPM 2.0 chip is used: % tpm2_getrandom --hex 32 1b8114ec9fda3fbcce3b096439af86e34f0e7a077d4e4e54ae6cf6097e49eb09 Let's see what happens inside. Run it with strace (-xx option is for hex dumping, -s sets max. string size): % strace -xx -s 10240 tpm2_getrandom --hex 32 Here we can see how tpm2_getrandom communicates with tpm2_abrmd daemon via read/write: write(3, "\x80\x01\x00\x00\x00\x0c\x00\x00\x01\x7b\x00\x08", 12) = 12 poll([{fd=3, events=POLLIN}], 1, 1000) = 1 ([{fd=3, revents=POLLIN}]) read(3,…

Read at the source

Time-based one-time password (TOTP) for 2FA, part I (opens on the source site)

Previously: RSA SecurID token Let's try to turn of 2FA TOTP on lichess.org website (the user is temp_user12) What's in the QR code? (I made a screenshot and extracted the QR code using zbarimg.) It's: otpauth://totp/lichess.org:temp_user12?secret=XYYUFRCR3YP7DMHSZOLAQWBRTEODNAZL&issuer=lichess.org The essence in the 'secret' part, base32-encoded binary blob. Using Google Authenticator app, import that key (scan QR code), and it will show something like this. (The app doesn't allow taking screenshots, so this is a photo of my device.) The code changes every 30 second. A pie-chart at right…

Read at the source

Unpacking a database of unknown type (opens on the source site)

There is a Rutracker (Russian torrent website) non-official dump that came as a file of some unknown database type. (There was also a GUI database viewer for Windows, which I won't run.) Let's see if I can unpack these files by myself. The file extension is meaningless '.RDB'. The file is compressed and/or encrypted: % ent tmp.bin Entropy = 7.990625 bits per byte. The header is: % xxd -g1 tmp.bin | head 00000000: da 36 32 31 33 37 33 34 da 37 7a bc af 27 1c 00 .6213734.7z..'.. 00000010: 03 ff e9 09 be 60 14 00 00 00 00 00 00 3e 00 00 .....`.......>.. 00000020: 00 00 00 00 00 fb 89 7a 12 00 3c…

Read at the source

My new linkedin profile (opens on the source site)

https://www.linkedin.com/in/dennis-yurichev-4132923b5/ (the post first published at 20260305.) List of my other blog posts. Subscribe to my news feed, If you noticed a typo/bug/error or have any suggestions, do not hesitate to drop me a note: my emails. Or use my zulip for feedback. Or Discord. Thanks in advance! Also, among my services is writing examples-rich manuals, references and help files. If you like my work and want something similar for your (commercial) product: contact me. If you enjoy my work, you can support it on patreon. Some time ago (before 24-Mar-2025) there was Disqus JS…

Read at the source

Hire an author/writer (opens on the source site)

Among my services is writing examples-rich manuals, references and help files. If you like my work, books, writings and want something similar for your (commercial) product: contact me. (the post first published at 20260129.) List of my other blog posts. Subscribe to my news feed, If you noticed a typo/bug/error or have any suggestions, do not hesitate to drop me a note: my emails. Or use my zulip for feedback. Or Discord. Thanks in advance! Also, among my services is writing examples-rich manuals, references and help files. If you like my work and want something similar for your (commercial)…

Read at the source

[Crypto] Toy SSH client in ~2k SLOC of Python, v6 (opens on the source site)

Previous blog posts: 1, 2, 3, 4. 5. This is bug-fix release. Mostly network bugs fixed. I started it in ~2022 mostly for learning, but it turned into practical tool, when I need to connect to some old routers, devices with algorithms like ssh-rsa, ssh-dss. Download (the post first published at 20260120.) List of my other blog posts. Subscribe to my news feed, If you noticed a typo/bug/error or have any suggestions, do not hesitate to drop me a note: my emails. Or use my zulip for feedback. Or Discord. Thanks in advance! Also, among my services is writing examples-rich manuals, references and…

Read at the source

[RevEng][CS] Fuzzy topological sorting (opens on the source site)

(It's assumed that the reader is familiar with topological sorting. (Re-)read the "Dependency graphs and topological sorting" in my book. Also with graphs, DAGs, callgraphs, simulated annealing.) It's a problem with topological sorting --- no cycles in DAG allowed. I can fix this. I'll find an order for some vertices so that the number of backward references would be minimized and forward references --- maximized. That would be the fitness function. I use simulated annealing, but many other similar algorithms would also work, I believe. Now I take an old Linux 0.99.15 (modern Linux is too big…

Read at the source

Hunting for extremal Latin squares using MaxSAT solver (opens on the source site)

(It's assumed that the reader is familiar with random walk, Latin squares and transversals.) Extremal LS (Latin Square) is the one that has minimally/maximally known transversals (lower/upper bounds). Here I'm going to describe how I found L15 with TS=170369 and added it to OEIS A091323. To my knowledge, this is a best lower bound for L15 as of autumn 2025. For random walk, we simply modify a cell (or symbol) in LS and ask MaxSAT solver to fix other cells so that LS will become valid (all LS constaints for rows/columns would be valid). Modified cell clauses are added as hard clauses (MUST be…

Read at the source

Testing word counting code using KLEE and CBMC (opens on the source site)

The exercise from the famous "The C Programming Language" by Brian W. Kernighan, Dennis M. Ritchie: #include <stdio.h> #define IN 1 /* inside a word */ #define OUT 0 /* outside a word */ /* count lines, words, and characters in input */ int main() { int c, nl, nw, nc, state; state = OUT; nl = nw = nc = 0; while ((c = getchar()) != EOF) { ++nc; if (c == '\n') ++nl; if (c == ' ' || c == '\n' || c == '\t') state = OUT; else if (state == OUT) { state = IN; ++nw; } } printf("%d %d %d\n", nl, nw, nc); } ... Exercise 1-11. How would you test the word count program? What kinds of input are most…

Read at the source

[Math] Intervals: Apache Maven version numbers (opens on the source site)

How intervals denoted formally: [a .. b] closed interval: {x | a ≤ x ≤ b} (a .. b) open interval: {x | a < x < b} [a .. b) half-open interval: {x | a ≤ x < b} (a .. b] half-closed interval: {x | a < x ≤ b} ( Donald E. Knuth - TAOCP, vol.2, 3rd ed. ) Apache Maven versions numbering inherited from mathematical notation: Range Meaning (,1.0] x <= 1.0 ... [1.0] Exactly 1.0 [1.2,1.3] 1.2 <= x <= 1.3 [1.0,2.0) 1.0 <= x < 2.0 [1.5,) x >= 1.5 (,1.0],[1.2,) x <= 1.0 or x >= 1.2. Multiple sets are separated by a comma. (,1.1),(1.1,) This excludes 1.1 if it is known not to work in combination with the…

Read at the source

[Math] Intervals: examples of closed intervals (opens on the source site)

... In many parts of mathematics ( recall \( \sum^{max}_{x=1} f(x) \) ). Closed interval denoted as [begin, end] (inclusive). Closed interval in Wolfram Mathematica: In[4]:= Sum[x,{x,1,10}] Out[4]= 55 ... In[2]:= Table[x,{x,1,10}] Out[2]= {1,2,3,4,5,6,7,8,9,10} (BTW, vectors often started at index 1, like in Wolfram Mathematica and also FORTRAN.) The notation ":" denotes a subarray. Thus, A[i : j] indicates the subarray of A consisting of the elements A[i], A[i + 1], ..., A[j]. We also use this notation to indicate the bounds of an array, as we did earlier when discussing the array A[1 : n].…

Read at the source

[Math] Intervals: examples of half-open intervals (opens on the source site)

Half-open intervals are used in many parts of programming. They are denoted as [begin, end) (end is not included in interval). In Python, range(start, stop) - half-open [start, stop) In C/C++/Java/Golang/other - for (i=start, i<stop; i++) - also half-open [start, stop) random.randrange in Python is also half-open, like range(): random.randrange(stop) random.randrange(start, stop[, step]) Return a randomly selected element from range(start, stop, step). This is roughly equivalent to choice(range(start, stop, step)) but supports arbitrarily large ranges and is optimized for common cases. The…

Read at the source

Flatten function/operation in functional programming (opens on the source site)

Flatten function/operation is what you want to apply to source code tree written in Java, like this: ├── hadoop-client-integration-tests │ ├── pom.xml │ └── src │ └── test │ ├── java │ │ └── org │ │ └── apache │ │ └── hadoop │ │ └── example │ │ ├── ITUseHadoopCodecs.java │ │ └── ITUseMiniCluster.java │ └── resources │ ├── hdfs-site.xml │ └── log4j.properties (the post first published at 20251208.) List of my other blog posts. Subscribe to my news feed, If you noticed a typo/bug/error or have any suggestions, do not hesitate to drop me a note: my emails. Or use my zulip for feedback. Or…

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.