Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
16s
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
61.
▲
by
16s
13y ago
Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is
62.
▲
by
16s
13y ago
Be careful, this is how devs expose private ssh keys.
63.
▲
by
16s
13y ago
Microsoft Active Directory servers (used in big business and government all over the world) uses one round of MD4 (no salt). That's a 4, not a 5.
64.
▲
by
16s
13y ago
If the goal is to teach kids to shut up, sit down and get in line, then it works as expected.
65.
▲
by
16s
13y ago
I hope antirez never stops coding to move into management. I first came to know him during the Engine Yard Hamming Distance contest (2009). I've read and followed his work ever since.
66.
▲
by
16s
13y ago
Ban crypto and then only criminals and governments would have it. Same as guns.
67.
▲
by
16s
13y ago
A lot of people are moving their hacking attempts under tor. They want to brute-force your ssh server, rdp, etc. but they don't want to go to prison.
68.
▲
by
16s
13y ago
In a well-monitored environment, it should draw attention and cause them to investigate the internal host making the queries.
69.
▲
by
16s
13y ago
I really like your blog post and your ideas. With new versions of BIND 10 allowing Python scripting, PowerDNS with Lua scripting and Unbound with Python, I think we'll start seeing more corps controlling DNS queries (or attempting to d
70.
▲
by
16s
13y ago
There's a comment in the source code about b64: # If you don't like non-valid characters in the hostname, # then use hex encoding rather than base64 So far, I've not encountered a failure using b64 encoding. But that could be
71.
▲
by
16s
13y ago
Those examples tunnel traffic over DNS. They do not specifically break large files up into small chunks and exfiltrate them off of a secure network with simple DNS queries.
72.
▲
by
16s
13y ago
This is an actual working example, not theory on how to do it. IMO, that's what makes it significant. Lot's of people talk about how this can be done, few show actual working examples (with source code) that others can re-create o
73.
▲
Exfiltrate Files with DNS Queries
(16s.us)
44 points
by
16s
13y ago
|
26 comments
74.
▲
Linux Trojan “Hand of Thief”
(blog.avast.com)
76 points
by
16s
13y ago
|
61 comments
75.
▲
by
16s
13y ago
As more and more people write code and become technically literate, I think we'll see lots of this sort of thing. Once the majority of normal people "get it" then it's all down hill for those trying to control ideas.
76.
▲
by
16s
13y ago
Would it be possible for devs and small companies in other countries to take advantage of New Zealand laws without actually being there?
77.
▲
by
16s
13y ago
You'd have to have the ability to change DNS records for their domains. If you can point "whatever.com" to a NS that you control, it's game over until they take it back.
78.
▲
Exfiltrate Data with DNS (With Source Code)
(16s.us)
3 points
by
16s
13y ago
|
0 comments
79.
▲
by
16s
13y ago
This is true. And if the FCC were to give up spectrum for use in mesh networks, they could always require that no encryption be used. They mandate this with amateur radio. A HAM's license could be revoked if he was caught sending encry
80.
▲
by
16s
13y ago
Two teaspoons of Taster's Choice. That's my perfect coffee. It's quick, affordable and gets the job done. Doesn't taste bad either.
81.
▲
by
16s
13y ago
I understand this. When security is not part of the culture of the company, and management just wants to ship software, devs won't have time to test. MS used to be this way (back before XP SP2). They stopped and made security a focus a
82.
▲
by
16s
13y ago
Unrealistic deadlines and sales reps promising features to clients is a large part of the problem. Get the changes in, test the usability, and ship it. Get it out to the client pronto. We have an earnings report due by X date and this will
83.
▲
by
16s
13y ago
Why is that variable set at 10? Who would question that? The spec says 10 too. It's the "at least 10" part that was missed. That's very subtle, does not stand out and is easily over-looked unless someone is really auditi
84.
▲
by
16s
13y ago
Lot's of very skilled people interview poorly. Nervousness, social stress, anxiety etc. So don't feel bad, people who interview applicants a lot know this. It's not a mark against you. If they are interested in you, they'
85.
▲
by
16s
13y ago
http://www.livephysics.com/tools/mathematical-tools/morse-co...
86.
▲
by
16s
13y ago
In many cases, you need only a few watts (5 or less) and with a good antenna can transmit globally.
87.
▲
by
16s
13y ago
I'm glad he made it out, but that's a sad story. When you stop and think about what he's saying, it's depressing. And, it's true.
88.
▲
Extraordinarily Fast UDP Scanner
(trouble.org)
2 points
by
16s
13y ago
|
0 comments
89.
▲
Crack this Homemade Crypto System and Win a Cool Prize
(16s.us)
2 points
by
16s
13y ago
|
0 comments
90.
▲
by
16s
13y ago
+1 Email encryption in the cloud isn't secure. It's convenient, easy to use and makes you feel warm and fuzzy, but that's about it. OpenPGP still stands.
More ›