Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
CyberRage
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
CyberRage
5y ago
I work in the industry if it wasn't obvious though for years now nothing to do with phishing but I do have some experience shall we say. 1. Building a phishing page and can accept 2FA and in real time(remember code is useless after 30
62.
▲
by
CyberRage
5y ago
There's no need for yubikeys. we have the ultimate key, our phones. Most modern phones have SE(Secure Element) or virtualized secure zone(ARM Trustzone) which can act as de-facto key. Google already uses it to great success(most people
63.
▲
by
CyberRage
5y ago
the hell are you talking about? why make out wrong "facts"? 2FA is very useful against phishing: https://security.googleblog.com/2019/05/new-research-how-eff...
64.
▲
by
CyberRage
5y ago
What? that's absolutely not the reason for 2FA... if he can key-log your passwords, he can keylog your 2FA code... deployment of a keylogger means your host is compromised, from there you can do so much you really don't need someo
65.
▲
by
CyberRage
5y ago
TOTP is definitely helpful vs phishing. They only last for 30 seconds, requiring better infrastructure(automated logins) which also tremendously helps with detection. The vast majority of phishing is just storing passwords for later attempt
66.
▲
by
CyberRage
5y ago
In the past, it wasn't quite obvious where EV's will land but today with every major auto-maker from Toyota\VW to GM investing heavily into EV's, I think its a foregone conclusion. EV's will allow countries to be less re
67.
▲
by
CyberRage
5y ago
So let's circle back to the original question. Pwning the app will only provide access to whatever permission it has and we are still sandboxed. Pwning a kernel module\driver will provide access to everything whether its messaging, cal
68.
▲
by
CyberRage
5y ago
Again, if you get a kernel exploit, you don't need access to the messaging app or to escalate privileges. you're already root. you can access any component without much restriction. How the data is stored has nothing to do with th
69.
▲
by
CyberRage
5y ago
I think you misunderstand how things work on modern mobile OS. You don't need to access the messages app in order to get access to the messages. it's the opposite actually, the messaging app needs permissions for the system level
70.
▲
by
CyberRage
5y ago
If you successfully exploit a kernel vulnerability, you don't need an iMessage bug.... you can pretty much access whatever you want.
71.
▲
by
CyberRage
5y ago
It is part of my job. many banks do. often embarrassingly so.
72.
▲
by
CyberRage
5y ago
Well that has nothing to do with the subject. the subject is zero-click exploits, this is not regarding authentication. The point of these apps is that I can get content(picture, message, video etc) to your local device and it get processed
73.
▲
by
CyberRage
5y ago
Well I would dare to say iMessage isn't the biggest target to convert to Rust. At the end of the day, it is still an app with app level permissions, sandbox etc. Kernel\Kernel modules are far more likely to be written as they allow for
74.
▲
by
CyberRage
5y ago
whatsapp doesn't rely on SMS protocols nor does it rely solely on phone numbers but is still being exploited quite often. Instant-Messaging = Worthy target for exploits. Just like web-browsers get exploited after years of patching.
75.
▲
by
CyberRage
5y ago
That might sound good in theory by in practice it's unlikely to go well(by default). Many services from banks to healthcare utilize SMS as a main way of communicating with end-users. many rely on dynamic numbers. Moreover, spoofing SMS
76.
▲
by
CyberRage
5y ago
When you let a terror organization run your country... it doesn't work
77.
▲
by
CyberRage
5y ago
Intel is facing some difficult times ahead. they were the kings of the industry for a while but now there is a lot of pressure and competition coming. AMD is re-surging with great technology, they already chipped away some market share in k
78.
▲
by
CyberRage
5y ago
Again, it is hard to compare because I don't know enough about Finnish. the first option is rather simple, assuming we have a good psuedo-random generator with low bias margins. we get: A-Z,a-z,0-9 = 58 options, Length = 16 58^16/
79.
▲
by
CyberRage
5y ago
That's old school. targeted attacks today, hone in on critical infrastructure before striking. Many times data is exfiltrated beforehand, backups are deleted. If someone went the trouble of compromising a 3rd party software vendor, he
80.
▲
by
CyberRage
5y ago
It seems to be though that it is consisted of some structured elements(I don't know much about Finnish orthography\honology) So if it has some predictable structure, statistical attributes etc, it can be exploited to reduce the search
81.
▲
by
CyberRage
5y ago
The second password can fail quite quickly assuming an attacker is going to target Finnish words to perform a dictionary attack, perhaps a Finnish website makes sense for something like this to be done. Psuedo-random is always better becaus
82.
▲
by
CyberRage
5y ago
Really? what about memory protection? temp file cleanup? keylogging? Encryption? what kind of KDF are you using? probably something old and quite brittle when it comes to hardware cracking. sit this one down boy
83.
▲
by
CyberRage
5y ago
Bias simply weakens your password. If you generate long elaborate passwords then they can resist some of these flaws but the point is you don't want to introduce a flaw when they are simpler and better solutions out there. Mistakes are
84.
▲
by
CyberRage
5y ago
I'm sorry but I have pretty good info about SW. I can tell things are rough there. More than anything, it proved that their model is flawed. Just the number of gov agencies that are forced to stop working with them is a major blow.
85.
▲
by
CyberRage
5y ago
That's not what I've said. I'm not a financial expert by any means but I think the stock market has proved again and again that it is not reliable and can be manipulated easily. People short-squeezing stocks, shooting their &
86.
▲
by
CyberRage
5y ago
That doesn't mean anything. in such a year their products should have flown off the shelves. Remote monitoring\management? in COVID year? just 3.5% that's horrendous
87.
▲
by
CyberRage
5y ago
Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with doze
88.
▲
by
CyberRage
5y ago
PHC had some of the biggest names in the crypto field, had NIST representation and multi-stage evaluations with top notch testing. PHC was far more mature in many ways over AES.
89.
▲
by
CyberRage
5y ago
Why should you trust AES? an algorithm chosen by a competition?
90.
▲
by
CyberRage
5y ago
"Non-public side-channel exploits seem inevitable" Have to disagree here buddy Argon2d has better resistance to TMTO and hardware accelerated cracking due to the data-depending memory access. Side-channels attacks are not practica
More ›