Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Snawoot
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
151.
▲
by
Snawoot
7y ago
When StrongSwan EAP-RADIUS plugin is in use, authentication delegated to RADIUS server. Actual EAP handshake occurs between VPN client and RADIUS server. [1] Some EAP authentication methods (namely, EAP-MSCHAPv2 and EAP-TLS) export Master S
152.
▲
by
Snawoot
7y ago
It is copy of snippet linked from 8ch.net: https://web.archive.org/web/20180504001844/https://8ch.net/b...
153.
▲
by
Snawoot
7y ago
Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snaw
154.
▲
by
Snawoot
7y ago
OpenVPN CA key also leaked: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa...
155.
▲
by
Snawoot
7y ago
> According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server. It's simply not true. Their CA private key which is used to issue certificates for ALL servers also le
156.
▲
by
Snawoot
7y ago
I already checked all passwords made of any printable character up to 7 symbols length. Full 8-symbol bruteforce will take about 120 days on my hardware, so I prioritized passwords with no special symbols first. Does anyone with hashcat and
157.
▲
by
Snawoot
7y ago
firefox.factor11.cloudflareclient.com:2486
158.
▲
by
Snawoot
7y ago
Here is standalone client for Firefox Private Network: https://github.com/Snawoot/firefox-secure-proxy Also works outside US.
159.
▲
by
Snawoot
7y ago
Here is standalone client for Firefox Private Network: https://github.com/Snawoot/firefox-secure-proxy Also works outside US.
160.
▲
by
Snawoot
7y ago
Here is standalone client for Firefox Private Network: https://github.com/Snawoot/firefox-secure-proxy Also works outside US.
161.
▲
Show HN: Standalone Client for Firefox Private Network
(github.com)
9 points
by
Snawoot
7y ago
|
0 comments
162.
▲
by
Snawoot
7y ago
Time for shameless plug, but I hope someone will find my experience useful. I tried wide variety of VPN solutions, including Wireguard, IKEv2, OpenVPN, L2TP/IPsec, PPTP. Eventually I came to conclusion: I don't need VPN at all wit
163.
▲
by
Snawoot
7y ago
It's weird, I use FF 68 and it works for me.
164.
▲
by
Snawoot
7y ago
http://web.archive.org/web/20190902014433/https://www.popsci...
165.
▲
by
Snawoot
7y ago
Also only available cipher for wireguard is Chacha20Poly1305. I wonder how comes technical information presented by this VPN service is such inaccurate.
166.
▲
by
Snawoot
7y ago
I'm former Russian resident. First, there are still some cases when permission for protest event is not required. It's a picketing performed by single person, for example. In this case police will pack protester in a matter of few
167.
▲
by
Snawoot
7y ago
Accepts TCP connections on listen port and forwards them, wrapped in TLS, to destination port. ptw maintains pool of fresh established TLS connections effectively cancelling delay caused by TLS handshake. ptw may serve as drop-in replacemen
168.
▲
Show HN: Pooling TLS Wrapper
(github.com)
2 points
by
Snawoot
7y ago
|
1 comments
169.
▲
Rsp – Faster Socks over SSH
(github.com)
1 points
by
Snawoot
7y ago
|
0 comments
170.
▲
by
Snawoot
7y ago
Rapid SSH Proxy. Like ssh -ND, but much faster. rsp is a SSH client which implements SOCKS5 proxy feature of SSH protocol. Key feature of this implementation is use of multiple connections to overcome downsides of multiplexing many tunneled
171.
▲
Show HN: Rapid SSH Proxy
(github.com)
2 points
by
Snawoot
7y ago
|
1 comments
172.
▲
by
Snawoot
7y ago
Distributed Randomness Beacon client Gathers entropy from multiple drand ( https://github.com/dedis/drand ) instances, securely mixes responses and outputs to kernel entropy pool or stdout. Suitable for use with League
173.
▲
Show HN: Distributed Randomness Beacon Client
(pypi.org)
2 points
by
Snawoot
7y ago
|
1 comments
174.
▲
by
Snawoot
7y ago
It's not just about losing job or other penalities, it is also about futility of resistance to corruption. If you are openly against system, you get replaced and your place will be taken by less experienced but more convenient person.
175.
▲
by
Snawoot
7y ago
Commenter in this branch put it all together just right. Also Dyatlov notes all industrial disasters was attributed to personnel error in Soviet Union, no matter which real reason it was, for political reasons. I'll let myself add some
176.
▲
by
Snawoot
7y ago
I hope my comment history will satisfy you. Basicly, some scenes in series are overdramatized. For example, Sitnikov was not convoyed by soldier to reactor roof - he went willingly, Dyatlov wasn't so bad as he portrayed and so on. Luck
177.
▲
Show HN: Full Boot Chain Protection for Linux with Secure Boot
(github.com)
1 points
by
Snawoot
7y ago
|
0 comments
178.
▲
by
Snawoot
7y ago
RFC 8461 Section 3 states: "These TXT records additionally contain a policy "id" field, allowing Sending MTAs to check that a cached policy is still current without performing an HTTPS request." So, yes, it is "skip
179.
▲
by
Snawoot
7y ago
If you are concerned, for both MTA-STS and STARTTLS-Everywhere you may use enforcing policy even against domains in testing mode at the cost of small possibility of delivery failure. postfix-mta-sts-resolver has config option strict_testing
180.
▲
by
Snawoot
7y ago
"Cache" term in MTA-STS is misleading. Standard encourages to fetch new policy even before expiration of cached copy. If you have some cached policy and "id" is not updated since then, you may skip actual request to poli
More ›