Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
armooo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Flash sale site Rue La La explores sale; Gilt interested($400 million)
(reuters.com)
3 points
by
armooo
12y ago
|
0 comments
2.
▲
Explaining python descriptors
(nedbatchelder.com)
6 points
by
armooo
13y ago
|
0 comments
3.
▲
by
armooo
14y ago
Reading this http://nelenkov.blogspot.com/2012/07/using-app-encryption-in... it looks like if you have root on your phone you can still access the APKs. Sounds like it is using the same encryption system as the apps on SD. But have have n
4.
▲
by
armooo
14y ago
Good point, I am not sure why the OP did not show the key.
5.
▲
by
armooo
14y ago
I tested this on the with the twitter api. This key was already leaked in 2010 at https://github.com/mitsuhiko/logbook/blob/master/twitter-sec... . So I will just post it here. https://twitter.com/armooo/status/237729837157060609 take a
6.
▲
by
armooo
14y ago
OAuth was designed to not require SSL. So only the oauth_consumer_key, which works as an client id, is sent over the wire. HMAC-SHA1 is then used with a shared secret key to sign all the requests. This key is what the maloc shim is finding,
7.
▲
by
armooo
14y ago
I pulled the keys out of the android client this weekend. Not as good of a write up, but I used apktool to convert the APK back to xml resource files and smali dalvik assembler. Greped for Hmac and added some logging. Did the same thing for
8.
▲
by
armooo
15y ago
http://db.tt/M5Zbe5Jr thanks
9.
▲
by
armooo
15y ago
If anyone has an invite I would like one <removed> Thanks edit I got mine thanks.