Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
besselheim
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
besselheim
10y ago
Anonymised telemetry reports are not the same as being spied upon. Anyway, Apple has the same kind of thing in iOS and OS X.
62.
▲
by
besselheim
10y ago
One example relating to OS X is that malware running as root can defeat anti-keylogger protections such as this: https://developer.apple.com/library/content/technotes/tn2150... If you were running your web br
63.
▲
by
besselheim
10y ago
This reminds me of the similar joy of stumbling across a pianola museum in Amsterdam. Always a pleasure to find such a well curated niche set of exhibits.
64.
▲
by
besselheim
10y ago
An online hex editor. Probably could do this fully in the browser.
65.
▲
by
besselheim
10y ago
Yet, aren't you also applying similar stereotypes to "leftists" here? Not everyone with a left-wing political outlook has the attitude you have described.
66.
▲
by
besselheim
10y ago
Another approach - controlling the USB device over WiFi, so it can be remotely triggered at any time: https://www.sensepost.com/blog/2016/universal-serial-abuse/
67.
▲
by
besselheim
10y ago
How do you mean? All current Windows versions and Linux distributions have built in support for running under Hyper-V, which the Azure hypervisor is based upon.
68.
▲
by
besselheim
10y ago
I used to concern myself with this, but eventually realised that it doesn't really matter, as I'll be permanently dead and gone. And in time, so will everyone who ever knew me. In the grand scheme of things, we're all irrelev
69.
▲
by
besselheim
10y ago
You can, you just need to have someone reverse engineer the pinning mechanism first to figure out how to disable or bypass it, or alternatively, log the data being wrapped in TLS. Same as has been done on mobile platforms (e.g. HttPeek for
70.
▲
by
besselheim
10y ago
Looking at the list of domains, they appear to be almost entirely unrelated to telemetry. Most likely this feature is a response to incidents such as this: https://www.wired.com/2011/03/comodo-compromise/ (in
71.
▲
by
besselheim
10y ago
The site I recall was Blogspot rather than Github: https://web.archive.org/web/20110602182718/http://skype-open...
72.
▲
by
besselheim
10y ago
I remember seeing an earlier incarnation of this around five years ago; I'm very impressed with the author's dedication to this project. I don't know if it is still the case now, but I recall that earlier versions of Skype we
73.
▲
by
besselheim
10y ago
Agreed, it's neat to see an anti-feature being subverted such that it becomes a feature. (The anti-feature being the enforcement of American prudity onto what should be an indifferent API.)
74.
▲
by
besselheim
10y ago
I suppose this would still be susceptible to this class of attack: https://www.usenix.org/conference/usenixsecurity16/technical... Unless you're very careful about which ranges of physical memory are mapped t
75.
▲
by
besselheim
10y ago
The root certificates trusted by Windows are fetched from Microsoft's servers as needed. You can download all of them using the command: certutil -generateSSTFromWU roots.sst Then if you open up roots.sst (it opens in certmgr.
76.
▲
by
besselheim
10y ago
The previous discussion has some good comments and links: https://news.ycombinator.com/item?id=8966785
77.
▲
by
besselheim
10y ago
Or both. Defense in depth.
78.
▲
by
besselheim
10y ago
Until a fix is released, this can be mitigated by blocking outbound TCP connections on ports 139 and 445. Individual users can do this using by setting up suitable outbound rules in the Windows Firewall with Advanced Security snap-in (wf.ms
79.
▲
by
besselheim
10y ago
Using dir normally does not display anything related to the alternate data streams, but if you use the /r option, their names and sizes will be shown.
80.
▲
by
besselheim
10y ago
It has "sls" as its alias, even easier to type.
81.
▲
by
besselheim
10y ago
Very interesting - does anyone know exactly what techniques they use to gather this data? I'm guessing to some extent it must rely on a jailbroken iOS to get past the .ipa code encryption, as with this similar analysis: https:/&#
82.
▲
by
besselheim
10y ago
> Really, the true advantage of a binary format is you generally assume that nobody messed with the data behind your back I would rephrase that a bit and say the true advantage is flexibility, as you're not subject to the constrai
83.
▲
by
besselheim
10y ago
The passwords are not necessarily being captured in logfiles, that's a huge assumption. We don't know anything about how eBay stores and manages their web server logs.
84.
▲
by
besselheim
10y ago
> Sensible?! Hahahaha! This has to be comedy. They are bigint-encoding identifiers? There is no sane reason to do this. This fixed machine-width type of character encoding isn't unheard of. For example, Windows uses tags of this s
85.
▲
by
besselheim
10y ago
You piqued my curiosity - just made one by extracting the syscall dispatch table from lxcore.sys and placing it alongside the Linux syscall list: https://goo.gl/QHGe1U A lot of coverage there, but interesting to see which o
86.
▲
by
besselheim
10y ago
If you disassemble lxcore.sys you can still see hints of the Android subsystem project that it grew from: the \Device\adss and /dev/adss devices, the application name Microsoft.Windows.Subsystem.Adss, various function names contai
87.
▲
by
besselheim
10y ago
I had the same issue with a second hand HP laptop. However, I could still log in as administrator on the Windows install, enabling me to dump the flash memory used to store the BIOS firmware and configuration, which included the password ha
88.
▲
by
besselheim
10y ago
Unfortunately this won't work on most modern systems where the password hash is held in nonvolatile memory, rather than a battery-backed volatile store.
89.
▲
by
besselheim
10y ago
That's true, they treated Sklyarov most unfairly, given that it was entirely legal in his home country.
90.
▲
by
besselheim
10y ago
If the reversing and reimplementation happens outside of the US you can avoid the DMCA issue entirely. Or take steps to publish anonymously.
More ›