Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
brl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
brl
13y ago
> What kind of attacks is this practice vulnerable to? I want to pretend to control target@example.com and the legitimate owner of this address is an OpenPGP user who has published a keyring on the public keyservers. 1) I create a keyrin
32.
▲
by
brl
13y ago
btw, how is a person signing a key in the usual WoT model supposed to know whether or not the email address specified in the key uid is actually controlled by the person standing in front of them at the key signing party with passport and
33.
▲
by
brl
13y ago
I don't know if it's very useful even if you do know how to sign keys and verify signatures.
34.
▲
by
brl
13y ago
You're also one XSS vulnerability away from losing all of your private communication to an attacker.
35.
▲
by
brl
13y ago
"Complete enabling for [REDACTED] encryption chips used in Virtual Private Network and web Encryption devices" AND "Large Internet companies use dedicated hardware to scramble traffic before it is sent. In 2013, the agency pl
36.
▲
by
brl
13y ago
One of the main reasons that Cryptocat is able to celebrate their high usability is because they didn't even attempt to tackle the most difficult usability problems in a system for secure communication. There is no such thing in Crypt
37.
▲
by
brl
14y ago
Guess again?
38.
▲
by
brl
14y ago
If your salt is 'short' you can still perform this attack. Assume a timing oracle, which when queried with a plaintext password will return an integer which is the length in bytes of the matching hash prefix. Choose a small prefix length (p
39.
▲
by
brl
14y ago
but not all of the subpoenas are secret, certainly is it rare for them to include NSLs (as Appelbaum has indicated the FBI hinted) and rarely if never are the dockets themselves sealed (as Appelbaum's lawyer is currently fighting)
40.
▲
by
brl
15y ago
Have you tried nav? https://code.google.com/p/emacs-nav/
41.
▲
by
brl
15y ago
Here's a presentation I gave a couple of years ago about research I performed to demonstrate exactly this: http://www.slideshare.net/bleidl/net-neutrality-and-internet...
42.
▲
Kerckhoffs’ Legacy: The history of open source and network security.
(keystream.subgraph.com)
1 points
by
brl
15y ago
|
0 comments
43.
▲
by
brl
15y ago
The first step should always be to confront your boss directly with your concerns. If that isn't a realistic option, it's probably for the best to go work somewhere else under competent leadership.
44.
▲
by
brl
15y ago
Perhaps not as ironic as you think: http://www.nytimes.com/2006/05/03/business/03cnd-raytheon.ht...
45.
▲
by
brl
15y ago
> And stop calling people who question your ineffectual and pointless public masochism "trolls", "cowards" and "stalkers". You made a HN account just to throw personal attacks at Jacob and think it's unfair to be called a troll or a sta
46.
▲
by
brl
16y ago
> He confessed. Last I heard he had not confessed and he is not cooperating with the prosecution. Do you know something different?
47.
▲
by
brl
16y ago
> Julian Assange has a history of, well, exaggerating about the threats against him. Do you care to substantiate that? Assange, who has not been charged with any crime, is currently the subject of an international arrest warrant which o
48.
▲
by
brl
16y ago
> Casting a u_int32_t over a 4-byte string (like an SMTP verb) to get a value you can switch() on. This is awesome beyond words. If I stumbled across this in the wild I would flip flop between awe and disgust until my head exploded. Le
49.
▲
by
brl
16y ago
You didn't really spell out why this trick works: array[index] == *(array + index) == *(index + array) == index[array]
50.
▲
by
brl
16y ago
Moxie didn't say anything more than that his phone number was in Jacob Appelbaum's phone. Jacob has a lot of telephone numbers, perhaps hundreds, including mine. He's a hyper-social guy who knows everybody. If merely appearing in Jacob's a
51.
▲
by
brl
16y ago
Since when is anybody alleging that Moxie is affiliated with Wikileaks?
52.
▲
by
brl
16y ago
As a Dvorak user, all of these JS games with their hardcoded keys are impossible to play without changing my layout back to Qwerty. 1,2,3 + arrow keys would be a better choice for sure.
53.
▲
by
brl
16y ago
What does Flash provide that makes it easier to develop games like this? If Flash is currently much better than Javascript, don't we just need better high level canvas graphics libraries?
54.
▲
by
brl
16y ago
REPL live in your browser here: http://hiji.tinyrocket.se/
55.
▲
Video demonstrates server compromise with new ASP.NET platform vulnerability.
(youtube.com)
4 points
by
brl
16y ago
|
0 comments
56.
▲
by
brl
16y ago
> What do you mean by "local SYSTEM"? The highest system privilege level on Windows. They were able to interactively run CMD.EXE as the LocalSystem account on the remote web server. > I eagerly look forward to details on it. Where
57.
▲
by
brl
16y ago
"It always follows the same pattern of arm waving and press releases, with a promised demonstration, and then the day of reckoning comes and...quiet." A few minutes ago, live on stage at a security conference in Buenos Aires (#ekoparty) the
58.
▲
by
brl
16y ago
As somebody who is familiar with some details of the vulnerability, I can assure you that the error reporting configuration is irrelevant. The HTTP response code is the only information needed for the attack. 200 vs. 500 vs. 404
59.
▲
by
brl
16y ago
Yes, exactly. Among other things, this attack allows you to forge authentication cookies on any ASP.NET application with a 100% success rate.
60.
▲
by
brl
16y ago
If pure journalism is declared a terrorist activity in your country, you've got bigger problems than appearing on a list of Wikileaks donors.
More ›