Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cantfindmypass
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
24 ms
·
1.
▲
by
cantfindmypass
12y ago
Correct, they cannot compute SHA256() or SHA256(SHA256()) of arbitrary data.
2.
▲
by
cantfindmypass
12y ago
Someone showed me this a while ago. Apparently it's an actual attack. https://www.youtube.com/watch?v=G50typU3mLg
3.
▲
by
cantfindmypass
12y ago
> I suspect they have a base OS installation and then have a post-boot encrypted partition which requires manual passphrase entry over ssh or console to unlock, containing all the relevant data. That's a pretty normal way to set up
4.
▲
by
cantfindmypass
13y ago
Being able to rebind the keys would be really nice. The keys are decently intuitive, but it sucks pretty bad if you have a split keyboard.
5.
▲
by
cantfindmypass
13y ago
Apple has had a working gotofail fix for OS X internally for days.
6.
▲
by
cantfindmypass
13y ago
the only source of this appears to be the updated whois information...
7.
▲
by
cantfindmypass
13y ago
The percentage of sites using SHA256 certificate is tiny, and most CAs are still SHA1 based.
8.
▲
by
cantfindmypass
13y ago
That is a different bug.
9.
▲
by
cantfindmypass
13y ago
I would be totally happy to put a proper stylesheet and some better copy together if someone wants to send me that (put it in a gist maybe?)
10.
▲
by
cantfindmypass
13y ago
I am now for informational purposes linking to the OS X patch released by i0n1c. http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.htm...
11.
▲
by
cantfindmypass
13y ago
I'm not checking for Safari vs OS X. I'm not sure what else to say to vulnerable OS X users - there is not really any effective mitigation besides turning the computer off.
12.
▲
by
cantfindmypass
13y ago
It became widely known outside of Apple due to the iOS patch.
13.
▲
by
cantfindmypass
13y ago
Yes, removing one line would fix it.
14.
▲
by
cantfindmypass
13y ago
The issue is that Apple's security engineers must have realized that there was a good chance someone would reverse engineer the patch, and from there find out the OS X is also vulnerable.
15.
▲
by
cantfindmypass
13y ago
Apple still hasn't released a fix for OS X...
16.
▲
by
cantfindmypass
13y ago
My web logs show lots of systems identifying as 10.9.2 pulling the test image from the bad server.
17.
▲
by
cantfindmypass
13y ago
I just noticed that his works differently than mine.
18.
▲
by
cantfindmypass
13y ago
Yes, the bug is a regression introduced in Mavericks.
19.
▲
by
cantfindmypass
13y ago
I don't know - I can't imagine that nobody on their security team pointed out that someone would promptly reverse engineer the patch and figure out that OS X is also vulnerable.
20.
▲
by
cantfindmypass
13y ago
There's not a whole lot I can do about that without adding a lot of complexity. You could try downloading https://gotofail.com:1266/test.png I suppose.
21.
▲
by
cantfindmypass
13y ago
I wanted to make something that gives something a little more useful than an error page if you're safe.
22.
▲
by
cantfindmypass
13y ago
I started making this before agl released that, though he had that up before I finished. Also, upon closer inspection, mine actually works differently from agl's.
23.
▲
by
cantfindmypass
13y ago
No OS X patch is available yet. :-( Chrome/Firefox shouldn't be vulnerable.
24.
▲
by
cantfindmypass
13y ago
There is no patch for Mavericks out yet. :-(
25.
▲
by
cantfindmypass
13y ago
I would be shocked if this doesn't apply to the email client as well.
26.
▲
Show HN: Check if your browser is vulnerable to the Apple SSL bug
(gotofail.com)
118 points
by
cantfindmypass
13y ago
|
68 comments
27.
▲
by
cantfindmypass
13y ago
I just made this - it'll tell you if you're vulnerable. https://gotofail.com/ Not very well tested, please let me know if it works for you. If you're on OS X Mavericks or on iOS 7 and haven't patched you
28.
▲
by
cantfindmypass
13y ago
No. The transmitters calculate signals such that constructive/destructive interference will combine to form a strong, clean signal in the precise location where the device is.
29.
▲
by
cantfindmypass
13y ago
Last time I looked into persona, it was essentially unusable for my usage - there's no reasonable way to use a different email address to sign up for every site. I like to know who leaked my email address when I start getting spammed.
30.
▲
by
cantfindmypass
13y ago
Square Enix's offerings on Android are non-functional on newish versions of the OS. Look at the reviews: https://play.google.com/store/apps/details?id=com.square_eni...
More ›