Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cdine
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
cdine
7y ago
Thanks! That was the goal. For those who aren't familiar, the original slides and our response blog posts are still up: https://codebutler.com/projects/firesheep/
2.
▲
by
cdine
7y ago
Firesheep co-author here. Thanks and agreed :)
3.
▲
by
cdine
12y ago
Source: https://github.com/SecurityInnovation/PGPy Documentation: https://pythonhosted.org/PGPy/
4.
▲
PGPy v0.3.0 Released – OpenPGP Implementation in Python
(blog.securityinnovation.com)
5 points
by
cdine
12y ago
|
1 comments
5.
▲
Scientists at MIT replicate brain activity with chip
(bbc.co.uk)
2 points
by
cdine
15y ago
|
0 comments
6.
▲
by
cdine
15y ago
For some time I've ran a box with PF forwarding all TCP ports to an SSH server. That plus a simple nmap connect scan has proved handy for countless annoying networks that try to block "common" ports, poorly configured captive portal network
7.
▲
One Nation Under Surveillance - Oxford University Press, 2011
(onenationundersurveillance.net)
2 points
by
cdine
16y ago
|
0 comments
8.
▲
Firesheep, a week later: Idiot Shepherds
(codebutler.com)
3 points
by
cdine
16y ago
|
0 comments
9.
▲
Firesheep, a day later
(codebutler.com)
77 points
by
cdine
16y ago
|
15 comments
10.
▲
by
cdine
16y ago
Indeed, Loopt appears to be one of the few high-profile sites to have done this right. SSL for everything, and cookies that are relevant to login sessions are marked secure. This is what we need everywhere!
11.
▲
by
cdine
16y ago
Most sites don't properly invalidate sessions when you log out, you can't protect yourself as well as you think. See our slide on this topic: http://codebutler.github.com/firesheep/tc12/#18
12.
▲
by
cdine
16y ago
It's 100% open source! Please feel free to review it. http://github.com/codebutler/firesheep It doesn't currently do anything with passwords, it's only pulling out cookies from HTTP Response headers. But it would be trivial to also get pa
13.
▲
by
cdine
16y ago
Yup, they're one of our examples of a "good" setup. However, Google leaks iGoogle and some other things (Latitude, address book, reader, ...)
14.
▲
by
cdine
16y ago
HTTPS Everywhere only works on a select few sites. You're up a creek for anything it doesn't cover. And Tor, there's lots of cases where operators did bad things. Don't trust it for sensitive information. http://blog.ironkey.com/?p=201
15.
▲
by
cdine
16y ago
This vulnerability (it hurts to even call it such at this point) has been around for years, and the attack has always been easy for a determined attacker to carry out. How else are we going to convince people to secure their sites and prote
16.
▲
by
cdine
16y ago
Well, hopefully it will then convince companies to properly secure their websites and actually protect users.
17.
▲
by
cdine
16y ago
I love SSH tunnels, but in regards to this particular problem, it really just pushes the problem off to wherever you ssh tunnel terminates. Do you trust you server operator? ISP? This is addressed in our presentation, here (VPN's are essent
18.
▲
by
cdine
16y ago
Sorry if it was misleading somehow, this is definitely not a vulnerability in Firefox. It's a Firefox extension that makes it easy to execute HTTP session hijacking attacks.
19.
▲
Firesheep: Easy HTTP session hijacking from within Firefox
(codebutler.com)
714 points
by
cdine
16y ago
|
341 comments
20.
▲
MS10-070 (.NET Padding Oracle Vulnerability) Post Mortem analysis of the patch
(musingmarc.blogspot.com)
1 points
by
cdine
16y ago
|
0 comments
21.
▲
by
cdine
16y ago
They specifically mention that the certificate size (and that of intermediates, among other things) impacts the message size and thus the TCP packet sizes used during handshakes. They actually explain all of this quite well, just read the e
22.
▲
by
cdine
16y ago
Interesting, thanks for the pre-coffee clarification. aka I can't read =] I'm sure people will still mess things up :)
23.
▲
by
cdine
16y ago
So, I get it and all that, what are some real world use cases of this and the postgresql equivalent? Who's actually using these things for something other than saying how fast they are? I just hope they aren't being used as public-facing JS
24.
▲
by
cdine
16y ago
This link is actually to an article titled "Legal challenge between Palo Alto company, Orange County hospital halts stem cell research"
25.
▲
Cyberattacks: Washington is hyping the threat to justify regulating the Internet
(news.yahoo.com)
29 points
by
cdine
16y ago
|
6 comments
26.
▲
by
cdine
16y ago
This link results in a redirect loop for me, the following seems to work: http://news.yahoo.com/s/csm/20100429/cm_csm/297733
27.
▲
by
cdine
17y ago
Has anyone else had experience with onlinkbank.com? That's the service which Verity has switched to for their online banking, which uses a single domain for all of their customers it seems (e.g. if You're with financial institution X you ac