Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nicolas314
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
nicolas314
10y ago
In the same spirit, there is at least one botnet dubbed Linux/Moose [1] dedicated to penetrating home routers for the sole purpose of creating fake followers on social networks. [1] http://www.welivesecurity.com/2016&#x
32.
▲
by
nicolas314
10y ago
Many civilizations used base 12, most probably because you can count 12 phalanges using your thumb. https://en.wikipedia.org/wiki/Duodecimal
33.
▲
by
nicolas314
10y ago
I am running two APs on 2.4GHz and one on 5GHz without issues. See here for a complete write up: https://nicolas314.wordpress.com/2016/05/30/openwrt-on-ubiqu...
34.
▲
by
nicolas314
10y ago
WiFi networks need to be configured every now and then, e.g. to set up a guest WiFi, change the password, change the channel to a less crowded space, or activate MAC-filtering to kick my neighbours out. With LEDE I can do all of that with a
35.
▲
by
nicolas314
10y ago
The Unifi controller is largely overkill when you just have one AP to manage. Booting up 200 megs of Java software on a desktop to just tweak a few bits quickly became old. Re-flashed my Unifi AC Lite with LEDE and configured it through Luc
36.
▲
by
nicolas314
10y ago
They are quite different beasts. HSMs offer tamper protection through various physical means like wrapping all components in resin, or implementing self-destruction mechanisms. Smart cards protect their secrets against all kinds of side cha
37.
▲
by
nicolas314
10y ago
Theoretically yes, though you would have to explicitly switch the original HSM into backup mode, an operation that requires one or more admins to be present and strongly authenticated, most often with smart cards.
38.
▲
by
nicolas314
10y ago
Nope, TrustZone is not tamperproof, cannot resist determined attackers who have access to the hardware. HSMs and smart cards are designed precisely to cover this use case.
39.
▲
by
nicolas314
11y ago
Account was closed a while back. Now I can still log in, but only thing I can do is watch my bill increase and my attached credit card stay attached until they charge it. Online fun!
40.
▲
by
nicolas314
11y ago
For what it's worth: I created an account to try it out in January, played a bit with a cheap instance, and deleted the instance. Got billed in February (about 1€) while there was strictly no activity going on. Got to wait until end of
41.
▲
by
nicolas314
11y ago
Since the Apple chip is derived from an ARM design it would make sense to have the secure enclave implemented with TrustZone rather than being provided as a separate piece of hardware. Most probably a TEE (Trusted Execution Environment). Lo
42.
▲
by
nicolas314
11y ago
Pi would be a good source, but they are in the wrong order.
43.
▲
by
nicolas314
11y ago
Definitely that, and the fact they cannot be copied. OTP fobs offer the same convenience but are based on shared secrets that can be stolen from the server (happened to RSA). With PKI your private key is only on your smart card and nowhere
44.
▲
by
nicolas314
11y ago
Certificates are public, they don't need protection. The private keys do. That said you always want to store a certificate close to its private key for practical reasons. Smart cards are useful to transform your keys into a real object
45.
▲
by
nicolas314
11y ago
There are browser-side APIs to generate key pairs, but there is no real standard as the KEYGEN tag is not widely supported, so on the server side you need to implement virtually one method per browser type you are addressing. And then you w
46.
▲
by
nicolas314
11y ago
On mobile clients they can be quite convenient though. No need to remember any password and good protection against shoulder-surfing. Relevant: https://www.youtube.com/watch?v=ybNWOhI-Q-4
47.
▲
by
nicolas314
11y ago
For information: OpenTrust (3 roots) is just the new name of the entity that was once Certplus (1 renewed cert).
48.
▲
by
nicolas314
12y ago
I also have trouble believing is that 3G/4G networks would not be affected. All of these protocols are based on symmetric cryptography, i.e. a shared secret between Operators and their SIM cards. Once you get the shared secret you have
49.
▲
by
nicolas314
12y ago
In many cases you have specific procedures in place for security-conscious MNOs, but some of these procedures are such a pain that you inevitably end up finding workarounds to get the business going, e.g. email or USB tokens between various
50.
▲
by
nicolas314
12y ago
I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM
51.
▲
by
nicolas314
13y ago
SIM cards don't know anything about the network they are running on, this all happens inside your terminal. They hold an IMSI (=contract #), a set of private keys, and some utility applets. SIM cards don't even know their own phon
52.
▲
by
nicolas314
13y ago
SIM cards are just your average smart cards dedicated to do mobile network stuff. You can buy your own blank smart cards from Gemalto and Oberthur if you so wish. Javacard is not Java. No OO, no classes, no GC, no floats, no strings, the on
53.
▲
by
nicolas314
13y ago
I have been working on OTA platforms for years with Mobile Network Operators worldwide, and I have yet to meet one that is only using DES for OTA keys. All the ones I know are using 3DES. Not sure where Nohl is getting his estimations from.
54.
▲
by
nicolas314
13y ago
You do not own the SIM card, it remains full property of your network operator. As such, they have a right to keep you off-limits. FYI: the main Javacard applet on a SIM card is the GSM applet, the one you use to authenticate against your n
55.
▲
by
nicolas314
13y ago
Agreed if you configure your HTTPS server to accept certificates from any issuer. But if you restrict it to a smaller list of CAs, users are only prompted to choose among their certificates matching those CAs.
56.
▲
by
nicolas314
13y ago
It definitely works with recent Chrome versions. I use this daily to check my professional webmail on an Android 4.2.2. Once you have provisioned a PKCS#12 into your keystore, open Chrome onto an HTTPS web site that requires certificates fr
57.
▲
by
nicolas314
14y ago
I am totally baffled that copy/pasting an image can be considered legally binding in 2013. Digital signatures with x.509 certificates have existed for ages now and these are rightfully legally binding anywhere in Europe. Please have a look
58.
▲
by
nicolas314
14y ago
Free.fr was once a real game changer, but that was 10 years ago. Over the past few months they have been caught red-handed filtering Google services (starting with YouTube) in order to pressure Google into footing the bill for their peering
59.
▲
by
nicolas314
14y ago
Sure there are workarounds. But why should I have to jump through hoops when my account at Amazon is already entrusted with a European credit card and merrily charging euros for all other goods?
60.
▲
by
nicolas314
14y ago
One recurrent issue with Amazon services is that they charge in US$ and currently do not accept euros. European banks charge an arm and a leg for micropayment conversions: last time I got a bill from AWS for 0.02$ it ended up costing me 20
More ›