Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
palant
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
palant
4y ago
Yes, that was their first iteration. If you think that this went any better than communicating via a local web server, well… https://palant.info/2023/01/09/touchen-nxkey-the-keylogging-...
32.
▲
by
palant
4y ago
Note : I am the author of this article. Authorities can issue certificates for IP addresses. They merely cannot issue certificates for non-public IP addresses. And: yes, maybe certificates for 127.0.0.1 should be disallowed altogether. But
33.
▲
by
palant
4y ago
Sure, antivirus software does inspection at the endpoints. Guess what: they usually employ their MITM CA for that. :-) It’s not like I haven’t written about that before. Here is a particularly disastrous implementation: https://p
34.
▲
by
palant
4y ago
Microsoft specifically requires that root certificates have an expiration time no longer than 25 years. See here: https://learn.microsoft.com/en-us/previous-versions//cc75115...
35.
▲
by
palant
4y ago
Note : I am the author of this article. Yes, they successfully moved away from ActiveX. Not sure about SEED, I think I still saw it in one of the applications. But there seems to be another contributing factor, the Korea Exchange Bank hack
36.
▲
by
palant
4y ago
On the individual level, the reception is remarkably positive. I’ve had lots of people thank me for this research, including people working for government agencies. The news coverage is mixed. Some articles are positive about this and are a
37.
▲
by
palant
4y ago
Interception of localhost traffic is in fact a non-issue, someone able to do it can do worse. So TLS really shouldn’t be necessary on localhost, that’s it.
38.
▲
by
palant
4y ago
Note : I am the author of this article. And what if somebody else gets hold of their private key and uses it to MITM? I mean, it’s only South Korea, it’s not like they have a neighbor country which would be willing to abuse this kind of th
39.
▲
by
palant
4y ago
Note : I am the author of this article. In fact, the article does explain this. The CAs that are on this list by default have to comply with strict criteria making sure they cannot be abused. Anything that has been added externally, avoidi
40.
▲
by
palant
4y ago
Note : I am the author of this article. There are semi-legitimate use cases. One is intranets where you might want to have HTTPS on non-public resources. More commonly the company installs their own root CA however so that they can monitor
41.
▲
by
palant
4y ago
Note : I am the author of this article. Yes, that’s what I also assume. I didn’t bother verifying however that mixed content warnings are generally not an issue with localhost in any browser that South Korea cares about (e.g. Internet cou
42.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. First of all, thank you very much for informing about this issue. I still remember reading the article you wrote back in 2007, and it really helped me navigate this situation. I doubt that peop
43.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. Yes, developing such an application would be fairly easy. From what I understand however, South Korea has laws against reverse engineering. So openly distributing this application would probabl
44.
▲
by
palant
4y ago
Disclaimer : I’m the author of this article. Quite a few people living in South Korea say exactly that: they keep an old laptop around only for online banking. And they try to avoid whatever else requires IPinside and similar applications.
45.
▲
by
palant
4y ago
Disclaimer : I’m the author of this article. As it says in the article, the application doesn’t check at all which website connects to it. It seems that they rely on their obfuscation, hoping that only eligible websites will be able to dec
46.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. Not really the same thing from what I can tell. Nitpicker is merely about isolating processes from each other, making sure keyboard input is only received by the currently focused process. Wind
47.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. Yes, default Content Security Policy of add-ons doesn’t allow eval(), and they likely couldn’t figure out how to change it. So it might be that they never even realized the security impact of t
48.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. All applications I’ve looked into so far were communicating via a local web server. It wasn’t always WebSockets, one would also see JSONP or even submitting data to a frame. They typically run
49.
▲
by
palant
4y ago
I was transferring the domain to a new provider, and the old provider decided to drop the DNS entries before the transfer was completed. Great service. :-/
50.
▲
by
palant
4y ago
Yes, statistically speaking “everyone I know” is unfortunately not a good sample. :-)
51.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. I wrote this sentence three months ago. Since then people already pointed out that mobile banking is being used as escape hatch. The question is still: how many people do this? Everyone younger
52.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. Not really. With C++, you don’t have to use manual memory management. In the typical scenario, C++ objects take care of memory without the developer having to think about it. And you have all k
53.
▲
by
palant
4y ago
Disclaimer : I’m the author of this article. Did you notice the plain HTTP (no SSL) download URLs for the “security software”? If not, you are missing out!
54.
▲
by
palant
4y ago
Yes, I’ve seen references to online gaming that also required these “security applications.” In this case it was likely to aid tracking users and to prevent cheating.
55.
▲
by
palant
4y ago
Ah, yes. Fixed. :-/
56.
▲
by
palant
4y ago
That’s in fact what I suggest in my blog post. But I am pretty certain that it is far from simple. I’m told that the previous Korean government already tried to tackle this issue and failed. It’s a huge and complicated mess.
57.
▲
by
palant
4y ago
Disclaimer : I am the author of this article. I think that this issue is really universal across all banks in Korea. I was told (but couldn’t confirm) that this is a liability question. Supposedly, there was a court ruling that held a bank
58.
▲
by
palant
4y ago
Note : I am the author of this article. Where did you get the idea that direct network access is required? To quote the article: “large applications interacting with websites in complicated ways.” Most attacks can be launched by an arbitra
59.
▲
by
palant
4y ago
The number of iterations is needed for login. The user enters their email address and password, and the app needs to know (before they actually log in) how many iterations to apply. There are approaches like the OPAQUE protocol which avoid
60.
▲
by
palant
4y ago
Disclaimer : I’m the author of this article. Yes. The number of iterations is presumably stored in the same customers database that they stole. Even if not: the number of iterations can be queried via a public API, anyone can do it if they
More ›