Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rainforest
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
rainforest
12y ago
I think it's slightly interesting in context of Cameron's recent comments against secure crypto and increasing surveillance. Surveillance can't prevent pretexting attacks like this, nor did crypto enable the perpetrator to ca
92.
▲
by
rainforest
12y ago
I suspect that this approach gets far more scalable with larger reserves due to transaction fees. It's probably also safer/easier to risk clients' capital than your own.
93.
▲
by
rainforest
12y ago
See also: Microsoft Code Digger [1], which generates inputs using symbolic execution for .net code, and EvoSuite, which uses a genetic algorithm to do the same for Java [2]. [1] : http://blogs.msdn.com/b/nikolait/a
94.
▲
by
rainforest
12y ago
They have a track record of trying to fingerprint and screwing with counterfeits, so it would appear there's evidence the driver doesn't happen to disable counterfeits, but actively disables them. To me there's a fuzzy distin
95.
▲
by
rainforest
12y ago
The latter. Some daemons, like CGI scripts will spawn a shell populated with environment variables from the client. With a vulnerable bash, commands in these get executed.
96.
▲
by
rainforest
12y ago
You could have the OS randomly generate a token and give it to the device and require it to repeat it each time it's plugged in. Devices without tokens or with unrecognised tokens would need user approval, those with the correct one wo
97.
▲
by
rainforest
12y ago
> maybe this medium can also be compromised. Indeed it can. Bunnie & xobs recently showed how to get code running on the controller chips of SD cards [1]. With your own implementation you could have the card present alternative files
98.
▲
by
rainforest
12y ago
That doesn't surprise me. I've seen these things (Aloha terminals) still running Windows 98. BOH was on Windows XP at least. From my experience, it's less about not having time, and more about being completely unaware of the
99.
▲
by
rainforest
12y ago
Google Location History might have something (even if you don't expect it to) [1] [1] : https://maps.google.com/locationhistory/b/0/
100.
▲
by
rainforest
12y ago
Exit nodes are already unnecessary; TOR allows you to operate services on the network itself ("hidden services"). However, it seems not everything is kept on the TOR network. I would've assumed that if someone were using TOR
101.
▲
by
rainforest
12y ago
Playing devil's advocate a little, the value in the data from an intelligence perspective is probably in the network it uncovers. If you know a circle of people are regularly exchanging encrypted messages, then you can try to target on
102.
▲
by
rainforest
12y ago
I don't think you'll get the right effect, if you cross your eyes your left eye will see the image intended for the right eye (the lenses don't focus on the opposing image). Still seems to give some sense of depth, though.
103.
▲
by
rainforest
12y ago
I like this idea as well, it seems fruitful enough that at least one organisation is providing it [0]. I would have thought overheads of getting new devices might cut into revenue though. I'd be interested to see what the difference in
104.
▲
by
rainforest
12y ago
This paper appears to claim up to 91% accuracy (precision) [1] by looking at hashtags, with a description of the approach they use (and a link to the software). The approaches probably aren't directly comparable since one depends on ha
105.
▲
by
rainforest
12y ago
See also: Wattch[1], a similar framework based on a similar idea. Wattch relies on simulation of the target rather than static analysis, however, but the application of instruction-level cost models seems the same. [1] : http://w
106.
▲
by
rainforest
12y ago
EvoSuite springs to mind for that one [1]. Java only though, but their publications describe how it works well enough to port the ideas from what I can tell. [1]: http://www.evosuite.org
107.
▲
by
rainforest
12y ago
I think Nvidia is at a point now where the CUDA toolkit is well-established that it can afford to start squeezing the people already using it. Based on my perspective (academia), universities seem to have invested heavily in CUDA, meaning a
108.
▲
by
rainforest
12y ago
It seems from the subtitle that this isn't just a known vulnerability, but one being exploited in the wild, if I'm not mistaken. Definitely a serious concern either way though.
109.
▲
by
rainforest
12y ago
In addition to KVM use couradical points out, it's also used in the Bitblaze BAP tool's TEMU component[1], which does dynamic analysis (including taint tracking) over x86 programs and kernels. [1] http://bitblaze.cs.ber
110.
▲
by
rainforest
13y ago
The article mentions the field was for a verification password; would Microsoft really admit that they'd implemented such a backdoor (a very strange one at that)? To me it seems more plausible that the verification answer was a series
111.
▲
by
rainforest
13y ago
In this case the wallet was stolen from the machine after it was rebooted into single user mode. With FDE the machine wouldn't have been usable when it was rebooted so the attack wouldn't have worked.
112.
▲
by
rainforest
13y ago
That's interesting. Do you know why content providers are OK for content to go to iOS without DRM (beyond client certificate checks) but not to Android or the desktop?
113.
▲
by
rainforest
13y ago
The iOS model uses App Store reviews (with whatever static analysis secret sauce they do), plus user permission requests for access to some things like location and contacts. I'd suggest Nokia's Symbian permission model was bett
114.
▲
by
rainforest
13y ago
Does that mean that Facebook will revoke them, or are they useless to an attacker?
115.
▲
by
rainforest
13y ago
Works with the open command from a shell too: open vnc://my_remote_mac
116.
▲
by
rainforest
13y ago
Could you elaborate on that? I would assume that most compiler steps are linear traversals of graphs and the time comes from lots of small IOs.
117.
▲
by
rainforest
13y ago
Isn't that part of the author's point? That Kurzweil is picking and choosing exponential developments because they fit his narrative? Since none of us know what the requirements of the Singularity are, it seems odd to extrapolate
118.
▲
by
rainforest
13y ago
Externally yes, but what if you can't hot swap consciousness? What if "you" remain in your body and all that happens is a clone of you is produced? Externally, both you and the clone behave identically and assert that you
119.
▲
by
rainforest
13y ago
It's worth noting that strncpy doesn't always null-terminate strings (on some platforms), so strlcpy is preferable.
120.
▲
by
rainforest
13y ago
Patrick Burns' R inferno[1] enumerates a lot of R's eccentricities and workarounds for them. I think R gets a lot better once you switch to using the libraries Hadley maintains like plyr and ggplot. I still think proficiency in R
More ›