Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
red0point
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
red0point
4y ago
Any idea where to get a good quality 30dBi antenna these days (for 2.4GHz or different frequencies)?
32.
▲
by
red0point
4y ago
Nice, thanks for the link. I‘m the author of AdaptOver, and I‘m in process to release a new version (paper is under submission atm) that removes the range limitations almost entirely by overshadowing the uplink instead of the downlink. It w
33.
▲
by
red0point
4y ago
The article focuses heavily on why existing solutions are bad, but doesn’t seem to propose novel detection techniques - or at least glosses a bit over the details of the detection algorithm. Would the approach be able to detect an AdaptOver
34.
▲
by
red0point
5y ago
I think the takeaway from the blog post is wrong and comments focusing on building a faster MVP miss the point. Not everything is a startup. This is a research project - and should be approached that way. There should be donors, a foundatio
35.
▲
by
red0point
5y ago
The rules implemented are very simple (taken from the patent application [1], the exact numbers are configurable). If there are <= 3 letters, one letter is bold. If there are == 4 letters, two letters are bold. If there are >
36.
▲
by
red0point
5y ago
It‘s a very cool approach, I think where it falls short is that each UE will get the same key. Much of the infrastructure around LTE & 5G is based on the assumption that noone but the operator has this key. However, since everyone has t
37.
▲
by
red0point
5y ago
They still do, since in 5G you can capture a SUCI, replace it on a later connection attempt, and observe if the phone can still attach. See [1], section 5.2.3, and it‘s implemented in [2]. Finally, localization attacks could potentially sti
38.
▲
by
red0point
5y ago
It doesn‘t need any keys, since the protocol itself is vulnerable to this. The Identity Request message that is sent is unauthenticated, but the phone replies with the IMSI nonetheless. Note that this is just one part of the attack, the att
39.
▲
by
red0point
5y ago
Keycloak is pretty standard for this. https://www.keycloak.org/
40.
▲
LTrack: Stealthy Tracking of Mobile Phones in LTE
(usenix.org)
110 points
by
red0point
5y ago
|
12 comments
41.
▲
by
red0point
5y ago
Maybe dumb to suggest, but when this happens usually the lens is dirty / a bit greasy, at least from my experience with iPhone cameras.
42.
▲
by
red0point
5y ago
I want to know what the absolute cheapest way of doing this is, without having a lot of CapEx. I thought of renting dedicated storage servers (e.g. Hetzner) and slapping Ceph on them. Do you have another, better, idea?
43.
▲
by
red0point
5y ago
As soon as you use a significant portion of it all the time, you don‘t have „1Gig internet“ to advertise anymore. Be happy to be able to provide actual 1Gbps as a best-effort to your coworking space! If I were a customer, I‘d be glad that I
44.
▲
by
red0point
5y ago
Congrats on building such a nice tool! I‘d gladly pay for something self-hosted, or some tool that allows me to download it on my own hardware. I don‘t want to solve the problem by A) paying even more money every month, much less even more
45.
▲
by
red0point
5y ago
Hi, fantastic product! It seems that you also do video transcoding - how are the limits there? I can't find explicit info alluding to video in your pricing page. Thanks!
46.
▲
by
red0point
5y ago
Does anyone know something able to do this in real-time? So it‘s able to sync, e.g. an LED light with music being played?
47.
▲
by
red0point
5y ago
This is very cool, but it seems extraordinarily cumbersome to pass on the generated super long string to another computer or mobile device.
48.
▲
by
red0point
5y ago
So what is the effect in the first part of the video on the website then? Are you saying they‘ve faked it?
49.
▲
by
red0point
5y ago
It is indeed just an extension of that very idea, developed at the same institution where design-by-contract has been introduced a few decades ago. However, instead of crashing at runtime due to a failed assertion, you get a guarantee that
50.
▲
by
red0point
5y ago
I think you’re looking at a program verification problem. With this tool: http://viper.ethz.ch/ You essentially sprinkle your functions with pre- and post conditions (& loops), press „verify“ and it will verify the corr
51.
▲
by
red0point
5y ago
Can you tell me how the limitation of the creation of read grants in luna is done?
52.
▲
by
red0point
5y ago
Sure, how can I reach you?
53.
▲
by
red0point
5y ago
Well done on that analysis. This is crazy and should be fixed by Backblaze as soon as possible. Did you publish your findings somewhere or notify Backblaze?
54.
▲
by
red0point
5y ago
You’re saying that security isn‘t black and white, but trust somehow is, which I find a bit weird, since they‘re intimately related. Backblaze could easily reduce the trust required, which they‘re not doing, but have been promising to do fo
55.
▲
by
red0point
5y ago
Of course, but it's not like other providers offer this ability already "baked in". At the same time, Backblaze only offers a security-theatre for encryption - they give you the ability to encrypt your backup private key with
56.
▲
by
red0point
5y ago
My issue with their encryption scheme is that although you can encrypt your private key before sending it to them, during restore, you still need to hand them the unencrypted private key. This feature is thus pure security theatre. You ga
57.
▲
by
red0point
5y ago
Just take a look at the egress pricing of B2 (10USD/TB) S3 (92 USD/TB) and then look at Hetzner's 1 EUR / TB. There is quite a margin there - same thing with the storage costs (23,5,1.5).
58.
▲
by
red0point
5y ago
I‘m trying to re-/sell cheap bulk object storage, by renting cheap dedicated servers (e.g. Hetzner), connect them using 10GbE and putting them into a big Ceph cluster. My problem is how to bill people for consuming object storage prope
59.
▲
by
red0point
5y ago
I think you could leverage SKIP LOCKED for this - this blog post https://www.2ndquadrant.com/en/blog/what-is-select-skip-lock... explains it nicely.
60.
▲
by
red0point
5y ago
Thanks! You mention that this is the simplest version, is there one where you use distinct keys? Also, regarding the IMEI - let‘s assume the UE nullified it, how would you distinguish between a legitimately nullified UE and a stolen UE that
More ›