Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rightos
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
rightos
9y ago
Tor botnets are extremely common for ransomware and Bitcoin mining... however, Tor is readily blocked on some networks, so other considerations should be made - a variety of available approaches is generally the way to go.
62.
▲
by
rightos
9y ago
I'm not referring to Windows as poor for telemetry, but it's tremendously easier to get malware that takes over your whole system on Windows than any other platform - consider the fact that downloading and running unsigned executa
63.
▲
by
rightos
9y ago
That's pretty ridiculous, we're talking about credit card purchases here, which can be trivially charged back, not bitcoin private keys... if you've worked with sensitive info on a Windows box though, that's probably a m
64.
▲
by
rightos
9y ago
> However it makes even me nerveous to use a banking application or similar on an Android. Can’t imagine what kind of shit my dad would have running on an Android device with all the fake fishing apps, bloatware, tracking etc going aroun
65.
▲
by
rightos
9y ago
There are a number of "socially responsible" ETFs with quite low fees - not as low, but not bad. Most focus on environmental goals, though some have worker rights, "biblical values" or equality goals too, some also seek
66.
▲
by
rightos
9y ago
I'm not suggesting a first party would do it, but say a platform akin to Pebble, Apple Watch or Android Wear were to enable an app like that to be developed. What part would be illegal then - the device itself? The app? The app store?
67.
▲
by
rightos
9y ago
Couldn't this simply be done in after market installable software on a general purpose smart watch?
68.
▲
by
rightos
9y ago
That study if I recall correctly completely misses the spillover to other websites, considering only reddit itself - but bans on sites like reddit and Twitter have lead to the rise of sites like Gab, 8chan and Voat in recent years. The spil
69.
▲
by
rightos
9y ago
That FAQ seems fairly vague - what I'm looking for is simply how connections are established - can I simply point the thing at another copy of VSCode running in my LAN? Or do I have to involve Microsoft servers on the internet for sess
70.
▲
by
rightos
9y ago
There's no root builtin, use Magisk with the Hide feature to prevent it from being detected by banking apps and such - even apps using the rather nasty SafetyNet work. With that said, I highly question why any banking app would check r
71.
▲
by
rightos
9y ago
By your own description, doesn't that make it a great model in "99%" of cases? If you outgrow it, sure, but your odds of a small business or little WordPress blog outgrowing such a thing are quite small. Paying more might not
72.
▲
by
rightos
9y ago
> So in other words "yes, that is a requirement that will eventually be on all android phones"? Am I misunderstanding something? Older phones being an exception does me little good going forward. To date it means that it's
73.
▲
by
rightos
9y ago
Those running the popular ESP8266 and ESP32 boards for various IoT devices: a fix has been published for the RTOS running on those boards. If you're building devices on these platforms, try to get this out to your customers as soon as
74.
▲
by
rightos
9y ago
SafetyNet doesn't actually detect custom ROMs, a stock LineageOS will pass it on most devices at least. It attempts to detect root or modifications to the ROM by malicious software. Certain newer devices have secure boot attestation th
75.
▲
by
rightos
9y ago
Ah yes, I see now that the patch is actually to wpa_supplicant. Well, hopefully this means no kernel patch will be needed.
76.
▲
by
rightos
9y ago
Does this resolve the issue on the AP side of things? Could I theoretically have an AP update that would resolve this with no need to update clients?
77.
▲
by
rightos
9y ago
Sniff the apps, uninstall if they don't, it's just plain unacceptable at this point. If there's something you really need that doesn't, set up a VPN.
78.
▲
by
rightos
9y ago
Not really - ultimately they're root, Google SafetyNet isn't, it has to run at the application level. Meaning Magisk will always win until remote attestation is enforced. There hasn't been a breaking update since July if I re
79.
▲
by
rightos
9y ago
Yeah, it fully replaces the whole version control tool.
80.
▲
by
rightos
9y ago
Look through the list yourself, but at least on my device, most of those kernel security issues aren't really of significant impact as apps don't have access to the APIs needed to trigger them and they're not remotely exploit
81.
▲
by
rightos
9y ago
Didn't you get the memo? If you stamp enough buzzwords on everything, it magically works, regardless of their relevance to the application.
82.
▲
by
rightos
9y ago
> We need issues, pull requests, comments, milestones, wiki, etc... all to be decentralized. No reason this stuff cannot be modeled using existing Git objects. https://www.fossil-scm.org/ pretty much does this.
83.
▲
by
rightos
9y ago
That's a very left-wing view of things - I don't necessarily disagree with it, but I think there are far less drastic changes that can be made to achieve a comparable result. You'll have a hard time selling a plan like that t
84.
▲
by
rightos
9y ago
Seems like a reasonable idea to me, has anyone attempted to apply some of the less controversial possible solutions here in the US? Like shorter patent lifetimes or a ban or reduction on drug advertising?
85.
▲
by
rightos
9y ago
It's a difficult balance to strike - you want the companies to keep developing drugs, you want onerous regulation on those drugs to make sure they're produced and tested for safety and efficacy. But then you want them to be cheap
86.
▲
by
rightos
9y ago
> weakened crypto that will be the demise of your Android rather than exotic exploits of your wifi. I don't think there's any truth to this - if the crypto were weakened you'd see it broken by that quite quickly - but it&#
87.
▲
by
rightos
9y ago
There's also a relatively low attack value and attack surface for encrypted Android phones vs encrypted iPhones. Everyone who runs an iPhone has it encrypted, while relatively few people running Android devices have them encrypted. In
88.
▲
by
rightos
9y ago
I'm referring to remote kernel exploits - things that would introduce a new attack vector. Say a bug in a say a network driver or protocol that would already be at ring0 - SELinux does not prevent such an attack. Something that would a
89.
▲
by
rightos
9y ago
That's pretty sweet, if I had to manage my own VMs I'd definitely look into SELinux for that feature. I can see an argument for a defense in depth approach here, but if there's only one service per VM and that service is alre
90.
▲
by
rightos
9y ago
> Instead of a locked-down server exposing a public key-only SSH port, you suddenly have a whole web application stack in there. There's no webapp stack to attack if you're only able to access it via a tunnel. If you're as
More ›