Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
semenko
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
semenko
11y ago
Back when Apps for Work was "Google Apps for Your Domain", non-business/vanity use was part of the marketing. I use (paid) Google Apps for personal & family stuff - and this seems like a pretty arbitrary restriction on Pl
32.
▲
by
semenko
11y ago
Yet another service not available to Google Apps users. :/ "You can only set up a family group with a personal Google Account, not a Google for Work or Google for Education account"
33.
▲
by
semenko
11y ago
Whoops, yep -- definitely wasn't that clear. As pointed out below, the policy is linked to: https://android.googlesource.com/platform/external/sepolicy/...
34.
▲
by
semenko
11y ago
The isolation seems mostly defined by this SELinux policy: https://github.com/android/platform_system_core/blob/lollipo... service media /system/bin/mediaserver class main us
35.
▲
by
semenko
11y ago
No, it shouldn't. WPA2's 4-way handshake allows client/supplicant & access point to prove they both know the PMK without directly disclosing it: https://en.wikipedia.org/wiki/IEEE_802.11i-2004#The_Fou
36.
▲
by
semenko
11y ago
Oh hey, any chance you could explain this bit of the /usr/bin/google-chrome script I've always wondered about? (Sadly, the bug is RVG.) # Sanitize std{in,out,err} because they'll be shared with untrusted child
37.
▲
by
semenko
11y ago
Agreed -- see this never-ending Chrome bug: https://code.google.com/p/chromium/issues/detail?id=177351
38.
▲
by
semenko
11y ago
Yeah, if you really want to do this, you can use chrome.permissions with "optional_permissions" set in your manifest requesting all urls -- then call permissions.request() on invocation to add a specific host. See: https:/&#
39.
▲
by
semenko
11y ago
That granularity exists -- it's called activeTab: https://developer.chrome.com/extensions/activeTab (Though it might not be possible to modify the referer with activeTab alone :/)
40.
▲
by
semenko
11y ago
The first thing that came to mind was @agl's discussion of TLS's overhead with Gmail: https://www.imperialviolet.org/2010/06/25/overclocking-ssl.h... It's a bit hard for me to reconcile "&
41.
▲
Google launches Android for Work sandboxed enterprise environment
(googleforwork.blogspot.com)
5 points
by
semenko
12y ago
|
0 comments
42.
▲
by
semenko
12y ago
Chrome does do pinning, but ignores pins when the cert parent is a privately installed cert (because this is a "feature" used by many enterprises). """ Chrome does not perform pin validation when the certificate cha
43.
▲
by
semenko
12y ago
Details via: https://securelist.com/blog/research/67962/the-penquin-turla... Notably, the C&C domain has been sinkholed by Kaspersky. This has been linked to the complex "Turla" industrial espio
44.
▲
by
semenko
12y ago
They buried the lede a bit -- since I doubt organized attackers are after the personal information of postal service employees: "It is also possible that the Chinese were after other types of data, analysts said. For instance, the U.S.
45.
▲
by
semenko
12y ago
For Google domains, this is handled by an internal Chrome extension called "cryptotoken". See, e.g. https://chromium.googlesource.com/chromium/src.git/+/master/... For all other domains, there&
46.
▲
by
semenko
12y ago
No one has mentioned the coolest feature of U2F/Fido auth: TLS Channel IDs. Via an internal Chrome extension ("cryptotoken"), authentication state & the handshake can be bound to a specific TLS session -- preventing cooki
47.
▲
by
semenko
12y ago
Yeah, it looks like more reasonably priced U2F/FIDO tokens are coming soon, probably to the Play Store. Behind the scenes, the auth layer in Chrome is handled by a sneaky extension. There's a huge listing of product IDs in the m
48.
▲
by
semenko
12y ago
Ah, it looks like their FAQ also says this is supported: Can I use the same Security Key with multiple Google Accounts? Yes. You can register the same Security Key with multiple Google Accounts. https://support.google.
49.
▲
by
semenko
12y ago
The next release of ChromeOS will include nearby/proximity unlock features integrated with Android L, which they're calling "Easy Unlock". There are a few somewhat-spammy blog summaries, e.g. http://www.omgchr
50.
▲
by
semenko
12y ago
EDIT: Looks like this is now working! Looks like there is a tiny UI bug -- make sure your account is correctly selected on the Security Token page if you have multiple accounts signed in. #userError Ouch, looks like a serious downside is th
51.
▲
by
semenko
12y ago
Seems a little unlikely, given Ksplice's patents (now Oracle's patents) covering the area. From an older post @ https://news.ycombinator.com/item?id=2791756 The first is "Method of finding a safe time to modi
52.
▲
by
semenko
12y ago
Cool! I wrote a similar extension for Chrome that simply enforces a user-adjustable maximum cookie lifetime (e.g. 21 days instead of 10+ years...). This seems to provide a good balance for login cookies that you don't necessarily want
53.
▲
by
semenko
13y ago
ErrataSec, at least (their IPs are implicated in the logs) says this is a false-positive generated by the minimalist SSL implementation in masscan: http://blog.erratasec.com/2014/04/no-we-werent-scanning-for-...
54.
▲
by
semenko
13y ago
Surprised no one's used this opportunity to talk about Google's gnubby / FIDO / U2F plans. Non-phishable two-factor auth token: http://fidoalliance.org/ See presentation: https://docs.google.c
55.
▲
by
semenko
13y ago
They get an A from Qualys (yay?): https://www.ssllabs.com/ssltest/analyze.html?d=bing.com … but no PFS :/
56.
▲
by
semenko
13y ago
The PCB they show ( https://s3.amazonaws.com/ksr/assets/000/935/465/b197830112a2... ) … has the model number (S2122B) of the SmartQ Z3 watch, too. http://forum.xda-developers.com/showt
57.
▲
by
semenko
13y ago
IIRC, Twitter is also concerned about this, and recently proposed a hash-based validation for externally included resources (though I can't seem to find their proposal right now …).
58.
▲
by
semenko
13y ago
The co-author of the study (Ridker) and the Brigham have already issued a Press Release disputing the reporter's spin. Ridker portrays the calculator issues as minor, and offers strong support for statins in risk reduction (which is wh
59.
▲
by
semenko
13y ago
(That's his name.)
60.
▲
by
semenko
13y ago
Nothing says reassuring quite like "supports WiFi" but also "WEP only" http://www.accessdata.fda.gov/cdrh_docs/pdf8/P080009c.pdf [pg. 101, section 5-21]
More ›