Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
semenko
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
semenko
13y ago
The HSTS commits /maybe/ suggest that Google thinks a Verisign intermediate was signing MITMs for Google properties. They just blacklisted "VeriSignClass3SSPIntermediateCA" See: https://chromiumcodereview.ap
62.
▲
by
semenko
13y ago
Sure, though there are simhash implementations, where you can compute a hash that itself can be used to compute a hamming distance between two inputs. (This is used a fair amount in search, to cluster similar documents.)
63.
▲
by
semenko
13y ago
Sure, but the Times piece /very strongly/ suggests it: http://bits.blogs.nytimes.com/2013/09/10/government-announce... (Perlroth quotes from a few unpublished, leaked memos.)
64.
▲
by
semenko
13y ago
The NYT piece today had different redactions than the Guardian, showing the NSA may have done this with commercial VPN ASICs. The Times includes "Complete enabling for [XXXXXXX] encryption chips used in Virtual Private Network and Web
65.
▲
by
semenko
13y ago
And a similar tweet: (WARNING / CRASH) https://twitter.com/daken_/status/303784082599456768
66.
▲
by
semenko
13y ago
Well, luckily, Twitter's domains & cert are added to the Chrome HSTS pins list, so Chrome should just serve a scary security error. Looks like their WHOIS data has reverted to normal. Not sure the NS records ever changed (though th
67.
▲
by
semenko
13y ago
Perhaps more critically, twimg.com (and now Twitter, it seems) has also been compromised. Both share the MelbourneIT registrar. $ whois -h whois.melbourneit.com twitter.com -> now owned by sea@sea.sy (Syrian Electronic Army) The name ser
68.
▲
by
semenko
13y ago
Reminds me of the IPv6 "Type 0" routing header disaster, where you could store data in routing loops. See, e.g. slide 30 of: http://www.secdev.org/conf/IPv6_RH_security-csw07.pdf
69.
▲
by
semenko
13y ago
They clearly mention this goal in their blog post: http://blog.wikimedia.org/2013/08/01/future-https-wikimedia-...
70.
▲
by
semenko
13y ago
(Keep in mind these slides are 5 years old, before Google Search over SSL) The NSA has clearly tapped trans-oceanic fiber -- why not also tap high-volume inter-datacenter links?
71.
▲
by
semenko
13y ago
> edit: Gmail messages must only be captured when they leave the Google network. It seems easier for the NSA to tap datacenter <-> datacenter fiber links inside Google's network. Why worry about decryption when you can have Go
72.
▲
by
semenko
13y ago
There was a lot more follow-up later, see e.g. https://lkml.org/lkml/2012/7/5/422 The important commit here is: http://git.kernel.org/cgit/linux/kernel/git/torvalds&#x
73.
▲
by
semenko
13y ago
Take a look at OwnCloud http://owncloud.org/ and BitTorrent Sync: http://labs.bittorrent.com/experiments/sync.html
74.
▲
by
semenko
14y ago
DNS aside, Name.com is one of the only registrars I know of with reasonable security practices. They support two-factor auth (almost no one else does), and have nicely scoped cookies (HTTP only, Secure flag, etc.).
75.
▲
by
semenko
14y ago
I was also looking to switch out some RV042 (tried the newer RV180 series -- terrible mistake). Finally settled on RouterBoard / MikroTik RB2011L-IN. The feature base is incredible: http://routerboard.com/RB2011L-IN
76.
▲
by
semenko
14y ago
Yeah, this piece is a little misleading. The author is referring to a nuanced difference between ethylene carbonate (EC) and propylene carbonate (PC) in the formation of a protective film around anodes. See this (paywalled) review of electr
77.
▲
by
semenko
14y ago
That may've been TTL-dependent -- though the record was only restored a minute or two ago. Educause is the EDU authoritative host.
78.
▲
by
semenko
14y ago
It's worse than that: $ whois mit.edu Domain Name: MIT.EDU Registrant: Massachusetts Institute of Technology Cambridge, MA 02139 UNITED STATES Administrative Contact: I got owned Ma
79.
▲
by
semenko
14y ago
I'd be interested to know what people were expecting from MIT (and would also like a public statement). The dockets (1) suggest MIT made the poor (perhaps incidental?) decision to involve the Secret Service, at which point the evidence beca
80.
▲
by
semenko
14y ago
Just a general plug for the Flask framework: http://flask.pocoo.org/ A lot of you are probably familiar with Flask and its awesome Jinja2 templating system. There's a well supported, officially approved extension called Frozen-Flask that
81.
▲
by
semenko
14y ago
"Now you are complaining that your hack stopped working." Just by comparison, Android supports on-device APN editing (see Settings -> More... [under Wireless and Networks] -> Mobile Networks -> Access Point Names). T-Mobile actu
82.
▲
by
semenko
14y ago
See: http://forum.xda-developers.com/showthread.php?t=1419170 The OTA was released this morning (I've flashed my unlocked Galaxy Nexus to 4.2).
83.
▲
Google Voice SMS bug: outbound texts sent from random numbers
7 points
by
semenko
14y ago
|
2 comments
84.
▲
by
semenko
14y ago
"but that's not how Google's services have ever worked." That's not totally true. A few services (Wallet, Account Activity) require you to re-authorize yourself. It's unfortunate that most Google products request "Full Account Access" (alon
85.
▲
by
semenko
14y ago
Nothing prevents genocide quite like a good mobile app #slacktivism
86.
▲
by
semenko
14y ago
Direct link to the Chromium blog post: http://blog.chromium.org/2012/10/pwnium-2-results-and-wrap-u... The commit that closes the exploit: http://src.chromium.org/viewvc/chrome?view=rev&revision=...
87.
▲
by
semenko
14y ago
Forget the 3D printer -- you can cut these by hand with a Pak-A-Punch (e.g. http://www.youtube.com/watch?v=kjhZdqCnrZA ).
88.
▲
by
semenko
14y ago
There's no good reason to suspect these are authentication chips. See, e.g. http://brockerhoff.net/blog/2012/09/23/boom-pins/ Just like Thunderbolt, the chip is most likely used to make the cable adaptive (so that all pins can be used for
89.
▲
by
semenko
14y ago
Agreed. There are a lot of other possible optimizations, from the often-mentioned buffer size settings: net.core.rmem_max / net.core.wmem_max net.ipv4.tcp_rmem / net.ipv4.tcp_wmem to metric tunings like: net.ipv4.tcp_no_metrics
90.
▲
by
semenko
14y ago
Interesting concept. The actual 404 pages look like: http://notfound-static.fwebservices.be/404/index.html
More ›