Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
skolor
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
skolor
12y ago
Have we seen malware ripping keys out of memory? It seems a stretch to think that making this slightly easier to do will result in it being more widespread. What reason does malware have to do this that isn't better served by DNS Hijac
32.
▲
by
skolor
12y ago
The difference looks fairly consistent: Febuary 1995: U6 is 183% of U3. Febuary 2000: U6 is 175% of U3. Febuary 2004: 173% Febuary 2006: 155% Febuary 2007: 182% March 2008: 178% Febuary 2009: 183% March 2010: 172% Febuary 2011: 177% Febuary
33.
▲
by
skolor
12y ago
The clever part is getting the startup repair command prompt with no additional tools. Its similar to the old windows login bypasses ( https://i.imgur.com/fqjnKh.jpg ) in that it gives on more tool to use for pentesting.
34.
▲
by
skolor
12y ago
I'm a little unclear what "success" is. Does the quote just mean within 18 months 50% of employees have left the company? Surely it doesn't mean that 50% of employees are getting fired after 18 months. A median employmen
35.
▲
by
skolor
12y ago
To expand on it, its also a security thing. Having my phone with a network of personal contacts and my computer with more work related data means a separate of attack surface. At this point, if you have anything worth securing, its probably
36.
▲
by
skolor
12y ago
Even if I had a full scale performance in a cell phone with great docking capabilities, I probably would rather have a separate desktop computer for working. Just being able to compartmentalize "social stuff" on my phone, and &quo
37.
▲
by
skolor
12y ago
That could quite possibly just being taking advantage of the torrent block downloading. Normally you download blocks based on the least available, but you can pull them in any order you want. This would allow the server to selectively buffe
38.
▲
by
skolor
12y ago
> run more exit nodes (which are depereately needed -- about 1k nodes for 2M users) What is the ideal ratio of exit nodes to users? It seems that too close to 1:1 is going to be almost as bad as too few nodes, at least to my (not particu
39.
▲
by
skolor
12y ago
Looks to me like they're just using Kali. Not that surprising, for someone doing that type of work.
40.
▲
by
skolor
12y ago
Looking at it again, you're right. Its definitely from the case files.
41.
▲
by
skolor
12y ago
The way I read that was that the phpmyadmin screenshot was not supplied by the FBI, rather it came from Krebs for the purpose of demonstration.
42.
▲
by
skolor
12y ago
Really? While you can argue that the bill might not do as much as you want towards cutting back the surveillance available, 1/3 of the sitting Congresspeople cosponsored a bill to reduce the abilities of FISA/FISC [1]. It has sign
43.
▲
by
skolor
12y ago
Do you have a solution to that? It seems like an intractable problem. If you want moderated conversation, there is the potential for moderator abuse. The same is entirely possible on HN, 4chan, or any moderated forum.
44.
▲
by
skolor
12y ago
Its because the result of buying from a terrible baker is I might get food poisoning. On the other hand, a terrible taxi driver could very easily get me killed. The regulations in place don't do a huge amount to fix either of those pro
45.
▲
by
skolor
12y ago
The kind of person I can see maintaining Truecrypt for a decade I can also see making this decision. They're upset and are completely done with the project. They take down all the old versions, knowing that the licensing means they
46.
▲
by
skolor
12y ago
Considering the licensing, its likely that the developers wanted to keep development to themselves, and never turn it over to someone else. If the ragequit theory is correct, its fairly reasonable for them to remove the previous versions to
47.
▲
by
skolor
12y ago
That's a fairly trivial check to make. I would be fairly shocked to find out that people have discovered multiple sidechannel attacks against Bitlocker to leak keys out (if you have physical access to the machine while the disk is decr
48.
▲
by
skolor
12y ago
That's effectively the same thing as releasing details of the bug. It would take time to take the patch and figure out the bug from it, but it would be fairly easily done for a determined attacker.
49.
▲
by
skolor
12y ago
Consider the case where the hacker gets in and sits on a machine that processes cards for a week. With bitcoin, the only people who would lose money is Dish, the users wouldn't have any direct effect.
50.
▲
by
skolor
13y ago
> Should a prosecutor be allowed to prosecute a case if he doesn't understand the actions taken by the prosecuted? Yes. There's no reason a prosecutor needs to understand the details of exploit development in order to prosecute
51.
▲
by
skolor
13y ago
I seem to remember quite a bit of hubbub recently about how meta-data related to communication could be useful, even if you couldn't get the content of the communication. Now I see a proposal for a "Secure email", which invol
52.
▲
by
skolor
13y ago
Correct, but that doesn't make the statement of the causes for SQLi any different.
53.
▲
by
skolor
13y ago
That's exactly what defines SQLi. Incorrect filtering of user data is precisely the reason why SQLi is a vulnerability.
54.
▲
by
skolor
13y ago
Its also more dangerous in the US. Since the majority of major web apps are hosted in the US, if you're in the US it is easy for the app's owners to go after you legally. It gets much more complicated if you're in another cou
55.
▲
by
skolor
13y ago
What? Encrypt it on your system, store the encrypted blob there. Add a simple web server to host them. If you do any crypto on these servers, obviously anyone with physical access could compromise it (although potentially not without alerti
56.
▲
by
skolor
13y ago
I haven't used Firefox seriously in a while, but the shift+F4 shortcut looks fairly similarly to the Chrome developer console (F12, select the Console tab). It looks like the Firefox shell is more designed for making new pages though,
57.
▲
by
skolor
13y ago
Pay-for-security is a bad path to go down. Compare pay-for-ssl to using md5 on the lower tier for password encryption, while the upper tiers get something like bcrypt, or you only get a salted password if you pay extra. It seems pretty absu
58.
▲
by
skolor
15y ago
I searched around a little bit, since I found the lack of details somewhat disturbing. This is the best I found: http://www.seattlepi.com/news/article/Facebook-hack-lands-UK... . From the sounds of it, he broke into an employees account (l
59.
▲
by
skolor
16y ago
I'm fairly sure most people kick around ideas like this at some point or another. It would definitely be cool to give a try. It does have the problem of playability. How do you keep someone's interest beyond a week or two of this? My though
60.
▲
by
skolor
16y ago
I'm not sure how well you would get ZFS working on it with so little RAM, although it may work better on OpenSolaris. On the other hand, I've got an Intel Atom processor, running with 1gb of RAM, and it runs ZFS reasonably well on FreeBSD.
More ›