Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
startling
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
startling
10y ago
if someone has physical access to your computer with secure documents present, and then you use it again , it's game over.
62.
▲
by
startling
10y ago
1) dl.sta.li is not on my site, and probably not on yours. 2) That's still suboptimal. You're giving each host on your LAN the ability to interfere with any newly-provisioned server. This is a perfect and hard-to-detect way for an
63.
▲
by
startling
10y ago
The stali source includes, among other things: * a full checkout of libressl: http://git.sta.li/src/tree/lib/libressl * a full checkout of expat: http://git.sta.li/src/tree/lib/
64.
▲
by
startling
10y ago
> Installation uses HTTP to fetch a boot volume image. This is a problem with all of the suckless software and it, well, sucks.
65.
▲
by
startling
10y ago
No, I mean that even if you add additional layers of sandboxing, the chrome process can still access the X socket. A process with the ability to read and write to the X socket can record keypresses, issue mouse and key events, etc etc. (The
66.
▲
by
startling
10y ago
My landlord already had it installed when I moved in, but yes, I can talk to the person at the door and press 9 to buzz them in.
67.
▲
by
startling
10y ago
All of that is only marginally helpful without X sandboxing.
68.
▲
by
startling
10y ago
Do you install firebug?
69.
▲
by
startling
10y ago
I've never seen that, but maybe I've never seen an answer by an actual google employee. :/
70.
▲
by
startling
10y ago
Manual analysis to mock out the anti-vm checks.
71.
▲
by
startling
10y ago
My apartment door buzzer calls my phone. Generally they don't even attempt to buzz me , and then make me pick it up on the other side of the city.
72.
▲
by
startling
10y ago
I think she may be a Google employee. Google's product / support forums are always like this, it's terrible.
73.
▲
by
startling
10y ago
The game jam is over, and so is dead.
74.
▲
by
startling
10y ago
Maybe it helps to reword "this kind of evidence is unethical" as "taking action on this kind of evidence alone causes social harm"?
75.
▲
by
startling
10y ago
"may have" = "is likely to have", "may not have" = "is not likely to have".
76.
▲
by
startling
10y ago
Assuming Let's Encrypt knows more about its sustainability than you do, and given that they can also invest their money in index funds if they believe it's the right approach, isn't giving the money to them outright just bett
77.
▲
by
startling
10y ago
If Let's Encrypt believes that's the best way to spend their money, they'll do that. Do you think you've thought more about their sustainability than they have?
78.
▲
by
startling
10y ago
I'm confused about this too. Maybe they believe systemd was adopted for performance, and JITing bash would mitigate performance concerns? I really doubt that run-once startup scripts would benefit from JITing, though. And memory overhe
79.
▲
by
startling
10y ago
those things aren't equivalent, at all.
80.
▲
by
startling
10y ago
Fortunately the only people who can read 1000-page documents are those who already have working PDF renderers, so the problem is self-limiting.
81.
▲
by
startling
10y ago
If you're not using https, you have no idea if your ISP, or someone e.g. sitting in your cafe, is attacking you.
82.
▲
by
startling
10y ago
The second bit of the exploit chain, CVE-2016-4655, leads to disclosure of kernel memory addresses. Once a single memory address is known, you can calculate the random offset of the kernel, and then exploit the third part to overwrite the r
83.
▲
by
startling
10y ago
Sure, but you shouldn't continue using the system.
84.
▲
by
startling
10y ago
It's only marginally helpful: it doesn't actually prevent attackers from uploading code to your server. Instead of having 'nc -l 8080 | bash' or whatever as your payload, an attacker can just run code instead. "pwd
85.
▲
by
startling
10y ago
This is totally wrong. Once you have RCE, you can upload code the same way you're executing code.
86.
▲
by
startling
10y ago
(From the lookout paper): "In order to maintain its ability to run, communicate, and monitor its own status, the software disable's the phone's 'Deep Sleep' functionality."
87.
▲
by
startling
10y ago
There are. "(Kernel) address space layout randomization" is one of them. It was circumvented here; that's part of why this is impressive.
88.
▲
by
startling
10y ago
Error messages, for one.
89.
▲
by
startling
10y ago
Because you are designing hardware with certain requirements that may not be fully met by a consumer device.
90.
▲
by
startling
10y ago
Find the fingerprint on their website / business card / Twitter / Keybase, download the full key from the keyserver. Anyone can upload any key to a keyserver with any name.
More ›