Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
theEXTORTCIST
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
theEXTORTCIST
9y ago
from the article "Two other groups are also launching tech start-ups to help victims share their experiences." "One group of women has already founded a start-up, BetterBrave, that aims to be an online hub for female workers
32.
▲
by
theEXTORTCIST
9y ago
the attacker MITM TLS has to present a certificate for the spoofed domain that was signed by a Certificate Authority the victim's browser trusts
33.
▲
by
theEXTORTCIST
9y ago
When talking HTTPS it's important to note that the protocol uses both asymmetric and symmetric key encryption. Asymmetric key exchange for secure session setup / authentication Symmetric key for secure session data encryption htt
34.
▲
by
theEXTORTCIST
9y ago
From the PDF: "Bitrot will burn libraries with merciless indignity that even Pets Dot Com didn’t deserve. Please mirror don’t merely link! pocorgtfo15.pdf and our other issues far and wide, so our articles can help fight the coming fla
35.
▲
by
theEXTORTCIST
9y ago
I believe you are correct in your understanding. Mine was a little different. I thought this was a classic asymmetrical routing scenario on the Internet with a cool eavesdropper twist. I'm assuming that because the sat system broadcast
36.
▲
by
theEXTORTCIST
9y ago
AFAIK HSTS doesn't break TLS MITM. A valid x509 certificate is generated by the attacker (using a Certificate Authority trusted by the victim's browser) for the domain the victim is visiting and all is well for both TLS sessions (
37.
▲
by
theEXTORTCIST
10y ago
obligatory 33s video: https://www.youtube.com/watch?v=z9GbUCQhIfA Dave from trustedsec/Derbycon opens a sensor locked door (it led to a staff area) at the hotel marriott with a nicotine vaporizor