Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
twr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
twr
10y ago
I almost wrote a zip parser. After studying the format a bit, I gave up that idea. - A valid zip does not begin with, as you would normally expect, a magic number. - A valid zip can contain arbitrary prepended data. - A valid zip can contai
32.
▲
by
twr
10y ago
Author's claim about ag7240-eth.ko seems incorrect. Running `strings` on it shows "license=Dual BSD/GPL". It's unlikely that the GPL license was chosen. Current firmware downloads contain the uboot source code. Base
33.
▲
by
twr
10y ago
Re-reading this post, I'm not sure why I typed IDA -- I meant baksmali. IDA is still useful for bundled ELF dependencies.
34.
▲
by
twr
10y ago
> Everyone else has to go with the binaries they distribute which, as the other poster has correctly argued, cannot be independently verified. Do you have reverse engineering experience on Android? APK uses the zip format. Extract its co
35.
▲
by
twr
10y ago
I think that issue highlights the problem with unofficial repositories. Users remained vulnerable because their upstream provider didn't update quickly enough. It culminated in a user spamming the official issue tracker with an outdate
36.
▲
by
twr
10y ago
Sending code to a desktop is easy to detect. Sending code to a non-web-based mobile app is easy to detect. Sending code to a browser isn't even detectable. In practice, no one audits JavaScript. If browsers offered the means to detect
37.
▲
by
twr
10y ago
> How would he notice unless he was actively watching? And what constitutes “off” the trail, anyway? If she strays off the trail for whatever reason, would she have to remember that her husband (or anyone else) might be watching and cal
38.
▲
by
twr
10y ago
> Protonmail with SRP and 2FA where a attack has to pretty tricky stuff but you still get a e2e system is far better then what we have now. Its a far more involved attack to just look at your old emails, and its easier to detect. Can y
39.
▲
by
twr
10y ago
Sure. She's dragged off the trail. Her husband notices and notifies the police. She halts during a physical confrontation. Her friend calls to check up on her, and calls the police when she can't be reached. She crashes and become
40.
▲
by
twr
10y ago
> I'm seeing in the comments that the level of trust in companies is higher than the trust in your government. Maybe that's occasionally deserved. I'm probably more paranoid about surveillance than you are. I wrote positiv
41.
▲
by
twr
10y ago
It can take many hours to surmise that someone has been kidnapped. Getting people to pay direct attention to someone's whereabouts, without having to constantly nag the person, is a huge win. Anyone who has ever expected an at-risk per
42.
▲
by
twr
10y ago
I don't need it either, but it's uncaring to imagine that millions of people don't. A young woman was abducted recently on a local trail. I don't believe she's been found yet. Perhaps this would have made some diffe
43.
▲
by
twr
10y ago
Binary packaging systems download microcode.dat (a text blob containing microcode) from Intel during the build process. Microcode.dat gets converted into an initramfs image that supplies the new microcode early in the system boot. Users dow
44.
▲
by
twr
10y ago
Intel microcode updates on Linux are provided through regular distribution repositories. There is no phoning home feature.
45.
▲
by
twr
10y ago
Whitepaper: http://www.cs.dartmouth.edu/~sergey/elfbac/bh16-elfbac-white...
46.
▲
Intra-Process Memory Protection for Applications on ARM and X86 [pdf]
(cs.dartmouth.edu)
2 points
by
twr
10y ago
|
1 comments
47.
▲
by
twr
10y ago
It's highly unlikely that the Canada Border Services Agency, of all organizations, is able to defeat competent modern crypto implementations. It's also quite unlikely that they can circumvent a basic `tar -c /dev/block&#
48.
▲
by
twr
10y ago
I succeeded at doing this to an old Asus Z68 motherboard. Steps: flashrom -p internal -r bios.rom ifdtool -x bios.rom python3 me_cleaner.py flashregion_2_intel_me.bin python2 dump_me.py flashregion_2_intel_me.bin -x python2 me_s
49.
▲
by
twr
10y ago
DNS interception usually takes place by redirecting traffic destined to port 53, like so: iptables -t mangle -A PREROUTING -p {udp,tcp} --dport 53 -j TPROXY --on-ip mitm-ip --on-port 53 Doing this isn't inherently malicious. Mos
50.
▲
by
twr
10y ago
Yes. For the record, I agree with what you wrote. Actual evidence suggests that American and European intelligence agencies knew that the justification for the war was being manufactured; Chalabi was simply a convenient scapegoat.
51.
▲
by
twr
10y ago
I assume that's in reference to Ahmed Chalabi. See, https://en.wikipedia.org/wiki/Ahmed_Chalabi https://www.amazon.com/Man-Who-Pushed-America-Extraordinary/... I haven't seen the claim p
52.
▲
by
twr
10y ago
It should be mentioned that Matthew Green linked the above blog entry in the article, so if you didn't read either post, you should.
53.
▲
by
twr
10y ago
Oops. Thanks for the correction! Looks like Windows and Mac Chrome developers are out of luck now, unless they are brave enough to try a solution listed here: https://stackoverflow.com/questions/23055651/disable-de
54.
▲
by
twr
10y ago
Chrome Dev and Chromium don't do that, however.
55.
▲
by
twr
10y ago
If malware can set arbitrary environment variables, it can also typically analyze and/or modify browser memory.
56.
▲
by
twr
10y ago
Depends on your take. Was he re-enacting the disabled reporter? Obviously not. Was he ridiculing him in a mocking caricature? For the audience, who is mostly unexposed to the subject, it seems likely. Such exaggerated mimicry is a regular o
57.
▲
by
twr
10y ago
In the first video, Mr. Trump tucks in his chin, draws back his eyelids, and adopts a "retarded" tone of voice. In the second video, Mr. Trump just moves his hands around a bit, as you say. I had not seen the first video until now
58.
▲
by
twr
10y ago
I think it's different, because Protonmail can target you, individually, at any time. Like, for example, upon receipt of a NSL. GPG is used asynchronously. In many cases, everyone would need to be compromised to go after one person. Th
59.
▲
by
twr
10y ago
GPG, when used correctly, is theoretically secure. Protonmail, like Lavabit, is insecure by design. They make no mention of this; they claim the inability to read your messages, which is trivially false. GPG has a track record of being secu
60.
▲
by
twr
10y ago
Protonmail is another crappy provider filling the void left by Lavabit. It doesn't have any additional security benefits beyond regular webmail providers that provide TLS: - Encryption is performed inside the browser. By delivering a m
More ›