Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
willstrafach
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
willstrafach
8y ago
It is totally awesome that you are not doing anything creepy, but I hope you can understand that some folks are going to be more wary nowadays and that is not a bad thing IMO.
92.
▲
by
willstrafach
8y ago
The firms would then have a much harder time knowing if the information is genuinely from end users, if they no longer collect directly from user devices.
93.
▲
by
willstrafach
8y ago
Ours (guardianapp) does exactly this as well, although exclusively for iOS. We are using the data we glean from the static + runtime analysis for an upcoming mobile firewall app but are open to other interesting opportunities. Please feel f
94.
▲
by
willstrafach
8y ago
A lot of work went into rooting out these trackers, what data they sent, and what apps they were in. We used a combination of static code analysis for each, runtime analysis (eg. Corellium), and network packet capture/analysis. The goo
95.
▲
by
willstrafach
8y ago
No, it does not.
96.
▲
by
willstrafach
8y ago
> Using API's available to a normal sandboxed app, the source port is mapped with the process ID, then mapped to the package identifier, and then Facebook knows how much data is being used by which apps. This is just not true at all
97.
▲
by
willstrafach
8y ago
What do you believe the “problem” is, exactly? What will it be “too late” for?
98.
▲
by
willstrafach
8y ago
That is a major accusation, can you provide source(s) to read more about this claim? It is at odds with known cases, such as the fight with Apple over iPhone encryption.
99.
▲
by
willstrafach
8y ago
They could just set a low TTL
100.
▲
by
willstrafach
8y ago
Corellium can run up to iPhone X, and certainly can run iOS 12 (Option is given for jailbroken or not jailbroken too). Only limit which you may be thinking of is that it only supports 64-bit ARM, so no emulation of the older devices.
101.
▲
by
willstrafach
8y ago
This is likely because his modified BlackBerry was a one-off project suited to his security requirements. My understanding is that internal hardware was removed/shielded, and I assume software modifications were made as well, like only
102.
▲
by
willstrafach
8y ago
This approach mitigates the class of vulnerability, neutering the effect of this one and any similar future vulnerabilities. This approach makes sense, since they do not know what this specific vulnerability is.
103.
▲
by
willstrafach
8y ago
This is correct, and not often understood.
104.
▲
by
willstrafach
8y ago
I doubt that. Card companies surely make good money on interest, but there is risk baked into that. A customer paying off their full balance means little risk yet they still make the 1-3% processing fee.
105.
▲
by
willstrafach
8y ago
Fraud protection is not really “provided” by anyone, it is simply a reversal of the charge, leaving the affected merchant holding the bag.
106.
▲
by
willstrafach
8y ago
This is not a mystery. It is a new iPhone device. The original reporting greatly misinterpreted some technical information and assumed the device to be something else.
107.
▲
by
willstrafach
8y ago
These appear to be in app ads. Not injected into actual browsing activity.
108.
▲
by
willstrafach
8y ago
> For PH it makes sense due to them already have infra to support it especially video streaming It is not their infrastructure. They appear to be using this white-label service according to code in the app (verified by looking at network
109.
▲
by
willstrafach
8y ago
Looking at source materials, it is not hard to see what they are doing. They have radome’s to obfuscate where their dishes are pointed, and use them to collect signals that pass through the Chinese and other satellites they can see. They ap
110.
▲
by
willstrafach
8y ago
> though I do remember reading a while back that "someone" managed to steal the list from sim card manufacturers on more than one occasion. To avoid getting folks too worried about it being a widespread issue, this occurred for
111.
▲
by
willstrafach
8y ago
I do not know this and many others probably do not. Would be great to see a source with proof that this has happened with PIA.
112.
▲
by
willstrafach
8y ago
You are referring to the command used to request where to route an SMS message, I assume? If so, carriers can (and have been albeit very slowly) restrict this activity so it is less of a free-for-all. That said, it seems they are intentiona
113.
▲
by
willstrafach
8y ago
> Corporate Big Brother can only make money from me. reply Equifax is a private corporation yet can do more harm than just making money, with little accountability.
114.
▲
by
willstrafach
8y ago
> Of course in reality, it goes to the Parallel Construction Department Not the case. US Person Information cannot be queried. You are referring to a practice used against foreign targets to obfuscate methods of surveillance (Reasonable
115.
▲
by
willstrafach
8y ago
No, that is an entirely different matter regarding far more precise location information.
116.
▲
by
willstrafach
8y ago
> btw, apple and google ad spyware process (google play service) will collect gps and wifi data without any user visible UI, not to mention download ads in the background. Would be nice to see actual proof of this. I am very familiar wit
117.
▲
by
willstrafach
8y ago
I work in infosec as well. I think you are conflating two very different things, even if both technically involve monitoring/filtering/logging/etc. The SOC at some company will use monitoring to combat threats, and will not h
118.
▲
by
willstrafach
8y ago
Some marketers perform lookups to remove inactive / non-cellular numbers from their lists in order to save on costs/time. I believe Google Fi and Google Voice are marked as VoIP in these lookups.
119.
▲
by
willstrafach
8y ago
If by vodka you mean unwanted data collection, that sounds pretty great.
120.
▲
by
willstrafach
8y ago
Your contacts example is great. I recall a company who initially offered a contact list backup app, and now they pivoted to phone number search / caller ID app.
More ›