Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
EricButler
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
EricButler
15y ago
It's difficult to keep track of all the various branches, is there a reason you haven't transferred the project to someone who can create a new proper release, update the website, etc?
32.
▲
by
EricButler
15y ago
Seattle, WA Übermind ( http://www.ubermind.com/ ) Hiring Android, iOS, UI/UX, and QA engineers. QA intern positions also open. See http://www.ubermind.com/#!/careers
33.
▲
by
EricButler
15y ago
Yep this is correct. See the note about "exclusion" on http://www.imperialviolet.org/2010/08/16/dnssectls.html
34.
▲
by
EricButler
16y ago
Dropbox's website was vulnerable to passive session hijacking until they took note of Firesheep and fixed it. Both this and the mobile issues would have been identified on the first day of a security audit by even someone with little experi
35.
▲
by
EricButler
16y ago
One of Nokia's problems has been lack of focus. I am a huge fan of Qt so I hate to say it, but keeping Qt, MeeGo, and especially Symbian alive (even with reduced investment) makes it sound like this problem has only gotten worse now that WP
36.
▲
by
EricButler
16y ago
For now, but support for Mifare Classic is a high priority.
37.
▲
by
EricButler
16y ago
Thank you! Although probably not as interesting, it would be great to add Mifare Classic support to FareBot, if you're looking for stuff to work on.
38.
▲
by
EricButler
16y ago
Thanks! Many RFID cards are basically tiny computers with each with a proprietary command protocol, so you can't read everything generically. MIFARE DESFire cards (ORCA, Clipper, newer Oyster) for example have a command protocol and basic f
39.
▲
FareBot: Read data from public transit cards w/ your NFC-equipped Android phone
(codebutler.com)
102 points
by
EricButler
16y ago
|
17 comments
40.
▲
by
EricButler
16y ago
As a commenter mentioned above, the weak point here is the fact that you only enforce HTTPS after the user has logged in. Since your login page is served insecurely, an active attacker could modify it to steal passwords. A well known tool t
41.
▲
by
EricButler
16y ago
I posted my thoughts on FireShepherd to my blog here: http://codebutler.com/firesheep-a-week-later-idiot-shepherds
42.
▲
by
EricButler
16y ago
While sites wait for services such as adsense to support SSL, adding a second Secure cookie and requiring on sensitive pages and to perform destructive actions can help reduce risk to users. Depending on the site, it may be OK to skip showi
43.
▲
by
EricButler
16y ago
Logging into insecure sites over Tor is probably not a good idea. It's always good to assume that people running exit nodes are not the most trustworthy. HTTPS Everywhere is good but only works on known sites (and known domains for those si
44.
▲
by
EricButler
16y ago
The script kiddies already have their scripts and already do this. Firesheep will hopefully allow users to see the problem in a way they can clearly understand.
45.
▲
by
EricButler
16y ago
When Gmail switched on SSL for everyone earlier this year they added "no additional machines" ( http://unblog.pidster.com/imperialviolet-overclocking-ssl ). Regarding IPs, there's a bigger issue here. People are used to being able to shut t
46.
▲
by
EricButler
16y ago
Wireshark is a very popular open-source tool. http://www.wireshark.org/
47.
▲
by
EricButler
16y ago
Oh, you just need to update to the latest version of Firefox (3.6.11). Your version is out of date and not secure. http://www.mozilla.org/security/known-vulnerabilities/firefo...
48.
▲
by
EricButler
16y ago
Thanks! If you or anyone has any problems, email me (eric@codebutler.com) with the details.
49.
▲
by
EricButler
16y ago
What was the error?
50.
▲
by
EricButler
16y ago
Foursquare doesn't support SSL at all. The best you can do is request a long-lived OAuth token, but even doing that requires sending the user's email/password in plaintext (although only once!).
51.
▲
by
EricButler
16y ago
Two great resources about urban livability for HNers in Seattle: Seattle Transit Blog ( http://seattletransitblog.com/ ) HugeAssCity ( http://www.publicola.net/category/column/hugeasscity/ )
52.
▲
by
EricButler
16y ago
When exactly is an earthquake not "unexpected"?
53.
▲
by
EricButler
16y ago
An app I wrote called FoursquareX ( http://codebutler.github.com/foursquarex/ ) uses the OSX CoreLocation API (Skyhook) for geolocation. Here in Seattle it's amazingly (and somewhat horrifyingly) accurate. As far as I know, Safari uses the
54.
▲
by
EricButler
16y ago
I don't like flash on the web, but I do occasionally run across a site that requires flash for navigation. I thought an extension would be interesting. Also, I have an ad blocker.
55.
▲
by
EricButler
16y ago
Very cool. I look forward to a Chrome extension that automatically replaces flash objects with this.
56.
▲
by
EricButler
16y ago
Thank you for the "Chrome to Phone" link, I wasn't sure this was available yet! I tried it, and it works instantly here.
57.
▲
by
EricButler
16y ago
I had not seen this, but it looks very cool! Thanks for the link! Curious, how did you find out about them?
58.
▲
by
EricButler
16y ago
Lately I've been trying to find a low cost (<$50) Linux device to use in a project. My only requirements are Wifi, USB (host), and a small form factor. Don't need a lot of ram/flash/etc or any video output. I've been really surprised by
59.
▲
by
EricButler
16y ago
All product demo videos should include a confused baby.
60.
▲
by
EricButler
17y ago
Not only that, but many people's default usernames included the last four of their social, if not the entire thing!
More ›