Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
HackinOut
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
HackinOut
10y ago
That is either by using the "connected version" or loosing the multi devices ability. BTW shouldn't the "connected version" be the one detailed on the home page? Sure sounds more attractive to me.
2.
▲
by
HackinOut
10y ago
I wouldn't use a password manager system that doesn't have the ability to change the master password. EDIT: You can't change any password really, without changing all of them (or having a separate master password). Seems unpr
3.
▲
by
HackinOut
10y ago
I can't believe Nigel Farage and a lot of pro Brexit campaigners have been calling it UK's "Independence day". Apart from being a very bad (purposeful?) analogy, it's seems to me pretty disrespectful to their own an
4.
▲
by
HackinOut
11y ago
Not aware of anything from Apple about this issue. It was just an assumption, sorry. What I did is test up to date devices (i think i even tested an up to date iOS 6) and couldn't get any specific SSID. The probe requests were still th
5.
▲
by
HackinOut
11y ago
It doesn't seems to be iOS 8 only. Recent versions of iOS 7 seem to be fixed as well. (Tested my phone earlier this week)
6.
▲
by
HackinOut
11y ago
My iPhone do connect auto-magically to FreeWifi_secure networks which is the preloaded SSID for the other french operator listed by Skycure. However it's supposed to connect with EAP-SIM [1]. Skycure mentions that "some of [those
7.
▲
by
HackinOut
11y ago
> (because iOS devices broadcast this when scanning for networks IIRC?) Not anymore, Apple fixed that in recent iOS versions. Probe requests are not divulging SSIDs anymore. However WifiGate uses common SSIDs and network operators preloa
8.
▲
by
HackinOut
12y ago
Good point for Apple. But I wouldn't call having your computer fixed 4 times in ~2 months lucky... Every brand seems to be having reliability problems with their products nowadays (in software as well as hardware). More than in the pas
9.
▲
by
HackinOut
12y ago
Double standards are also seen in their "Removal Instructions" post on their forum. When uninstalling SuperFish, it seems suddenly important to remove the root certificate... "It is very important to delete the certificate e
10.
▲
by
HackinOut
12y ago
Komodia, the company behind the tech contracted by the maker of SuperFish, actually (tries) to makes sure invalid and self-signed certificate do generates a warning in the browser. And then they password protect the private key with... the
11.
▲
by
HackinOut
12y ago
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-... "This article wil
12.
▲
by
HackinOut
12y ago
Wow... Now Lenovo is "soon" going to explain how to remove this certificate after the "uninstall" in a buried forum post... http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
13.
▲
by
HackinOut
12y ago
"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly." This was just edited, here is the post before that: https://web.archive.org/web
14.
▲
by
HackinOut
12y ago
Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...
15.
▲
by
HackinOut
12y ago
Except if the adware just modify OS proxy settings, like madeofpalk mentioned. Firefox does not take those into account.
16.
▲
by
HackinOut
12y ago
It does not. Firefox has it's own implementation, which is pretty great (supports all kind of proxies/socks).
17.
▲
by
HackinOut
12y ago
"Someone will extract the private key in the next few hours, and then HTTPS will be basically completely broken for all Lenovo users -- anyone will be able to spoof any site to them." Do you mean the proxy is remote? That is not
18.
▲
by
HackinOut
12y ago
TheNextWeb does a poor job at reporting technical facts: "[...] its own self-signed certificate authority which effectively allows the software to snoop on secure connections [...]" "[...] the certificate allows the softwa
19.
▲
by
HackinOut
12y ago
Before this went down, the highest recorded fold was at 987654px. Somebody had fun with the experiment or has a nice 1755K screen :)
20.
▲
by
HackinOut
12y ago
Most viruses are identified by their signature only, because most of them are dumb. Heuristics for unknown threats are often there purely for marketing. AVs have all more or less the same signature database due to the same reason as above,
21.
▲
by
HackinOut
12y ago
"Grid fins worked extremely well from hypersonic velocity to subsonic, but ran out of hydraulic fluid right before landing." "Upcoming flight already has 50% more hydraulic fluid, so should have plenty of margin for landin
22.
▲
by
HackinOut
12y ago
I would expect that even if it wasn't mentioned, I mean it's a freaking internet access in a fast moving object 30,000 feet above ground! I don't like what Gogo just did, but kudos for undertaking this challenge. barnaby ment
23.
▲
by
HackinOut
12y ago
1) They are not blocking (completely) Youtube. But still plausible. 2) Then why would they be doing it only on video streaming websites? [1] Also, if they are so obvious about their methods from now on, one nice thing is that we won'
24.
▲
by
HackinOut
12y ago
Sounds like good news. I can understand why they would choose amazon payments since amazon has more credit cards on file than anybody else including Paypal. But Amazon payments or Paypal (I am not referring to their gateway offering) is oft
25.
▲
by
HackinOut
12y ago
Back to the Future was slightly off :) I love electric vehicles of all sorts, let's enjoy them to the fullest, the hoverboard will be there soon enough.
26.
▲
by
HackinOut
12y ago
According to tweet author[1], this happened only with Youtube, and was not related to captive portal mechanism whatsoever. So I would side with her on the why: Poor plane internet access was overloaded by videos streamed from Youtube and so
27.
▲
by
HackinOut
12y ago
Well they would be facing the unforeseen consequences while not even filtering the HTTP host header (the youtube page is displayed). Unless they forgot to disable the MITM once the user is granted full internet access... EDIT: Those are
28.
▲
by
HackinOut
12y ago
it doesn't redirect to the signup page. i believe it's to throttle streaming, but there are better ways to do it https://twitter.com/__apf__/status/551132865555996673 EDIT: Still from same author: no,
29.
▲
by
HackinOut
12y ago
* asymmetric key pair
30.
▲
by
HackinOut
12y ago
I think "Phase 3" is indeed too much. I would think this tool would be more useful for "simple" MITM than for PSK phishing.
More ›