Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
amckenna
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
amckenna
2y ago
> "After this story published, Apple told [Kim Zetter] they just posted the instruction about the DIT to their web site yesterday [MAR 21], timed to the public release of the researchers' findings, which means that developers w
2.
▲
by
amckenna
2y ago
Kim Zetter has a great post walking through some details and commentary across a few sources, related to the vulnerability - https://www.zetter-zeroday.com/apple-chips/ > The cryptographic key itself isn’t placed in
3.
▲
by
amckenna
5y ago
I distinctly remember IV being big in the patent troll space, but I haven't seen anything recently. It looks like in the past ~8 years they have moved on or stopped for some reason.
4.
▲
by
amckenna
5y ago
I really don't understand how they can make this statement: > The report states that when the car started, security video shows the owner in the driver's seat, contradicting reports at the time of the April 17 accident that the
5.
▲
by
amckenna
6y ago
I believe the difference here is the temperature. If you look at KSTAR's operating tests you can see that they have run for 72 seconds in the past, so they must be implying 20 seconds at > 100M, or their statement about the 20s runt
6.
▲
by
amckenna
7y ago
This is where I diverge from Jimmy, as he is misinterpreting what the commenter is saying. The commenter is talking about _audit logs_ of changes to Wikipedia being kept in WORM compliant record, which is a good idea - audit logs should be
7.
▲
by
amckenna
8y ago
Here is a good example of an attack against a system secured by SMS based 2FA: https://medium.com/@CodyBrown/how-to-lose-8k-worth-of-bitcoi...
8.
▲
by
amckenna
9y ago
Exactly. The case is not alleging that Walmart is engaging in a broad conspiracy, despite what the title of the article seems to suggest. It is simply saying that the plantif was terminated when he brought up to management that there were i
9.
▲
by
amckenna
9y ago
Correct. There were several goals with the launch. The primary was successful payload insertion, the secondary goals were the successful return of the outer two boosters to land, and the central booster to a drone ship down range (success u
10.
▲
by
amckenna
9y ago
On a related note here is a proposal for a recent update to the animal emoji set. It's interesting to see the factors they consider when choosing whether or not to integrate a new emoji. I didn't know that much thought went into w
11.
▲
by
amckenna
9y ago
For not impressed I use one of these four: - https://emojipedia.org/neutral-face/ - https://emojipedia.org/expressionless-face/ - https://emojipedia.org/unamused-face/ - htt
12.
▲
by
amckenna
9y ago
This was a very helpful explanation, thank you! Does using hexagons represent the start of a paradigm shift for mapping applications or is it something that has been used for a while? This is the first I have heard of it, but based on your
13.
▲
by
amckenna
9y ago
Vitamin D is fat soluble and isn't cleared by the body as quickly as other vitamins such as B. Therefore it can be taken in higher doses, but less frequently. This is often done for convenience sake. A 3000-5000IU pill every week is ea
14.
▲
by
amckenna
9y ago
Here is some more context - http://pythonsweetness.tumblr.com/post/169166980422/the-myst... The connection between the linked article in this comment and the linked page for this post is that there is a potentiall
15.
▲
by
amckenna
9y ago
Take a few minutes to read the blog posts by the creator. Writing aside the general process and motivation around creating a custom hashing algorithm is very strange - "Curl-P was created by following the idea of simplicity. While de-j
16.
▲
by
amckenna
9y ago
IOTA's relationship with top-tier companies was more than nebulous it was intentionally deceptive. They stated they had a partnership with Microsoft's Azure, when in fact they were simply using some Azure services. I don't th
17.
▲
by
amckenna
9y ago
You could just take a different route
18.
▲
by
amckenna
9y ago
Those aren't equivalent comparisons. The issues with Ethereum have all been with regards to implementations of applications on top of the ETH layer - parity bug and DAO hack being the two biggest. Neither was due to mistakes in the und
19.
▲
by
amckenna
9y ago
Yup, that's why Dash coin has partnered with KuvaCash to help fight inflation and provide easier access to funds in Zimbabwe - https://www.dash.org/2017/11/23/KuvaCash.html It'll be an interesting t
20.
▲
by
amckenna
9y ago
Absolutely. The 24hr trading volume on gdax.com (connected to Coinbase) is 15,524 BTC (~$93,144,000) and that's just the BTC/USD market on a single exchange.
21.
▲
by
amckenna
9y ago
That may be the case with their free accounts or money earning YouTube accounts, but that is not the case for subscription based GSuite business accounts. The GSuite accounts are set up so that an offending user is a sub-account of the pare
22.
▲
by
amckenna
9y ago
That's a great idea! Does anyone know if this technique works with iOS 10? The linked blogpost is for iOS 7 and 8
23.
▲
by
amckenna
9y ago
Bingo. While there are issues with the developers and their decision making process the real issue is with the large mining conglomerates that control huge portions of the network. They have enormous influence on what changes are actually r
24.
▲
by
amckenna
9y ago
I totally agree that most web pentesters don't generally need to know how buffer overflow and binary exploitation techniques work but I think an understanding of how low level systems function and how they can be exploited is useful ac
25.
▲
by
amckenna
9y ago
Unfortunately I can't get into too much detail because I had to sign an NDA (to prevent cheating). But the process was similar to when I have found them in the wild: identify the app, install it locally, fuzz various parameters (it was
26.
▲
by
amckenna
9y ago
The author of the article doesn't represent all western views any more than you represent Turkey. However, given the fact that we have a chance to interact here (thanks Internet!) tell me/us what you would like me/us to know
27.
▲
by
amckenna
9y ago
I think the point is more that security certifications CAN be worthless and you don't NEED them, but that doesn't make them inherently bad/worthless. I think the author's argument should be that the industry has begun to
28.
▲
by
amckenna
9y ago
Don't know if you have taken it in the last year or so since they updated it, but it's pretty tough. You may be able to use a public exploit to elevate your shell once on a box, but getting code execution was the difficult part. O
29.
▲
by
amckenna
9y ago
She went through standard TSA searches - scans, pat downs, and explosive chemical swabbing. (I travel twice a month and have TSA-Pre and I still have to go through that 1/3 of the time). She was then questioned about the nature of her
30.
▲
by
amckenna
9y ago
EFF has posted guidance on this issue: https://www.eff.org/files/2017/03/09/digital-privacy-border-...
More ›