Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
crunchatized
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
crunchatized
4y ago
> to obscure cash flows, something which is specifically illegal. It's only illegal under 18 U.S. Code § 1956 to conduct transactions to obscure the source of "the proceeds of some form of unlawful activity." There'
2.
▲
by
crunchatized
4y ago
The phrase 'according to the treasury' and Ctrl-V are doing a lot of work there. The government says a lot of things. The other day the Secretary of State claimed Tornado Cash was a DPRK sponsored hacking group before deleting the
3.
▲
Why Is It Taking So Long to Secure Internet Routing? (2014)
(queue.acm.org)
2 points
by
crunchatized
5y ago
|
0 comments
4.
▲
by
crunchatized
5y ago
Let's Encrypt is the lone, singular CA that actually already had a defense against this attack. > In multiple vantage point verification, a CA performs domain control validation from many vantage points spread throughout the Intern
5.
▲
by
crunchatized
7y ago
> but see for a less hysterical writeup) See where? Did you miss including another link here?
6.
▲
by
crunchatized
7y ago
It's true, as worded, it doesn't make any sense. What would make sense is that in August 2017, Rohrabacher wanted to strike a deal for actual, solid evidence that would debunk the idea that the Russian government hacked the DNC (a
7.
▲
by
crunchatized
7y ago
Maybe, but this doesn't appear to be an actual example of brazen Trump corruption. The journalist's summary of the lawyer's summary of the ex-congressman's statement appears to be inaccurate to the point of being fake ne
8.
▲
by
crunchatized
7y ago
It's true, the Mueller report is light on actual evidence and in places rather heavy on hedging language. But it seems not an unreasonable guess in this case that there was possible use of "WikiLeaks's private communication s
9.
▲
by
crunchatized
7y ago
The evidence is so comprehensive, and yet we can't see it. Pages 36 to 51 of volume one of the Mueller report concern the hacking and dissemination of DNC emails. It has many detailed claims and conclusions, but what's notably mis
10.
▲
by
crunchatized
7y ago
Yeah, Comey did say in 2017 that they could only get CrowdStrike to hand over their analysis, and never got direct access to the machines. https://www.washingtonpost.com/news/post-politics/wp/2017/03...
11.
▲
by
crunchatized
7y ago
Of all the things that aren't evidence, an indictment is possibly among the most not-evidence things. A judge famously said you could indict a ham sandwich. In practice, grand juries say whatever a prosecutor wants them to say. And as
12.
▲
by
crunchatized
7y ago
The Ars article is at least very transparent about its conclusions and what evidence they're based on. https://arstechnica.com/information-technology/2016/06/gucci... "We still don't know who h
13.
▲
by
crunchatized
7y ago
> a witness statement by former U.S. Republican congressman Dana Rohrabacher who had visited Assange in 2017, saying that he had been sent by the president to offer a pardon. > The pardon would come on the condition that Assange compl
14.
▲
by
crunchatized
7y ago
Rohrabacher visited Assange in August 2017, when this offer supposedly took place. [1] Assange wasn't placed in solitary confinement, a form of torture, until 2019, after he was arrested by UK authorities. Of course in 2017, he was bei
15.
▲
by
crunchatized
8y ago
Right, there's a good security reason they have the registration step. Though I don't think what you described is quite how it works. The FIDO and CTAP protocols don't let the Relying Party provide any entropy to the authenti
16.
▲
by
crunchatized
8y ago
I mean, you can. But the heavily flawed PKI is rapidly improving from the dumpster fire it has been. The glaring 'blindly trust every CA to never go rogue' problem is on the edge of being solved, with browsers beginning to require
17.
▲
by
crunchatized
8y ago
It doesn't say that IANA defined it to not have HTTPS anywhere at all.
18.
▲
by
crunchatized
8y ago
> using IP's to try to figure out what site is what doesn't work. Every mainstream browser sends the server's domain name in plaintext at the start of the TLS connection,[0] so (short of domain-fronting, which browsers don
19.
▲
by
crunchatized
8y ago
? https://www.example.com/ It's had HTTPS since at least 2014. [0] [0] https://crt.sh/?id=5857507
20.
▲
by
crunchatized
8y ago
All 3 of the concerns GP listed are completely agnostic to the topic of the web page or the behavior of its audience. It's not your fellow webpage visitors or community that are most likely to be in a position in the network to be doin
21.
▲
by
crunchatized
8y ago
Serious question, is it your contention that no lawyer has ever lost a case defending an innocent person, in the entire history of the bar association, because that's just impossible? Cuz the vast majority of these were not plea bargai
22.
▲
by
crunchatized
8y ago
Critics of the criminal justice system have been railing against the utterly lopsided plea bargaining system, among many other CJ issues that all serve to prop up the others. Some cursory googling turns up: https://www.jstor.org&
23.
▲
by
crunchatized
8y ago
People's inability to afford bail isn't an argument for plea bargains, that's an argument for letting people go on their own recognizance and abolishing cash bail, instead of keeping half a million unconvicted people in Ameri
24.
▲
by
crunchatized
8y ago
Relevant chart? https://en.wikipedia.org/wiki/Nolan_Chart Alternatively, https://xkcd.com/868/
25.
▲
by
crunchatized
8y ago
I'd have to see this scattered polling, but this really seems like a claim somewhere between "Catholics who say they don't believe in transubstantiation," and "self-identified Scots not from Scotland," consider
26.
▲
by
crunchatized
8y ago
There doesn't technically have to be a way to register new sites. There is, but theoretically there never actually had to be, given keys are generated deterministically on-demand, using the website's domain name effectively as a s
27.
▲
by
crunchatized
8y ago
Given the justification for plea deals is the crowded dockets, alternatively, you could talk to your representatives to reform the laws so fewer acts are crimes that get people arrested in the first place. Also alternatively, instead of usi
28.
▲
by
crunchatized
8y ago
Nothing mandates it. In fact, it's specifically discouraged in the WebAuthn spec: > Authenticators may implement a global signature counter, i.e., on a per-authenticator basis, but this is less privacy-friendly for users. Since you
29.
▲
by
crunchatized
8y ago
It's not that kind of nonce. It's not even called that formally, it's called the 'signature counter.' It's just a part of the plaintext signed with the keypair. There is zero risk of what you're talking ab
30.
▲
by
crunchatized
8y ago
What contradiction? It just plain isn't part of the threat model. Was that not clear? Although, actually reading the spec, it can actually double as a bit of extra authenticator of the website. Any site has to first request registrati
More ›