Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
csoghoian
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
csoghoian
3y ago
The successor to Do Not Track is the Global Privacy Control, which companies are required to respect in several states, including California and Colorado. Support for GPC is already built into Firefox and Brave, but must be enabled in the p
2.
▲
by
csoghoian
5y ago
The Open Technology Fund provides free security audits for open source projects. Apply here: https://apply.opentech.fund/red-team-lab/
3.
▲
by
csoghoian
10y ago
DHS is a law enforcement agency, which regularly uses surveillance techniques, some of which exploit security flaws in devices and software. When you share information about security flaws with DHS, you're sharing them with ICE and the
4.
▲
by
csoghoian
10y ago
So you didn't tell the Federal Trade Commission, even though they previously investigated (and punished) HTC for doing something similar?
5.
▲
by
csoghoian
10y ago
This seems very similar (or perhaps even worse) than the fact pattern in the HTC/Carrier IQ case. https://www.ftc.gov/news-events/blogs/business-blog/2013/02/... Did you provide the Federal Tra
6.
▲
by
csoghoian
10y ago
I think that some webcam indicator lights are vulnerable to remote disabling. Although it is certainly possible that some are not, I and most other users have no way of knowing which lights are reliable, and which ones are vulnerable. As
7.
▲
by
csoghoian
10y ago
1. My employer, the ACLU, filed two comments in the Rule 41 process. The first, before public comments were even solicited, resulted in DOJ dropping one of their proposed changes to rule 41, which would have permitted the gov to piggyback f
8.
▲
by
csoghoian
10y ago
I've researched this issue extensively, and I've not found a case before where a thousand people in the same place were searched pursuant to a single search warrant, let alone a thousand people or items located in different places
9.
▲
by
csoghoian
10y ago
The FBI has been using malware since at least 2003 [1], probably a few years before that. Today, the FBI has a dedicated team, the Remote Operations Unit, based out of Quantico, which does nothing but hack into the computers and mobile phon
10.
▲
by
csoghoian
10y ago
This isn't just about the district where the judge is based. There is also the bigger question of whether or not judges should be authorizing bulk hacking operations. The three Tor watering hole operations (Freedom Hosting, Torpedo and
11.
▲
by
csoghoian
10y ago
Pay an award booking service to find you the best flights possible. There are several out there, and they know a lot more than you about how to find obscure flights/routing. it's worth the $150.
12.
▲
by
csoghoian
10y ago
Actually, weev neither wrote the script nor ran it. Those were done by his codefendant. Weev took the data provided to him by his codefendant and gave it to Gawker.
13.
▲
by
csoghoian
11y ago
The Federal Trade Commission is an independent agency. They don't take orders from the President. (I know, because I worked there for a year)
14.
▲
by
csoghoian
12y ago
You might want to look at this: https://dnshistory.org/dns-records/mail.clintonemail.com http://whois.arin.net/rest/net/NET-24-187-234-184-1/pft
15.
▲
by
csoghoian
12y ago
You say "Redphone? Whisper? and various other projects - while very cool - didn't achieve even as much popularity as GnuPG" The Axolotl protocol that was created for Whisper System's TextSecure is now used, by default, b
16.
▲
by
csoghoian
12y ago
I pitch stories regularly to reporters. Dan is by far one of the best reporters in the business, and is the person I go to whenever I have something that is interesting, but far too technical for the mainstream press. He always does an exce
17.
▲
by
csoghoian
12y ago
The US Marshals are not the only federal law enforcement agency doing something like this. According to documents I obtained through a FOIA in 2012, ICE has purchased an airbourne mounting kit and paid for airbourne training for their Sting
18.
▲
by
csoghoian
13y ago
As one of the complainers (and the person who filed the bug you linked to), I'm happy to see Google make some progress here. I'm even happier to see that they hired Adrienne Felt, who is excellent, and are letting her improve the
19.
▲
by
csoghoian
13y ago
Why wouldn't the FBI or NSA just demand the encryption keys and then sign their malware?
20.
▲
by
csoghoian
13y ago
The government obtained a 2703(d) order for the stored non-content data of a particular user (suspected to be Snowden, but redacted from the court documents). They then obtained a pen register order, for real-time metadata about that same u
21.
▲
by
csoghoian
13y ago
Yahoo still doesn't use HTTPS by default, for email or search. Not using HTTPS is huge, gift-wrapped present to the NSA. It also means that the NSA can get Yahoo users' communications without even having to bother Yahoo, as they c
22.
▲
by
csoghoian
13y ago
Having worked at the FTC for a year in the team that goes after companies for violating consumers' privacy, I can comfortably say that you are 100% right on that point. The FTC (unfortunately) does not police deceptive statements about
23.
▲
by
csoghoian
13y ago
If Syrian rebels aren't using computers, why would pro-government forces bother to send them malware? See: https://www.eff.org/deeplinks/2012/12/iinternet-back-in-syri... Your unsupported claim that the
24.
▲
by
csoghoian
13y ago
There appears to be a bit of a conflict between the cardinal rule you were taught when you worked at NSA of not collecting information on US persons with the current practices of the NSA. The Section 215 program in which the NSA has been co
25.
▲
by
csoghoian
13y ago
Justin, have you read the recently leaked NSA rules outlining how they define a non-US person for the purpose of FAA surveillance? See: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi...
26.
▲
by
csoghoian
13y ago
Cody, on his own blog, described the sale of the vulnerability as follows: In 2010, we (the startup I was running with friends at the time, UPM) decided to license the opening technology to a locksmithing company for law enforcement purpose
27.
▲
by
csoghoian
13y ago
If researchers in this community are going to sell security vulnerabilities to the government, I think that fact should be well known. daeken's work on hotel locks got a lot of press, but the fact that he had two years earlier sold that inf
28.
▲
by
csoghoian
13y ago
And by many people, you include yourself, right? Long before you disclosed the vulnerability in Onity hotel locks to the public, the startup you had co-founded "licensed" the same flaw to Lockmasters Security Institute, a company that train
29.
▲
Taming of the shrewd: can the ACLU free Android from carrier control?
(theverge.com)
1 points
by
csoghoian
13y ago
|
0 comments
30.
▲
by
csoghoian
13y ago
Given that high-value zero days are mostly bought by governments from defense contractors and security companies. There. Fixed that for you.
More ›