Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
devconsole
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
devconsole
8y ago
Growth hacking is hard . We had to learn a few tricks to grow our Hacker News alternative ( https://laarc.io ) Suppose you were to start a site similar to HN. How would you get the word out? The most reliable way to grow is to h
2.
▲
by
devconsole
12y ago
It looks like I was wrong about this. Will multiple datacenters allow you to continue setting up new accounts using nothing but bitcoin? If you don't need to provide identification, then this might be an interesting avenue to explore
3.
▲
by
devconsole
12y ago
I just tested it. It looks like I was incorrect. People told me that Reddit shadowbans you if you create a new account using Tor. Maybe that was the case for awhile, or maybe it's true for a certain subreddit, but it doesn't se
4.
▲
by
devconsole
12y ago
This is a perfect illustration of how to get busted. For example, the whole idea of "How can I acquire a burner phone?" is misguided, because as soon as you speak into a burner phone, your voiceprint alone is enough to identify y
5.
▲
by
devconsole
12y ago
Then the authorities trace the server component to the person who sold it on Craigslist. And if your opsec isn't perfect, you're busted right there: Did you forget to set up a new email account for all of your craigslist transact
6.
▲
by
devconsole
12y ago
Not a bad idea, assuming you don't care about taking other people's property and using it in ways they don't expect for personal gain. But it's difficult. Once you no longer control the underlying hardware guarantees,
7.
▲
by
devconsole
12y ago
Agreed, but the sheer scope of this operation forces us to consider whether the authorities are playing by all of the rules. Since we don't know which rules are still reliable, the best defense is simply to assume your server is compr
8.
▲
by
devconsole
12y ago
It's an open question whether Tor has been compromised to the point that it's now trivial for authorities to locate where darknet websites are hosted. I'm simply making the observation that if your opsec is good enough, you
9.
▲
by
devconsole
12y ago
It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it po
10.
▲
by
devconsole
12y ago
There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their re
11.
▲
by
devconsole
12y ago
Hi dang. Someone downvote bombed a conversation I was having with some fellow HN users: https://news.ycombinator.com/item?id=7726544 All the comments below that link had a downvote except one of mine. I tried to correct i
12.
▲
by
devconsole
12y ago
Whats DMA access? Direct Memory Access access? This is what happens today. Not in some far off distant distopioan future meant to invoke fear in the ignorant/lazy. Why not talk with me without the snark? This topic seems like it i
13.
▲
by
devconsole
12y ago
The reason it's good to proactively think of future threats is because so many past concerns have proven to be true. Several months ago, no one on Hacker News really believed that BIOS backdoors were much of a threat. But today it&#x
14.
▲
by
devconsole
12y ago
Also to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create&#
15.
▲
by
devconsole
12y ago
The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent. I didn't intend to argue that. I'm saying that strong anonymity OS's li
16.
▲
by
devconsole
12y ago
Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibi
17.
▲
by
devconsole
12y ago
A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item
18.
▲
by
devconsole
12y ago
If that were strictly true, then SOPA would have passed.
19.
▲
by
devconsole
12y ago
Not really. They don't have a way to change their laws. It's Putin's Russia.
20.
▲
by
devconsole
12y ago
What I mean is, how would we verify the BIOS firmware matches what that source code should produce? If it's possible for us to make our own builds (i.e. there's no cryptographic signing for the BIOS binaries) then an adversary ca
21.
▲
by
devconsole
12y ago
Could you "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud? What a fantastic idea. This seems worth pursuing. It should be possible to configure a modern browser to work with low bandwidth: HTML&
22.
▲
by
devconsole
12y ago
How would you verify on demand that the BIOS isn't compromised?
23.
▲
by
devconsole
12y ago
It could be possible to enable someone you trust to use your infrustracture. You don't have to know who this person is. For example, this devconsole HN account that I'm using now is an anonymous HN account, meaning as long as To
24.
▲
by
devconsole
12y ago
With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while. You
25.
▲
by
devconsole
12y ago
It's worth noting that Tails doesn't make you impervious. Tails uses Tor, and Tor is vulnerable to NSA and GCHQ attacks. Specifically, they have the capability of deanonymizing individual targets. I hypothesize that this capabi
26.
▲
by
devconsole
12y ago
Perhaps the scariest thing is their plan to collect and store all data on all of your activities, then retroactively mine it. That is, from the moment you use the internet for the first time as a 9 year old until the day you die as an 89 y
27.
▲
Why is Tor's growth curve shaped so strangely?
(metrics.torproject.org)
1 points
by
devconsole
13y ago
|
0 comments
28.
▲
by
devconsole
13y ago
Highlights from the slides: Your CPU chipset is also standalone webserver. Most vPro chipsets (MCHs) have: - An Independent CPU (not IA32!) - Access to dedicated DRAM memory - Special interface to the Network Card (NIC) - Execution environ
29.
▲
Introducing Ring -3 Rootkits: BIOS rootkit targeting vPro chipsets (2009) [pdf]
(blackhat.com)
74 points
by
devconsole
13y ago
|
26 comments
30.
▲
Attacking Intel BIOS (2009)
(blackhat.com)
2 points
by
devconsole
13y ago
|
0 comments
More ›