Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
haxrob
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Hiding in plain sight – Mount namespaces
(haxrob.net)
4 points
by
haxrob
1y ago
|
0 comments
2.
▲
by
haxrob
2y ago
Can attest, having searched through literally thousands of pages of documentation in an attempt to attribute the payment processing switch vendor when analysing the ATM jackpotting malware ‘fast cash for Linux’[1]. The best I could do was d
3.
▲
FASTCash for Linux
(doubleagent.net)
4 points
by
haxrob
2y ago
|
0 comments
4.
▲
by
haxrob
2y ago
"CrowdStrike cash on hand for the quarter ending April 30, 2024 was $3.702B, a 26.38% increase year-over-year." [1] [1] https://www.macrotrends.net/stocks/charts/CRWD/crowdstrike/c...
5.
▲
by
haxrob
2y ago
> Not to downplay it but at least this requires users to download the Onavo app, which isn’t so common. 10 million installs on Android, according to AndroidRank[1]. What we don't know (yet) is what % of those installs had the FB com
6.
▲
by
haxrob
2y ago
Thanks, I have modified the wording and also quoted you and linked this HN post on the blog page.
7.
▲
by
haxrob
2y ago
> This wasn’t simply Facebook hijacking random people’s traffic because they accepted the ToS or used the Facebook app Do you have further insights or references on what was the "trigger condition"? This is a new case, separate
8.
▲
by
haxrob
2y ago
The analytics domain was "sc-analytics.appspot.com" in which the lack of pinning is described at the tail end of the blog post.
9.
▲
by
haxrob
2y ago
> Victims that were being paid to participate I believe you might be referring to what happened in 2019? [1] This is a separate issue. [2] I do clarify this in the blog post, although it might be better to move the relevant text near the
10.
▲
by
haxrob
2y ago
> from what I can tell FB paid SC users to participate in “market research” and install the proxy. The app was available on both the Google Play and Apple App stores for anyone to download. > The way most of the writeups make it sound
11.
▲
How did Facebook intercept their competitor's encrypted mobile app traffic?
(doubleagent.net)
503 points
by
haxrob
2y ago
|
209 comments
12.
▲
by
haxrob
3y ago
For those wondering, danielwmayer is one of the authors of the CrowdStrike article linked in the parent.
13.
▲
by
haxrob
3y ago
Thanks Mike for sharing your insights.
14.
▲
by
haxrob
3y ago
Recommend taking a read of CrowdStrike's write up on this [1]. The threat actor maintains a presence on the roaming exchange through compromising "at least 13 telecommunication companies". > If it's the former, then i
15.
▲
by
haxrob
3y ago
> I believe them to be an adjacent team to the more well known Mustang Panda This is interesting - the attribution for this actor has remained elusive for quite some time due to their consistent operational security. Could you elaborate
16.
▲
by
haxrob
3y ago
Hey OP here - I mostly agree with your points in respect to AMap. It's a legitimate mapping service and location SDK. > Why not mention it's AMap in the tl;dr summary? The GPS data is being sent to two different companies - the
17.
▲
by
haxrob
3y ago
Hi HN, this is my efforts in reverse engineering a BLE car battery monitor where it's app has over 100,000 downloads on the Google Play store alone. It turns out it's sending GPS, cell phone tower cell IDs and Wifi beacon data to
18.
▲
Discovering that a Bluetooth car battery monitor is siphoning location data
(doubleagent.net)
709 points
by
haxrob
3y ago
|
299 comments