Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
m8urn
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
m8urn
5y ago
> "Pitch" is not a contract. But false advertising is definitely a thing one can sue over. And bait and switch might be subject to FTC fines.
2.
▲
by
m8urn
9y ago
Binisoft Windows Firewall Control is quite good.
3.
▲
by
m8urn
9y ago
Even with Enterprise edition it is very difficult to disable all telemetry. The lowest official setting for telemetry is "security" which still sends data to Microsoft (see https://docs.microsoft.com/en-us/win
4.
▲
by
m8urn
9y ago
Yeah, that's pretty bad blaming one employee when a single security hole on a single server resulted in the loss of personal information for 146 million people.
5.
▲
by
m8urn
9y ago
Here is the list of installed applications: http://imgur.com/a/mdrTv Also note that the only third-party software running at the time was wireshark, DNSQuerySniffer, and Glasswire.
6.
▲
by
m8urn
9y ago
Plus I have been doing this for 20+ years and have found many times settings that were incorrectly documented--it's even confusing to them.
7.
▲
by
m8urn
9y ago
I actually didn't spread them widely, I tweeted them. If you follow me you would know I tweet things like that all the time. I observed these connections and showed the settings I have set that should have prevented them. I haven'
8.
▲
by
m8urn
9y ago
Actually I made this error twice, which is far from "countless times". The one Allow Telemetry setting would not have made a difference because I had also configured it manually and the Teredo setting doesn't actually disable
9.
▲
by
m8urn
10y ago
Harassing and brigading isn't getting the word out, it's hysteria about a conspiracy theory.
10.
▲
by
m8urn
10y ago
And what if they were wherewolves, wouldn't you want to know that too? The problem here is the confirmation bias and logic errors going on with all the theories that there really is no believable proof unless you actually suspend your
11.
▲
by
m8urn
10y ago
Watching in horror… yet can't stop looking.
12.
▲
by
m8urn
11y ago
Another aspect of this is that they make the regular contract plans cost more than twice what they did before, even with a non-smartphone, essentially pushing you into the Next plan.
13.
▲
by
m8urn
12y ago
Yes, three of my accounts are on the list.
14.
▲
by
m8urn
12y ago
First of all, a good number of these passwords were simply gathered through google. Some were gathered via the archive.org archive of pastebin pastes and their normal web page archive. Some were from forums that were located via google. Thi
15.
▲
by
m8urn
12y ago
As I explained in the article I seriously doubt that any more than a tiny number of these passwords are still valid. And there is no reason for them to be, having already been widely available, indexed (and cached) by every search engine, a
16.
▲
by
m8urn
12y ago
And it has been for 20 years
17.
▲
by
m8urn
12y ago
The first column is username, followed by a tab, followed by the password.
18.
▲
by
m8urn
12y ago
The main reason I have always included usernames and passwords in my research is because it allows me to analyze frequency data across multiple sites. Although I could have anonymized the usernames, I thought it would be best to keep them i
19.
▲
by
m8urn
12y ago
Public dumps mostly from the last 5 years, but some as old as ten years
20.
▲
by
m8urn
12y ago
The trafficking charges were dropped but he still was charged as an accessory after the fact. http://cryptome.org/2015/01/brown-105.pdf
21.
▲
by
m8urn
12y ago
Actually three of my own passwords are on there, I left them in
22.
▲
I Am Releasing Ten Million Passwords
(xato.net)
594 points
by
m8urn
12y ago
|
216 comments
23.
▲
Is 123456 Really the Most Common Password?
(xato.net)
2 points
by
m8urn
12y ago
|
1 comments
24.
▲
by
m8urn
13y ago
It all seems so sincere. Except when you see how closely this matches the talking points the NSA sent home with employees ( https://s3.amazonaws.com/s3.documentcloud.org/documents/8445... )
25.
▲
by
m8urn
13y ago
That is a key point--that no system can ever be secure as long as the host has some way of intercepting messages. The fact is that no matter how secure Levison makes the system, there will always be some way he could intercept messages if h
26.
▲
9 Ways to Restrain the NSA
(xato.net)
6 points
by
m8urn
13y ago
|
3 comments
27.
▲
by
m8urn
13y ago
"A fingerprint is only useful for authentication, not key derivation" exactly
28.
▲
by
m8urn
13y ago
The problem is that fingerprint matching isn't exact, there are thresholds you must allow for so there is no exact code to match to. Although some implementations may make this possible, it is an issue that all biometric methods must a
29.
▲
Fingerprints and Passwords: A Guide for Non-Security Experts
(xato.net)
34 points
by
m8urn
13y ago
|
11 comments
30.
▲
by
m8urn
13y ago
Again, that's the whole point. He wasn't able to provide them with what they wanted, and doing so meant that he either had to allow them to intercept messages (or passwords) on Lavabit's application servers, which is the on
More ›