Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
michaellosee
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Hashcat and oclHashcat have gone open source
(hashcat.net)
2 points
by
michaellosee
11y ago
|
0 comments
2.
▲
by
michaellosee
12y ago
+1 to this. During the presentation they scan the entire internet for open VNC ports that do not require authentication. There were many found (thousands?), the most surprising being a mainframe that looked like it controlled a railway in
3.
▲
by
michaellosee
12y ago
It seems that error code may not involve data input format but rather indicates DB2 is out of resources[1]. Honestly this release might be a little early for IBM as well. Any sort of verbose error message is at least a low risk information
4.
▲
by
michaellosee
12y ago
GPUs love hashing things, do you think ArrayFire would make that easy to do? I would LOVE to use the library to create an opensource GPU cracking program. Hashcat is amazing but is closed source. I am giddy with excitement at the prospec
5.
▲
by
michaellosee
12y ago
Thank you, I knew I was missing something. Also, I found that iOS 8 (mostly) fixed the backdoor: http://www.zdziarski.com/blog/?p=3820
6.
▲
by
michaellosee
12y ago
>(iOS 8) virtually eliminates the possibility that the encrypted data can be unlocked without the passcode. I am not the first to point out that it is stupidly easy to bruteforce passcodes that are based on digits (like many phone passco
7.
▲
by
michaellosee
12y ago
There are several symmetric encryption algorithms to choose from, the default is CAST5 (according to this[1] random mail post). This would only be used to encrypt the private key on disk. Now I'm curious of the methods of decrypting d
8.
▲
by
michaellosee
12y ago
When I saw 1 trillion guesses per second I immediately wondered what algorithm was being referenced. My single GTX 780 hash performance varies wildly by algorithm. A few numbers: NTLM - 1.2 billion/sec MD5(Wordpress)- 600 milli
9.
▲
by
michaellosee
12y ago
That statement was made tongue in cheek, mostly to illustrate that 1) police are only protecting and and serving themselves when seizing our stuff and 2) removing the incentive would help reduce the problem (along with other points made by
10.
▲
by
michaellosee
12y ago
Good point. This has me thinking more about the root of the problem. It seems like the justification they use most of the time is related to drugs. Perhaps asset forfeiture is a another example of how the war on drugs undermines our civi
11.
▲
by
michaellosee
12y ago
There is an amazing correlation between how much money police seize and what percentage of that money they can keep. The states that allow police to keep a high percentage of the money take in many millions per year, and the opposite is tr
12.
▲
by
michaellosee
12y ago
That is true. Those first two recommendations are good bang for your buck (for the newbies), I guess I forgot I have a technical audience here :-) Now that I'm thinking about it transparent bridge mode might do the trick as well.
13.
▲
by
michaellosee
12y ago
They gave the exploit a "1337 compromise" award, so it is almost as bad as it gets. While you still have the Q1000, be sure that you have the remote interface disabled and use the NoScript browser plugin. Those two items will mit
14.
▲
by
michaellosee
12y ago
I demonstrated the Actiontec Q1000 exploit on Track 0. As a security professional I am very interested in responsible disclosure, and had already reported the vulnerability to Century Link 6+ months before Defcon (slight correction to the
15.
▲
by
michaellosee
13y ago
> So how do we get as comfortable looking at recent mistakes as we are looking at the ones in the distant past? We probably can't - there's too much baggage. Self Determination Theory (SDT, http://www.selfdeterminati
16.
▲
by
michaellosee
13y ago
Some thoughts. In my experience, the lack of vulnerable code in a secure application is not the product of savvy developers who never make mistakes. A hardened web app usually gets that way because someone took the time to find and fix so
17.
▲
by
michaellosee
13y ago
+1 for keto. The wife and I have lost 20 lbs each in the last 3 months.