Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mrkoot
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Large scale blocking of TLS-based censorship circumvention tools in China
(github.com)
2 points
by
mrkoot
4y ago
|
0 comments
2.
▲
TPM sniffing attacks on non-Bitlocker targets [re: LUKS FDE with discrete TPM]
(secura.com)
2 points
by
mrkoot
4y ago
|
0 comments
3.
▲
by
mrkoot
7y ago
FWIW, N=1: I'm Dutch and don't recall the word "uitwaaien" being commonly used like this throughout society. It's only used in informal settings, e.g. between friends/family/colleague (AFAIK), and has litt
4.
▲
by
mrkoot
7y ago
For better or worse, this helps establish neural networks that are not (or less?) vulnerable to deception via e.g. fake eyeglasses [ LINK: https://dl.acm.org/citation.cfm?id=2978392 ] and adversarial stickers [ LINK: https
5.
▲
by
mrkoot
8y ago
Vendor confirmed the issue, noting that it exists in "probably all versions" of Dropbear (i.e., v2018.76 and earlier) and that a patch will follow in the next couple of days: http://lists.ucc.gu.uwa.edu.au/pipermai
6.
▲
by
mrkoot
8y ago
...and apparently the same issue exists in Dropbear up until current version (2018.76 / Feb 2018), which has an entirely different code base. A comment on /r/blackhat [0] led a colleague and me to look at Dropbear's sour
7.
▲
by
mrkoot
8y ago
Yes. Large corporate networks often still have (some) production systems that allow password-based authentication. I don't know how widespread it still is, but I still encounter it frequently at clients (which may be a skewed sample).
8.
▲
by
mrkoot
8y ago
+1. But just to be sure: that does not prevent testing for usernames and hence enumerating software by testing for known/common service account usernames (e.g. "_tor" on OpenBSD and "debian-tor" on Debian-based OSs)
9.
▲
by
mrkoot
8y ago
Exactly - it also works for non-SSH accounts, thus allowing software enumeration by testing for default/common/known default service users. For instance, an OpenBSD box running Tor may have a user "_tor", a Debian-based
10.
▲
by
mrkoot
8y ago
Blog post: https://www.nccgroup.trust/uk/about-us/newsroom-and-events/b...
11.
▲
Singularity of Origin: a DNS rebinding attack framework
(github.com)
2 points
by
mrkoot
8y ago
|
1 comments
12.
▲
NCCA Polygraph Countermeasure Course Files Leaked
(antipolygraph.org)
14 points
by
mrkoot
8y ago
|
4 comments
13.
▲
by
mrkoot
8y ago
The 10-part series 'How to get Smarter: A guide to critical thinking, cognitive biases, and logical fallacies' published between in Jan-Apr 2018 at Life Lessons is also quite comprehensive. Covers 50 topics, 5 per post. I apologiz
14.
▲
by
mrkoot
9y ago
It incorrectly classified me (@mrkoot) as a bot w/.923 probability.
15.
▲
by
mrkoot
9y ago
Alexandre Anzala-Yamajako posted interesting comments on this to [Cryptography] (@metzdowd.com): > IMO a statistical approach based on taking a bunch of data a saying essentially "I don t see any signs that it s not random" is
16.
▲
by
mrkoot
9y ago
The BCP's scope is broader than state actors: "The motivation for PM can range from non-targeted nation-state surveillance, to legal but privacy-unfriendly purposes by commercial enterprises, to illegal actions by criminals".
17.
▲
by
mrkoot
11y ago
In March 2015, Karsten Nohl is quoted wrt type C in the context of BadUSB: '"The additional openness and flexibility of USB Type-C comes with more attack surface," says Karsten Nohl, one of the researchers who first discovere
18.
▲
by
mrkoot
12y ago
It works - thx!
19.
▲
MILDEC: “Cyber Deception” is a Specific Focus Area for USAF in FY15-FY16
(blog.cyberwar.nl)
1 points
by
mrkoot
12y ago
|
0 comments
20.
▲
"Intrusion software" now export-controlled as "dual-use" by Wassenaar
(blog.cyberwar.nl)
3 points
by
mrkoot
13y ago
|
0 comments