Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
santaragolabs
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Silly proof of concept: Anti-phishing using perceptual hashing algorithms
(anvilsecure.com)
3 points
by
santaragolabs
5y ago
|
0 comments
2.
▲
Anti-phishing using perceptual hashing algorithms
(anvilsecure.com)
2 points
by
santaragolabs
5y ago
|
1 comments
3.
▲
by
santaragolabs
6y ago
This reminds me of the science fiction novel The Water Knife by Paolo Bacigalupi. From the Amazon description: "In the near future, the Colorado River has dwindled to a trickle. Detective, assassin, and spy, Angel Velasquez “cuts”
4.
▲
Azure Sphere Reverse Engineering
(anvilventures.com)
1 points
by
santaragolabs
6y ago
|
0 comments
5.
▲
Defeating Secure Boot with Symlink Attacks
(anvilventures.com)
1 points
by
santaragolabs
6y ago
|
0 comments
6.
▲
Unpacking Bosch Surveillance Camera Firmware
(anvilventures.com)
5 points
by
santaragolabs
6y ago
|
0 comments
7.
▲
A bug and a misconfigured file share: a tale in two parts
(anvilventures.com)
1 points
by
santaragolabs
7y ago
|
0 comments
8.
▲
Looking Inside the Box: Reverse Engineering the Dropbox Client
(anvilventures.com)
5 points
by
santaragolabs
7y ago
|
0 comments
9.
▲
by
santaragolabs
8y ago
Oh wow, thanks Keith, first of all for mosh! I've been using it daily for several years now. It's been great! Second of all for clarifying and correcting me regarding the algorithm-usage. I don't know where I got it from and
10.
▲
by
santaragolabs
8y ago
Sure. But that's why my point was about mosh ( https://mosh.org/ ). It just uses TCP+SSH for the authentication part and then it sets up an encrypted UDP-tunnel on the server-side with the mosh-client then just sending
11.
▲
by
santaragolabs
8y ago
That work is great. A related paper on earlier work where traffic analysis on skype was being done and where the researchers were able to extract individual phonemes and then reconstruct speech that way. It's one of my favorite papers.
12.
▲
by
santaragolabs
8y ago
Man, this paper is a classic. I love traffic analysis attacks like this. I did something myself six years back albeit with a somewhat contrived example figuring out what someone is looking at on Google Maps via request and response sizes. E
13.
▲
by
santaragolabs
8y ago
No-one said anything about the president or the NSA being involved. There are tons of ways this can work. And it actually happens. Just once you're flagged and are inside The Machine you get detained upon entry whilst they confiscate y
14.
▲
by
santaragolabs
8y ago
I've done some security contracting work for the folks in Walldorf over the years; I've seen first-hand some SAP FTE's getting insanely frustrated putting in their expenses in their own systems. Which was pretty hilarious to
15.
▲
by
santaragolabs
9y ago
Tangibly related due to it being Ellen Ullman. Oh wow. So I read "The Bug" of hers just after it came out (14 years ago) and it's such a poignant read about someone being slowly driven mad because he can't find a very pe
16.
▲
by
santaragolabs
9y ago
It's not about how stupid Americans are but the insane vilification of anything that reeks like socialism. You (*see edit below) live in the richest country on the planet which is incapable of providing clean drinking water to all of i
17.
▲
by
santaragolabs
9y ago
OP / author of the tool here too. Feel free to come up with any questions or suggestions regarding this. The tool has already proved its worth for me personally but I'm always open to reasoned input why I'm an idiot because I
18.
▲
Linux Attack Surface Analysis Tool
(anvilventures.com)
8 points
by
santaragolabs
9y ago
|
1 comments
19.
▲
by
santaragolabs
9y ago
I've been a personal paying user of Fastmail for over 5 years now. It's been great. For my own company and for another business I started late last year I've also selected Fastmail as an email provider again. Just wanted to s
20.
▲
Infosec ethics in zero days, exploits and attribution
(anvilventures.com)
4 points
by
santaragolabs
9y ago
|
1 comments
21.
▲
by
santaragolabs
9y ago
So I've been in the position, a few years back, where I spent months doing comprehensive code reviews of these energy distribution management systems and what not more. It's all super scary legacy stuff and the code in general is
22.
▲
by
santaragolabs
9y ago
Yep, people can infer a lot. I did a demo of this a couple of years ago for my employer at the time by creating a tool which, in a slightly contrived scenario, is able to figure out what one is looking at on Google Maps over SSL. Blogpost (
23.
▲
by
santaragolabs
9y ago
Here's one that is maybe more concrete. And I hope I'm understanding everything correctly. Say you're a startup running your infrastructure in AWS. You spread it out over three different regions and within each region you use
24.
▲
by
santaragolabs
10y ago
Yep and they change things around every once in a while too. I RE'd dropbox several times using several different techniques. I just checked my old tarball containing a script which downloads dropbox binary, downloads the Python interp
25.
▲
by
santaragolabs
10y ago
And to follow-up; several works on the history of science are great and it is great for learning that history is very messy. Also in science things are never as black and white as people several decennia down the line tend to think about ho
26.
▲
by
santaragolabs
10y ago
This is basically the thesis of Paul Feyerabend who used it as his main argument against there being a scientific method. His book "Against Method" is one of the best works on Philosophy of Science I've read during my univers
27.
▲
by
santaragolabs
10y ago
As someone who spent a lot of time in the past 5 years at MSFT and also at tons of other firms doing security work / SDL-work on code bases; there are very few companies where a giant C/C++ code base is getting even close to the q
28.
▲
Saving Polar Bears When Banner Grabbing
(blog.ioactive.com)
5 points
by
santaragolabs
11y ago
|
0 comments
29.
▲
Saving Polar Bears When Banner Grabbing
(blog.ioactive.com)
3 points
by
santaragolabs
11y ago
|
0 comments
30.
▲
Simple bruteforce detection tool (2014)
(santarago.org)
23 points
by
santaragolabs
12y ago
|
0 comments
More ›