Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
theEXTORTCIST
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
theEXTORTCIST
8y ago
I am trying to understand your post. Is it cheaper per yard to hire a concrete truck than to mix concrete (with free aggregate/sand) yourself?
2.
▲
by
theEXTORTCIST
9y ago
There is the issue of the TLS connection of images fetched in the app (other things too?) being tied to a domain without a valid cert. In other words, you could MITM the TLS session between the wifi user and the Tindr servers for AT LEAST p
3.
▲
by
theEXTORTCIST
9y ago
I agree that you need "both halves" in this scenario to sign the transaction. At some point during the spend from the wallet, the privkey that matches the wallet pubkey has to touch memory. This privkey can in theory be compromise
4.
▲
by
theEXTORTCIST
9y ago
The attacker only needs to have compromised the device which spends from the wallet file
5.
▲
by
theEXTORTCIST
9y ago
I don't think it's "stupid" to C2 via chat API. It would be "stupid" to have no fallback mechanisms
6.
▲
by
theEXTORTCIST
9y ago
plot twist: active breach investigation on going with all 3 majors
7.
▲
by
theEXTORTCIST
9y ago
TOR does not protect DNS queries out of the box. You must configure your PC to query through TOR or all of your DNS queries have the potential to leak to your ISP https://tor.stackexchange.com/questions/8/how-does-
8.
▲
by
theEXTORTCIST
9y ago
This seems like a really cool device. One that I would certainly purchase. What weird stretch goals they have. I wonder if these are jokes? "$8m = Signatures of entire team printed inside the phone case $10m = Free encrypted VPN tunnel
9.
▲
by
theEXTORTCIST
9y ago
This is one of the biggest points that I have seen taught in driver training courses and repeated throughout my life. Most of the events people refer to as car accidents are crashes/collisions.
10.
▲
by
theEXTORTCIST
9y ago
This is definitely a confusing sentence, especially for a non English speaker. You can reword the sentence and add something in front (e.g. "The researchers"). "The researchers are using psilocybin assisted group therapy for
11.
▲
by
theEXTORTCIST
9y ago
Interesting... there doesn't appear to be any fire suppression systems pictured in the mining buildings
12.
▲
by
theEXTORTCIST
9y ago
Report it anonymously to your insurance provider (*not sure if this is possible and/or would actually do anything)
13.
▲
by
theEXTORTCIST
9y ago
The data URL scheme is abusable. Firefox and Chrome correctly redirect to localhost via javascript data:text/html,http://www.mostSecureInternetBankVictim.com/customerLogin.php%2FreallyLoginRandomData=130r193fj02jf-2j
14.
▲
by
theEXTORTCIST
9y ago
I just tried this on Chrome 60.0.3112.90. Both Firefox and Safari throw phishing warnings with these URLs. http://news.ycombinator.com@1572395042 Chrome takes me to 93.184.216.34 no warning Then I tried http://securit
15.
▲
by
theEXTORTCIST
9y ago
In society we have an endless amount of social warnings, "Don't drink too much, you'll get ill. Don't do drugs, you'll become an addict. Don't drive without your seatbelt, you can die. Don't watch too much
16.
▲
by
theEXTORTCIST
9y ago
I have heard one of these in San Francisco, CA in the USA. The music had a really high pitched note behind it that sounded horrible.. like a cross between a mosquito and the buzzing of an input jack
17.
▲
by
theEXTORTCIST
9y ago
Forcefully taking private property from individuals to later sell to other private parties for private use sounds like the nightmare version of eminent domain.
18.
▲
by
theEXTORTCIST
9y ago
to add to your post, that affiliate link stays active on amazon accounts that clicked it for 24hours and pays out to the owner for every product purchased in that time frame
19.
▲
by
theEXTORTCIST
9y ago
Was waiting for this comment. I often ask myself, "Do I want any entity to have a copy of the exact dates and amounts of my entire daily consumer activity?". Whether anonymized or not there is a tremendous amount of knowledge that
20.
▲
by
theEXTORTCIST
9y ago
Some relevant info: In the USA average consumers are protected by the FDIC for the balances of their deposits up to $250,000. A large number of banks have consumer liability limits in place for protection from fraudulent charges on their cr
21.
▲
by
theEXTORTCIST
9y ago
this is an interesting application... was linked in the article safestrike.it
22.
▲
by
theEXTORTCIST
9y ago
Link to the Orin Kerr article: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201... Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference be
23.
▲
by
theEXTORTCIST
9y ago
From my comment, the SPECIFIC details of the tool's concepts of operation, implementation, and capability. The field guide provides great detail on operations and limitations of a specific existing tool (sample GUI screen shots, poten
24.
▲
by
theEXTORTCIST
9y ago
Just because a threat vector is well known and not cutting edge does not make the SPECIFIC information of its existence, implementation, and capability completely worthless
25.
▲
by
theEXTORTCIST
9y ago
Pretty interesting how many bits of identifying information are available based on system fonts. if you've never seen EFF's Panopticlick check out https://panopticlick.eff.org
26.
▲
by
theEXTORTCIST
9y ago
point taken, I had not read it this way originally but your interpretation makes sense edit: I knew I saw something about this somewhere earlier today. Still, this proves nothing because it's source less. https://www.politie
27.
▲
by
theEXTORTCIST
9y ago
Untrue according to the crabs article interview with the woman "Petra Haandrikman, team leader of the Dutch police unit that infiltrated Hansa." https://krebsonsecurity.com/2017/07/exclusive-dutch-cops-on
28.
▲
by
theEXTORTCIST
9y ago
Using a standard channel for public key exchange is half the battle. The other half is using a trusted channel to verify the public key does indeed match the public key you were originally sent. "Trusted channel" can be broadly in
29.
▲
by
theEXTORTCIST
9y ago
The only reason I mention that this is at all probable is because of the length of a PGP key. How often is the average user of a site like this logging in to verify even the last few bytes of a PGP pub key compared to what is saved in their
30.
▲
by
theEXTORTCIST
9y ago
Law enforcement could have easily MITM'd the PGP. They replace the public key of a vendor with their own public key (on the vendors's page, without the vendor's/buyer's knowledge), then the buyer address gets encryp
More ›