Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tkems
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
tkems
6mo ago
One that I have been experimenting with is using analog phones (including rotary ones!) to act as the satellites. I live in an older home and have phone jacks in most of the rooms already so I only had to use a single analog telephone adapt
2.
▲
by
tkems
2y ago
I can confirm that Aliexpress doesn't allow me to checkout with a USA address and states that items can't be shipped to my region. -edit: Since this post it seems that I can order items again? Very odd.
3.
▲
by
tkems
2y ago
I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other features) for something like $10/yr. Why wou
4.
▲
by
tkems
2y ago
From what I've read, myQ is pretty locked down and doesn't support local control (outside of a HomeKit device that I think is no longer supported). I would guess that the cert pinning would prevent such MITM attack, but I could be
5.
▲
by
tkems
2y ago
Yes, RF (radio frequency) remotes I've seen include my garage door opener, some overhead fans in bedrooms, gates, remote outlet/light controllers.
6.
▲
by
tkems
2y ago
I would check out the Unleashed firmware [1]. I've had pretty good luck with it so far. [1] https://github.com/DarkFlippers/unleashed-firmware
7.
▲
by
tkems
2y ago
As someone in cybersecurity, it is handy as a low frequency RFID reader as Android phones only support higher frequency. Having something compact and in a single unit (compared to a Proxmark) makes it easier to 'grab-n-go'. It is
8.
▲
Unmasking Vulnerabilities in Cheap IoT Cameras from One Chinese Manufacturer
(trevorkems.com)
1 points
by
tkems
2y ago
|
0 comments
9.
▲
by
tkems
2y ago
This is a great run down of the process to extract the firmware from these types of devices without desoldering the flash. I've done a fair amount of reverse engineering and a lot of devices have similar vulnerabilities. I think more t
10.
▲
by
tkems
2y ago
With Google Wallet (the only one I have at the moment), it is not static for the ticket. It has a NFC and barcode option. The barcode changes every 15 seconds for me.
11.
▲
by
tkems
2y ago
I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar o
12.
▲
by
tkems
2y ago
One issue I have with the Flock cameras installed in my city is that they are installed on public land (right next to the road) and paid for with tax dollars.
13.
▲
by
tkems
2y ago
One of the Flock cameras was installed in my city nearby where I live. Once I noticed it, I thought it was a red light camera at first since it was near an intersection. I did some research on them and found that they are completely wireles
14.
▲
by
tkems
2y ago
If banks would spend money on this and not enabling support for hard to phish MFA options like hardware keys (FIDO2), I would change banks. We have solutions to most of the phishing attacks, but most people find them hard to use or don'
15.
▲
by
tkems
3y ago
Wow, I just submitted the consumer disclosure report this morning after finding out about it from somewhere else. I am VERY interested to see if anything is reported from my car since I don't have any of the addons/monthly fees.
16.
▲
by
tkems
3y ago
This sounds like HomeLink and is indeed more complex. My understanding of it is that they partner with lots of companies to support their rolling/fixed codes and remotes so that they can be paired to your garage door. I linked this in
17.
▲
by
tkems
3y ago
The largest garage door manufacture in the US uses the Security+ and Security+ 2.0 algorithms that are rolling, but can be fairly trivially decoded to gain the serial number and rolling value of a remote. [0] This is how the flipper zero de
18.
▲
by
tkems
3y ago
I would say that money is the root of the problem. I think that most VOIP providers don't want to loose out on unencrypted traffic (both legitimate and spam). Also, why do I seem to always get spam from a few providers? And why aren&#x
19.
▲
by
tkems
3y ago
This was my thought too. While I do think going after this kind of scam is a good first step, I don't see overseas operators not using this any less. Most spam calls I get don't follow the do not call list, why would they follow t
20.
▲
by
tkems
3y ago
I find this strange but not surprising. I've heard of speed bumps in the past related to 'hackers in town' and I wouldn't be surprised if it comes out later that it had something to do with it, even if unfounded. I think
21.
▲
Breaking Bitlocker – Bypassing the Windows Disk Encryption [video]
(youtube.com)
111 points
by
tkems
3y ago
|
69 comments
22.
▲
by
tkems
3y ago
This seems that Apple went to way too much thought to avoid a simple solution: Just let users sideload apps and put up a few warning messages like Android. Must have had a bunch of high-priced lawyers think this up. Also, what is this Core
23.
▲
by
tkems
3y ago
From what I understand, cars are a bit more complex now then garages. KeeLoq, from my understanding, is not 'breakable' like garage doors. It does have weaknesses, but more related to the raw cryptography/math. Since KeeLoq i
24.
▲
by
tkems
3y ago
While rolling codes can be secure (KeeLoq [0] is a more secure example but has it's own issues), this [1] is an example of some of the weaknesses that can happen if a rolling code algorithm is broken. I have personally been able to cap
25.
▲
by
tkems
3y ago
Just a heads up about the Flippers U2F implementation [0] and the possible weaknesses compared to a Yubikey/other U2F key. [0] https://modusmundi.com/posts/u2f-flipper/
26.
▲
by
tkems
3y ago
This sounds a lot like the KeeLoq algorithm [0] (minus the hashing part). From my research into the rolling code space, I think most remotes don't quite have the CPU/featureset to support a real, secure crypto system with things l
27.
▲
by
tkems
3y ago
For Chamberlain brands [0] there is some research that shows that their rolling code system (Security+ and Security+ 2.0) is quite easy to decode/decrypt [1]. This feature is supported in the flipper firmware, but is restricted (you ca
28.
▲
by
tkems
3y ago
As someone with a HackRF PortaPack knockoff I got from ebay, I would agree that SDRs are better and cheaper than ever before. However, I think the average person will struggle with using a HackRF for more complex projects. I've used UR
29.
▲
by
tkems
3y ago
For IR remotes, there are a few ways to go about it. If you have a remote you want to clone, you can just use the flipper to clone and map buttons to a custom remote. If you don't have the remote and have a common device (like TVs), I
30.
▲
by
tkems
3y ago
I would check out the Proxmark3 Github repo [0]. They have a cheatsheet [1] with the basics on how to get started. I also did a talk about RFID security last year about the basics [2] To get started, the basics are: low freq (LF) is usually
More ›