Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
trash_panda
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
trash_panda
8y ago
Not only do they not address the technical aspects of the paper, their response starts with a direct personal attack: "It seems Nadim (the author of this paper) took it really badly when we called him out for intentionally spreading fa
2.
▲
by
trash_panda
8y ago
The analysis by Kobeissi is correct, and the claims by ProtonMail are a stretch, and sometimes they don't mean anything. For example, from their security details page [1]: "This means we don't have the technical ability to de
3.
▲
by
trash_panda
8y ago
You can actually see what code your browser is running, you have view source and all the developer tools to analyze the JS code. This is their main defense, they will probably post a link to their GitHub page where the code of the front end
4.
▲
by
trash_panda
8y ago
I think what he means with certifications is that they'll get you the jobs you don't really want. For example, CEH (Certified Ethical Hacker) is a certification you'll see in a lot of job postings. The thing is, if you know t
5.
▲
by
trash_panda
8y ago
Of course, you're welcome. I forgot to address the salary question. Six figure jobs are common in this industry, but experience is required to get those jobs. I don't personally know of anyone that did the change at your age, but
6.
▲
by
trash_panda
8y ago
First of all: what in particular do you find interesting of the security field? Are you more interesting in the offensive or defensive side? I guess that given your background, the smoothest transition will be to something like application
7.
▲
by
trash_panda
8y ago
This is really useful for security testing, where unexpected input could have security implications. There is a similar project, which I think is better organized and has more lists to play with: https://github.com/danielmie
8.
▲
by
trash_panda
8y ago
Agree, but I also read this as a little condescending towards Chinese workers. We tend to attribute their success to corruption, exploitation, or brute-force (given their population). But, could it be that they have something going for them
9.
▲
by
trash_panda
8y ago
There is no such thing as a "standard threat model". That's why the threat modeling concept exists in the first place, so you can adapt different solution to different requirements. It is totally OK if you are extremely worri
10.
▲
by
trash_panda
8y ago
Privacy and security are intertwined. I believe Signal's decisions are based on the objective of making secure communications easy. If they catered to what some people want (no phone numbers and federated network) then the regular user
11.
▲
by
trash_panda
8y ago
Google tracks you, yes. But Google also takes good measures to ensure that they are the only ones that can track you (and the Google Play apps of course). You may be obsessed with Google and they tracking you, but that's ok. What I thi
12.
▲
by
trash_panda
8y ago
From their first blog post [1]: "We’re not placing any particular bounds on this project and will work to improve the security of any software depended upon by large numbers of people, paying careful attention to the techniques, target
13.
▲
by
trash_panda
8y ago
Actually, you're both incorrect. It's "plata o plomo". "Plata" can mean "silver" or "money". In this context they are referring to "money". "Plato" is literally "pla
14.
▲
by
trash_panda
8y ago
It isn't a matter of whether it's "secure" or not. The problem is that their security model is based around JavaScript code being pushed to your browser where all the "cryptography" will happen. Yes, maybe your
15.
▲
by
trash_panda
8y ago
Holy, I forgot about that one! You're totally right and I'm surprised it's not one of the main arguments for this push for HTTPS.
16.
▲
by
trash_panda
8y ago
Of course, you're right. My phrasing was not the best. The rogue CA would need to perform a classical MiTM as all the other mortals do, having access to the signing keys does not give you special MiTM powers, other than when you actual
17.
▲
by
trash_panda
8y ago
This is important. Because the discussion around HTTPS tends to train users into think that HTTPS = Web Security. I totally agree that it's important, and I understand the attack vectors. But what about your outdated WordPress/Joo
18.
▲
by
trash_panda
8y ago
You don't need to have private keys to exploit this scenario. Let's say you own example.com, and you add a certificate by Let's Encrypt. If Let's Encrypt is a malicious actor, they could MiTM a connection to your site, a
19.
▲
by
trash_panda
8y ago
If it's an NSA honeypot it will still be a positive thing for 99% of use cases. Also, why would they do this? It's smarter to compromise the existing CAs.
20.
▲
by
trash_panda
8y ago
I see what you mean. And this is the problems with this subject and why most of the times these discussions end up nowhere. We end up discussing on what this hypothetical "regular user" does with biased examples from our own exper
21.
▲
by
trash_panda
8y ago
Of course, but I think that your portrayal of the regular user is not of a regular user at all. The regular users I know don't even know what syncing is, what the cloud is, what integration is. I know lots of people that have their hom
22.
▲
by
trash_panda
8y ago
Totally agree with your familiarity argument. I think that's the main reason why Linux can't compete. One can think that the desktop OS for a regular user is a commodity, so why replace it? The benefits for the regular user of usi
23.
▲
by
trash_panda
8y ago
I think that your view on the needs of the regular user is pretty agreeable. I don't get why you got these kind of replies. Nothing you said was controversial about the regular user's needs. I too have experience working with some
24.
▲
by
trash_panda
8y ago
A quick line count shows that the file from your link has 14354 entries, while the one on the github repo has 65357.
25.
▲
by
trash_panda
8y ago
A good solution I've found for ad blocking is using the following hosts file: https://github.com/StevenBlack/hosts Which sinkholes every known ad/malicious domain. It's been pretty useful, and it hasn&#x
26.
▲
by
trash_panda
8y ago
Really? When was this released? I can't believe I've missed this one lol. Does it support screen sharing? I thought to Java client was the only thing available, and it's terrible to run on Linux.
27.
▲
by
trash_panda
8y ago
- Webex. I would go with the classic Office suite, but what I would really want in that area is support for open formats from Microsoft. This way anyone can write their fully compatible editor, and we could actually use Libreoffice.
28.
▲
by
trash_panda
8y ago
True! A lot of people use Linux and the ecosystem because it's free. And that's a good thing! It's great to have this open alternative where people without economic resources can rely on solid systems without having to worry
29.
▲
by
trash_panda
8y ago
An interesting solution could be to first enter the username, then the OTP/Key, then the password. I haven't given it a lot of thought and can't find anything wrong with it.
30.
▲
by
trash_panda
8y ago
I understand that, but let's say I try to phish you with a fake login page. Of course, the Yubikey won't send the code to that fake page as the domain name doesn't match, but an unsuspecting user could still enter his/he
More ›