Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xorbyte
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China
(gfw.report)
1 points
by
xorbyte
2y ago
|
1 comments
2.
▲
by
xorbyte
2y ago
Wallbleed, a buffer over-read vulnerability that existed in the DNS injection subsystem of the Great Firewall of China. Wallbleed caused certain nation-wide censorship middleboxes to reveal up to 125 bytes of their memory when censoring a c
3.
▲
by
xorbyte
9y ago
If he doesn't like your site, he may not allow you to use his service, which is something the TOS already cover. Over time, such capricious terminations could lead to the Board seeking action against the CEO, depending on the impact to
4.
▲
by
xorbyte
9y ago
macOS and iOS don't support OpenVPN with the built-in client. You can use strongSwan-based VPNs (e.g., as would be deployed through Algo) or Cisco, but for OpenVPN you'll need a custom client which, unfortunately, very likely brin
5.
▲
by
xorbyte
9y ago
I think you may be confusing deterministic reproducible builds (that remove randomness and ensure binaries have the same content hash regardless of who builds them (so you can reproduce what the maintainers did and verify the source and bin
6.
▲
by
xorbyte
9y ago
Not all tonic water is low cal, a 350 mL bottle can be 100 calories from the 30g of sugar added.
7.
▲
by
xorbyte
9y ago
Any comparatively large corporation very likely has a release process for these sorts of things where a bunch of groups (like PR, maybe Legal etc) would take a look. Releasing company IP as open source outside of such a process would be a g
8.
▲
by
xorbyte
9y ago
Back issues are always included in the current issue, hence the zip. Keep recursing that way (or use binwalk)
9.
▲
by
xorbyte
10y ago
There's nothing in the OPs post suggesting SSH was exposed to the public, or that the breach happened over SSH. So it's important to secure that, but it's also important to think holistically about the attack surface.
10.
▲
by
xorbyte
10y ago
You assume the breach happened over SSH. This is valuable information to securing SSH, but it's entirely possible the original breach happened over some other service, and there were some other steps involved in the breach before the S
11.
▲
by
xorbyte
12y ago
The article makes no mention of TLS anywhere, and the example endpoints are all HTTP. So, this is a thoroughly insecure implementation, relying on very weak security mechanisms, prone to straightforward interception and tampering, replay et
12.
▲
by
xorbyte
12y ago
Wouldn't that just be regular Xen?
13.
▲
by
xorbyte
13y ago
Not sure how you see progress and innovation otherwise. Much of what is good in Linux comes from experimentation and people/distros 'doing their own thing' which sometime improved the ecosystem, and sometimes resulted in aban
14.
▲
by
xorbyte
13y ago
Similarly echoed in the OpenWRT talk from 30C3 https://www.youtube.com/watch?v=Y-OlUxeS57E
15.
▲
by
xorbyte
13y ago
No, I think this means PayPal recognizes tptacek's CCs and forces a log in. Even with a new card, perhaps they'll just base it on the name and refuse to process it without an account login.
16.
▲
by
xorbyte
13y ago
OTR is only used in one-on-one communications in CC; group chat mechanisms are custom, and may now converge towards the mpOTR draft but that's still a pretty big risk.
17.
▲
Internet-Wide Scan Data Repository
(scans.io)
3 points
by
xorbyte
13y ago
|
0 comments
18.
▲
by
xorbyte
13y ago
Much of Jacob's presentation echoes many of the articles he (and others) had published in Der Spiegel earlier that day, going into a little more into the technical aspects (to the extent they are known and/or can be inferred.) Whi
19.
▲
by
xorbyte
13y ago
Look if anyone in your institution has created a dissertation template for LaTeX, or if you can use one [from elsewhere]( https://github.com/briandealwis/ubcdiss ). I personally found the formatting to be the hardest par
20.
▲
by
xorbyte
13y ago
MultiMarkdown might be more suitable for large documents, as it allows the inclusion of files between documents, cross-references etc.
21.
▲
by
xorbyte
13y ago
But ECB for media is particularly egregious, particularly since even the Wikipedia page on ECB shows how remarkably 'visible' large things encrypted with ECB are.
22.
▲
by
xorbyte
13y ago
Would this legal around the world? AFAIK Canada and probably parts of the US don't allow wearing bulletproof vests, and while a suit might be harder to identify as such, I'm wondering if it's still problematic.
23.
▲
French gov used fake Google certificate to read its workers' traffic
(theregister.co.uk)
11 points
by
xorbyte
13y ago
|
1 comments
24.
▲
by
xorbyte
13y ago
von Neumann is 'skirt chasing' but Curie is 'slutty'?
25.
▲
by
xorbyte
13y ago
The previous hackathon was near Zurich https://whispersystems.org/blog/hackathon-zurich/ , so it's certainly not out of the question it will be outside of the US again, some time in the future.
26.
▲
by
xorbyte
13y ago
It seems to still do that, however I have not had any problems installing gpg2 via homebrew and overwriting the destination binary, e.g., brew link gpg2 --overwrite (use the above with `--dry-run` first; I only have one symlink tha
27.
▲
by
xorbyte
13y ago
Hushmail implements GPG, though perhaps it does not pass your definition of 'popular'. Any current implementation of GPG by _web email_ is probably insecure as it would rely on JavaScript cryptography. Perhaps when the W3C passes
28.
▲
by
xorbyte
13y ago
FWIW, someone on Crypto.SE reached out and received comments from DWave stating that it's not a problem in the foreseeable future. http://crypto.stackexchange.com/a/439
29.
▲
by
xorbyte
14y ago
This depends on intent. I don't want to confound exploration with activism, but there are many instances where damaging a company may be the ethical thing to do. In the long run, avoiding damage is in the hacker's continued interest to be a
30.
▲
by
xorbyte
14y ago
A CS degree has no bearing on one's ability to 'ship software', since that's not what a CS degree is meant for. I see a lot of disappointed second-years want to be taught how to better write software, but they're in a CS degree because it c
More ›