HN user

16s

3,211 karma
Posts57
Comments891
View on HN
16s.us 12y ago

Decrypt to Anything

16s
2pts0
crashcoherency.net 12y ago

Misuse of Encryption in KusabaX

16s
2pts0
www.adafruit.com 12y ago

Tor in a Box

16s
2pts0
www.fireeye.com 12y ago

New IE Zero-Day Exploit in Memory Only

16s
3pts0
16s.us 12y ago

Crack Passwords Without Hashes

16s
1pts0
16s.us 12y ago

Source Code to a Passive Keystroke Logger

16s
1pts0
16s.us 12y ago

One Time Pad Contest

16s
1pts0
16s.us 12y ago

Exfiltrate Files with DNS Queries

16s
44pts26
blog.avast.com 12y ago

Linux Trojan “Hand of Thief”

16s
76pts61
16s.us 12y ago

Exfiltrate Data with DNS (With Source Code)

16s
3pts0
trouble.org 12y ago

Extraordinarily Fast UDP Scanner

16s
2pts0
16s.us 12y ago

Crack this Homemade Crypto System and Win a Cool Prize

16s
2pts0
16s.us 13y ago

Decrypt to Any Message

16s
3pts0
16s.us 13y ago

Decrypt the Same Message to Different Strings

16s
4pts0
16s.us 13y ago

Free One-Time Pad Encryption Software

16s
1pts1
twitter.com 13y ago

Encryption the NSA can't crack

16s
2pts0
twitter.com 13y ago

A One Time Pad Encrypted Message

16s
1pts0
16s.us 13y ago

Counting Bits - Time and Space Why it's Important

16s
2pts0
www.youtube.com 13y ago

NSA & Obama - Can You Hear me Now?

16s
7pts0
16s.us 13y ago

Keystroke Logger Source Code - Republished

16s
2pts0
www.youtube.com 13y ago

Ted Nugent - Free Men and Women Have the Right to Defend Themselves

16s
1pts0
16s.us 13y ago

Free TrueCrypt Hard Drive Password Cracking

16s
39pts25
16s.us 13y ago

Bruteforce TrueCrypt Encrypted Disk Passwords

16s
1pts0
nplusonemag.com 13y ago

Leave Your Cell Phone at Home

16s
11pts0
twitter.com 13y ago

Twitter and One Time Pad Encrypted Messages

16s
4pts3
16s.us 13y ago

Cracking Passwords on an Intel Celeron CPU

16s
72pts20
16s.us 14y ago

Calculating the Bit-Strength of Real Passwords

16s
4pts0
16s.us 14y ago

Microsoft Active Directory Password Hashes are Plain MD4

16s
2pts0
www.openwall.com 14y ago

Solar Designer on Password Hash Storage

16s
8pts0
news.ycombinator.com 14y ago

Walled Gardens are Driving me to JavaScript

16s
55pts71

Often times, the hack is through a web front-end. Back-end systems (such as DBs) are heavily firewalled, logged, monitored, etc. and are generally very well protected. Systems guys (OS and DB) know security pretty well and have been doing it for a long time now.

Much of the web software that powers the front-end is complex (PHP, Java, .Net, JS, CSS, SQL, includes, 3rd-party libraries from everywhere, etc). That complexity has a broad attack surface that is difficult and time consuming to test. And many devs are late to the security party (unless we're talking OpenBSD developers).

Management wants to push out new features by X date. Devs have very little time to test and are behind on security anyway. Hackers have all the time in the world to poke at the web front-end and test every possible combination of things until they finally get in.

In a nut-shell, that's the problem as I've seen it.

This is the same reason I re-wrote a lot of my Python code in C++ many years ago. Distributing one self-contained, statically linked executable just works and even the most clueless user can download and run it.

But I still use a lot of Python and I'm sure this guy still uses a lot of Ruby. Everything has its place.

Very well said. There is no one perfect programming language, no one perfect algorithm and no one perfect data structure for all problems and constraints you will face as a CS practitioner.

Really, a CS education is just preparing you to pick the right solution for the problem/constraints at hand. For example, you can loop through a list. That approach works fine. However, when you begin to scale, you may find that look-ups against a tree-based data structure or perhaps a hash table are much more time efficient at the cost of more complexity, more space and more educated programmers.

Great read. This sentence sums it up best I think, "Why, why, why would people expect to get great results if they flaunt all the best-practices that have developed over the past 20 years?"

The world is all about trivialities today and escapism (let's not face reality). Especially in the West. Young men and women (in general) don't really mature until their mid 30s and some never do.

We have an entire generation of people distracted every 30 seconds by fart apps, juvenile videos and self-photos in the bathroom. We need more engineers, doctors and lawyers and serious thinkers.

Maybe I'm just getting older, but that's my honest opinion.

Triple rot13 (like Triple DES) is government approved.

    echo -n word | \
    > wm --rot13 --words stdin | \
    > wm --rot13 --words stdin | \
    > wm --rot13 --words stdin    

    result: jbeq
However, the result is the same as a single round.
    echo -n word | wm --rot13 --words stdin

    result: jbeq

Security through obscurity is useless. I have heard people repeat this for the last 20 years. They are wrong and they have no idea what they are talking about. They just parrot what others say. Like chaos it perpetuates itself.

We camouflage tanks. We build stealth fighters. If obscurity had zero value, we'd just paint the tanks bright pink with hot orange flames and drop all the stealth research too. No need to sneak around. Obscurity is useless right?

Hide from the bear and it might not find and eat you. Move your ssh port and your logs will have less idiots out there filling them up. That fact alone is worth changing ports.

Obscurity has its place along side other tactics. And when you put it all together, you'll have a more secure system.

So please cut the "Security through obscurity" crap.

The way I read the standard, the string 'soccer1' is a valid/compliant PCI password. At least it for PCI-DSS v2.

8.5.10 Require a minimum password length of at least seven characters.

8.5.11 Use passwords containing both numeric and alphabetic characters.

In fact, the string 'password1' exceeds the requirements.

There are large working Python 2 code bases in a lot of organizations. It works great. Fabulously reliable. Extremely well-tested. Been running great for years. They have no desire or need to upgrade and will run Python 2 and pay devs to maintain it forever.

Welcome to the real world.

Some words should be universal... like shark. But I don't think start-up falls into that category.

Any sane person would be afraid of them.

Lay in this tunnel. You're immobilized and can't move. Oh and no one can hear you call for help because of the loud jack-hammer like sounds. Wear these head-phones and we'll blast music into them so you'll feel better. Squeeze this little thing if you panic and we may come and help you.

Microsoft turned Windows 95 into a full-fledged multi-user operating system. Segmented user space? Unix had done that for years. All users where admin and it was horrible, but lot's of apps ran on it, so people bought it and used it. Then they merged Win95 into WinNT and gave us Windows 2000.

Now they are turning a full-fledged multi-user OS into a tablet OS. Let's make this tank into a bicycle. History tells us there will be a few painful years.

I use C++ because of the std containers (vector, map, set, etc). I don't have to roll my own and I'm free to think about the problem at hand rather than how to get the proper data container for this, that and the other.