HN user

FredericJ

3,533 karma

meet.hn/city/ch-Lausanne

Socials: - FredericJ .at.hn - bsky.app/profile/fredericjacobs.com - linkedin.com/in/jacobsf

Interests: Cybersecurity, Entrepreneurship, Hardware, Mobile Development, Outdoor Activities, Open Source, Privacy, Remote Work, Research, Science, Running, Space Tech

---

https://www.fredericjacobs.com

[ my public key: https://keybase.io/fj; my proof: https://keybase.io/fj/sigs/e3rY17MpkBX1jZhBeZNehXRVLcKvDxglvCpgChFC5hE ]

Posts118
Comments65
View on HN
sifted.eu 2y ago

IBM sues a Zurich-based startup over 'unlawful' use of mainframe technology

FredericJ
4pts1
www.quantamagazine.org 9y ago

Graph Isomorphism Vanquished – Again

FredericJ
3pts0
europeanaviationnetwork.com 9y ago

European Aviation Network (EAN) for inflight WiFi over Europe is airborne

FredericJ
4pts0
www.fredericjacobs.com 9y ago

Check.torproject.org and IPv6

FredericJ
5pts0
forums.comodo.com 10y ago

Comodo has filed for express abandonment of LetsEncrypt trademark applications

FredericJ
302pts93
research.googleblog.com 10y ago

Announcing Google Research, Europe

FredericJ
197pts149
android-developers.blogspot.com 10y ago

Android N APIs are now final, get your apps ready for Android N

FredericJ
2pts0
x80.org 10y ago

JsCoq – Coq Proof assistant running in a browser

FredericJ
1pts0
www.fredericjacobs.com 10y ago

On SMS Logins II: An Example from Telegram in Russia

FredericJ
4pts0
www.fredericjacobs.com 10y ago

Axolotl and the Quantum Computers

FredericJ
2pts0
www.mathstat.dal.ca 10y ago

Quipper, a programming language for quantum computers

FredericJ
3pts0
community.hpe.com 10y ago

Zero Day Initiative Announces Pwn2Own 2016

FredericJ
3pts0
www.youtube.com 10y ago

Centriphone – an iPhone video experiment by Nicolas Vuignier

FredericJ
2pts0
www.fredericjacobs.com 10y ago

Revisiting the NSA Suite B Announcement

FredericJ
14pts1
blog.computationalcomplexity.org 10y ago

The Growing Academic Divide

FredericJ
2pts0
www.nsa.gov 10y ago

NSA releases first “transparency report” [pdf]

FredericJ
2pts0
www.fredericjacobs.com 10y ago

Some Bits from the NSA COMSEC Guide

FredericJ
2pts0
developer.apple.com 10y ago

Cryptographic Libraries

FredericJ
57pts13
medium.com 10y ago

The (failed) Economics of Android Security

FredericJ
4pts0
zerodium.com 10y ago

Million Dollar iOS9 Bug Bounty

FredericJ
95pts75
lessigforpresident.com 10y ago

Lessig runs as “Referendum President”

FredericJ
3pts0
szabo.best.vwh.net 10y ago

Essential reading about threshold secret sharing by Adi Shamir

FredericJ
1pts0
bits.debian.org 11y ago

Reproducible Builds Get Funded by the Core Infrastructure Initiative

FredericJ
2pts0
firstlook.org 11y ago

Popular security software came under relentless NSA/GCHQ attacks

FredericJ
6pts0
eprint.iacr.org 11y ago

How Secure and Quick is QUIC? Provable Security and Performance Analyses

FredericJ
11pts0
www.eff.org 11y ago

Who Has Your Back? Government Data Requests 2015

FredericJ
153pts46
medium.com 11y ago

The Fight for Root - A look into OS X System Integrity Protection

FredericJ
16pts1
www.theguardian.com 11y ago

Snowden files 'read by Russia and China': 5 questions for UK government

FredericJ
8pts1
www.apple.com 11y ago

Apple announces creation of two 20-megawatt solar farms to power stores in China

FredericJ
2pts0
medium.com 11y ago

Another reason for TLS: Iran filters websites using the HTTP “Host” header

FredericJ
1pts0

Just a quick warning though. A lot of those flights are not originating from the city or main airports. For instance, the "Brussels" flight they suggest taking is from an airport that is one hour away from Brussels (in Charleroi). It means that you will need to spend some more money to get to the city centres. These additional costs from "low cost" airports to the cities do add up to a significant amount on that entire itinerary. Just something to keep in mind.

This issue is intrinsic to the security model of Android before Marshmallow.

If an app is going to be able to send a contact, share a location, make a phone call ... all these permissions need to be demanded upfront, which I understand can be scary.

You also need to keep in mind that nobody is going to use "secure messaging" if it's a pain to use. You obviously don't want to be copy pasting contact information in the app for instance.

I'm glad to see that Android is following iOS's permission model where permissions are only asked at run time.

Isn't it ironic to see so much inline assembly while Apple is telling third party devs that they can't distribute binaries on WatchOS and that iOS apps are moving towards Bitcode too?

Apple's crypto people definitely know that assembly is key in performance and side-channel resistance of cryptographic implementations. They use it constantly. I guess at some point they will just ask 3rd party devs to call corecrypto methods if they want to use encryption in Bitcode apps.

But this means that you'll have to wait for Apple to implement whatever primitive you need for your app. Good enough in most cases but encryption apps with special needs will find this annoying.

Especially since a few implementations are actually borrowed from open-source projects. The 25519 implementations are from DJB's supercop for signing and Adam Langley's Donna for ECDH, both available online with open source licenses.

Important: The headline was modified since I submitted this. Apple didn't actually open-source the code. They give you a 90-day licence to read the code.

Apple grants you, for a period of ninety days from the date you downloaded the Apple Software, a limited, non-exclusive, non-licensable license under Apple's copyrights in the Apple Software to make a reasonable number of copies of, compile and run the Apple Software internally within your organization only on devices and computers you own or control for the sole purpose of verifying the security characteristics and correct functioning of the Apple Software;...

In this specific case, DMCA doesn't apply. But it's interesting to read GitHub's policy about taking down forks.

GitHub will not automatically disable forks when disabling a parent repository. This is because forks belong to different users, may have been altered in significant ways, and may be licensed or used in a different way that is protected by the fair-use doctrine. GitHub does not conduct any independent investigation into forks. We expect copyright owners to conduct that investigation and, if they believe that the forks are also infringing, expressly include forks in their takedown notice.

https://help.github.com/articles/dmca-takedown-policy/

The issue is that you're not Google's client. Maybe buy something from them (a large amount of ads), then try to get support?

For those not familiar with Craig Murray:

- former British ambassador to Uzbekistan

- he accused the Karimov administration of human rights abuses, which he argued was a step against the wishes of the British government and the reason for his removal.

- complained to the Foreign and Commonwealth Office that intelligence linking the Islamic Movement of Uzbekistan to al-Qaeda was unreliable, immoral and illegal, as it was thought to have been obtained through torture

- was subsequently removed from his ambassadorial post on 14 October 2004

Source: https://en.wikipedia.org/wiki/Craig_Murray

Edward Snowden had predicted a radicalization of a class of professionals. We're coming to the point where, similarly to nuclear physicists after Hiroshima, we decide as a community to not let our skills be used for unethical purposes.

[dead] 12 years ago

It's based on vulnerabilities disclosed in Stefan Esser's iOS security workshop.

Put.io 12 years ago

Hey, I was one of the movies.io guys. We did remove the torrenting part of the website more than a year ago.

Before that, you could indeed pick a film, download the torrent in the cloud and directly stream it from our web interface.

Good old days but we all moved on to new challenges.