Unless you have access to a mobile phone's baseband source code, you cannot really trust anything about its level of security.
This was discussed on HN a while back and comes up quite often:
HN user
Security analyst and researcher based in Vancouver, British Columbia.
https://cariad.keigher.ca
Unless you have access to a mobile phone's baseband source code, you cannot really trust anything about its level of security.
This was discussed on HN a while back and comes up quite often:
(ignore what I said here)
Not the best link but here's something to chew on:
http://www.universetoday.com/15403/how-long-would-it-take-to...
However, despite these advantages in fuel-efficiency and specific impulse, the most sophisticated NTP concept has a maximum specific impulse of 5000 seconds (50 kN·s/kg). Using nuclear engines driven by fission or fusion, NASA scientists estimate it would could take a spaceship only 90 days to get to Mars when the planet was at “opposition” – i.e. as close as 55,000,000 km from Earth.
But adjusted for a one-way journey to Proxima Centauri, a nuclear rocket would still take centuries to accelerate to the point where it was flying a fraction of the speed of light. It would then require several decades of travel time, followed by many more centuries of deceleration before reaching it destination. All told, were still talking about 1000 years before it reaches its destination. Good for interplanetary missions, not so good for interstellar ones.
There's talk of other drive systems being able to pull it off but this is the only one that actually has been tested but never built to scale.
Keep in mind that at best it would take maybe 1,000 years with current technology to get there with a probe or human-supporting ship. It would be highly unpopular however as it involves exploding nuclear bombs behind the craft to get it there that fast--that and it would probably cost trillions to build the thing.
You're assuming that they have a vested interest in holding their Bitcoins for some greater good.
PBKDF2 is not for password storage.
If the server had bcrypt configured to take a second per password, multiple everything by 4. And so on. What I think is needed as a supplement to "use bcrypt / scrypt" is a "and use it this way so you don't accidentally open your server to DoSing or give a poor experience", because a 10 seconds-to-compute-on-a-Xeon hash is great from a security standpoint if your hashes get leaked, it sucks from a user experience to have to wait at least 10 seconds to login, and if you have to service multiple logins at once your server's not going to be able to do anything else if you just use bcrypt/scrypt synchronously.
If you're in a situation where you're needing to rely on hashing a user's password for every action, your application has far worse problems than what password storage method is in play. Moving from your current password storage method that is inadequate to one that would be better also takes into account that you haven't done something completely wrong with session states.
[edit]
I misread the poster I was responding to assuming that they meant that the user was re-authenticating on each request. My thought process was that if they're storing credentials in a cookie in lieu of a session ID then that needed to be addressed first before even going down the avenue of correcting password storage.
As part of a presentation I did at a local OWASP chapter, here are some numbers based on just using CPython's Hashlib processing of 14,000,000 someodd passwords:
Intel Xeon E5-1620 3.6 GHz: SHA: 8.16 seconds, SHA256: 11.01 seconds, MD5: 8.7 seconds
AMD FX-8320 3.5 GHz: SHA: 10.63 seconds, SHA256: 13.49 seconds, MD5: 10.06 second
Intel Celeron N2840 2.2 GHz: SHA: 32.4 seconds, SHA256: 39.75 seconds, MD5: 28.95 seconds
Intel Pentium M 1.7 GHz: SHA: 37.98 seconds, SHA256: 48.12 seconds, MD5: 34.49 seconds
SHA512 isn't going to make it much better.
A weak password is a weak password no matter how good the hashing is. I think that you're referring to this bit from last year:
http://www.pxdojo.net/2015/08/what-i-learned-from-cracking-4...
The author of this piece was doing about 156 hashes per second and after just over five days, he had only gone through and cracked 4,000 account passwords--we're talking 0.0001% of Ashley Madison's supposed userbase here. To run just over the 14,000,000 passwords from RockYou.txt on every single user account from AM, it would take up to at least two billion years.
No. You cannot effectively use the techniques you can use against SHA/MD5 to attack the three I mentioned.
SHA and MD5 can be calculated entirely in a CPU's registers without having to rely on RAM. Bcrypt for example requires the use of a matrix as part of its calculation, slowing down the process. A GPU has so few channels from the processor to memory that it cannot be effectively done in parallel.
All one has to do with Bcrypt is just adjust the difficulty and any advances in GPU technology or whatever can be nullified.
There are several services (including one run by me).
https://canar.io (mine)
Mine lets you free-form search whereas HaveIBeenPwned is there for searching just e-mail addresses.
Any developer today that is developing an application and isn't using something like Argon2, Bcrypt, or Scrypt should be considering a plan to move away from whatever they're currently using yesterday. There is no reason to be using anything less than those three and continued use is in my mind negligence.
If at all possible you shouldn't be storing passwords to begin with and instead relying on another service for authentication.
This should be the takeaway from this article.
A few people will donate bitcoin. A few things can be bought directly with bitcoin. On average, you'd expect that the fraction of your income paid in bitcoin would be similar to the fraction of goods and services that you can pay for with bitcoin.
The point of donating money to the author of the piece is to encourage them to continue writing this epic story. Giving them Bitcoin is akin to leaving a tip to your server where the tip appears to be currency but rather instead is a Chick tract with the suggestion that you'll pray for their soul.
gratipay offers bitcoin payments, which, if they implement it right, would eliminate the middleman [...] when the financee cashes out using bitcoin
And tell me, how does one cut out the middleman when they convert their Bitcoin earnings to US dollars or whatever currency they prefer?
As far as unauthorized use of campus resources, I think the university would be better served by suing AT&T for failing to adequately protect its network.
It is not the responsibility of a network service provider to protect the assets of a customer. If you're given a network link and an allocation of IP addresses, it is your responsibility to use them wisely and securely.
Or maybe universities and organizations could teach their employees to handle network security better.
This is more sane thinking.
It should be noted that what weev was doing is nothing new and is really just this:
$ cat payload.ps |netcat -q 0 $printer_ip 9100
This is what was originally posted:
WIND Mobile. The plan isn't offered any longer but there are similar ones available.
France and Austria, unlike Canada are very much dense so the infrastructure required to setup an LTE/UMTS/etc network is less costly.
To travel from Vancouver to the next principal Canadian city (Calgary), it requires 900 KM of driving and there's only really one metropolitan area of sorts between the two, meaning that you're going to be setting up cell towers that handle only so much traffic in a day.
As a result, to get service where you end up with just traffic shaping once you go beyond 6 GB (beyond that there is no real limit really), you need to go with a carrier that only services the larger cities. So in my case, my carrier services just Vancouver, Edmonton, Calgary, Toronto, and Ottawa, which are fairly dense areas with a combined population of 18 million or so, or just about half of the country's population. Once I leave the city, I have to piggyback on to other carriers however.
Hence why mobile carriers suck in Canada because the bigger carriers do not want to eat into their fairly large profit margins. They can afford to offer such plans, but they simply don't want to.
For the record, I pay $40 CAD/month ($30 USD or 27 EUR) for unlimited North American calling and text plus the "unlimited" data use.
$399 USD is great, but why are we still stuck with 16 GB of storage on base model phones? You can barely put a day's worth of music on your phone and you cannot always stream via services like Spotify.
Spotify accounts for 2 GB of traffic per month on my phone and some plans are barely affordable when you want more than that--fortunately I can do up to 6 GB before I am traffic shaped, but that isn't the say the same for all carriers in this country.
I believe that the passwords were exposed in the breach but at the moment I don't have them to look at.
Generally I recommend that if you think that your password has been exposed that you just reset your password as if you have to ask that question then you might want to reconsider your password reuse.
Yup. Coming down the pipeline will be hashing of suspected password lists being posted too.
(I am the creator of Canario)
Every app that runs on your systems with enough privilege could sniff your username and password and send it out.
Every app that runs on your systems with enough privileges can dump the memory and extract information via that.
Conservatives in the UK are not alone; they're taking a page from the Tories in Canada where Harper did the same thing.
http://www.cbc.ca/news/technology/faq-the-issues-around-muzz...
Here's a better question: how do you qualify a "good" anti-virus engine?
I met him when he was visiting Vancouver a few years ago and had exchanged e-mails with him a few times. It's really sad to see him pass away.
12,000 transactions per hour translates to 200 transactions per minute or 3 per second. However, you're being generous here because what you're suggesting is what it currently does at best, when in reality it is anywhere between 1 and 3 transactions per second, meaning that it is doing anything between 86,400 and 288,000 per day--that's a large spread.
Visa claims it can do 2,000 transactions per second or 172,800,000 per day and Paypal suggests its maximum is 115 per second or 9,936,000 total per day [1]. At best, Bitcoin is able to handle 3% of the volume that Paypal is able to and it doesn't even register as a blip when compared to a single major credit card.
If we continue to read the link I cited for those numbers, we get these details:
Let's assume an average rate of 2000tps, so just VISA. Transactions vary in size from about 0.2 kilobytes to over 1 kilobyte, but it's averaging half a kilobyte today.
That means that you need to keep up with around 8 megabits/second of transaction data (2000tps * 512 bytes) / 1024 bytes in a kilobyte / 1024 kilobytes in a megabyte = 0.97 megabytes per second * 8 = 7.8 megabits/second.
This sort of bandwidth is already common for even residential connections today, and is certainly at the low end of what colocation providers would expect to provide you with.
If we were to expect that everyone was to get onboard the blockchain, we would have to assume that we're all going to start sucking up 0.97 MB per second, or about 82 GB a day. This would mean that in a month, one would use just about 2.5 TB of bandwidth. If the average residential user were to want to transfer 2.5 TB for just a blockchain (ignoring modern life's pleasures like Netflix and other streaming services), you'd have to find an Internet service that would not impose a usage cap. As it stands with Comcast, if you exceed 300 GB, you'll get charged $10 USD for every 50 GB you use [2], meaning that a month's worth of transactions will cost you just about $450 on top of what you already pay for the privilege of having access to a blockchain.
This doesn't even take into account that transactions are replayed once confirmed so those numbers could end up even higher if the whole protocol isn't changed. Heck, I am not even taking storage into account which is a different problem all together.
The idea that blockchains are going to be the future is pure lunacy. It's either going to be limited to data centres that can handle this load or it's not going to be used at all. It has no future for the general public and is part of the reason why Bitcoin in itself is not practical.
[1] https://en.bitcoin.it/wiki/Scalability - Bitcoin's "official" wiki backs this up
[2] https://bgr.com/2015/11/19/comcast-data-cap-2015-bad-for-us-...
Meanwhile, with most credit cards, the entire interface is that you hand out the secret directly. Maybe they'll even make a carbon copy of it with a click clack machine depending on where you live, and this is acceptable. So acceptable that here in 2016, on-the-fly credit card numbers is a niche service offered by a few companies and you need to install a desktop Adobe Flash app to even use it.
You're overlooking something here.
Ignoring the fact that the merchant won't typically see the credit card number if I am using it physically, you are correct that I have to offer it up to them if I am using an online store. However, there is an important distinction between a credit card number and a Bitcoin private key that you're neglecting to look at here.
A credit card number is just a reference to an account between the card holder and the issuer. In a situation where the credit card number becomes exposed via negligence not on the part of the card holder, the card holder themselves in almost all situations is not liable for the charges incurred that were not of their own. So if Target for example gets breached like they did in 2014 where millions of credit card numbers were exposed, the account holders of those affected cards are not on the hook for any purchases that they did not make. In fact, issuers and payment processors were largely able to determine who was affected and issued new cards very quickly.
The only situation I can easily recite where you are on the hook for your credit card number being exposed is if you willfully expose it to a third party. It is at this point that the credit card issuer can tell you to effectively "buzz off" and pay for the undesired purchases.
In the situation where the card becomes compromised, the solution for the issuer is to issue a new credit card number and then to deny all use of the previous number going forward. All charges are then reversed and it's a matter between the payment processor and the merchant to flesh things out. In a few days the consumer will have a new card and even in extreme cases with certain classes of credit cards, they'll have a card hand-delivered to them within 24-hours.
With Bitcoin, if the private key becomes exposed (and there are many, many ways for this to occur), then there is no recovery nor any third party to rely on to get the coins back. You're effectively out of luck and must then generate a new private key and public key and start anew.
Also with Bitcoin you need to install a third-party application on your phone or computer in order to make use of it. I can easily send a payment via credit card via telephone, Internet, or in person.
For the things where reversing payments is a desired feature, you can build that on top of crypto-currencies (e.g. by using an escrow), so is not like it has to be the wild west.
As it stands with credit cards, it's 180 days maximum for a chargeback; meaning that the consumer has six months to make up their mind on any transactions they may not deem acceptable.
How long should it be in escrow if we're to switch to Bitcoin? I don't see how merchants will want to wait six months for them to see any payments and I don't see how consumers will want to see the timespan lessened.
Meanwhile, you give your credit card number to someone and they can just pull money out of it
Here's a Bitcoin private key: 5JcgxNrn4WFcA8trEix7ComAyLNEsDEyBqYVjEo8JaaXWQQNg1u
Now you have the ability to drain whatever coins are in that wallet and I'll never see them again unless you somehow decide to return them to me.
You can probably convince a layperson to give you their private key through the same means you could ask them to tell you their passwords or whatever personal information they should not divulge.
As you use your credit card, over time you give more and more people a direct line of access to your credit until it expires or gets revoked.
Credit cards are a form of payment. I go and pay my bill for using that credit card. A month before the card expires, the issuer sends me a new card. Provided I don't neglect to pay my bill and don't abuse it, my credit card will almost always allow the transaction to go through immediately.
Until I can generate credit card numbers on the fly with one-time-use amounts of money, I'll have a use-case for Bitcoin.
https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
"To access the ShopSafe service, sign in to Online Banking and choose Use ShopSafe from your credit card Account Activity screen. Enter your spending limits and the ShopSafe service will automatically generate a temporary 16-digit account number, with expiration date and security code, that allows you to complete your purchase while protecting your privacy."
https://www.cardbenefits.citi.com/products/virtual-account-n...
"When shopping online or by mail order, you can use a randomly generated Citi card Virtual Account number instead of your real account number. Simply click Enroll in/Get below to begin using Virtual Account Numbers.
All purchases made with your temporary number will appear on your monthly statement with your other purchases and will include the Virtual Account Number that was used for each transaction."
As someone who has been robbed by PayPal I find bitcoin to be quite useful.
So I buy a service with Bitcoin and it ends up being fraudulent, how do I get my Bitcoins back?
If I buy a service with my credit card and it ends up being fraudulent, how difficult is for me to get the charges reversed?
One of them relies on the fraudster having a change in heart and the other may not necessarily be fun but is more than likely to happen.