HN user

aj3

731 karma
Posts22
Comments266
View on HN
www.nasa.gov 2y ago

Thinking Obliquely: Robert T. Jones, the Oblique Wing, NASA's Ad-1 Demonstrator

aj3
1pts0
web-highlights.com 3y ago

Web Highlights

aj3
1pts0
media.defense.gov 4y ago

Network Infrastructure Security Guidance (NSA) [pdf]

aj3
1pts0
medium.com 4y ago

I Track My Tasks in Obsidian

aj3
1pts0
www.vice.com 4y ago

But, Mr. Zuckerberg, How Do You Play Basketball Against a Hologram?

aj3
7pts0
pastebin.com 4y ago

Conti announcement about REvil server takedown by US Government

aj3
2pts0
www.reddit.com 4y ago

Ads are now able to bypass Google Play to install apps WITHOUT user consent

aj3
55pts15
www.digitalturbine.com 4y ago

Installing apps on a single touch (bypassing the app store)

aj3
3pts0
interestingengineering.com 4y ago

NASA Says Blue Origin 'Gambled' Its Chance to Build a Lunar Lander Away

aj3
35pts3
msrc.microsoft.com 4y ago

BitLocker Security Feature Bypass Vulnerability

aj3
3pts0
github.com 4y ago

iOS on QEMU

aj3
1pts0
www.vice.com 4y ago

Scientists Just Ruled Out an Explanation of a 16-Day Signal

aj3
5pts0
threatpost.com 4y ago

Microsoft Warns: Another Unpatched PrintNightmare Zero-Day

aj3
21pts0
twitter.com 4y ago

Robert Graham evaluates Mike Lindell's data

aj3
7pts1
en.wikipedia.org 4y ago

Nirvana Fallacy

aj3
1pts0
joonas.fi 4y ago

SAML Is Insecure by Design

aj3
300pts180
support.microsoft.com 4y ago

Mitigating NTLM Relay Attacks on Active Directory Certificate Services (Ad CS)

aj3
2pts0
www.zdnet.com 5y ago

Another Vulnerability in PrintSpooler Service

aj3
2pts0
warsus.github.io 5y ago

A Commentary on the Sixth Edition Unix Operating System

aj3
3pts2
www.microsoft.com 5y ago

Securing our approach to domain fronting within Azure

aj3
2pts0
news.ycombinator.com 5y ago

Ask HN: Security-Oriented HN Alternative

aj3
1pts1
news.softpedia.com 5y ago

Linux Is Becoming the Windows Alternative Microsoft Never Wanted

aj3
2pts2

The strategy that MEV bots use is not a law. It is not even defined or endorsed by Ethereum standards, and arguably is not an intended feature of the network.

You could alternatively claim that the guys defined their own protocol which addressed market inefficiency (which MEV is). Imo it's insane to claim that a trading technique you invented should have zero risk, and any losses you take are an indication of theft.

Tokens are property.

What law says this? Technically, tokens are smart contracts, basically OOP classes with both data and behavior. They also by design have public methods which are meant to be triggered by anyone on the chain. It's not at all obvious that triggering these methods in an unexpected order or with unexpected data is breaking any laws whatsoever. It's bytecode anyway, so there's no human readable EULA's or explanations on what you're allowed to do with the token.

But you're not signing EULA's in order to participate in the network. Moreover, there are no real "laws / regulations" within the network either, specifying what you are or are not allowed to do. Ethereum standards merely determine how the software is supposed to work, but even then I'm sure Ethereum devs would oppose treating their docs as an agreement (because they don't offer any warranty, licensing or attestation). Moreover, there is an express goal to have a diverse set of software clients, so even developing your own software to be interoperable with existing standards can't be constructed as "an attack".

All this to say, I just fail to say how this can be constructed as "changing the terms of the transaction". There was no legal agreement between parties and no existing precedent to treat this as a malicious attack at all.

All I see is a Wall Street establishment pulling strings in order to protect their investment, by asking for a sudden government oversight in the system that was built with the express goal of not requiring any government oversight.

My Pinephone Setup 4 years ago

Android has different security guarantees compared to desktop/server Linux. E.g. people should expect that none of the installed software can hijack the phone completely and that most damage from malware should be mitigateable by uninstalling malicious app.

There were over a dozen of 0day exploits this year alone. Some used in water hole style attacks, so not even that targeted. And these are state of the art incidents which would have pwned even users with all the updates installed.

After the patch has been pushed out, exploits become progressively cheaper so letting users to postpone security updates is a crime.

Right. Session is stored either in cookies or in Local Storage. Both get cleared when you "clean cookies". If there is no device session, next time you're trying to log in, service will ask to show the second factor (so that hacker can't steal your account through finding the password on some other website).

Firefox didn't work, because person deleted session and didn't have second factor (nor backup auth methods). Chromium worked, because it still had device session.

I'm traveling and using TOR and VPNs just like everybody else and haven't faced any issues. There most definitely is a problem with communicating security/accessibility tradeoffs to the public though, so I'm not putting blame on the op here.

AFAIK, there are exactly two ways to avoid getting phished. One is using physical security keys (not implemented everywhere and we can't expect everyone in the world to buy one). The second one is checking the domain you're in.

Please, do elaborate on what other ways of phishing preventions you have in minds.

Archived version: https://archive.md/z3t8O

Note that it uncritically accepts report from 2009 which according to company was meant to be risk modeling exercise. Authors outright dismiss everything either KPL or CapGemini has to say themselves and does not even try presenting mitigations that presumably have been put in place, changes in infrastructure since 2009 and other more contemporary reports.

From the security perspective both snaps and flatpaks are preferable to dep/rpm for browsers, email clients, office suite, document viewers and other stuff that is used to parse untrusted data often (due to [wip] sandboxing and auto update).

Snap packages are better maintained (more often with direct involvement of the app developer) and generally receive updates a bit earlier than flatpak. In both cases you need to pay attention who the app maintainer is and I'd argue that in case of unknown maintaners deb/rpm packages are safer choice.

That's exactly what's happening right now. But before NFTs the most plausible ways were either opening a business accepting crypto (not unlike meatspace money laundering involving cash-accepting businesses) or having lucky strikes on gambling platforms (where you can play against yourself).

For a larger operation going business route is still preferable but on an individual level NFTs are much easier due to ridiculously high margins that have been normalized there.

How do you check who was the first in practice? Blockchain is large and will grow larger. NFTs hold URLs not hashes, so the same artwork could be represented by multiple hashes. The url could also point to a different artwork now compared to what was there before.

More importantly people don't work like that. In practice most "fake news" are based on quote mining which is easy to disprove without any knowledge of cryptography whatsoever by just checking the original source, but people share this crap without any verification because it conforms to their beliefs.

Technical solutions won't fix social issues.

Yes, but if you buy the watch you can put it on your hand, use it and show it to me. NFT is more akin to a photo of an invoice from the workshop you attended - it might have some sentimental value to you, but it's not a watch, does not have intrinsic value and I don't have to respect it.

So what? Say you have an account X which holds funds from criminal operations (e.g. ransomware payments). If you cash it out directly there's no doubt you're a criminal. But if you use that money to pay yourself for an NFT, now you can possibly deny that you have any knowledge about source of X income.

Better yet send money from X through a bunch of privacy oriented tokens like monero, tumblers and mixing services, losing 20-50% in the process and consolidating the rest in account Y. Now you have plausibly clean money but you can't pay taxes yet as there's no paper trail for this income. Solution is easy, buy an NFT from yourself, declare it, pay taxes and buy a new yacht.