HN user

alexwright

77 karma
Posts0
Comments50
View on HN
No posts found.
Gate Tower Building 13 years ago

"Normally, highways are still built underground in these cases, and passing through a building is an extremely rare occurrence."

Did they mean underground? Seems like an underground motorway would be even more impressive or unusual than this building.

All the cable modems I've used (UK) have always downloaded a an image over TFTP on boot. As I understand it they can come up with a very minimal loader and reach out for their config to the local "node" for configuration, and this can include new firmware. On the support line they're adamant that you reboot the things before proceeding past the IVR. Which makes sense.

The last I heard about it the different levels of service (bronze/silver/gold they were at the time, 5/10/20Mbit/s) are just based on the MAC the modem sends on this initial config/handshake. When I moved from 20 to 50 I was told to reboot the modem and it came up will an all new shiny more craptastic than ever web interface as well as setting it's WAN port to 50Mbit/s

I should have said for a product like Lavabit, ie mail as secure/private as SMTP likely gets right now, I hope it wouldn't be unreasonable. However, in my heart of hearts, I knew it was too much to ask for.

I guess anyone that knows how to create and setup a client side TLS cert and key would also already know privacy and SMTP can't really live together, and would setup a deaddrop for gpg encrypted messages.

You can have a client side key BTW. It's a complete dick to setup and each UA is different so it's really not viable for a product for the unwashed masses. But for something like Lavabit I don't think would be unreasonable.

When I attempted a similar thing on a C64 the external 5.25" disk drive was similarly inoperable. Turned out the elastic bands from the motor to the little ring that camped the disk had just gotten too lose with age.

Was a pain in the ass finding one that was tight enough to stay on and not to tight just just stop anything moving but got it eventually.

Might be worth popping the lid off and checking yours?

This is just a common misconception over what Moore said, and what his law means. Hint: it has nothing to do with the clock speed or even directly the prefromace of your CPUs.

Moore's law is the observation that, over the history of computing hardware, the number of transistors on integrated circuits doubles approximately every two years. Which is still very much the case: http://en.wikipedia.org/wiki/File:Moore%27s_law_graph.svg

Bitcoin doesn't work by passing tokens around to represent the value. In a Bitcoin spend the value is simply added to the wallet/address's balance. Any further spend is deducted from the wallets balance.

The "coin" is not a single token that lives on and is broken apart to be spent, so there's no way a coin could self destruct after being transferred.

I'm using the onboard/ondie Intel HD4000 and it works. You might have a driver that is blacklisted. Chrome and I think other browsers have a list of drivers known to allow execution of dangerous shader code and block WebGL in those cases.

This is what sdfjkl is intending I think. Have the TVs/Whatever on the other side so they can't scan your network shares to get the information to send back the HQ.

I would be much more effective, straightforward and ultimately more useful though, to firewall the TVs from the internet outbound so they can collect data all they like and never send it home.

Unknown drivers? How much do you know about any of the other drivers for any of the hardware? Most NICs and Video chipset drivers now come with a binary blob you have to feed it, it's completely opaque binary microcode.

As far as video hardware goes Intels is far more open than the other two vendors of actual useful video hardware anyway.

Or reply in some side channel, piggy back the next (expected, ie when the user has switch back to normal mode) UMTS radio packet for example. I don't know the packet structure but I expect there are areas that could be re-purposed covertly. We did after all fit the entire SMS system into such a space.

The radio interface could listen/wait without even replying, ie wouldn't make the GSM RFI speaker noise. If governments, carriers and law enforcement could all manage to use this so incredibly rarely that it's never been observed.. then it could be real.

Given the types of people that would have to have access / knowledge of this though. For example people that suspect their partner of infidelity and is on the police liaison team of a carrier say...

I agree it's very unlikely, someone would have noticed it by now.

A form to enter the sha1 of your email address so they can check against a list of addresses they've already sha1ed? And a form that takes the email for people that don't give a shit or don't know wtf a sha is.

Maybe just a .txt of the hashes too, but then no ones coming to your web service I guess.

What you planning to do with my public keys? Or worst case encrypted private keys.

Now putting something into ~/.ssh/...

When I stick a AA battery on a Peltier, to work out which side is which on unmarked unit, it actually does "feel" very cold really quickly. Hot side is obviously also very hot, very quickly.

I'd think it's more likely that the hot side is going to be the problem. Dissipating that heat without something like liquid cooling and active fans.

Zoomquilt 13 years ago

I dunno about everyone else, but on this 24" Dell IPS I can see the next image being loaded and then scaled, does it every few seconds. The details starts getting a bit blurry them pop, new asset super imposed and we start scaling.

A) That's what they were after though: “all information necessary to decrypt data stored in or otherwise associated with [the account].” A rogue cert and MITM would get the password for the account though, unless B.

B) Anyone who knows what they're doing and has something they really want to keep secret? Maybe if someone had such a secret they'd learn to check the cert, maybe even install an extension that would highlight unexpected changes.

The way I've handled it in the past in Varnish is just to look for the upgrade request and do basically: "Whao they wanna do websockets? I give up, return(pipe);" which means Varnish will from then on just ferry bytes from one sock to the other.

With a different key though.

Once you've got this new cert. you can MITM, but you can't use it to decrypt the traffic already captured. Also anyone paying attention sees the cert. fingerprint change out of the blue.

CA like Verisign don't have the key though, this misconception is too common. If you're doing it right the CA is just signing a cert you've generated, they never see the key.

Cyber is pretty clearly defined among the people who use it. Other words are not.

Maybe the people using these terms (ie, people creating a "defence force" for the UK) should be more in touch with... more current lingo?

Sure would give them at least a vague sense of credibility if they called this something more like an internet/network orientated security... force.

On the otherhand, maybe these people having the massive tell of proclaiming "but this is CYBER." is a good thing? We know to dismiss what ever they're suggesting as uninformed and generally a terrible idea.