HN user

bengross

109 karma
Posts22
Comments9
View on HN
www.networkworld.com 13y ago

A gift guide to please any geek ... 25 years ago

bengross
1pts0
www.messagingnews.com 14y ago

Your New Year's Resolution--Pick Better Passwords

bengross
1pts0
www.messagingnews.com 15y ago

ForeverSave Prevents Lost Work on the Mac

bengross
1pts0
www.messagingnews.com 15y ago

Pros and cons of Time Machine vs. CrashPlan for Mac backups

bengross
1pts0
www.webecologyproject.org 15y ago

Make people powered botnets of Twitter zombies with Mechanical Turk and Pawnfarm

bengross
2pts0
www.messagingnews.com 15y ago

Why Pinboard.in Is My Favorite Alternative Bookmarking Service to Delicious

bengross
55pts36
www.messagingnews.com 15y ago

Disk is cheap, your time is not. A simple and effective backup strategy for OS X

bengross
1pts0
www.messagingnews.com 15y ago

Data Evaporation and the Security of Online Identities

bengross
1pts0
www.gpgmail.org 15y ago

GPGMail - OpenPGP for Apple Mail and GPG Keychain Access for OS X

bengross
1pts0
www.messagingnews.com 15y ago

How and Why to Sniff Smartphone Network Traffic

bengross
3pts0
www.orbicule.com 15y ago

Safari Extension to enable Incognito mode for Google and Facebook

bengross
1pts0
www.readwriteweb.com 15y ago

Developers Can Now Access Locations of 250 Million Phones Across U.S. Carriers

bengross
30pts13
www.messagingnews.com 15y ago

No Frills SSL Certificates are Inexpensive and Useful

bengross
3pts1
www.messagingnews.com 15y ago

How to Email a Complete Web Page From Any Browser

bengross
2pts1
www.messagingnews.com 16y ago

How Standard is FaceTime on the iPhone? Packet Capture Verification

bengross
1pts0
bengross.com 16y ago

IPhone Screenshot and Photo Smart Album Hack

bengross
1pts0
www.messagingnews.com 16y ago

Preparing Your Site for the iPad

bengross
1pts1
www.messagingnews.com 16y ago

Markdown Simplifies Writing for the Web

bengross
3pts1
www.messagingnews.com 16y ago

Why Does My Text Look Funny? Character Set Encoding Detection and Conversion

bengross
4pts0
www.messagingnews.com 16y ago

The State of User Tracking and the Impossibility of Anonymizing Data

bengross
7pts0
www.messagingnews.com 16y ago

Trends in Password Masking Security and Usability

bengross
1pts0
www.messagingnews.com 16y ago

A Better Way to Share Links in Email

bengross
1pts1

I wish the article's author had done a little bit of background work to find references to the CCC presenter's research.

Here is the paper published last year describing the research on fingerprinting. The second URL at uni-regensburg.de does not require an ACM account to download the paper.

Website fingerprinting: attacking popular privacy enhancing technologies with the multinomial naïve-bayes classifier http://portal.acm.org/citation.cfm?doid=1655008.1655013 http://epub.uni-regensburg.de/11919/1/authorsversion-ccsw09....

Dominik Herrmann, University of Regensburg, Regensburg, Germany Rolf Wendolsky, JonDos GmbH, Regensburg, Germany Hannes Federrath, University of Regensburg, Regensburg, Germany

"Privacy enhancing technologies like OpenSSL, OpenVPN or Tor establish an encrypted tunnel that enables users to hide content and addresses of requested websites from external observers This protection is endangered by local traffic analysis attacks that allow an external, passive attacker between the PET system and the user to uncover the identity of the requested sites. However, existing proposals for such attacks are not practicable yet.

We present a novel method that applies common text mining techniques to the normalised frequency distribution of observable IP packet sizes. Our classifier correctly identifies up to 97% of requests on a sample of 775 sites and over 300,000 real-world traffic dumps recorded over a two-month period. It outperforms previously known methods like Jaccard's classifier and Naïve Bayes that neglect packet frequencies altogether or rely on absolute frequency values, respectively. Our method is system-agnostic: it can be used against any PET without alteration. Closed-world results indicate that many popular single-hop and even multi-hop systems like Tor and JonDonym are vulnerable against this general fingerprinting attack. Furthermore, we discuss important real-world issues, namely false alarms and the influence of the browser cache on accuracy."

Also related (no account required to download the paper):

Compromising Tor Anonymity Exploiting P2P Information Leakage http://fr.arxiv.org/abs/1004.1461

Pere Manils, Chaabane Abdelberri, Stevens Le Blond, Mohamed Ali Kaafar, Claude Castelluccia, Arnaud Legout, Walid Dabbous (All - INRIA Sophia Antipolis / INRIA Rhône-Alpes)

"Privacy of users in P2P networks goes far beyond their current usage and is a fundamental requirement to the adoption of P2P protocols for legal usage. In a climate of cold war between these users and anti-piracy groups, more and more users are moving to anonymizing networks in an attempt to hide their identity. However, when not designed to protect users information, a P2P protocol would leak information that may compromise the identity of its users. In this paper, we first present three attacks targeting BitTorrent users on top of Tor that reveal their real IP addresses. In a second step, we analyze the Tor usage by BitTorrent users and compare it to its usage outside of Tor. Finally, we depict the risks induced by this de-anonymization and show that users' privacy violation goes beyond BitTorrent traffic and contaminates other protocols such as HTTP."

I agree that it looks bad, but I think they are getting a huge flood of new signups and imports based on all the news around Yahoo potentially shutting down Delicious. All parts of the service were fast (one of the major features for me) until the TechCrunch article yesterday.

I'm using Pinboard.in right now to navigate my collection of bookmarks and manage tags and I don't notice any slowdown. I suspect the slowdown is actually limited to new imports and archiving. There has been no downtime related to all the new signups as far as I have seen. The developers are active on Twitter http://twitter.com/pinboardin and the Google Group http://groups.google.com/group/pinboard-dev/ so you can check out the discussion yourself.

I guess it all depends on how valuable the service is to you. For me, the one-time signup fee seems minimal for the value I get from a service that I use nearly every day. I've used many other bookmarking services, some of which have already disappeared like Gnolia. Pinboard is very stable, faster than Delicious, and the developers respond to requests quickly. I have no connection with Pinboard other than as a happy customer, but I regularly recommend the service and think it is worth paying for.

I use Pinboard to help collect data for many of my research projects and the archiving capability ($25/ year) is great retrieving pages that have already disappeared, that I want to go back and reference. Yes, I could use other free services and the Internet Archive Wayback Machine (which is amazing), but the speed, support, and reliability of Pinboard make it easily worth the cost. I prefer that services I rely on have a sustainable business model. Charging a very reasonable fee to provide quality service seems like a good model to me.

The company says the service is opt in this press release: http://www.location-labs.com/press_article.php?newsid=80 and in the comments here: http://techcrunch.com/2010/06/21/location-labs/ and here: http://www.readwriteweb.com/archives/is_geofencing_the_next_...

Although, I have to say this is not at all clear (at least to me) from reading through their website or even by reading their privacy policy http://location-labs.com/privacy.php

"The topic of SSL certificates is a bit arcane, but the much of security of our everyday online purchases depends on SSL. Yet, fewer services use SSL than one might hope. It is possible to buy a basic no-frills SSL certificates from a universally accepted certificate authority very inexpensively–less than $15 a year–if you shop around. In most cases, it makes no sense to use a self-signed certificate, to purchase a certificate from a second tier provider, or to purchase a chained certificate."

I'm interested in any comments. I'll see them here on Hacker News or the version on my personal site. http://bengross.com/no-frills-ssl-certificates-are-inexpensi...

It is common for people I talk to complain that it is a pain to email complete web pages from most browsers. This article lists are best options I found. My favorite is to first reformat the page using the Readability bookmarklet. Please comment if you have other solutions.

This article started out as a set of notes for myself, but I ended up finding so many resources, I thought other people might find it useful, so I wrote it up. There details and resources on ads, navigation, layout, and user interaction, and testing.