Similar approach taken for Amazon's Echo Dot exposing parts of setup process and some broken parts: https://medium.com/@dweinstein/amazon-echo-dot-explorations-...
HN user
daemonize
Check out Frida (iOS and Android) http://www.frida.re/
Not to mention that one can tether via Bluetooth or USB in addition to WiFi hotspot. How are they to distinguish between someone using their hotspot via either of those two transports? I don't see them having a technical means that could distinguish someone USB tethered to cell phone using its data plan from just a cell phone using LTE data.
I recommend highland.js for node http://highlandjs.org
Even in a multiple-thread scenario?
Don't worry, each vendor will have an opportunity to screw up SE for Android policy. Additionally, many kernel flaws will be possible to use for disabling these mechanisms to once again get privilege sufficient to write to /system if needed.
I believe banks would be better served sending emails with links that open their mobile app instead of popping up a web browser.
Good luck groking that mess.
Not if the private key is stored in a secure hardware token.
sounds like some bullshit to me... "we got hacked because we don't use our own shitty software." Security is a tough business. Just look @ hbgary.
I think showing the actual disassembly would help people understand. it might lose some so maybe as a side bar.
I was disappointed that there was no mention of side channel attacks and countermeasures.
http://web.mit.edu/press/2012/thwarting-eavesdropping-data.h...
Edit: added link
interesting how something so trivial as sockets (but in the context of a http browser) can stir so much talk of decentralization. maybe if people pull their heads out of their asses about web and embrace native apps again...
I would imaginr that the flat panel could be hooked to a servo and a control loop be used to optimize poiting attitude in real time to compensate for the sun's natural cycle.
http://en.wikipedia.org/wiki/Homomorphic_encryption for a writeup on the concept.
Japan has no defense investment. 'nuff said.
China could either put it back in their coffers or invest in Brazil. Consider that they have Sino-Brazilian trade and technology agreement.
What about China bailing. How bad does it need to get before they decide to pull out?
You're right, sry. Was on my mobile and must have glossed over that. Next time I will RTFA fully.
This says a lot about the ISP's ethics if they are shown to be consenting to this. One thing I didn't see in the EFF article is something a user could do about it: use SSL! This may eventually force these companies into more nefarulious and active techniques of hijacking, but it should alleviate the basic technique they are employing now, if i am not mistaken.
uhm. this "revelation" was already written about the first time jailbreakme did this, at least a year or two ago... Why is this news?
Socat can do this: first read: http://www.dest-unreach.org/socat/doc/socat-tun.html then read: http://www.dest-unreach.org/socat/doc/socat-openssltunnel.ht...
The guidelines break the contract of being under 10 lines of code, maybe not directly, but in spirit.