HN user

dan000892

254 karma
Posts0
Comments37
View on HN
No posts found.

Where are they linking to just one? The chart shows three: Palantir, AWS GovCloud, and GCP w/FR-High Assured Workload.

The chart should show ITAR also IMO. Only Palantir and AWS GovCloud would have checkboxes and that’s extremely relevant to defense contractors. (Vertex AI is available within an FR-High assured workload but not ITAR, the only conceivable reason for which would be foreign person access to the US sovereign production environment.)

…or booting from alternate media to retrieve data from the disk in situ (depending on which measurements are used to seal the key in the TPM).

“Don’t let perfect be the enemy of good.” Vulnerabilities/limitations should be understood and you have every right to determine that TPM+PIN is the minimum control that addresses threats you’ve modeled and reduces risk to a tolerable level, but TPM-only encryption is not pointless. It reduces risk by increasing required attack complexity without impacting usability. That’s enough for a lot of people.

My mother was diagnosed with MG 25 years ago. Her first symptoms were droopy eyelid and double vision. Plasmapheresis helped, Prednisone had nasty side effects (glad to hear that sounds not to be the case for your father), prismatic glasses to un-double her vision kind of helped?

As her symptoms increased—-speech delay, difficulty swallowing, eye misalignment, all stemming from fatigue-induced nerve conduction delays which can culminate in respiratory failure—-myasthenic crisis, they opted for thymectomy (open surgery). She was probably 50 and while the recovery was lengthy, it drastically improved her symptoms and the amount of activity she could do before arose symptoms appeared. No more prism glasses or multi-second speech delays, or weekly plasmapheresis visits. If she spent too much time being active or driving on a sunny day (squinting), she’d feel the ocular fatigue first and know she had to rest or take a prednisone. Now her eyes are failing for other reasons but the thymectomy bought her 25 years and counting.

I’m glad your father survived his crisis. It sounds like you’re doing all of the conservative treatments (which is good; steroid noncompliance is a risk factor for crisis).

There are new medications that directly reduce or deactivate AChR antibodies. Non-invasive video-assisted thoracoscopic thymectomy is more viable today too (and thymectomy has been shown to decrease the frequency and severity of crises even where the thymus was considered normal). Plasmapheresis remains generally effective, if time consuming.

MG sucks. From one son to another, I hope you can get a few more good decades with your parent too.

Presumably this is the same thing whatismytenantid.com does under the hood.

Interesting (to me) is that the OpenID configuration endpoint provides the tenant ID for not only Commercial tenants but US Government (GCC & GCC-High) as well because the Azure AD portal has relatively new functionality to configure cross-tenant access settings by tenant ID or domain name but Gov tenants require you to obtain the tenant ID from the organization which is either security through obscurity or due to use of some Commercial-only Graph API call.

Not only is there phishing opportunity, it's being actively exploited to much greater financial effect (check fraud and identity theft), and you don't even need to go to the lengths of creating a company profile or a website as anyone can create a job posting for any company (with rare exception) [1].

Here's a very real series of events I'm privy to:

- Bad guy gets a domain name confusingly similar to the target company (maybe tack on "inc" or "llc").

- Bad guy gets access to a LinkedIn account (doesn't matter who or if they're connected to the company; stands to reason that a hacked account with existing connections adds credibility) and updates the title to CEO of target company.

- Bad guy posts an "Easy Apply" ad for a remote job with target company.

- That job listing automatically appears on target company's LinkedIn page.

- Bad guy begins receiving contact info for the job and gets to work.

- Following a weak interview process conducted entirely over IM or email, the candidate is hired.

- New hire provides identity documentation at bad actor’s request.

- Bad actor sends new hire a check with instructions to buy equipment for their home work area from a specific vendor who is also the bad actor.

- New hire deposits check and bank makes funds available before the check clearance process actually completes.

- New hire buys a few thousand dollars’ of equipment from a vendor that doesn’t exist with money they don’t actually have.

- Check bounces and the jig is up.

By the time target company found out, LinkedIn has removed both the job ad and the profile that created it, but did not and would not reach out to the applicants to warn them of the scam nor provide those applicants to the target company (y'know, the company the applicants thought they were applying to; citing "privacy reasons").

While [1] says LinkedIn can do something to restrict who can post jobs on behalf of your company, it's wholly undocumented (and I suspect may not work well for companies relying on both internal and external sourcing). The only defensive measure I've identified is setting up a job alert for your company, specifically for Easy Apply and/or Remote positions as that seems to track with the scam.

[1] https://www.bleepingcomputer.com/news/security/you-can-post-...

Yeah, my wife and I are both members of various slack workspaces (work, volunteer groups, social/industry groups, etc) so it was beneficial to use the same tool (with a free, private workspace) for us to not only chat but also keep track of things in different channels (#wanderlust, #whatdowedo, #whatdoweeat, etc).

I was about to say that due to the new 90-day policy, we stand to lose pretty much allof the content in those channels but as it turns out, except for one message from July 2020, we already have. I suppose it doesn’t matter to me now if it’s 10k messages or 3 months of history but the former amounted to 24 months.

Doesn't Motorola have location tracking systems which integrate or add-on to their radio systems?

Yes, the APX8000 has support for location tracking but we decided it'd be inappropriate to request anything of the regional communications center since they have their hands full with far more meaningful improvements to the 12 cities (40-odd fire stations) they support. Also, while I see value in tracking unit locations at our music festival events in particular, it falls well short of necessary.

You could also look at using APRS for location tracking...

APRS would require we all have technician licenses and suitably equipped 2M radios. While a few of us are hams, it's not feasible to request dozens of volunteer EMTs go through that. Also APRS tracker hardware is at least twice as expensive as LilyGo's LoRa options ($55 for a T-Echo or $65-85 for a T-Beam w/case and battery vs $115 for the cheapest APRS tracker I've found--QRP Labs' LightAPRS [1]--not including designing a case and power delivery).

Also - you should be able to set up your phones with priority network access on FirstNet, right?

We are indeed eligible for wireless priority services on our personal phones. AT&T FirstNet includes data priority but the couple members who got it didn't see an improvement. Verizon Frontline offers data priority but no one's opted in yet and T-Mobile only offers voice priority so low confidence in its viability.

Fundamentally, Meshtastic's attractiveness is not only in its low hardware cost but the lack of friction in not requiring anything of anyone beyond "hey, clip this thing on your bag, thanks."

[1] http://qrp-labs.com/lightaprs

I have this same need and am preparing an evaluation of Meshtastic in the field this month.

I'm part of a volunteer EMS division within a paid fire department and we staff foot teams and medical carts at large events at our 90,888-capacity stadium (football, concerts, etc; well over 100k including tailgaters at our biggest game of the year) and music festivals with 10-40k attendees on the adjacent golf course.

While we have fancy Motorola APX 8000XE, our on-site dispatch wholly lacks visibility into unit locations and the abysmal cell service precludes software solutions leveraging mobile phones.

Hertzbleed Attack 4 years ago

OR DOES IT???

Oh, it doesn’t? Carry on.

I’m quite fatigued by the recent (?) increase in comparisons of current vulnerabilities, attacks, and adversarial capabilities to Stuxnet and can’t help but tune out when it’s invoked. Yes, the ‘96 Bulls were the best team of all time. That has no bearing on how good the Bulls are now and sure as hell shouldn’t blind you to how good other teams have gotten since…

Replace the entire team with dang.

What is the scalability of dang?

For deeply indebted and cash-flow poor companies like Twitter is about to become (at the surprisingly high--and positive--$1.5B EBITDA, interest is going to erode that by upwards of 60%), is there an equivalent service offering? dang-as-a-service, or "daas", if you will?

This stuff is rad. I took a class on hardware implants with Joe Fitz a couple years back—on the heels of that wholly unsubstantiated Bloomberg article about China embedding rice grain-sized hardware implants into Supermicro motherboards that magically found their way only to select F100s and gov’t agencies—where we made a PCB to interface an ATtiny85 to an unpopulated UART header on some IoT device but instead of soldering it down we just taped it with this.

(The UART provided a root shell and enough power to “boot” the ATtiny which simply waited a few seconds and then ran some commands to initiate a reverse shell to a server under our control every time the device was powered on. Thanks to this tape and the device’s tool-less case (and convenient unpopulated header with space around it), it was enlightening how trivially easy it’d be to develop and deploy such an implant to an operating device (with the caveat that I wouldn’t consider the connection robust enough to survive transport).

It’s also useful to connect SMD EEPROMs to unpopulated/desoldered pads for testing without installing a socket.

In 2004, I found myself breaking waves at the helm of my land yacht of a 1991 Crown Victoria LTD on the rolling hills of an upstate New York forest road when I came upon an inferior vehicle which required overtaking. Alas, once a rare passing zone appeared and I positioned to overtake and put my foot down, the pedal limply dropped to the floor and I began to slow. (Of course it was once I was right next to the guy who rightfully gave me a WTF look but I digress.)

After finding a good shoulder on which to beach my LTD and popping the hood, I found the problem: the socket side of the ball-and-socket throttle cable linkage had broken and would no longer hold together. Looking in my (voluminous undergrad compsci-student) trunk for a solution, my eyes landed on the -shiny- beigy PC tower, specifically the floppy drive. A couple strands of the disused 34-pin floppy cable well tied proved to be strong but flexible enough to hold that joint together and get me back to school.

Despite my college having a robust automotive program (which I even had a suitemate in), I never replaced the part and that hack held until I got rid of the car 10 years later (though I kept the other 30-odd strands of the cable in the glove box just in case).

While nostalgic, don’t read this as supportive because today I’m far more likely to find a CANBUS interface in my trunk than a floppy cable.

Flash devices maximize the longevity of the cells by wear leveling. The on-board controller maintains a map between the physical cell layout and the logical layout that's changing with every single write operation.

Extra cells are used both reactively and proactively.

Reactively: Error when erasing or write/verifying a cell? Copy contents to spare cell, flag old cell as bad, update the map, maybe complain if running low on spare cells but otherwise call it a day.

Proactively: Cells are only rated for so many erase operations which directly informs the longevity (total bytes written) of a drive. MLC cells can be written to 3,000 times and SLC 20,000 but the latter is much more expensive. For use cases where greater longevity is required (without spending SLC money), why not put a disk together that has twice as many cells as it needs and wear level across all of them? If you `dd if=/dev/zero of=/dev/sdX bs=64k status=progress` your 32GB drive and it'll complete after 32GB but you have no way of knowing how many more cells that drive has that you didn't touch.

(Also as one of the parents pointed out, disk controllers are getting smart. You don't know if it was transparently compressing data too causing you to touch even fewer cells. ATA Secure Erase is the way to go.)

From your comment I'm not sure if you're aware but there are two established standards that do just that:

ATA Secure Erase is an optional security feature implemented by many flash-based disk devices specifically because write degradation and overprovisioning preclude them from being wiped via overwrite as you would magnetic media.

More SSD disk controllers than you may realize have an AES encryption engine and persistent storage for the key. The controller is encrypting/decrypting on the fly transparent to the user/system. A secure erase simply rolls that key (and flags all the cells as empty).

As noted in the sibling comment, there must be trust in the device itself that the old key is unrecoverable (or the data recoverable if the prior key had been compromised).

hdparm on any linux liveusb (e.g. Clonezilla) and an eSATA dock and you can nuke a few disks a minute with two commands:

  hdparm --user-master u --security-set-pass p /dev/sdX
  hdparm --user-master u --security-erase-enhanced p /dev/sdX
hdparm has other arguments that can tell you if this is supported and how long the drive says it'll take to do it.

The other standard is TCG's OPAL. An AES media encryption key (MEK) is generated to encrypt/decrypt all data on the fly. The MEK is encrypted with a user-defined key encrypting key (KEK) and that encrypted MEK is stored on the drive. At boot the user (or some external process) needs to supply the drive with the KEK to decrypt the MEK and begin transparently decrypting/encrypting data on the fly. Splitting the disk into multiple "locking ranges" with independent MEKs and KEKs is also described in the spec enabling secure wipe of just a portion of the disk. Lose the KEK or destroy the MEK and the data is unrecoverable.

I'd say this option still requires trust in the disk itself but since TCG dictates not just the interface but also the implementation and has a corresponding certification process (as well as reliance on an off-device key), I reckon TCG OPAL devices should be more trusted than those that simply claim to implement the ATA Secure Erase command, but I haven't had an opportunity to test any.

The very first technical standards for slot machines in Nevada are ESD testing to confirm it’s safe for the player and that the integrity of the device is unimpacted by 27kV discharge to any point on the exterior of the machine while it’s being played (and the test labs really go to town finding gaps in panels and really trying to make something bad happen).

Given the absence of mechanical reels and the fact that the components likely to be susceptible to glitching aren’t remotely close to the outside of the machine this isn’t a viable attack method for machines in operation.

Source: NV Tech Standard 1 [1] also have zapped modern slot machines with an ESD gun.

[1] https://gaming.nv.gov/modules/showdocument.aspx?documentid=2...

Expanding on Puerto Rico's primary export...

Per the FDA, Puerto Rico produced (pre-Maria) $40B of pharmaceuticals for the US alone. 40 of those products and devices were deemed critical as they're the only producer or there's no viable alternative [1].

The largest (in terms of unit count) production was Normal Saline with Baxter's P.R. factory supplying 50% of U.S. hospitals with small volume saline bags (<=250mL as opposed to the more common 1L) prior to Hurricane Maria which took out their production facility [2]. The hurricane is widely credited as the cause of our national saline shortage (though as [2] details, it exacerbated a shortage that already existed for several other reasons).

[1] (PDF warning): https://www.fda.gov/media/108975/download

[2] https://www.nejm.org/doi/full/10.1056/NEJMp1800347

While lame, that certainly seems much more feasible than mass-producing 1500 copies of an electronic badge (or even a mock thereof) in the span of a couple days but it also renders mention of the sanctioned (actual) badge counterfeiting competition (which to my knowledge involves paying competitors) irrelevant.

Given that #badgelife folks have difficulty manufacturing hundreds of badges they themselves designed and there's been no real scrutiny of attendee badges as would surely result if it were found that 5%+ of attendees had counterfeits, I have to call bullshit.

If reasonable evidence is presented to the contrary, I will eat my hat by donating the $300 I won't be spending for this year's DEF CON admission to the EFF.

I'm sure I'm devoting more time to villages, workshops, and non-DEF CON talks than I used to (after all the official talks end up on YT a couple months after the event). It did seem to me--CP elevator choke point notwithstanding--that separating talks from the rest of the con by a 20+ minute walk did shorten LINECON but I'll concede there's a small chance that I'm becoming more patient or (more likely) that my experience was not representative.

Regardless, I am very intrigued by your experience with counterfeit badges. I'm familiar with the counterfeit badge contest and many jokes were made about last year's "urinal cakes on a lanyard" but this is the first I've heard suggesting there was effectively mass production of counterfeit badges. Can you tell us more?

That’s been a constant DEF CON theme at least since the Rivera days but had (IMO) improved incrementally with the move to multiple larger venues and was expected to be all but resolved with the move to the new Caesars Forum

(New venue is/will be (?) absolutely enormous; featuring the largest “pillar-less” ballrooms in the world it promised the ability to accommodate not only all talks and villages in a single venue again but everyone in a single keynote talk. Looking forward to witnessing that next year.)

edit: It's occurred to me that it could conceivably be more difficult to get into talks at this year's virtual event than it would have been in-person. Perhaps they'll implement a virtual waiting room so we can get our LINECON fix.

Daytripper 7 years ago

dd's destruction is gated by the device's write performance and so data may be recoverable if the operation is interrupted.

For those of us with SSDs that transparently leverage AES encryption, the following generates a new keypair and marks all cells as empty instantly nuking it (and restoring the device's write performance to factory-fresh):

  # hdparm --user-master u --security-set-pass p /dev/sdX; hdparm --user-master u --security-erase-enhanced p /dev/sdX
More info on the ATA Secure Erase instruction and how to tell if your storage device supports it can be found here: https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase

Wow, that’s a really interesting result I haven’t heard! Do you recall at what brand you experienced this? I generally visit Shell and Chevron stations across CA but I’d make an exception to attempt to repro that.

For those still subjected to these who don’t know: Most video-enabled pumps in the US can be muted by pressing the second button from the top on the column of four buttons to the right of the display.

I consider it a small quality of life improvement to not hear the same Seth Meyers joke two or three times while fueling.

As opposed to the “but I might get sued” argument, I find this argument totally reasonable. Thank you for stating it so clearly.

I’m cautiously optimistic but recognize that we need more data because evidence-based medicine is all about testing hypotheses. The hypothesis here is that continuous 1-lead monitoring will provide a net benefit to the population employing it. Maybe it will and maybe it won’t; Either way I think it’s pretty cool that we’re about to amass a ton of relevant data from which we’ll be able to derive an answer.