HN user

dgrove

441 karma

my public key: https://keybase.io/drgrove; my proof: https://keybase.io/drgrove/sigs/7vNTktyLv2POAACx2FJXZP2H_CuAyrmGv17wvdW9DLk openpgp4fpr:c92fe5a3fbd58dd3ec5aa26bb10116b8193f2dbd

Posts27
Comments32
View on HN
milksad.info 2y ago

Milk Sad Disclosure

dgrove
136pts125
twitter.com 3y ago

Waymo unveils design for new autonomous fleet

dgrove
7pts0
www.youtube.com 4y ago

What's New in Spot (May 2022)

dgrove
1pts0
blog.trailofbits.com 4y ago

Disclosing Shamir’s Secret Sharing Vulnerabilities and Announcing ZKDocs

dgrove
1pts0
9to5mac.com 5y ago

Security fail by Apple allowed total remote control of iPhones via WiFi

dgrove
2pts0
gitlab.com 6y ago

CVE-2019-19604: Git Submodule Arbitrary Command Execution

dgrove
5pts0
github.com 7y ago

A federated package registry for anything, but mostly JavaScript

dgrove
1pts0
events.google.com 7y ago

I/O Transmission

dgrove
3pts0
www.google.com 7y ago

Get more done with the new Chrome

dgrove
1pts0
store.google.com 7y ago

Google Titan Security Key now available

dgrove
176pts139
twitter.com 8y ago

Signal Is Down

dgrove
1pts0
cve.mitre.org 8y ago

Auth0 CSRF Vulnerability allows for authentication bypass

dgrove
2pts0
androidthings.withgoogle.com 8y ago

Build with Android Things

dgrove
3pts0
chronicle.security 8y ago

Chronicle Security, a Google X Cybersecurity Moonshot

dgrove
6pts0
startup.google.com 8y ago

Tools to help with your new startup

dgrove
2pts0
www.android.com 9y ago

There's a home screen for everyone. #myAndroid

dgrove
4pts0
twitter.com 9y ago

Google I/O 2017 Dates Announced

dgrove
3pts0
vr.google.com 9y ago

Google Earth VR

dgrove
460pts148
www.android.com 9y ago

Android.com makes a game out of it's 404 page

dgrove
2pts0
plus.google.com 9y ago

Android Phones Tips and Tricks

dgrove
1pts0
github.com 10y ago

Show HN: An opinionated Koa API generator with batteries included

dgrove
1pts0
arstechnica.com 10y ago

8 bits, 8 players, 8 projectors, and one Nintendo Entertainment System

dgrove
2pts0
developer.android.com 11y ago

Android M Preview 2 Now Available

dgrove
5pts0
github.com 11y ago

Bringing Your OS X Terminal to the 21st Century

dgrove
6pts4
hackaday.com 11y ago

Tindie, the Etsy and Yelp for Electronics

dgrove
1pts0
blog.dannygrove.com 11y ago

Writing Extensible Configurations

dgrove
1pts0
status.travis-ci.com 11y ago

Travis CI is Down

dgrove
2pts1

Bitcoins entire premise is around the movement of unspents. If you always use the same wallet for every transaction it is pretty easy to track who sent the money. If you instead are always sending your money to a newly derived wallet from your HD (Hierarchical Deterministic) root it does make it much more difficult to track what money was money being spent on something and what money is part of a persons total value

iCloud security code can come over SMS if your account is configured as such, therefore the above example of a SIM port applies

Lots of talk about passwords, but fewer about password managers. The password managers listed in this do not protect against backdoors. Lastpass, for example keeps all your passwords in plain text once you've unlocked it. Passwords stored in Apples Keychain can be synced across devices and a remote attacker can do something like a sim port, gain access to your iCloud account and then sync to their computer leaving you vulnerable.

Password managers should be bound to hardware tokens and each password should be individually encrypted, as well and individually decrypted that also force physical tap.

Password Store is a perfect example of this. Physical password managers are also on the rise, see: Ledger and Mooltipass

Multiple teams I've been on at multiple companies have done this process, but with donuts and other foods. A little bit of public shame goes a long way.

I use pass for my password manager which links to my yubikey that has my gpg key on it. My yubikey has touch enabled which means that even if someone got access to my machine with my yubikey on it and asked me to tap they would only get that single password. As far as TOTP is concerned it's the same thing. The TOTP section of my yubikey has it's password and also requires a tap

Google Authenticator does not help prevent against a compromised device (as all TOTP secrets and seeds are on device) and is truly a pain when working with multiple phones. Personally I use Yubico Authenticator as all the TOTPs live on my Yubikey. That, in combination with a password then clicking on a totp i want and tapping my yubikey provides me with only that code. When I first seed the yubikey with a new TOTP i also backup a copy of the QR code text and save it into my password manager in the unfortunate event of having to swap out yubikeys.

You're not inherently trusting your VPN service to: a) not track you b) not keep logs c) not disclose this information to your actual ISP

You're also now just sitting behind whatever ISP your VPN uses which knows everything you're doing and sells it back to who-ever.

If your not rotating your VPN services that still allows you to be tracked via that IP. At the end of the day all your data still belongs to someone and can be used for whatever. Until DNS over TLS is complete and rolled out across the board your metadata can still be used.

Not to mention all of the other things associated with this. Even being connected to a VPN via your phone will still leak information like your coarse location, wifi networks and bluetooth beacons nearby which all get sent to your primary phone carrier and whatever applications you use.

I'm not dismissing that, I'm just stating that we were literally here 5 days ago talking about another alternative. One that already has an entire team backing it and keeping security in mind. There are probably 10s to 100s of different android builds with and without google. There are definitely a few that will outshine others: Cyanogen, Oxygen, Lineage, AOKP, TWRP to name a few that stick out in my mind. It's just funny that not even 5 days later we're back again with another android fork that google-less.