HN user

ergot

1,227 karma
Posts237
Comments54
View on HN
www.theguardian.com 9y ago

Telling Facebook you've changed your phone number

ergot
1pts0
blog.malwarebytes.com 9y ago

From a fake wallet to a Java RAT

ergot
2pts0
electrek.co 9y ago

Solar power cost down 25% in five months

ergot
1pts0
www.theguardian.com 9y ago

Utopian ideas on climate change will get us precisely nowhere

ergot
4pts2
www.sciencedaily.com 9y ago

Your 'anonmyized' web browsing history may not be anonymous

ergot
3pts0
www.slashgear.com 9y ago

Tesla Autopilot update now rolling out with new semi-autonomous features

ergot
1pts0
www.phoronix.com 9y ago

Mozilla's Servo Is Whooping the Other Browsers in Performance

ergot
3pts0
blog.bradfieldcs.com 9y ago

Being confidently programming language agnostic

ergot
235pts127
blog.prototypr.io 9y ago

Align SVG Icons to Text and Say Goodbye to Font Icons

ergot
3pts0
www.youtube.com 9y ago

Ekoparty Security Conference – 2016 Recorded Lectures (YouTube Playlist)

ergot
1pts0
uptane.github.io 9y ago

Uptane – Securing Software Updates for Automobiles

ergot
3pts0
remotephone.github.io 9y ago

Practical Docker for Security Admins

ergot
2pts0
dadario.com.br 9y ago

Docker for Automating Honeypots or Malware Sandboxes

ergot
2pts0
users.telenet.be 9y ago

Technical Details of the Enigma Machine

ergot
51pts12
brooksreview.net 9y ago

Full Time VPN

ergot
1pts0
blog.cryptographyengineering.com 9y ago

A very casual introduction to Fully Homomorphic Encryption (2012)

ergot
137pts21
theintercept.com 9y ago

Surveillance Self-defense Against The Trump Administration

ergot
16pts10
iridiumbrowser.de 9y ago

Iridium Browser – A Browser Securing Your Privacy. That’s It

ergot
1pts0
www.theguardian.com 9y ago

Green Bank: the town that banned Wi-Fi

ergot
2pts0
jia.sipa.columbia.edu 9y ago

The U.S. Government and Zero-Day Vulnerabilities

ergot
2pts0
couchpota.to 9y ago

CouchPotato – Download movies automatically, and in the best quality

ergot
2pts0
www.obdev.at 9y ago

Little Snitch 3 – Protect your privacy

ergot
377pts215
tonyarcieri.com 9y ago

Key rotation, user experience, and crypto reporting

ergot
1pts0
crypto.stanford.edu 9y ago

Computing Arbitrary Functions of Encrypted Data [pdf]

ergot
2pts0
mailarchive.ietf.org 9y ago

NSA attacks on GCM-SIV [pdf]

ergot
2pts0
improsec.com 9y ago

Bypassing Control Flow Guard in Windows 10

ergot
1pts0
securitycafe.ro 9y ago

Practical JSONP Injection

ergot
1pts0
pentest.blog 9y ago

Windows Privilege Escalation Methods for Pentesters

ergot
2pts0
uptane.github.io 9y ago

Uptane – Securing Software Updates for Automobiles

ergot
1pts0
gist.github.com 9y ago

Don't use VPN services

ergot
2pts0

Worth listening to Jake Appelbaum's 'digital anti repression workshop' [1]. In this he explains why he takes the hard-drive out of his laptop and just uses a TailsOS thumb-drive for his computing. It would be actually hilarious when staff ask to peruse the contents of your computer for contraband, only to discover the laptop doesn't have a hard-drive.

[1]: part 1 https://www.youtube.com/watch?v=HHoJ9pQ0cn8

[#]: part 2 https://www.youtube.com/watch?v=s9fByRmAHgU

For those wondering how to create your own custom Tor onion adress, look no further than: https://timtaubert.de/blog/2014/11/using-the-webcrypto-api-t...

And for those who think Protonmail are the only service with a custom address, think again, because Facebook has one too: https://facebookcorewwwi.onion/

You can find a tonne more at this list:

https://github.com/chris-barry/darkweb-everywhere/tree/maste...

And staying on topic, Mailpile has their own .onion

https://raw.githubusercontent.com/chris-barry/darkweb-everyw...

Maybe even subsidising their offering

Yeah there's a few VPNs that look shady because of their pricing. One that springs to mind is LeafVPN[1]. For $5.00 you get to send all your traffic to Mallory. And it even has `LEA` as the first three letters, so you're safe! This is not an endorsement of this service BTW.

[1] https://leafvpn.com

Brilliant list. I always wondered how many commercial VPN providers use code from these. I suspect setting up the VPN is easy enough, but coding the billing backend might be trickier.

Best giving them all a whirl and making up your own mind. A good starting point is The Live CD List[1] website. If you're switching from Windows to Linux for the first time, Linux Mint will certainly smooth the transition for you. Also for newbies, Ubuntu is a great first option.

I usually test distros in a VM instead of installing them on bare metal. So far I have not found a distro specifically tailored to development though, and the question really should be what tools are best for development?

In that case, Emacs/Vim[2] would be a good start, and being able to develop without an Internet connection helps harden your coding ability too as you're not so reliant on the solutions of others. Go for one day of coding without Stack Overflow/Google and see how you fare.

[1] http://livecdlist.com/

[2] https://stackoverflow.com/questions/1430164/differences-betw...

I use them all, because I have a 1TB Samsung SSD with the Xen hypervisor running on it, which means I can dedicate whole operating systems to specific browsers. Each browser has its own 'unique selling point' and I use each browser according to my needs.

-Firefox for privacy

-Tor Browser Bundle for enhanced privacy

-Brave for micropayments

-Vivaldi for customization/tweaks and reading the news

-Chrome because it's ultra fast

-Microsoft Edge just because I can

A physical switch is for surety and peace of mind, whereas a software switch you have to be careful, because I don't trust my machine's OS to keep the speakers muted, no matter how much the chain of trust has not been compromised, there's always a weak link somewhere. Physical switches or death.

Another reason to disable JS whilst surfing with Tor Browser Bundle. This article mentions the HTML5 Audio API - Something that should be stripped entirely from Tor Browser Bundle (TBB), but instead stays because TBB shares too much code with Firefox.

Also there's nothing stopping someone simply muting their speakers, or physically removing the speaker from their system if they can (some BIOS chips allow this, aswell as physically turning off the camera)

https://en.wikipedia.org/wiki/Carrier-grade_NAT

    Carrier-grade NAT (CGN), also known as large-scale NAT (LSN),
    is an approach to IPv4 network design in which end sites,
    in particular residential networks,
    are configured with private network addresses that are translated
    to public IPv4 addresses by middlebox network address translator
    devices embedded in the network operator's network,
    permitting the sharing of small pools of public addresses among many end sites.
    This shifts the NAT function and configuration thereof from the customer premises to the Internet service provider network.

The idea behind obfsproxy is that you don't want it looking like port 443 on the wire. You can infact mask the traffic using the domain fronting technique providing you setup obfsproxy correctly. I haven't tried it myself, but I have analyzed Tunnelbear's 'ghostbear' feature with wireshark and the traffic looks fairly innocuous which is what we're aiming for.

https://community.openvpn.net/openvpn/wiki/TrafficObfuscatio...

Here's a detailed overview of so called 'domain fronting' https://www.bamsoftware.com/papers/fronting/

Some VPNs use a module called obfsproxy which uses the fronting technique. One VPN service I recall using it is called Tunnelbear. You can read more about this feature here: https://help.tunnelbear.com/customer/en/portal/articles/2435...

This is not an endorsement of Tunnelbear, I just thought it would be noteworthy mentioning that VPN services offer this now to thwart censorship.