HN user

fuzzbang

99 karma
Posts0
Comments27
View on HN
No posts found.

Which you apparently didn't read thoroughly. I clearly state that the secure way to use TrueCrypt is to never mount the hidden volume in protected mode. That will enable the scenario you describe. I even state the reason why you want use it the way I suggest is to minimize the amount of hidden data that is overwritten.

No, it is not false. The important thing with a spinning disk is locality of reference. You want the blocks which store the file content to be as close together as possible, to minimize the head seek times. This means you want as long a chain of contiguous blocks as possible. This does not mean that you want all those blocks to be at the beginning of the disk. In fact, the exact opposite. You want to start that chain at a random location so you are more likely to have a large number of contiguous unallocated blocks. See the implementation of HFS+ Extents, or Ext4, or UFS for examples of how this works.

They can prove it sufficiently to force you to hand over your password. File systems have a particular behaviour, they allocate blocks in certain ways. Most notably, they use all of the space available to them equally (or, pseudorandomly anyway). If a file system never allocates any data in the last N bytes, where N is a very large number, that is indication that the file system is treating the volume as Size-N. Since this behaviour is the signature of a hidden volume in a TrueCrypt container, that is "proof". It will be sufficient proof for a court of law.

Essentially you are arguing that the file system implementation exhibited implausible behavior (it allocated only from the first N% of bytes), and that TrueCrypt exhibited implausible behavior ("ok, normally that would mean a hidden volume, but not in this case!").

All of which is to say, that TrueCrypt's implementation of Hidden volumes (as typically used by end users) is not actually plausibly deniable.

It is not that difficult to prove that a hidden volume exists. The TrueCrypt implementation of hidden volumes means that the "hidden" partition is all allocated at the end of the visible partition. If you have a 20G TC volume with a 4G hidden volume, the file system in the non-hidden volume will never allocate a block beyond 16G. This shows up as very anomalous file system layouts at the block level. Simple visualization of the block allocations will show a clear delineation where the hidden partition starts. The TC implementation of hidden volumes is definitely not robust as plausible deniablility.

The police forensics investigators know to look for this already. It is in their recommended best practices for how to handle TrueCrypt volumes.

The safest way to use a TrueCrypt hidden volume is:

  * Create the largest regular volume that you can. 
  * Create the smallest hidden volume that you can.
  * Never mount the hidden volume as "protected"
The idea is that your sparsely populated cover volume won't create enough block allocations to have an obvious "end", and additionally, that those blocks will have a low likelihood of being allocated inside your hidden volume and overwriting your secret data.

While there are definitely benefits to using a VPN, they do not provide anonymity. They provide privacy, and it is not the same thing.

"No one is going to go to jail for you". If a VPN provider is legally required to log your activity or face jail time, guess what? you're getting logged! To assume otherwise is just asking for trouble.

All of this is better addressed in this slidedeck.

http://www.slideshare.net/grugq/opsec-for-hackers

You should clean the data from the user before passing it to the shell. There is a trivial remote command execution vulnerability in the URL ("echo 'GET /;$(cat /etc/passwd)'|nc ..."). I assume there are more.

You have to be more specific than that. These days information security is a huge field. Network security is a misnomer since almost no one works on "network security", which is about protocols not applications / operating systems.

I'd suggest being more specific about what sort of project you're interested in. Will you be doing original research on the size of botnets (you and everyone else in the world); maybe write a tool for something, I'd suggest writing a real webapp security assessment tool. I hate doing web app assessments. Another thing that would be really useful would be collaborative information sharing during a pen test (I've put a lot of thought into this one and could give you more pointers)...

If you want to play it safe, just write another fuzzer. Everyone writes fuzzers. Or you could write some VoIP security tools.

Bangkok meetup 17 years ago

Where is it announced? In particular, how does one find out where / when it is to show up?

Bangkok meetup 17 years ago

The Londoner is at the corner of Sukhumvit 33. Easy to get to. The Bull's Head is down Suk 33/1, very easy to get to by BTS. The Phrom Phong station exit is just in front of the mouth of the soi.

I don't know where the Langsuang Starbucks is, never been there.

Bangkok meetup 17 years ago

The Londoner is larger and doesn't get as packed as quickly (avoiding peak times, of course). Bull's head is a superior pub no doubt, but is not great for a largish meeting.

At any rate, anywhere will do. When is this scheduled for? I'm figuring on heading to the islands later this week.

Bangkok meetup 17 years ago

When are you around in Bangkok? It seems there is something of a community out here, but I'm not aware of any previous meetings.

I learned Thai by living with a Thai girl who spoke no English. Took about 6 months to become fluent. My suggestion is get a "long haired dictionary" and you'll pick up the language in no time. :)

The best way to learn is to have no choice but to speak the language. Then don't be afraid to fail. I learned Indonesian by speaking to taxi drivers and any other locals I came in contact with. Same process I used with Javanese.

The trick is to start with a basic vocabulary and set of phrases. Then treat the phrases as templates and swap words in and out. You'll be wrong a lot, but the native speaker might phrase it correctly and repeat it back... just repeat what they said and smile. Repeat this process until you're fluent. :)

Firstly, US companies tends not to care about other countries. To the extent that they do, it is mostly European countries that are important. The reason is pretty simple -- money. First world countries can (and will) pay for things. It is generally more useful to have paying customers as your user base. (Here I include customers of other products, i.e. "eyeballs" that you can sell to advertisers. Advertisers want access to people who buy products.)

Secondly, the third world has shown rather resoundingly that it doesn't want non-Microsoft products. Here in Thailand I routinely see Thai people install Windows XP onto their iMacs and Macbooks. They don't use OSX, and I have never met a Thai using Linux. Even laptops which are supposed to have Linux pre-installed will routinely have XP installed by the shop before they are sold.

Here, the reasoning is a bit more complex. For starters, Thai language support. XP has very good Thai support (i.e. it actually has a Thai language locale). OSX does not at all, and Linux has extremely half-assed Thai language support. Obviously, Thailand isn't an important market to Apple and Linux using Thais haven't stepped up to do the translation. This is a unique issue for Thais, so we can ignore it for the general "Third World". I would suggest, however, that most Third World users don't speak English as a first language. Some African countries will do ok with French or English (or German!) locales, so we'll leave it at that.

Besides language issues, the main issue I've encountered here in Thailand is that Thai people want to learn marketable computer skills. They believe that since everyone uses Windows and Office, if they learn, for example, Linux and Open Office, they will have the wrong skill set. They want to emulate the West so they can be successful, and the West uses Microsoft. Thats what they want to use too.

Microsoft is quite deeply ingrained into the computing culture over here. If a Thai wants to add you to their IM list, they will ask you "do you have M?" <<are you on M[SN Messenger]?>>. Alternatively, they might just say "add email someusername42" <<add the MSN Messenger contact someusername42[@hotmail.com]>>. Microsoft defaults are just assumed (MSN Messenger, hotmail.com, etc.)

So, given that OSX and Linux can't penetrate into the third world (and in Apple's case, probably don't even want to)... why would you assume that Chrome OS will? That is, assuming that Google even cares (which is a huge assumption)...

Actually, I speak fluent Thai, there is no word for Yes or No. There is ไม่ which is a negation word, and ใช่ which basically means "correct"/"right", not "yes". The Thai question format is generally: Q: Hungry? หิวไหม A: Not hungry. ไม่หิว A: Hungry. หิว

There are other question indicator words, but the one you're referring to is for "correct or not" type questions, e.g.

Q: This road, right? สอยนี้ใช่ไหม A: Right. ใช่ A: Not right. ไม่ใช่

Alternatively, for a lot of statements you can just respond with the polite ending words, ครับ for men and ค่ะ for women.

The question, "would you like one of these?" in Thai would be, "เอาไหม่"... literally, "want?". The correct response is then either: ไม่เอาครับ or, เอาครับ ... that is the polite form for "do not want", or "want". There is no other way to respond to that question (except without the polite ending).

Well, 4k USD per month is ~130k THB. The purchasing power of the Baht means that that is about equivalent to ~10k USD. (As an example, a can of Coke costs 12 THB in a 7/11).

130k will buy you a lot of luxury in Thailand. You can get a very good condo for 30k per month. You can each out for every meal of every day for about 1.5k per diem, so 45k for food. That still leaves 55k for spending on going out, buying clothes, utilities, gadgets, etc. etc. That is more than "comfortable".

Even 70k per month is more than enough for a very comfortable lifestyle. Local food costs < 100 THB per meal, so you could eat for less than 300 THB per day. A reasonable condo is only 20k if you're willing to live away from the tourist areas.

You know, you can have a car in other countries as well. In Jakarta you can have a car and driver for less than the cost of a car in the US.

Personally, I think everyone should live in a different country for at least one (1) year. You'll gain a lot of perspective on your own country in the process. Just like learning another language teaches you more about your native tongue, so living in another country teach you about your own culture. Combine the two (new language, new country) for a serious eye opening.

For example, the Thai language has no words for "yes" or "no". There are no yes/no questions in Thai.

Only after being removed from pervasive US media do you recognize how much hollywood movie content is US centric and self-referential.

Honestly, if you love living in the US, go live somewhere else in the world for one year. You'll either love the US more, or you'll decide that you enjoy living somewhere else more than you anticipated. Either way, you'll have gained invaluable life experience.

Living in Thailand doesn't mean you have to work in Thailand. That is the crucial difference...

I live here (Thailand) and do contract work at near western rates. That means I can live for months off the revenue from a single project.

To be fair though, the cost of living in Thailand is higher than the article makes out. Rent is quite high (if you want to live in a good location), and having western food all the time gets expensive. Expect to spend about 30k THB per month on ChefXP and FoodByPhone.

As for a variety of foods, Bangkok is hard to beat. Except for the lack of decent mexican food (Sunrise Taco should be burned down), we have pretty much anything you could want to eat... and it can be delivered to your door w/in 45minutes for less than you'd pay in the US.

Bangkok is a 24hr city. You can get good food any time day or night. There are always things to do no matter what the hour... ผมรักกรูงเทพฯมากๆเลย

I've lived on 4 continents (Africa, N. America, Europe, Asia), and I seriously believe that Thailand is the best country for living.

There is a much better article here (you can actually understand what he has done): http://www.oneitsecurity.it/22/01/2009/mac-os-x-vulnerabilit...

I haven't read the slides, so I can't say specifically what he's done, however this is nothing new [1]. Essentially, he has ported a known technique, for executing programs within a host address space, to the OS X platform. It is neither "new" nor an "attack", so the article is extremely misleading.

From the article it appears that he's implemented a framework for injecting code into another process on OSX. It sounds like he uses the original binary to either a) hook execution, or b) access dynamic libraries[2]. [The part about using addresses from the existing Mach-O binary isn't clear as to the purposed purpose].

This "attack" is actually more like a technique for running a binary without creating an on-disk image. For examples of why you'd want to do this see phrack [3].

[1] Userland Exec, 2004. http://seclists.org/fulldisclosure/2004/Jan/0001.html

[2] Cheating the ELF: Subversive dynamic linking on UNIX platforms, 2001. http://mirror.sweon.net/madchat/coding/Cheating_elf.pdf

[3] Remote Exec, 2005(?). http://www.phrack.com/issues.html?issue=62&id=8

Netcat is an old and venerable Unix hacker tool. If you want to be a better hacker the netcat README is required reading. I would also recommend reading the source code, in particular the comments. Hobbit can be quite funny at times.

Netcat is usually installed on linux systems these days, but it is seldom compiled with -DGAPING_SECURITY_HOLE like it should be. Those really were the good old days...