HN user

geographomics

1,052 karma

25db6c1376d93247b27c430492fd49@gmail.com

Posts22
Comments275
View on HN
www.devsecops.org 10y ago

DevSecOps – Manifesto

geographomics
2pts0
www.youtube.com 10y ago

A music-making machine constructed using 2,000 marbles

geographomics
2pts0
aeon.co 10y ago

Could machines have become self-aware without us knowing it?

geographomics
4pts2
notes.tweakblogs.net 10y ago

High-Color GIF Images

geographomics
2pts0
marcinciura.wordpress.com 10y ago

Smiths, Millers, Priests: European Occupational Surnames

geographomics
1pts0
github.com 10y ago

Pupy: a remote administration tool with an embedded Python interpreter

geographomics
1pts0
atlas.ripe.net 10y ago

Become a RIPE Atlas Probe Host

geographomics
1pts0
github.com 10y ago

Peinjector: MITM PE file infector

geographomics
26pts4
www.playingwithpigs.nl 10y ago

Playing with Pigs

geographomics
136pts74
www.irit.fr 10y ago

A study of a text-sharing platform driven by biblioleaks and crowdsourcing [pdf]

geographomics
1pts0
security.cs.rpi.edu 10y ago

Hardware Reverse Engineering Course

geographomics
96pts9
ithare.com 10y ago

Improve Security Against Brute Force Attacks Without Overloading the Server

geographomics
1pts0
blogs.coreboot.org 11y ago

The truth about Purism: Why Librem is not the same as libre

geographomics
44pts2
vimeo.com 11y ago

Noisedive

geographomics
1pts0
thecreatorsproject.vice.com 11y ago

This Is What Happens When You Repost an Instagram Photo 90 Times

geographomics
3pts0
paper-bird.net 11y ago

Why I am not Charlie

geographomics
2pts0
www.theguardian.com 11y ago

Musician rebels embrace darknet to explore uncensored Internet frontiers

geographomics
9pts0
dedis.cs.yale.edu 11y ago

Dissent – Accountable anonymous group communication

geographomics
244pts25
www.youtube.com 11y ago

Timelapse video of a sunspot

geographomics
4pts1
www.bbc.co.uk 11y ago

Virgin's Richard Branson offers staff unlimited holiday

geographomics
7pts0
www.cheswick.com 11y ago

The McCollough Effect

geographomics
56pts16
www.skeptic.com 11y ago

Are UFO Alien Faces an Inborn Facial Recognition Template?

geographomics
5pts0

It is a security measure, as it involves authentication through the series of knocks. It's a weak security measure on its own, so you obviously wouldn't want to rely on port knocking by itself, but it does have utility in preventing an attacker from discovering the service through a simple port scan.

I don't quite understand why you're saying it adds nothing at all.

If the port knocking was obscuring an unauthenticated root shell then you would have a good point, but this is a defence in depth measure that adds to the security. It helps because it's one more hurdle for an attacker to bypass.

Most of the commentary here so far is really quite tangential to the actual research done. Everyone commenting on this article should make sure they've read the study first, with particular attention to the 'Limitations' section on page 11: http://m.jmq.sagepub.com/content/early/2016/02/25/1077699016...

One other feature of the study that limits its wider applicability is that it is entirely US-centric. It would be interesting to read follow-up work on samples taken from other cultures and countries.

After the initial period of adaptation, I found it actually increased productivity. Perhaps it was just preventing already-established bad habits that arise from having the internet constantly available.

On the topic of work environment: in one job I worked at, we had the Internet machines completely separated from the work machines. If you needed to check something you had to physically walk over to the Internet desk. Great for focussing on the task at hand without distraction, and considering carefully what information you need.

That's quite a delight for the ears. Reminds me of Stéphane Picq's work on the Dune computer game soundtrack, back in the early 90s. It had some similar sounds.

Nonetheless, if Apple had designed the update mechanism to require both a signed firmware image, and authentication by the user, then the FBI's request would not be possible. Such a design would also help to mitigate the end-user effects of an insider attack at Apple, where a rogue employee signs malicious firmware, or leaks the signing key to some adversary.

I'd be very surprised to meet a computer scientist who doesn't know what a stack is. It really is a fundamental part of computer science.

Jailbreaks address a different type of vulnerability - that of incorrectly written code or poorly designed systems, that can lead to a privilege escalation.

The vulnerability that the FBI are using is the ability of Apple to update the iPhone with arbitrary code, provided it has been signed with their secret key. It's an important feature, of course, but still a security vulnerability - albeit an irrelevant one for the vast majority of iPhone users.

I agree - this is the type of vulnerability that, assuming Apple is extremely careful about protecting their signing key, is only exploitable by court order or similar state request. This crypto implementation on iPhones and the like isn't really designed to protect against that, it's really more to prevent the common criminal from accessing your personal data. Apple already comply with law enforcement requests to access iCloud backups and other such data, so assisting with this passcode crack isn't really much of a stretch.

The purpose of the non-disclosure sections of this law is to prevent the suspect being wiretapped (or similar) knowing that they're being wiretapped.

It's not exactly very useful if someone under active investigation finds out that they're being watched, and changes their communications behaviour as a result.

In this case, it wouldn't need to be applied as the suspect is dead.