HN user

graystevens

851 karma

[ my public key: https://keybase.io/graystevens; my proof: https://keybase.io/graystevens/sigs/_4qVvqrHehM0x3Xm0Iw5bXNk1N-BsvIXcn6C9FAVe3U ] findkismet: 7aa1f72a72193c6baa62b247c4dce3bd441fe4a01aaf341be66dff13e1574334

Email: graham@grh.am

Posts36
Comments166
View on HN
grh.am 5mo ago

M1 MacBook Pro as a K3s Node with Asahi Linux

graystevens
1pts0
lidlayer.com 8mo ago

LidLayer – Preserve MacBook Stickers

graystevens
2pts0
lidlayer.com 3y ago

Show HN: LidLayer – Preserving Laptop Stickers on MacBooks

graystevens
1pts1
grh.am 6y ago

Preserving Laptop Stickers – A Post Factum

graystevens
1pts0
www.kickstarter.com 7y ago

Show HN: LidLayer – Protect and Preserve Your Laptop Stickers

graystevens
2pts0
grh.am 7y ago

Preserving Laptop Stickers – A Post Factum

graystevens
2pts1
grh.am 7y ago

Preserving Laptop Stickers – A Post Factum

graystevens
3pts3
grh.am 7y ago

Preserving Laptop Stickers on MacBooks

graystevens
612pts334
monzo.com 7y ago

Monzo Is Launching in the USA

graystevens
9pts0
grh.am 7y ago

NVMe SSD Upgrade Guide for an Early 2015 MacBook Pro

graystevens
3pts0
breachinsider.com 7y ago

Data Breaches like Apollo are why we exist

graystevens
1pts0
breachinsider.com 7y ago

Data Breaches like Apollo are why we exist

graystevens
2pts0
breachinsider.com 7y ago

Security for Startups Guide

graystevens
3pts0
grh.am 8y ago

A Look at the Compromised Gitea Release

graystevens
2pts0
grh.am 8y ago

Deploying a Hugo Static Site Using GitLab, CI/CD, and SSH

graystevens
2pts1
breachinsider.com 8y ago

Show HN: Honey Buckets – Find out who is snooping through your Amazon S3 buckets

graystevens
4pts0
breachinsider.com 8y ago

Show HN: Honey Buckets – Find out who is snooping through your AWS S3 buckets

graystevens
2pts0
doublepulsar.com 8y ago

Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

graystevens
188pts101
breachinsider.com 8y ago

Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

graystevens
71pts43
www.arqbackup.com 8y ago

Arq 5 Mac security update

graystevens
1pts1
www.kb.cert.org 8y ago

Windows 8 and later have been failing to apply ASLR

graystevens
3pts0
breachinsider.com 8y ago

Credential Stuffing: How breached credentials are put to bad use

graystevens
1pts0
breachinsider.com 8y ago

Show HN: Breach Insider – Find out about your data breach, before everyone else

graystevens
3pts1
breachinsider.com 8y ago

Show HN: Breach Insider – Find out about your data breach, before everyone else

graystevens
1pts1
news.ycombinator.com 9y ago

Ask HN: Feedback on my single founder startup – Breach Canary

graystevens
4pts0
news.ycombinator.com 9y ago

Ask HN: UK Startups and VATMOSS

graystevens
3pts9
hmarco.org 10y ago

Back to 28: Grub2 Authentication 0-Day

graystevens
84pts16
www.troyhunt.com 10y ago

000webhost breached in March 2015 – 13M records accessed

graystevens
5pts0
news.ycombinator.com 10y ago

Ask HN: Keybase.io Invite

graystevens
2pts9
www.malwaretech.com 11y ago

Surviving reformats by infecting the hard disk firmware

graystevens
64pts34

A project I posted a few years back on HN for an invisible full-lid sticker for MacBooks, so that you could both protect them _and_ keep your stickers once you get a new laptop. I finally found a cost effective manufacturing solution, so setup a shop for them!

LidLayer - https://lidlayer.com

Some of you may remember something similar from a few years ago: https://news.ycombinator.com/item?id=20405957

Well, I'm back, and this time I've managed to turn this into an actual physical product! It all started with a simple blog post back in 2019, which gained enough traction on various websites that it seemed worthwhile pursuing. So, a Kickstarter[0] was, well, started – but it never gathered enough momentum to get it across the line (and looking back, rightly so), and so everything got put on hold.

Then the pandemic happened, and I’m kind of glad the idea hadn’t taken off. I did however continue to get a trickle of messages and DMs asking what happened to LidLayer, and if there were any plans for the future…

Fast-forward a year or two, and I get the opportunity to go to a conference for work – the beautiful Objective by the Sea (ObtS)[1], where I am surrounded by stickered MacBooks! The idea of LidLayer immediately pops back into my head, and I can’t help but take another look at it, to see if I can make it work (it must be good if I keep coming back to it, right?).

So, I managed to find a supplier who can accurately cut the LidLayers way more cost-effectively than I ever could, meaning I could finally bring this whole thing back to life. And, what that also means is that because the cost of producing these has gone down, I can pass that saving on to you! Win win win!

[0] https://www.kickstarter.com/projects/grham/lidlayer-protect-...

[1] https://objectivebythesea.org/v5/index.html

We started something similar with BreachInsider (https://breachinsider.com) to allow businesses (or I guess individuals?) to do this themselves with minimal overhead or resources. The idea being that they sprinkle these ‘users’ throughout their databases and see where they show up, and be alerted if they ever get contacted or show up somewhere unusual (Pastebin etc.)

We ran something similar, firing ‘insiders’ across many of the top 100 sites and services, to spot breaches (either in the traditional sense of security incidents, or lapses in privacy for end users).

So it remains sticky when removed, but I certainly wouldn't expect it to fit quite as snuggly the second time around. Interesting idea though, but my initial reaction would be no, not re-applicable.

I think that might work for certain popular brands - Dell XPSs certainly crossed my mind, as well as the Lenovo Thinkpads. Both are likely to have a vinyl equivalent available that could be used, although I'd want to thoroughly QC how the Thinkpad lid holds-up with the residue on removal.

I have heard people use pihole linked with a VPN to act as a way of minimising tracking whilst on 3G/4G. It acts as a DNS server, so you could tweak your VPN config to run all queries through your pihole instance.

WireGuard for iOS 8 years ago

Depends on the country I am in as to whether or not I want to VPN whilst on a mobile connection (whether that is for just having an IP in my home country or don’t fancy my traffic going over their wires).

It is primarily for public and/or untrusted WiFi connections, or so that I can take packet captures of iOS applications easily without a jailbreak or connecting the phone via USB to a Mac.

WireGuard for iOS 8 years ago

I’ve been using the TestFlight beta for a while now - since it was first announced - and it’s been a great experience so far. The recently added option to activate on-demand is great, as it means I can now force VPN for any WiFi and/or mobile data connections.

The primary niggle I came across was transferring the keys between my host and the client, however after a bit of tweaking I found it far easier to just utilise the QR codes option. For those interested, I wrote about my experiences on my blog[0]

[0] https://grh.am/2018/wireguard-setup-guide-for-ios/

Well timed – I’ve been trying to get back into blogging, as a way of sharing and giving back, as well as improving my personal ‘brand’.

I was never really happy with the visual format of my site, which I think put me off writing at times - “if it were me, I’m not sure I’d read this in this format, it’s too visually taxing”. However with a quick style change to something much more basic, I’m feeling much more confident.

I think my final hurdle, which this article may help with, is my writing style. I get the impression that my ‘style’ changes fairly regularly, or depending on the topic or post I write for a different audience. This likely doesn’t matter too much for those visitors who come for a single post and move on, but anyone who would like to peruse around may get a slightly jarring experience.

Reposting from the other thread at https://news.ycombinator.com/item?id=18299015*

It is unclear from any reporting as to how this technically happened, which is a shame but hopefully that will be made public in the coming days. Some other outlets[0] have an interesting statement:

The breach also included details about where each passenger had traveled and any comments made by customer service representatives. The amount of data accessed varied among passengers.*

Based on those details, and the mention of 'no passwords were compromised', chances are this breach has come from an internal helpdesk type system, or possibly CRM. If however the statement around the passwords changes, that opens up a few other possibilities.

What this doesn't sound like, are the attacks we saw on British Airways[1] and Ticketmaster[2], where javascript was injected into the payment pages to vacuum up payment details from customers.

The statement around "The company has no evidence that any personal information has been misused" is always an interesting one, and is one of the many reasons I created my startup Breach Insider[3], so that data breaches like this could be detected much sooner (not 7 months later, as we have seen here), with minimal false positive alerts, and definitive evidence if any data has been misused. By using real email addresses that are unique to each company/business, you can be sure to find out if that data ever leaks & is abused for things like spam or phishing.

[0] https://www.theverge.com/2018/10/24/18019958/cathay-pacific-...

[1] https://www.britishairways.com/en-gb/information/incident/da...

[2] https://www.riskiq.com/blog/labs/magecart-ticketmaster-breac...

[3] https://breachinsider.com

It is unclear from any reporting as to how this technically happened, which is a shame but hopefully that will be made public in the coming days. Some other outlets[0] have an interesting statement:

The breach also included details about where each passenger had traveled and any comments made by customer service representatives. The amount of data accessed varied among passengers.

Based on those details, and the mention of 'no passwords were compromised', chances are this breach has come from an internal helpdesk type system, or possibly CRM. If however the statement around the passwords changes, that opens up a few other possibilities.

What this doesn't sound like, are the attacks we saw on British Airways[1] and Ticketmaster[2], where javascript was injected into the payment pages to vacuum up payment details from customers.

The statement around "The company has no evidence that any personal information has been misused" is always an interesting one, and is one of the many reasons I created my startup Breach Insider[3], so that data breaches like this could be detected much sooner (not 7 months later, as we have seen here), with minimal false positive alerts, and definitive evidence if any data has been misused. By using real email addresses that are unique to each company/business, you can be sure to find out if that data ever leaks & is abused for things like spam or phishing.

[0] https://www.theverge.com/2018/10/24/18019958/cathay-pacific-...

[1] https://www.britishairways.com/en-gb/information/incident/da...

[2] https://www.riskiq.com/blog/labs/magecart-ticketmaster-breac...

[3] https://breachinsider.com

I personally really liked how the PoC went – I plan on doing a full write up in the next couple of days, which will outline what I did, start to finish.

Here is an example of the sticker/skin and the finish. Excuse the slightly 'off' cut on the corner – I'm looking to produce a highly accurate template for each of the various models. https://imgur.com/FfQ3XQs

I’m working on a skin for developer laptops so that you can apply those sweet conference and startup stickers. No more risking your resale value, or even physically risking damage to your expensive MacBook.

I want the skins to be identical to the original laptop material so that they are practically invisible. So for the MacBooks, a silver aluminium sticker (or space grey etc.)

I’ve done a proof of concept and it worked brilliantly (in the process of writing this up) and its allowed me to display my old ‘laptop’ as a keepsake, whilst being able to sell the laptop on in almost perfect condition.

I’m thinking of going down the crowdfunding route, as a way of proving there is a market, as well as helping to fund someone of the equipment needed.

Edit: Added they’d be a near identical match to the original laptop, rather than just a plain ‘sticker’

I got fed up of going to conferences and getting some cool stickers that I never get to put anywhere.

The obvious idea is to put them on your laptop, but that can make reselling it difficult, and you lose those stickers if you sell it with them still attached.

So... I’ve managed to find some sticky-backed vinyl that looks almost exactly like the aluminium used on the MacBooks and MacBook Pro’s. I’ve stencilled and cut out a couple of lids and when applied you can barely tell they’re on there. They look awesome.

I’ve had them on nice hot laptops for a couple of months (with cool stickers applied on top) and they peel off fairly easily, but most importantly, leave zero residue.

I’m planning on figuring out if there’s a market for these ‘skins’ and going from there. I’ve take pictures along the way so I’ll put a blog together about it shortly, and gauge interest.

* Breach Insider (https://breachinsider.com)

* Data breach detection made easy, using pseudo-users with real information, unique to your business.

* Current stage: Bootstrapped and profitable. Working on (gradual) growth!

* Content marketing.. lots and lots of content marketing, to build our 'trust' within the community. There is nothing worse than a security startup that no-one has heard of.

I’ve got the same machine and will be looking to upgrade the SSD shortly with a lovely nvme m.2 ssd thanks to an adapter. The thought of going from 128GB to 1TB for ~£280, plus the performance upgrade, almost certainly means I’ll be holding onto this one for a while. (Shame it’s only got 8gb of RAM...)

I believe they are referring to proxying requests to third parties, rather than the first part of the post which refers to proxying to your own backend.

Proxying requests to a third-party will mean browser security features like CORS will assume they are entirely safe due to them appearing to come from your domain, and not “gist.github.com” etc.

For those that took part in previous years, would this be suitable for those of us running (or thinking of starting..) bootstrapped startups, as solo-entrepreneurs?

I ask because the curriculum looks great, but wondered if the mentoring might be a little more focused towards the more traditional startups looking to progress to VC funding, rather than those of us that are taking things a little slower on our own.