HN user

iraklism

199 karma
Posts6
Comments41
View on HN

Worth noting that the CC in London operates for 15 years now. I’m sure there is a wealth of data that can be analysed, and I’m even more sure that there are a number of studies and papers that have explored its usefulness and positive/negative impact on traffic/economy/environment/public transportation.

There is definitely a portion of people that this applies to. However, I’d wager that the majority of the Cryptocurrency market capitalisation is from people that really want to become millionaires really fast.

We deal with this almost every week, as in, we get into systems by searching through email:password leaks and use them.

There are a number of mitigating controls that can be applied here. Most will hamper usability, some will not.

There is a “simple” solution. Enforce 2FA. If not at the login, then before “dangerous” actions (transfer funds , change password , buy X/Y/Z )

“There’s a couple of good options (and this is not an exhaustive list) for pre-made tool VMs. Obviously you have Kali Linux for offensive tools and penetration testing, but you can also use Security Onion for the defensive side – intrusion detection and network security monitoring.”

Seems like it’s there.

I catch myself internally debating this from time to time.

On the one hand, we are encouraged to make decisions based on facts/data/evidence. Speculation is speculation. Anything goes.

On the other hand, if we only do this we are bound by the “reality” that has been provided to us. No evolution/revolution can occur.

History is filled with documented cases of these “conspiracies”.

I’d be really interested in hearing other peoples’ views on this.

The .feedback scam 9 years ago

You did the math, seemed small to me but that's how many seconds it takes to make 600 , assuming ~900 mil profit per quarter.

Spellfucker 9 years ago

I like this. I would love to see this being used in APT data exfiltration / DLP bypasses.

I was about to comment something similar , but then I saw your post. Btw I don't know why people are down voting it.

This is an important point. This research comes after 10 days of the leak. I have been following the leak closely, I've even compiled a list with all the analysis and resources on a gist.

Good guys, bad guys, kids, bored Blackhats, had enough time to practically follow the step by step instructions in order to implant the backdoor. It doesn't take more than 30-40 mins for the first read till a successful exploit.

The short answer is that we have no idea of knowing how many of those were backdoored by the NSA.

Also worth noting is that the leak happened 3-4 months ago. A lot of people had access to this privately.

Right on the money with the "Real World" anecdote.

We do penetration tests for a wide range of clients across many industries. I would say that the bigger the company, the more childish flaws we find. For sure the complexity, scale, and multiple systems do not help towards having a good security posture , but never assume that because you are auditing a SWIFT backend you will not find anything that can lead to direct compromise.

Maybe not surprisingly, most startups that we work with have a better security posture than F500 companies. They tend to use the latest frameworks that do a good job of protecting against the standard issues, and their relatively small attack landscape doesn't leave you with much to play.

Of course there are exceptions.

I get that we have to be open with tech. After all most tech seemed "impossible" "unrealistic" and "unfeasible" even a couple of years before they go mainstream.

But you have touched some use cases that are more frequent than most people think. London is a great example. My hometown Athens is much more closer to London as far as driving is concerned as opposed to LA or NY. I guess many other metropolis also.

How will AI brand A communicate with AI brand B about life critical decisions ? Hey we can either both crash to each other or kill that kid on the pavement. ( just an example , I don't want to go to the morality of the situation)

I assume there is going to be a "standard " . But have a look at your everyday tech. Standards are not easy. There are still WiFi routers/repeaters that cannot talk to each other nicely, just to give an example.

Usually in life critical systems you don't have interoperability issues because there is no interoperability. Huge fail-safe systems from a single vendor.