HN user

jor-el

1,063 karma

http://serializethoughts.com/

Posts88
Comments41
View on HN
blog.isosceles.com 2y ago

Phineas Fisher, Hacktivism, and Magic Tricks

jor-el
3pts0
www.ft.com 3y ago

‘We are full’: the rebirth of Europe’s sleeper trains

jor-el
3pts1
arstechnica.com 4y ago

One institution keeps claiming math’s highest award

jor-el
7pts0
eprint.iacr.org 4y ago

Trust Dies in Darkness:Shedding Light on Samsung’s TZ Keymaster Design[pdf]

jor-el
2pts0
www.mattblaze.org 4y ago

Testing Phone-Sized Faraday Bags

jor-el
368pts201
www.nytimes.com 4y ago

The Married Will Soon Be the Minority

jor-el
45pts93
papers.ssrn.com 5y ago

Zero-Commission Individual Investors,High Frequency Traders,& Stock Mrkt Quality

jor-el
2pts0
www.xda-developers.com 5y ago

Google will make the Android Runtime (ART) a Mainline module in Android 12

jor-el
2pts0
thenewstack.io 5y ago

Which Programming Languages Use the Least Electricity? (2018)

jor-el
3pts0
arxiv.org 5y ago

Dissolving the Fermi Paradox (2018)

jor-el
3pts0
arstechnica.com 5y ago

Quantum reality is either weirdly different or it collapses

jor-el
1pts0
en.wikipedia.org 5y ago

Long Hair in Singapore

jor-el
2pts0
www.cnet.com 6y ago

Next BMW might only have heated seats for 3 month

jor-el
2pts3
www.pnfsoftware.com 6y ago

Reversing DexGuard

jor-el
2pts0
thehill.com 6y ago

Elon Musk calls for Amazon to be broken up: 'Monopolies are wrong '

jor-el
10pts2
web.archive.org 6y ago

Debugging Behind the Iron Curtain (2010)

jor-el
2pts0
news.ycombinator.com 6y ago

Ask HN: Problem of social unrest and shutting down Internet

jor-el
10pts16
arstechnica.com 6y ago

Apple tells moviemakers that villains can’t use iPhones, Rian Johnson says

jor-el
19pts6
github.com 6y ago

Function order shuffling to defend against ROP and other types of code reuse

jor-el
2pts0
manybutfinite.com 7y ago

iPhones, Armed Robbery, and Hacking (2018)

jor-el
13pts5
www.bloomberg.com 7y ago

India’s Rickshaw Revolution Leaves China in the Dust

jor-el
2pts0
www.dwheeler.com 7y ago

Do not install or develop mobile apps unless you have to

jor-el
7pts1
www.astronomy.com 7y ago

Voyager 2 spacecraft approaches interstellar space

jor-el
2pts0
arstechnica.com 7y ago

Wayback Machine director outlines the scale of everyone's favorite archive

jor-el
246pts32
arstechnica.com 8y ago

Thailand cave rescue relied on talent, luck, and on sticking to the rules

jor-el
59pts11
www.rte.ie 8y ago

EU hits Qualcomm with €1B fine for Apple deal

jor-el
1pts0
www.troyhunt.com 8y ago

Is India's Aadhaar System Really “Hack-Proof”?

jor-el
3pts0
lwn.net 8y ago

Notes from the Intelpocalypse

jor-el
1pts2
github.com 8y ago

Htop Crashing on MacOS High Sierra

jor-el
4pts0
arxiv.org 8y ago

Camera Based 2FA Through Mobile and Wearable Devices [pdf]

jor-el
1pts0
Denuvo Analysis 1 year ago

You can take a look at SiMBA++ -> https://github.com/pgarba/SiMBA-

It is a C++ implementation of SiMBA [1] - a tool to handle linear MBAs, made available by Denuvo itself. Denuvo have another tool - Gamba for handling some variety of non-linear MBAs. And then further improvisation by another researcher - MSiMBA [3].

SiMBA++ since written in C++, it is fast and it integrates well into the LLVM passes to automatically identify the MBAs and replace them in the LLVM IR with simplified expressions. So no additional work required.

Shameless plug - me and my colleague (author of SiMBA++) recently gave a talk about using LLVM for deobfuscation of WASM, where we talk about MBAs, SiMBA++ etc. The idea is not limited to WASM, it is language agnostic once you have a binary lifted to LLVM IR. https://www.youtube.com/watch?v=gKRdOcuXbYI

[1] SiMBA - https://github.com/DenuvoSoftwareSolutions/SiMBA [2] Gamba - https://github.com/DenuvoSoftwareSolutions/GAMBA [3] MSiMBA - https://github.com/mazeworks-security/MSiMBA

I have an iPad from 2012 with retina display, still a good device, but on slower side. The battery backup is still mighty good (can last around 6-8 hours easily with constant use). It is running iOS 9.5 (probably?). It is a potential security risk too, so I dont use it for browsing random internet stuff. Instead I mostly use it for consuming media content - like podcasts, youtube videos etc, which I pre-download on my homeserver setup.

I put my old laptop and hard disks to use as a homeserver, I have scripts running which download podcasts and youtube channels I view often, and at night I can just use my iPad to consume this. Another plus with this setup is, I dont need to see those annoying YT ads, and I always have the videos backed-up with me even if the channel is taken down or the author removes videos.

I also use my iPad as a roku remote over WiFi. Overall I am able to extract utility than just throwing it away.

With software-as-a-service becoming widespread and the practice of micro-transactions starting to become common, soon people might start questioning that was digital payment revolution worth it? If made life easy in the starting, but now its turning out to create more headaches. The old way of paying hard cash and walking off was much better.

Some I see are surprised to see the level of obfuscation used in the application. Many pointed, many ingredients for the obfuscation used in the app are off-the-shelf and few of them can be said to be well known in the industry, but still there is a cost in integrating them into a product. Obfuscation is notorious in breaking things which should work normally (normal compilation process) and as a own goal making it hard to debug as well. Integrating, testing, debugging and difficulty in debugging production crash logs is a considerable cost.

That said, obfuscation is increasingly being used in mobile applications now. Check your banking application or some government applications, you will find obfuscation being used. With mobile applications getting richer and lot of code executing on the client side, makes it compelling case to secure applications by using obfuscation (as a defense-in-depth approach).

Open standards like OWASP MSTG [1] MSTG-RESILIENCE-9 recommend such approach.

  Obfuscation is applied to programmatic defenses, which in turn impede de-obfuscation via dynamic analysis.

[1] https://github.com/OWASP/owasp-masvs/blob/master/Document/0x...

I am curious to know how the Uber/Lyft drivers operate with such laws. Often they need to access maps, how does the law apply to such drivers?

I second this. It is very well written and among the top fantasy books I have read. The only frustrating part is the release of third book is no where near in the horizon.

In my personal experience getting started with cybersecurity career is tricky. Many companies want cybersecurity professionals, but most of them are not willing to train one. It creates the dreaded situation - companies dont hire you because you dont have experience, but you need a job to get experience.

A good way to get started is to take up any opportunity you get (and of course, of your interest), so you get a foot in the door. Other comments have talked about internships and certifications, I would like to highlight OSCP certification. It is hands on certification, and it will give you a good feel about the whole pentesting process. It is fairly respected certification in the industry and getting one will surely help you in getting a good starting job.

Also, keep honing your skills on various aspects of security, on job, you might not be dealing with all security topics all the time, but they show up and it helps to know about them. For example, you might be evaluating a C codebase with some applied cryptography. You may have all your focus on improper memory handling, but knowledge about applied cryptography can be helpful to contribute better.

For me the main takeaway from the article is that the robbers have become sophisticated enough to perform phishing attacks to get iCloud credentials.

Also, the author says using Authy is a good alternative as it provides encrypted backup, but account authentication is via OTP to the registered phone number, so it brings back to the same problem. Is there other alternatives to this?

I have come across many pentesting labs using these tools to deal with obfuscated binaries. You can check Quakslab's blog, they have articles on this [0]. Another interesting project is of cracking Tigress VM using Symbolic execution [1]. The use has dramatically increased in past few years as many new tools are available and also hardware is more performant now. I am also using these tools in my day-to-day job to deal with obfuscated binaries and reverse engineering. I use Miasm [2].

PS: My company is hiring for such roles https://www.reddit.com/r/netsec/comments/b90hep/rnetsecs_q2_...

[0] https://blog.quarkslab.com/deobfuscation-recovering-an-ollvm... [1] https://blog.quarkslab.com/deobfuscation-recovering-an-ollvm... [2] https://github.com/cea-sec/miasm

Last time I took such overnight train in Europe was Frankfurt to Copenhagen in 2013 by DB, and it was nice and comfortable. Trains always have more leg space and moving around areas than an airplane. With budget airlines they are trying to cram in as many people as possible, almost to the point of making you feel claustrophobic.

With trains there is no hassle of going to the airport, as they are mostly around city center. Also, I found people to be more friendly in trains, unlike in airplane, where most people have their headphones on, and do-not-disturb expressions.

Its very much same in Singapore as well. In supermarket, more often than not, cashier puts one item in one plastic bag, so if you are buying a weeks grocery, you easily get 10-12 plastic bags just like that. The vegetables are pre-packed covered with plastic. Some fruits are packed with another harder plastic - apart from the laminated plastic. And the thing that bothered me the most is during chinese new year, each mandarin is covered in plastic individually. Why do you want to cover each mandarin, for a fruit which already has a thick peel!!

With developed countries, with all educated residents, are finding hard to curb plastic use (or lack of effort), it looks humanity is still some distance away to make a serious dent to use of plastic overall.

The Undoing Project: A Friendship That Changed Our Minds by Michel Lewis. [0]

It is about the one of the greatest paternship between Nobel laureate Danny Kahneman and his colleague Amos Tversky.

Kahneman and Tversky’s extraordinary friendship incited a revolution in Big Data studies, advanced evidence-based medicine, led to a new approach to government regulation, and made much of Michael Lewis’s own work possible. [1]

The book is very well written and if you have read Kahneman's Thinking fast and slow, then you should also read this one.

[0]https://www.amazon.com/Undoing-Project-Friendship-Changed-Mi... [1]https://www.goodreads.com/book/show/35631386-the-undoing-pro...

Gemalto | Software Engineer | Singapore | C Developer for iOS Platform | Full Time | Visa/Relocation

Position: C developer for iOS platform

Gemalto provides mobile platform solutions to various industries, including governments and banks, across the globe.

This role is very specific to C developers who have a good understanding of the iOS platform, and have a past experience in writing secure code.

For more details: https://www.linkedin.com/jobs/view/995878745/

Can someone throw some light on why Google is not using ARM Trustzone technology? Many current Android OEMs are using it, particularly Samsung KNOX is security mechanism all built around trustzone technology.

What advantages does these Titan chips offer over the existing trustzone technology.

Kudos! This a great work. I remember few years back when I was exploring TLS, there were no such resources and it took many months of trial and error to get some reasonable understanding. I tried doing a similar thing, but was only able to do for couple of packets [0]. Surely such an illustration will go a long way to help newbies to understand a complicated protocol.

[0] https://serializethoughts.com/2014/07/27/dissecting-tls-clie...

I am interested to understand how does these attacks work. The article states, after the victim disclosed the CC number there were ATM transactions performed using it.

How are scammers able to generate a physical card in first place to perform ATM transaction? Is it something similar to card skimming with cards having magnetic stripe? Can this attack be performed with cards using chips?

Also I often come across a fraudulent transaction being performed even if only credit card number is disclosed, while cvv and expiry date are not. As per my understanding all 3 info is needed to perform a transaction.

Do anyone have some resource where these attacks are discussed in detail and how they are carried out.

Gemalto Pte Ltd | Singapore | Mobile Security Researcher/Pentester | Singapore Full-time | ONSITE| Visa/Relocation

Position: Mobile Security Researcher/Pentester (Android and iOS)

Job Description:

Gemalto provides mobile platform solutions to various industries, including governments and banks, across the globe. This role is very specific to mobile platforms- Android & iOS. The core responsibilities are:

- Perform pentesting on mobile products - source code reviews - Risk Assessment - Researching on new attack and defense techniques for mobile applications. - Act as consultant to internal teams and provide advise for best security practices, applied crypto, authentication, secure programming etc. - Reverse Engineering mobile application (native, Java, ObjC).

Desired Skillset: - Understanding of the attack paths on mobile applications - Understanding about common OS exploits: Jailbreaking/Rooting/Flashing a device, custom kernels, custom ROMs, hooking frameworks - Comfortable with ARM/Aarch64 assembly . - Knowledge of classic attacking techniques: data cloning, reverse engineering, traffic interception, hooking, debugging (like gdb, jdb, other tools like Burp suite, Substrate, Frida, Cycript, IDA etc.) - Knowledge of iOS/Android security frameworks – their implementation and mitigation controls - Knowledge about applied cryptography and best practices. - Experience with reversing obfuscated code (C, Java, ObjC) using tools/techniques like symoblic execution, unicorn etc, is a plus.

It is a small well managed team, with challenging work and mostly involves working independently. Training and attending conferences opportunity is provided.

If you are interested to learn more about the role, feel free to contact me at vikas.gupta@gemalto.com.

On Linkedin: https://www.linkedin.com/jobs/view/729732099/

I completed the series a month back. I found 1st book to be a bit slow and need to force myself to read sometimes. But 2nd book thoroughly caught my imagination and I would say the best of the 3 books in the series.

Till now I have found this to be the best summary for someone who is technical, but does not understand all gory details of CPU working.

Cydia performs dynamic hooking, and patches the function in the runtime. In theory app's signature should be intact (I have never come across this scenario in practice, so might be wrong). Generally, application implement additional checks for function hooking and dynamic library injections to prevent such attacks.