HN user

jvdh

1,511 karma

Twitter: @1sand0s Blog: https://1sand0s.nl

Posts24
Comments424
View on HN
www.youtube.com 9y ago

Al Jazeera Investigations: Spy Merchants Selling Surveillance Software

jvdh
1pts0
ooni.torproject.org 9y ago

New Ooniprobe Mobile App: Measure Internet Censorship and Performance

jvdh
1pts0
www.vusec.net 9y ago

DRAMMER: Flip Feng Shui Goes Mobile

jvdh
3pts0
www.caida.org 9y ago

Spoofer Project

jvdh
1pts0
vusec.net 9y ago

Flip Feng Shui

jvdh
2pts0
www.ieee-security.org 10y ago

Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector [pdf]

jvdh
3pts0
www.rfc-editor.org 10y ago

An HTTP Status Code to Report Legal Obstacles [pdf]

jvdh
4pts0
lists.alchemistowl.org 10y ago

U.S. Will Renegotiate Wassenaar Arrangement

jvdh
1pts0
hackaday.com 10y ago

First Raspberry Pi Zero Hack: Piggy-Back WiFi

jvdh
1pts0
cesgdigital.blog.gov.uk 10y ago

Making security better: Passwords

jvdh
3pts2
tools.ietf.org 10y ago

Confidentiality in the Face of Pervasive Surveillance

jvdh
28pts0
thebulletin.org 10y ago

Is artificial intelligence really an existential threat to humanity?

jvdh
4pts0
www.reddit.com 11y ago

The Taboo of Burnout

jvdh
1pts0
www.bgpmon.net 11y ago

What caused today's Internet hiccup

jvdh
188pts27
www.sigcomm.org 11y ago

A Qualitative Assessment of the 2012 Botnet Internet Census [pdf]

jvdh
1pts0
safecurves.cr.yp.to 12y ago

How to manipulate curve standards: a white paper for the black hat [pdf]

jvdh
3pts0
james.grimmelmann.net 12y ago

Letter to PNAS Editor calling for retraction of Facebook study article [pdf]

jvdh
1pts0
1sand0s.nl 12y ago

Morality on the Internet

jvdh
1pts0
1sand0s.nl 12y ago

Making DNSSEC more accessible

jvdh
1pts0
1sand0s.nl 12y ago

DNSSEC has failed

jvdh
84pts36
yro.slashdot.org 12y ago

Now Published: Study showing Pirate Bay blockade has no effect

jvdh
1pts0
snowdenandthefuture.info 12y ago

Eben Moglen: Snowden and the Future

jvdh
5pts4
factsandotherfairytales.com 13y ago

The Least Stressful Job for 2013? A Real Look at Being a Professor in the US

jvdh
48pts53
blog.cmyplay.com 16y ago

MacBook Prices Around the World

jvdh
2pts0

From what is currently known it seems plausible that Marcus Hutchins should at least be under investigation. Some of the things he has done in the past were murky. Stopping a large ransomware attack (by accident) does not change that fact.

I have not seen remarks in the security community that people were afraid of being arrested out of the blue like Marcus Hutchins.

The point of the letter is that there is something as being polite.

Intel telling him about it at some point would have been polite.

This is earnest in that he would have liked someone from Intel to tell them.

It is completely earnest in the sense that he is not expecting any money from it. Likewise he has never expected anything from Linus Torvald when MINIX was used as the primary source of inspiration for the Linux kernel when he started out with it. Although they did have some pretty serious discussions about it, but nothing more than that.

It should be noted that Minix is code that was developed by university researchers. Researchers who are payed for by (primarily) European and Dutch tax euros.

Also note that many of that time, energy and money to modify GPL code is not just programming time, but also a lot of legal advice time. With BSD-like license it should be immediately clear what you can do with the code (i.e. almost everything).

I'm guessing they are also going after the "fitness club" like profit idea. That is, get a subscription, use it frantically in the beginning. Then slowly you go less and less, but still keep the subscription because you never know when you might want to be healthy again. Or cancelling it is too much of a hassle for just $10/month.

They had a perfectly fine businessmodel. 1Password has been running for years without the SaaS model:

P. S. Please don’t think our excitement for memberships has anything to do with money. We’re completely self-funded so we don’t have any investors forcing us to make changes by looking solely at our bottom line. We were doing just fine selling individual licenses and AgileBits was already steadily growing before 1Password Teams was even introduced.

https://blog.agilebits.com/2017/07/13/why-we-love-1password-...

this raises an interesting question: does one side have an advantage with an incorrectly oriented board? Googling it doesn't really seem to give an answer.

Most results that I found note that it probably does not affect the game that much. If you're planning to write down moves it may become confusing when someone with a correctly set up board tries to replay it.

The naming of "private key" versus "secring.pgp" is very valid criticism.

Also the fact that it crashes on first use, and that it is all not very user-friendly are all valid criticisms (still!).

PS. please don't down vote because you disagree.

Encrypted email for this user group is certainly not over, and there is still no realistic alternative for it. So PGP is not going to go away completely.

They don't because GPG is ancient, and there was no proper way to do email validation back then. It is sort of better now, but still very hard to do.

If you have realistic worries that someone can intercept your email, then email validation of your GPG keys is not going to help.

The author probably exaggerates, but identifies a very valid point. You really don't want to have this kind of confusion about something that you are planning to trust your secrets to.

There is still very much a set of users in the incident response community that relies on PGP. These are professional teams that need to communicate with each other. They talk about upcoming disclosures, current abuse, upcoming operations or patches, et cetera.

This stuff is almost all short to mid-term secret. Most of this will become public in a month or so. Leaking meta-data is an assumed risk (or too much hassle to avoid, take your pick).

If you mean "logging" as in web server logs, then it completely depends on the configuration of the server and there is nothing the client can do about it..

If you mean "transferring over the network", then yes, HTTPS only shows the server you are connecting to, but not the specific URL.

Then again, that can be deduced from the transfer sizes that are still shown.

Although with most TLS implementations they will see the size of your transfers, thus still giving away which URL you visited....

.onion addresses are like a public key. The server needs to have a private key.

Vanity addresses, ones that have a name at the beginning, require some processing in order to find the right public key.

Vesper, Adieu 10 years ago

In this case the reason is that not only the sync service costs money, but also the custom font they use costs money. So just letting it sit there would still cost money (on top of the fee for the app store itself).

FreeBSD Myths 10 years ago

Windows handles a lot of abstractions, to hide users from the nitty gritty details (OS X does the same thing). One of those things is hiding as much of the file system as possible.

Unix usually has users engaged at a lower level, adding a startup daemon means moving a file to a certain place. That shows that filesystems are much more the direct interface for the operating system.

Also, it is possible to have a Unix operating system, but have a completely different filesystem underneath. This is just not possible for Windows users. So there is no choice, so it is nothing Windows users think about in general.

Alternative title: Guy forgets laptop at security checkout and blames TSA for his stupidity.

I emerged from the scanner without any problems, collected my 2 bags and incidentals, and proceeded into Terminal 5. After awhile, I looked into my backpack and realized that I didn’t have my computer. My heart skipped a beat! I turned around and rushed to the security area.

The life and the work back then is very different from the life and work that we have now. A big factor is that there is no war to motivate people to work hard. Another is that labour circumstances are very very different now than what they were previously.

Finally almost nobody who reads HN does repetitive manual labour. Manual productivity is very different from mental productivity.

From my own experience, I'm not even productive for 40 hours per week. Let alone working 50 hours consistently every week.

The best information is at the very end of the report where all the tables and graphs are. They show that munition workers are at peak production at around 50 hours or so. There are many many caveats for drawing conclusions from these results:

  * The collected data is from 1915-1920
  * The collected population is very very small 
    (most sets are less than 50 individuals, one is ~100)
  * The work performed by the population is extremely repetitive manual labor
With these caveats, it is safe to say that most of the audience of HN has nothing to gain from the results of this study.