HN user

killnine

283 karma
Posts20
Comments95
View on HN
www.vpnmentor.com 8y ago

GPON Home Router Critical RCE

killnine
1pts0
www.reddit.com 11y ago

Blackbank hacked supposed proof

killnine
1pts0
motherboard.vice.com 11y ago

Don't Just Rely on Tor: Security Advice from an Alleged Dark Web Veteran

killnine
3pts0
shime.github.io 11y ago

I used OS X for a week and wrote a blog post about my experience

killnine
3pts0
www.wired.com 11y ago

Feds Demand Reddit Identify Users of a Dark-Web Drug Forum

killnine
219pts215
gist.github.com 12y ago

Heartbleed python script

killnine
2pts0
outsidelens.scmagazine.com 12y ago

Removal method secret code Find iPhone iCloud Lock BYPASS

killnine
1pts0
news.ycombinator.com 14y ago

Ask HN: [email] what is the solution?

killnine
1pts1
news.discovery.com 14y ago

Mars Viking Robots 'Found Life'

killnine
26pts5
e.businessinsider.com 14y ago

Did Facebook Paid Too Much For Instagram? Remember How Yahoo Blew It

killnine
1pts0
www.bbc.co.uk 14y ago

Half a million Mac computers 'infected with malware'

killnine
4pts0
sbranigan.wordpress.com 14y ago

The Latest on Credit Card Frauds

killnine
11pts0
sbranigan.wordpress.com 14y ago

Tracking & recoverying a stolen iphone using AP finding SW

killnine
1pts0
corycardio.tumblr.com 14y ago

Authentication Systems: Per-Site vs. Single Sign On

killnine
1pts0
sbranigan.wordpress.com 14y ago

DoS in cell phone network. A bit on femtocell- the network "extender"

killnine
2pts0
vulnfactory.org 14y ago

Universal Motorola Root Exploit : Reverse Bounty Experiment : Failed

killnine
2pts0
www.droid-life.com 14y ago

Android OS And Kinect, Creates Minority Report Like Experience

killnine
3pts0
news.ycombinator.com 14y ago

Ask HN:Which is cheaper: a new technology or a new bill?

killnine
1pts0
news.ycombinator.com 14y ago

Ask HN: Looking for a 'how to hire' type-ish thread from a githubber

killnine
1pts1
news.ycombinator.com 14y ago

My jam: HN ==most valuable, useful site I've ever check on a reg

killnine
4pts0
Chatroom.horse 11 years ago

bad.horse

bad.horse

bad.horse

bad.horse

he.rides.across.the.nation

the.thoroughbred.of.sin

he.got.the.application

that.you.just.sent.in

it.needs.evaluation

so.let.the.games.begin

a.heinous.crime

a.show.of.force

a.murder.would.be.nice.of.course

1. because somebody there wants to solve a challenge

2. because somebody there wants to fix a problem

3. because somebody there wants to help other people

4. because somebody there wants to wave their org's flag everywhere this good news goes

5. because somebody there wants to make the world a better place

I personally have difficulty finding postings. While my resources do include the normal hiring places, I find that both the amount of "cybersecurity" posts in the normal places and the amount of "cybersecurity"-geared hiring places, are surprising low.

Maybe my difficulty lies in my perceived demand quantities versus postings I find.

With every HN Whos Hiring thread, I tell myself I need to write a tool to filter the posts based on buzz words, because scanning hundreds of the job openings for "security", "penetration", and the like is a major pain.

I know some about it. As it stands right now, law firms need to find, trust, and pay forensic investigators. The firm has to leave some data collection up to the investigator, and then have some data turned over. By data, I mean hard drives, images of hard drives, images of network shares, email exchanges, etc.

The law firm has to pay for the data collection, the disk space to store the data, the transmission of data back and forth (investigator found something good, buys external HD, ships it via the mail), the data analysis, the investigation and reporting, and then sometimes the expert witness.

Sometimes, the law firm does not know what they're looking for, in other words, there is no smoking gun piece of data. Sometimes, the goal is to find something, anything, that would hint, point, or prove a goal.

What this means is that a retainer can either be here is 10hours worth of analysis/investigation to find the email we know was sent that contains this particular text. They do not plan on the analysis and investigation to exceed that and usually the result is we found it/didn't find it and we did it in the time allotted or under the time.

It can also be, "we're looking for evidence that this type of event has occurred". This is where the billed-hours start stacking up. Its hard enough digging through other people's emails, documents, and pictures looking for something, let alone digging without having something in particular to look for.

The point is, I believe that they, the law firms, want to, and need to, bring this in house. This greatly improves the process. But now they need security, real security, because its not their data being stored, it is their client's client's data and so forth. It becomes very sensitive.

They need infrastructure. They need to be able to forensically acquire data. Forensically store data. Forensically analyse data. Forensically share data. The infrastructure needs to be fast, easy, and effecient. We're seeing 6TB hard drives now... shares of much, much larger size. And they do not want to be storing their client's data in someone else's cloud.

Then they either need technicians and investigators or the ability to hire and grant access to their data on their network to the tech/investigator. They need technicians to provide solutions to the inevitable problems run into (i.e. how can I acquire each of the 2 drives in this FusionDrive raid and return to the lab and build the raid on something other than osX?) And they need investigators experienced at honing in on relevant data while digging through vast troves of data.

it is absolutely not a ludacris dream. I've been dreaming it for years. All my machines run linux. As long as I'm NOT on a phone or tablet, I sign in, ssh, restore tmux/screen session, and pull X via xpra.

Why my phone is unable to be a terminal to all my other machines is beyond me.

I should have 1 hard drive and 1 "computer", and 1 desktop. Every other machine should be a window to this desktop.

At least... in my dream world.

they're less common now

Source?

arent sent instantly so an attacker could intercept or alter them

intercept where?

Most attackers ... generate plenty of logs

Source?

They can implement FSS and remote logging.

Point is, thus far they have not, and their first choice was not what the author views as more secure.

How can you be so sure it was not accidental?

Seems to me, the need to be in control is enough motivation for these acts... without ever thinking that someone will have to build a Chinese amazon