HN user

lvh

6,761 karma

Co-founder at Latacora. We bootstrap security practices. Check us out at https://latacora.com, or e-mail us at youagain@latacora.com. I focus on infrastructure security and cryptography.

President of the Clojurists Together Foundation. We help the Clojure ecosystem, primarily by funding important open source projects (like CIDER, Ring, Reagent, Calva, Fireplace...), but also critical infrastructure like Clojars. https://www.clojuriststogether.org/

Feel free to contact me at _@lvh.io or professionally at lvh@latacora.com. Twitter: @lvh.

I wrote an introductory course on cryptography called Crypto 101. It's available for free and pairs well with cryptopals:

   - https://www.crypto101.io
   - https://cryptopals.com/
[ my public key: https://keybase.io/lvh; my proof: https://keybase.io/lvh/sigs/3Vhvhy8z2GAvOxd_cISVYLuz61aGzZ8f6AKzD2uAWVA ]
Posts60
Comments1,717
View on HN
alexgaynor.net 3mo ago

If it could have, why didn't it?

lvh
2pts0
www.latacora.com 1y ago

Datomic and Content Addressable Techniques

lvh
166pts40
www.latacora.com 1y ago

Cryptographic Right Answers: Post Quantum Edition

lvh
109pts52
www.latacora.com 2y ago

Our approach to building security tooling

lvh
6pts0
www.clojuriststogether.org 6y ago

Clojurists Together Foundation

lvh
3pts1
latacora.singles 6y ago

The SOC2 Starting Seven

lvh
109pts65
latacora.micro.blog 6y ago

Stop Using Encrypted Email

lvh
475pts547
www.lvh.io 6y ago

Solving regex crosswords with logic programming and Clojure

lvh
4pts0
twitter.com 6y ago

Near-universal (pre iPhone 11) iOS bootrom exploit

lvh
18pts4
transient.fail 6y ago

An overview of Spectre/Meltdown style bugs

lvh
4pts0
www.yubico.com 6y ago

Apple’s NFC Update Enables YubiKey Authentication

lvh
2pts0
github.com 6y ago

Show HN: Format-preserving redaction for structured test data

lvh
1pts1
blog.quarkslab.com 6y ago

Reverse engineering a finite field multiplication operation

lvh
2pts0
abcnews.go.com 7y ago

Japan's cybersecurity minister has never used computer

lvh
2pts0
www.contrastsecurity.com 7y ago

CVE-2018-15685 – Electron WebPreferences Remote Code Execution

lvh
2pts1
groups.google.com 8y ago

RCE vuln in gddo (Go docs hosting)

lvh
1pts0
www.wyden.senate.gov 8y ago

Sen. Ron Wyden Asks NIST to Consider WireGuard to Replace IPSEC and OpenVPN [pdf]

lvh
5pts1
www.reddit.com 8y ago

Critical vulnerability in monocypher

lvh
1pts0
www.circleid.com 8y ago

Why you must learn to love DNSSEC

lvh
4pts1
twitter.com 8y ago

WireGuard now works on unmodified Android 6+ devices

lvh
3pts0
duo.com 8y ago

Duo finds SAML vulnerabilities affecting multiple implementations

lvh
8pts2
shibboleth.net 8y ago

Critical auth bypass vulnerability in Shibboleth

lvh
1pts0
arxiv.org 8y ago

Combining SGX and Rowhammer for undetectable malware

lvh
2pts1
www.youtube.com 9y ago

Covert cache-based channel between EC2 instances (demo)

lvh
2pts1
www.securityweek.com 9y ago

Critical Cisco IOS, iOS XE RCE Vuln from Vault7

lvh
3pts0
www.fossil-scm.org 9y ago

Fossil SCM 2.1 with SHA3 and graceful upgrading

lvh
1pts0
www.fossil-scm.org 9y ago

Fossil SCM 2.1 released with SHA3-256 support and graceful upgrading

lvh
2pts1
www.rfc-editor.org 9y ago

RFC 8032: Edwards-Curve Digital Signature Algorithm (EdDSA)

lvh
3pts1
support.apple.com 9y ago

Apple Security Update released, fixes several serious vulns

lvh
2pts5
www.lvh.io 9y ago

2016 Retina MacBook Pro Caveats

lvh
265pts308

This is a fantastic example of applying deception strategies in practice as part of a detection & response plan. The most common use case is as a canary, but it absolutely works as evidence of compromise, too.

I won't comment on the specifics of the case (the complaint comes across as very convincing), but I will remind people that it's common for investigations to ostensibly show an employee doing bad things, when in reality it's e.g. that employee's credentials/devices that are compromised.

Re: hashing: Yes, but I'll leave that one to Paul who is a lot smarter than I am :)

Re: QA: can you say a bit more about the type of coverage you're worried about? Is your concern that we'd be missing APIs, or that the storage format itself breaks, resulting in fact elision? payne (the underlying project) has a borderline obnoxious amount of tests, but that doesn't mean we didn't miss anything :)

FYI: we're planning a followup post for people who are less interested in the Datomic mechanics and more interested in the usefulness to investigations and other security functions. Informally, I think of it this way: your SIEM has the deltas, but often you want the contextual states in between the deltas (and a lot of investigation is about trying to reason about that state). We built this tool originally to support that, and it turned out that approach was also super useful for things like compliance, CSPM...

We already wrote a high level blog post here: https://www.latacora.com/blog/2023/11/01/our-approach-to-bui... -- but the one I'm hoping to write is more of a case study.

I don't know if I count as a "feline friend", but: SIDH kept the DH shape. Being able to upgrade the protocols we had relatively closely is appealing. "Structure is useful but seems precarious" wasn't exactly secret knowledge.

The additional information you need is that that's what Thomas Wouters does (and has done for as long as I've known them, which is many, many years).

They may often be used with small embedded computers, but 1 Coral TPU handily beats even a top-end CPU for the stuff Frigate needs it to do -- and it does it at minuscule power draw. Sure, it's inference-focused, and that means it has limitations: it sucks for e.g. speech models, too. But it's pretty great at what it does and gets used in real applications too. My guess is you saw the USB-C model, but they do M2, big cards with multiple M2 slots, and miniPCIe (popular in industrial applications) too.

My daily driver is a 1986 911 Turbo (aka the 930). That's a nearly 40 year old car, they make a similar new infotainment system that works for even older cars. Thing runs like a dream, and they tried very hard to make it "fit" in the old interior even though it clearly had completely different design constraints.

That's fair. Maybe my security background is shining through here. I guess we used to have "slashdotting" but that doesn't generalize well :)

I did do some napkin math to quantify how much that bad traffic may have been: HA estimates between 6857-25576 intallations of the MyQ integration. Let's say 16k clients. HA makes it really easy to detect and "add" the integration (which counts as an installation even if it's not configured), so, that's definitely not all clients hitting the API. Let's say it's 50%, so 8k actually using it. Most users just notice myQ is broken. Let's say some fraction retry, which would look the same as an extra user from a volume perspective. Call it an even 10k users (including repeat users).

The most recent change is after they broke everything past the OAuth dance. Let's say the OAuth request is 1kB. The retry code retries up to 5 times with exponential backoff. Let's say 5 requests over 10 min.

(5 requests / 10 minutes) * 1 request/user * 10k users = 5k requests/minute, or 83 per second, amounting to 83kB/s inbound.

There's no reason to assume those requests would synchronize, but I'm sure there's something (let's say every single myQ user updated at the same time).

If what they're saying is true, sounds like actually malicious botnet wielders can ransom the living daylights out of them. Given 1Tbs DDoS attacks they'd only need a tiny fraction of the full bore ion cannon! ;-)

[1] https://github.com/arraylabs/pymyq/blob/master/pymyq/request...

Why did that software work mostly fine most of the time since 2017? Even Chamberlain admits their blocking is deliberate. Even Chamberlain's external statements suggest this is part of their corporate strategy.

Why is Chamberlain's API so brittle it can't stand prodding from what they claim is a tiny fraction of users, even if those are misbehaving? Do you agree that comparing that to DDoS is ludicrous, and suggests either dishonesty or a fundamental misunderstanding of what "DDoS" means?

That helps, but a remote integration doesn't _have_ to be hostile. I get that it's different from IoT, and most of my stuff is local Zigbee after learning the hard way, but my Home Assistant also talks to the Norwegian meteorological institute and Tailscale :)

One reason this is tricky to do is because up until let's say the last 6 months or so, myQ _wasn't_ hostile, even if it was Cloud-based. (I get that that aligns with your point! I'm not arguing with you there.)

Odds are that whatever nice Chamberlain opener you want will have myQ built in because that's their business strategy. You can try getting a different brand if you're voting with your wallet -- but if all you care about is security: the Cloud connectivity is optional and you can just not connect it to WiFi.

The ratgdo is more trustworthy, and it just connects (really easily, too, especially with the new v2.5 board) to the opener via the same contacts that the dry contact button does.

Based on my local big box store and garage installer availability, Chamberlain has a de facto monopoly. They also pulled the rug out from under customers: that behavior had been in Home Assistant since 2017, and it's their own recent changes that caused the alleged "DDoS". They say it's to promote official products, but the company previously had a local hub that didn't require their cloud service and discontinued it.

The API breakage coincides pretty well with their brand new CTO, whose objective is apparently "transformation to a smart access software company".

It's unclear if the CTO just doesn't understand that "DDoS" generally implies malice, or if they're intentionally using that language to blame users for using their product.

Good news: ratgdo, an ESP-based local solution works great. I hope the author is making a decent profit on the kits.

Latacora's primary infrastructure auditing tool is called payne, after Cecilia. It takes "snapshots" of infrastructure: e.g. an entire AWS resource graph, and then makes that available via fast queries. It figures out what your cloud is made of by looking at API responses (which kind of are like emission spectra I guess?) :)