HN user

maxt

1,253 karma
Posts221
Comments46
View on HN
github.com 9y ago

iOS system-wide VPN based Tor client

maxt
3pts0
libreswan.org 9y ago

Libreswan VPN software

maxt
2pts0
www.aclu.org 9y ago

Trying to Keep the Internet Safe from Warrantless NSA Surveillance

maxt
150pts63
www.dni.gov 9y ago

RAW SIGINT Guidelines [pdf]

maxt
2pts0
tonyarcieri.com 9y ago

Key rotation, user experience, and crypto reporting

maxt
1pts0
eprint.iacr.org 9y ago

Post-quantum key exchange – a new hope [pdf]

maxt
3pts0
github.com 9y ago

QMASM: A Quantum Macro Assembler

maxt
56pts4
blog.nviso.be 9y ago

A practical guide to RFID badge copying

maxt
1pts0
eprint.iacr.org 9y ago

MASScan: Stopping Microarchitectural Attacks Before Execution [pdf]

maxt
1pts0
blog.torproject.org 9y ago

Exploring Tor with carml

maxt
3pts0
blog.elpassion.com 9y ago

Simple and Terrifying Encryption Story

maxt
2pts1
github.com 9y ago

Key Transparency – A transparent and secure way to look up public keys

maxt
2pts0
github.com 9y ago

Sovereign – Set of Ansible playbooks to build and maintain your own personal cloud

maxt
3pts0
certsimple.com 9y ago

Never see localhost HTTPS warnings again

maxt
1pts0
blog.skullsecurity.org 9y ago

Going the other way with padding oracles: Encrypting arbitrary data

maxt
2pts0
www.ssls.com 9y ago

SSL Certificates. Buy Cheap SSL Certs from $4.99/yr

maxt
2pts0
www.isi.edu 9y ago

Yubikey and SSH authentication

maxt
3pts0
www.nas.nasa.gov 9y ago

Using GPG to Encrypt Your Data

maxt
236pts99
blog.fastmail.com 9y ago

PGP tools with FastMail

maxt
1pts0
wiki.cementhorizon.com 9y ago

List of Personal VPN Software

maxt
3pts0
thehackerblog.com 9y ago

Respect My Authority – Hijacking Broken Nameservers to Compromise Your Target

maxt
2pts0
www.technologyreview.com 9y ago

This $500 Tablet Brings Words to Blind Users’ Fingertips

maxt
2pts0
www.scip.ch 9y ago

Write-up of character filter bypass in ASP.NET using Razor Code

maxt
1pts0
www.bloomberg.com 9y ago

Volkswagen Agrees to Plead Guilty in Diesel-Emissions Scandal

maxt
2pts0
9to5mac.com 9y ago

iPhone market share grows 6.4% in USA, takes share from Android in most markets

maxt
19pts20
googleyasheck.com 9y ago

Googley as Heck – My journey to becoming a Google engineer

maxt
3pts1
theconversation.com 9y ago

Fighting online trolls with bots

maxt
3pts0
www.technologyreview.com 9y ago

Policing abuse on Reddit with Artificial Intelligence is impossible

maxt
1pts0
www.siliconrepublic.com 9y ago

New EU telecoms privacy rules will hit Facebook and Google in pocket

maxt
1pts0
www.techdirt.com 9y ago

ISPs Pushing for Elimination of New FCC Broadband Privacy Rules

maxt
4pts0

I never knew you could style custom elements like <awesome> with CSS.

I wonder however about the compatibility with different browsers. Could potentially break some sites on older browsers / those on legacy machines / those still surfing the web on dusty old Windows 2000 machines.

I doubt it affects them that much, as there's always going to be powerusers. They get a lot of their telemetry from unsuspecting users / laymen buying those cheap Windows10 tablets you see everywhere now.

No that's the only caveat. I much prefer to use scripts, as these programs are a bit of a black box. But at least they're digitally signed and recommended by the wider Windows 'powertoy' community so you're allowed to trust them.

I recall about a week after the Snowden disclosures some people saying the Snowden leaks were deliberate and that NSA has kept up this tradition of false flag disclosures. If anything, the whole web is certainly more secure now, and Snowden is even quoted as saying: "I still work for the NSA" after the leaks. I don't buy the rhetoric that NSA is simply all about slurping up plaintext. They have a duty to secure the web too. It's a weird paradox that they both want more security and want all the plaintext they can salvage.

I've started to use PaaS (Platform as a service) because it's way more convenient and reduces the headache of getting a simple blog up and running. VPSes are often difficult to harden and many of the recipes online for spinning up servers are not tried and tested and often leave gaping security holes in the installation. At least with PaaS these holes are patched because they are widely deployed on many machines and have to be secure by design. Here's a few to get you started:

https://www.ctl.io/appfog/

https://bitnami.com/

https://www.cloudfoundry.org/

https://www.openshift.com/

Here's a Mashable article about adopting HTTPS served via plain old HTTP:

http://mashable.com/2011/05/31/https-web-security/

It worries me that major websites like this have still not made the switch to HTTPS/TLS yet. Quite irksome are the reasons (actually, excuses) site owners sometimes give like overhead, claiming switching over to HTTP/TLS will be costly and annoying, or even worse - that their threat model doesn't include HTTPS, and the burden is on the visitor to encrypt their connection to the site. The onus is on both parties to encrypt, instead of shunting the encryption to the visitor. As for threat models, the news can be a sensitive topic for some, and HTTPS can be of great service to visitors who enjoy their privacy.

I enjoy initiatives like Secure The News[1] which is a small public awareness campaign urging news outlets to adopt HTTPS/TLS. Initiatives like Google's HTTPS Transparency Report[2] are great too and give us great insight into the adoption rate of HTTPS/TLS:

[1] https://securethe.news/

[2] https://www.google.com/transparencyreport/https/grid/

Principles 10 years ago

Now and then I like to revert back to first principles. The moment things become refined, elegant, or complex, is usually when I have to see the woods from the trees and apply first principles to it.

One principle I live by is minimalism. With technology it's easy for things to become rapidly complex. It's worth applying mindfulness to technology and seeing the results. Most of my solutions are easy solutions with no cruft, instead of complex solutions with bells and whistles galore.

Another principle I try to apply is doing one thing at a time, which ties into minimalism. It's so easy to fall into the trap of distractions and multitasking. I've trained myself over the years to cull distractions, and segmented my workflow into discrete single duty units of work. If I'm on Skype, then I'm on Skype, & I'm not checking my email or Twitter too. If I'm on Hackernews, then I'm just on Hackernews, and not lurking in Reddit too, etc. It seems obvious, but focusing actually requires training.

Virtualization has helped with this, and it's not uncommon seeing me spinning up a new VM for the sole purpose of video conferencing, and having an entire operating system just for Twitter, etc

There's underblocking and overblocking. Underblocking is allowing TOR traffic through, but also letting TOR traffic flood your servers.

It's obvious that if you have a flood of nefarious traffic like this then you should throttle the TOR traffic. Overblocking is outright blocking TOR with no reason other than because you can, and it leaves many legitimate users frustrated and feeling like the site just self-censored itself.

It would be suitable in these cases to strike a happy medium and allow some TOR traffic through, but throttle suspicious-looking requests like mini 'swarms' of TOR exit IPs hitting the site all at once, which I think HN does, because some TOR idens work, whilst others do not.

Sometimes I get roadblocked from viewing Hackernews when using TOR. I say sometimes, because I normally have to change my identity/location to view HN's frontpage (whilst logged out). It can become a hit or miss type scenario where the HN servers are not as strict upon my third, or usually fourth identity and allow TOR traffic through.

Let the goals give you a sense of direction. It doesn't matter (well it probably does if you're running a business and are watching your margins), but it doesn't matter if you're not reaching your numbers.

Ask absurd questions. Ask silly questions like: "What could I do to profit from this method next year and make 1000% more than I usually do?" or

"How many strengths do I have right now that I can build on, and maximize production / sales?"

It's quite possible to break the Internet by blanket-blocking core Google IPs[1]. I tried blocking these in my firewall and my surfing sessions became really slow. I would much prefer things like uBlock which do it at the browser level and it doesn't cause a lag.

    74.14.192.0/18
    216.58.192.0/19
    216.239.32.0/19
    64.233.160.0/19
    66.249.80.0/20
    72.14.192.0/18
    209.85.128.0/17
    66.102.0.0/20
    74.125.0.0/16
    64.18.0.0/20
    207.126.144.0/20
    173.194.0.0/16 
This is usually because if you're resolving domains to 0.0.0.0 or 127.0.0.1 in hosts then there is an inbuilt timeout as localhost is typically not running any services.

Best to make localhost run a service. A personal thing I use is lighthttpd[2] which ensures such a lag is vanished

[1] https://gist.github.com/int64ago/1d72c80e8082b78777c9

[2] https://en.wikipedia.org/wiki/Lighttpd

There's an interesting article on how the movie Wargames[1] influenced the public consciousness surrounding hacking.

Another movie similar to Mr Robot is Algorithm which I'm surprised nobody has mentioned:

https://www.youtube.com/watch?v=6qpudAhYhpc

[1] http://www.nytimes.com/2016/02/21/movies/wargames-and-cybers...

What annoyed me about Mr Robot is the stereotype / trope of a hoodied punk teen wielding their talent with a computer which has been done to death already in other movies (I class Mr Robot as an extended movie with episodes).

Hackers can be anybody infact, and it doesn't help that the hoodied punk stereotype is perpetuated. Think Stallman, Zimmermann, & Eric Raymond, not Zero Cool or Neo.

Being in a highly privileged position on the global Internet sounds cute, but it's not actually cute at all. It is opportunistic in nature and tantamount to living in an autocratic regime like China.

Apparently this bill respects human rights, but I disagree. Slurping up all the plaintext you can is outright opportunism and sly.

I only use a VPN for:

- Spoofing my geo-location

- Securing my phone's traffic when surfing on a 'free' or tariff-ed wireless hotspot

Sure, the provider might not keep logs, but it's certainly not for casual surfing, or heavy surfing. Stick to old reliables like TLS, TOR, and ADBlockers for vanilla /ISP connections

You might want to read these concerning VPNs and privacy:

- http://blog.hidemyass.com/2011/09/23/lulzsec-fiasco/

- https://torrentfreak.com/police-seize-two-perfect-privacy-vp...