HN user

mukyu

2,004 karma
Posts77
Comments346
View on HN
www.mitls.org 10y ago

SLOTH – Security Losses from Obsolete and Truncated Transcript Hashes

mukyu
112pts20
arstechnica.com 10y ago

Judge tosses Wikimedia’s anti-NSA lawsuit because Wikipedia isn’t big enough

mukyu
10pts0
www.metzdowd.com 10y ago

OpenPGP SEIP downgrade attack

mukyu
43pts5
blog.zimperium.com 10y ago

Zimperium ZLabs Raising the Volume: New Vulnerability Processing MP3/MP4 Media

mukyu
5pts0
imgur.com 10y ago

Imgur Vulnerability Patched

mukyu
13pts2
samvartaka.github.io 10y ago

Detecting an asymmetric Curve25519 backdoor in RSA key generation algorithms

mukyu
96pts11
www.psmag.com 10y ago

Is It Ethical to Watch Murder Caught on Tape?

mukyu
2pts1
arstechnica.com 10y ago

GitHub attacked again as Chinese developers forced by police to pull code

mukyu
7pts1
www.geek.com 10y ago

Amazon joins in on killing Flash, stops accepting Flash ads

mukyu
211pts77
arstechnica.com 10y ago

Drones used to monitor bears send their heart rates through the roof

mukyu
1pts0
randomoracle.wordpress.com 10y ago

On Safenet HSM key-extraction vulnerability CVE-2015-5464 (part I)

mukyu
11pts0
www.thedailybeast.com 10y ago

How Bees Revealed a Pot Farm Beneath the Maraschino Cherries

mukyu
44pts54
motherboard.vice.com 10y ago

The Biggest Dark Web Markets Rake in Up to $500,000 a Day, Study Says

mukyu
2pts0
www.wired.com 11y ago

Meet the Master of the Old-School Clicky-Clacky Keyboard

mukyu
1pts1
threatpost.com 11y ago

VUPEN Founder Launches New Zero-Day Acquisition Firm Zerodium

mukyu
1pts0
arstechnica.com 11y ago

A handy cheat sheet for North Korea’s private “Internet”

mukyu
2pts0
blog.trailofbits.com 11y ago

How We Fared in the Cyber Grand Challenge

mukyu
20pts0
the1709blog.blogspot.com 11y ago

Private Copying Exception is no more for now?

mukyu
1pts0
www.theverge.com 11y ago

Was Reddit always about free speech? Yes, and no ¯\_(ツ)_/¯

mukyu
5pts0
www.businessinsider.com 11y ago

School lunches in Indiana have spawned a black market for condiments

mukyu
1pts0
www.fireeye.com 11y ago

Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign

mukyu
6pts0
blog.ammaraskar.com 11y ago

Minecraft Vulnerability Advisory

mukyu
13pts1
kamil.hism.ru 11y ago

How I could delete any video on YouTube

mukyu
186pts34
www.alchemistowl.org 11y ago

PoC||GTFO 0x07 [pdf]

mukyu
2pts0
lists.mindrot.org 11y ago

OpenSSH 6.8 released

mukyu
95pts42
www.insinuator.net 11y ago

Revisiting Xen’s X86 Emulation: Xen XSA 123

mukyu
1pts0
www.reuters.com 11y ago

Snowden says he'd like to return to Geneva

mukyu
4pts0
helpx.adobe.com 11y ago

Security Advisory for Adobe Flash Player (CVE-2015-0313)

mukyu
1pts0
dolphin-emu.org 11y ago

Dolphin Progress Report: January 2015

mukyu
1pts0
github.com 11y ago

Security vulnerabilities in Oracle DSR

mukyu
1pts0

The talk about needing to constantly add more entropy or 'manage' it is nonsense. djb says it best: http://blog.cr.yp.to/20140205-entropy.html

Briefly, once you have say 256 random bits it is trivial to use AES and CTR mode and turn that into 2^71 random bits until you need to rekey. If you cannot get more entropy in the time it takes to use up all of those numbers something is completely broken. The only problem you can have is not having enough entropy to bootstrap (such as VMs or needing to generate a key at poweron on an embedded device), but this paper gives little more than lipservice to it.

Murray claims that a clause about "reverse-isms" is a cornerstone of a CoC and yet three out of the four resources she mentions as being acceptable do not have one. The only one that does is a community explicitly designed to be a safe space[0] for marginalized groups with a shared ideology. That requirement is perfectly in line with their communities goals. That does not mean it is appropriate for all groups or even all groups that are trying to promote inclusiveness. The argument about "tone policing" and other supposed deficiencies is exactly the same.

The rest of Murray's article is not actually about the actual CoC or any flaws with it.

They did hastly accept the supposed "problems" (that is, it was not a 1:1 copy of the geekfeminism CoC) and tried to fix them. People then complained because they do not believe that things specifically designed for one specific community and are not recommended by most of the experts are appropriate for a general CoC to be used for myriad different communities with far different goals than one specific wiki. TODO then decides that maybe they should actually take some time to think about things instead of circling the wagon around their kneejerk changes.

Garrett then argues that they released something broken and should have consulted the experts and that was one page document is of the same complexity as a 1,000,000 loc kernel. Well, it wasn't broken and it is in line with what most experts suggest, or at least it has not been cogently argued that it was not.

[0] I am using their own definition: http://geekfeminism.wikia.com/wiki/Safe_space

Aaron Swartz's last interview is really apropos. [1] He discusses how speech has changed and why we should be concerned over private companies' suppressive actions now rather than just governments.

Also, those arguing that governmental assertions of free speech rights only apply to government actions are not familiar with the relevant case law in the US. [2]

Similarly, those claiming that censorship can only be done by state actors are using an incredibly idiosyncratic definition that basically anyone other than a hardcore libertarian would disagree with. [3][4][5] Say it is the 1980s and a college newspaper prints something that upsets someone. They then steal and destroy all copies of that issue once they are printed. How is this action by a non-state actor different enough to be put in another category?

Scott Alexander also has a good read on these issues. [6]

[1] http://www.wired.com/2013/04/aaron-swartz-interview/

[2] https://en.wikipedia.org/wiki/Pruneyard_Shopping_Center_v._R...

[3] https://en.wikipedia.org/wiki/Censorship

[4] https://www.aclu.org/what-censorship

[5] http://rationalwiki.org/wiki/Censorship

[6] http://slatestarcodex.com/2015/07/22/freedom-on-the-centrali...

The power differentials in WoW are a lot bigger than 2%. I would wager that less than 90% of the players even are LFR geared, but assume a casual player with a mix of LFR gear, crafted, legendary, heroic BoEs is probably sitting around ilvl 663. Depending on their spec and the fight and playing well they are probably doing 30k DPS [0]. Someone in full mythic 4p (ivl 700+) is going to be doing 55-60k+. [1]

These numbers aren't going to be a perfect comparison because of fight length, strategy changes when you overgear content, skill differentials, etc but gear is pretty important.

One could easily argue that having the highest end gear does not really serve a purpose if you aren't doing any actual raiding or PvP though.

edit: I should probably mention that the last expansion (released last November) did a massive stat squish. In the last tier, t16, an LFR geared player would be doing 30k (ilvl 496ish), 100k (ilvl 528-540), and 1.0m+ (mythic/580+). Player power was increasing so much they had to start working around not being able to increase raid boss HP higher than 2^31 - 1. 25 man heroic Thok had ~2b HP for example.

[0] https://www.warcraftlogs.com/rankings/7#bracket=2&difficulty...

[1] https://www.warcraftlogs.com/rankings/7#bracket=7&difficulty...

This article is simply incorrect. The passwords are only stored in plaintext when there are no OS-level or desktop environment options available to protect them.[0] In the absence of such a system where exactly do you expect Chrome to store the encryption key for the list of passwords?

[1] https://code.google.com/p/chromium/wiki/LinuxPasswordStorage

edit: Apparently there are people that run either incredibly old versions of chrome or don't run a keystore daemon and actually upload all of their dotfiles to github so I guess that part is technically accurate.

That would presume that the dictionary in question was a copyrightable work. The US has weak database copyright protection due to Feist. There is also Assessment Technologies to consider, but I don't believe that involved the DMCA.

No action may be brought under this title alleging infringement of copyright based on the manufacture, importation, or distribution of a digital audio recording device, a digital audio recording medium, an analog recording device, or an analog recording medium, or based on the noncommercial use by a consumer of such a device or medium for making digital musical recordings or analog musical recordings. [0]

In fact, the Rio's operation is entirely consistent with the Act's main purpose – the facilitation of personal use. As the Senate Report explains, "[t]he purpose of [the Act] is to ensure the right of consumers to make analog or digital audio recordings of copyrighted music for their private, noncommercial use." S. Rep. 102-294, at 86 (emphasis added). The Act does so through its home taping exemption, see 17 U.S.C. S 1008, which "protects all noncommercial copying by consumers of digital and analog musical recordings, " H.R. Rep. 102-873(I), at 59. The Rio merely makes copies in order to render portable, or "space-shift", those files that already reside on a user's hard drive. Cf. Sony Corp. of America v. Universal City Studios, 464 U.S. 417, 455 (1984) (holding that "time-shifting" of copyrighted television shows with VCR's constitutes fair use under the Copyright Act, and thus is not an infringement). Such copying is paradigmatic non-commercial personal use entirely consistent with the purposes of the Act. [1]

[0] 17 U.S. Code § 1008 Prohibition on certain infringement actions

[1] 180 F.3d 1072. 1078-1079. 51 U.S.P.Q.2d (BNA) 1115 (9th Cir. 1999)

So the law does specifically say that making digital copies of music for non-commercial use is ok and it has been reviewed by the judiciary (to some extent).

There is also 17 U.S. Code § 117 which allows backup copies or computer programs "that such new copy or adaptation is for archival purposes only and that all archival copies are destroyed in the event that continued possession of the computer program should cease to be rightful".

You can still get yourself in trouble related to the DMCA depending on what you are doing, but all of your assertions are false.

Various Wikipedia's do have what you are imagining.[0] People are not normally automatically given the right to review changes and even if you do manage to review malicious edits they are easily reverted by others.

Every language has their own policies, but the English Wikipedia only has it enabled on certain pages.[1]

[0] http://meta.wikimedia.org/wiki/Flagged_Revisions

[1] http://en.wikipedia.org/wiki/Special:StablePages

There is nothing that prevents an online voting system from having a truly secret ballot. There is a class of algorithms[0] designed to compute a verifiable result from private inputs without revealing those inputs. One of the major applications of them being researched is voting.[1][2][3]

[0] http://en.wikipedia.org/wiki/Secure_multi-party_computation

[1] https://eprint.iacr.org/2014/075

[2] http://arxiv.org/abs/1502.07469

[3] https://www.iacr.org/cryptodb/data/paper.php?pubkey=2203

It is a bit odd to go to a journalist first with a vulnerability disclosure and then when they are patched poorly to just publicly disclose instead of going back to the vendor. 'Several weeks' does not even seem like an extremely long time span either all things considered.

On the other hand even major players are constantly having low hanging fruit bugs delivered to them very cheaply due to bug bounty programs (like the two recent Facebook bugs). Paying $5k a bug and having no other costs (such as bad press) could be 'cheaper' than actually giving people security training and having audits. If companies started getting burned by these failures maybe they would work harder to prevent them ahead of time.

Email is an incredibly common method for domain validated certificates. The other common options are a TXT/CNAME record or uploading a specific file to a certain URL.

The requirements for domain validation are:

11.1.1 Authorization by Domain Name Registrant For each Fully-Qualified Domain Name listed in a Certificate, the CA SHALL confirm that, as of the date the

Certificate was issued, the Applicant (or the Applicant’s Parent Company, Subsidiary Company, or Affiliate, collectively referred to as “Applicant” for the purposes of this section) either is the Domain Name Registrant or has control over the FQDN by:

1. Confirming the Applicant as the Domain Name Registrant directly with the Domain Name Registrar;

2. Communicating directly with the Domain Name Registrant using an address, email, or telephone number provided by the Domain Name Registrar;

3. Communicating directly with the Domain Name Registrant using the contact information listed in the WHOIS record’s “registrant”, “technical”, or “administrative” field;

4. Communicating with the Domain’s administrator using an email address created by pre-pending ‘admin’, ‘administrator’, ‘webmaster’, ‘hostmaster’, or ‘postmaster’ in the local part, followed by the at-sign (“@”), followed by the Domain Name, which may be formed by pruning zero or more components from the requested FQDN;

5. Relying upon a Domain Authorization Document;

6. Having the Applicant demonstrate practical control over the FQDN by making an agreed-upon change to information found on an online Web page identified by a uniform resource identifier containing the FQDN; or

7. Using any other method of confirmation, provided that the CA maintains documented evidence that the method of confirmation establishes that the Applicant is the Domain Name Registrant or has control over the FQDN to at least the same level of assurance as those methods previously described.

Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, v.1.2.3 https://cabforum.org/wp-content/uploads/BRv1.2.3.pdf

Netflix got sued and investigated by the FTC for the data released for the Neflix Prize contest. One the plaintiffs could be linked to their imdb account by similar reviews and there were additional reviews in the Netflix dataset to imply that they were lesbian while still in the closet.

AOL had to pay a settlement after the search data they released identified people.

.. really? Someone else already linked a mirror so I don't need to bother, but I never would have known if you didn't tell me.

That seems like a bit of an over-zealous heuristic for spam. Also, it seems silly to have two different threads just because one URL has https in the first place.