https://github.com/ereuter/PyEOT - Eric did a great job breaking down the protocol that was impacted.
HN user
neilwillgettoit
I originally reported this to ICS-CERT in 2012. The American Association of Railroads denied, deflected, and dismissed the claims for 13 years until CISA finally agreed with me that publication was the only option left to pressure the rail industry to fix this vulnerability. This vulnerability is still unfixed in the USA and all rail operations are vulnerable to it. This could lead to inducing brake failures that could cause a derailment and the ability for anyone to shutdown all rail operations across the USA.
Before the switch, 80% of the time I would get the unsolvable ones.
The move to the new reCAPTHA alone has made it a lot more usable for tor users.
That share via email in their demo is just ripe for abuse.
I'd rather not be forced to sign up with twitter.
How is this 'analysis' ?
That's a great point. It's one thing to be able to program it yourself, and another to understand enough to ask the right questions about the code to learn how it works.
If they had the ability to QA the outsourced team's work at a semi-granular level, I'd imagine there would be a lot less disconnect between the work done and expectations.
I think it would be a much more positive indicator if they had chosen to learn the skills necessary to create their product.
I would not take a startup that is outsourcing their development seriously. All of the institutional knowledge of how a product works goes right out the door. If you cannot fix your own product if it breaks, do you really own it?
That is a fantastic response.
Replace 'older candidates' with 'candidates who are less likely to sacrifice their work/life balance.'
1. Candidates that demand compensation for sacrificing their work/life balance are more expensive. Tech isn't that hard to learn. You can get pretty good at a particular tech within 2 years of learning it. Why pay a candidate tons of money for them to give up their work/life balance, when you can hire one that will give it up for little?
2. Candidates that value their non-work time don't know the latest tech. They spend their evenings with their families / kids / friends / hobby whereas those who do are constantly learning the latest stacks at home to benefit their work.
3. Candidates that would rather go do something not work related after work don't pass the 'beer test' with those who's life choices are work-centric.
You don't need a complex guidance package when traditional direction finding and triangulation will produce coordinates that can be used to direct artillery, air strikes, IED, etc. Sigint targeting is quite common.
higher power. The n900's transmitter was 15nW (1.5e-8 W), which is why it was legal. For a claimed 6km radius, I would assume this is about 3-7W output.
It's just a low power FM station with a raspberry pi in it as a controller. It would be highly illegal to use this device in most modern nations without a license.
This seems like a bad idea. It would make targeting dissent with kinetic means very easy. It's one of the whole reasons that shortwave broadcasts are still around.
http://www.thetruthaboutguns.com/2015/05/robert-farago/break... It looks like tracking point is closing up shop.
Do you guys dump anonymized link data into https://threatexchange.fb.com/ ?
It is known that you guys do regularly use Webroot to scan links in messages, so it's not a stretch that Recorded Future can be setup on a similar type program. http://www.eweek.com/security/facebook-webroot-expand-securi...
they could use some caching for this site.
This sounds like a lot of buzz words.
It could be as simple as they saw a bunch of UDP traffic with a spoofed src that was a dprk ip block.
As a security researcher, the most impressive part of this is the response timeline from Facebook's security team. 3~ hours from first report to temporary patch! That's insane.
This is correct. If you ever look into how social media botnets are constructed and run, the good ones already do all the command and control through headless webkit tools. It's one of the primary reasons that it is so difficult to filter out whether or not a social profile is indeed a person or not from a statistical observation at mass.
This is how you get sued and/or arrested.
If you want some details about it: http://l8security.com/post/36715280176/uv-281284-samsung-pri...
Customer service 101: don't publicly shame a negative review. It only helps your ego, not your business.
ideally you would think they would pay more than the blackmarket rates for the bugs. it's a capitalist economy in the bug markets.
For the Bug mentioned in this post it was $500.
you're a hero of mine. thank you for this. seriously.