HN user

neilwillgettoit

695 karma
Posts19
Comments48
View on HN
www.cisa.gov 1y ago

All Trains in the USA are vulnerable to wireless RF command injection

neilwillgettoit
2pts2
wetw0rk.github.io 1y ago

0x01 – Killing Windows Kernel Mitigations

neilwillgettoit
118pts13
medium.com 10y ago

UBNT AirVision Auth Bypass – One Way Shodan.io Gets Images

neilwillgettoit
3pts0
medium.com 10y ago

How Threat Intelligence can work against you

neilwillgettoit
2pts0
www.youtube.com 11y ago

How Government Can Prepare for and Respond to Social Media Hacks

neilwillgettoit
2pts0
michenriksen.com 11y ago

Gitrob – OSINT gathering tool for GitHub

neilwillgettoit
63pts7
www.facebook.com 12y ago

Facebook – Taking Down the Lecpetex Botnet

neilwillgettoit
2pts0
l8security.com 13y ago

So you want to hack a TV station?

neilwillgettoit
2pts0
l8security.com 13y ago

PayPal Bug Bounty - a lesson in not being a fuckup

neilwillgettoit
168pts25
l8security.com 13y ago

Beating Google Two-Factor Authentication with App Specific Passwords.

neilwillgettoit
8pts13
www.zingcheckout.com 14y ago

Civil GPS spoofing attacks - practical use cases.

neilwillgettoit
3pts0
mashable.com 14y ago

Mom Hacks into a school computer 110 times to change her children's grades

neilwillgettoit
2pts0
www.opendns.com 14y ago

OpenDNS 2012 Sysadmin Awards Applications open

neilwillgettoit
1pts0
krebsonsecurity.com 14y ago

Festi BotMaster Igor Artimovich Responds to Kerb's Article about Him.

neilwillgettoit
3pts0
blog.cloudflare.com 14y ago

The Critical Security Flaws that Resulted in Last Friday's Hack

neilwillgettoit
189pts48
threatpost.com 14y ago

Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest

neilwillgettoit
3pts0
github.com 14y ago

Lazy function parameters using C++11 lambdas

neilwillgettoit
3pts0
www2.research.att.com 14y ago

F-35 Joint Strike Fighter Coding Standard Documentation

neilwillgettoit
133pts52
ifixit.org 14y ago

IFixit's Review of the New iPad's User Repairability.

neilwillgettoit
2pts0

I originally reported this to ICS-CERT in 2012. The American Association of Railroads denied, deflected, and dismissed the claims for 13 years until CISA finally agreed with me that publication was the only option left to pressure the rail industry to fix this vulnerability. This vulnerability is still unfixed in the USA and all rail operations are vulnerable to it. This could lead to inducing brake failures that could cause a derailment and the ability for anyone to shutdown all rail operations across the USA.

That's a great point. It's one thing to be able to program it yourself, and another to understand enough to ask the right questions about the code to learn how it works.

If they had the ability to QA the outsourced team's work at a semi-granular level, I'd imagine there would be a lot less disconnect between the work done and expectations.

Replace 'older candidates' with 'candidates who are less likely to sacrifice their work/life balance.'

1. Candidates that demand compensation for sacrificing their work/life balance are more expensive. Tech isn't that hard to learn. You can get pretty good at a particular tech within 2 years of learning it. Why pay a candidate tons of money for them to give up their work/life balance, when you can hire one that will give it up for little?

2. Candidates that value their non-work time don't know the latest tech. They spend their evenings with their families / kids / friends / hobby whereas those who do are constantly learning the latest stacks at home to benefit their work.

3. Candidates that would rather go do something not work related after work don't pass the 'beer test' with those who's life choices are work-centric.

Pocket FM 11 years ago

You don't need a complex guidance package when traditional direction finding and triangulation will produce coordinates that can be used to direct artillery, air strikes, IED, etc. Sigint targeting is quite common.

Pocket FM 11 years ago

higher power. The n900's transmitter was 15nW (1.5e-8 W), which is why it was legal. For a claimed 6km radius, I would assume this is about 3-7W output.

Pocket FM 11 years ago

It's just a low power FM station with a raspberry pi in it as a controller. It would be highly illegal to use this device in most modern nations without a license.

Pocket FM 11 years ago

This seems like a bad idea. It would make targeting dissent with kinetic means very easy. It's one of the whole reasons that shortwave broadcasts are still around.

[dead] 11 years ago

they could use some caching for this site.

This is correct. If you ever look into how social media botnets are constructed and run, the good ones already do all the command and control through headless webkit tools. It's one of the primary reasons that it is so difficult to filter out whether or not a social profile is indeed a person or not from a statistical observation at mass.