HN user

nwh

5,848 karma
Posts4
Comments1,809
View on HN

I didn't mean to suggest that at all, I was commenting on the concept of having executable keyboards outside of the usual application sandbox rather than yours in particular.

So "Material Design" is "Flat Design" with shadows?

I'm not sure I can quite get used to this particular theme at all. The colors are pretty gaudy, the main action buttons (brown and purple) particularly are almost unreadable to me. I couldn't find the input boxes at all even though they had a header, they just parse as horizontal rules rather than something I can click on an add text. I respect the effort that has gone into creating this, but on a fundamental level I don't feel this is a good step in interface design.

iOS8 keyboards still make me very uncomfortable. How many of them contain keyloggers?

It's not even if I have one installed, the people I communicate with will be using them too, and they can compromise me.

[dead] 12 years ago

Ⓘ ⒽѦ℣Є Ѝ☺ ⒾℶⒺѦ ШℍΛṮ ⑂Оμ'℞Ⓔ ⓉⒶℓĹĸⅠИҀ ѦβⓄⓊŦ

The "instructions" at the start of the app are a bit baffling. I spent a good few minutes looking at a screen that told me to tap and drag and a weird orange circle that keys popping up above the capture button. In fact the entire selection with the ISO and shutter speed are a little on the janky side, I'm having a good deal of trouble seeing what I'm actually selecting. It's more completely random than anything with the shutter speed as my thumb obscures the entire view. Weird control usability aside it seems fairly functional, I've wanted something like this for a while.

Do you have a privacy policy somewhere with details about the information you collect from the application? I was unable to find any on your website.

It's unreasonable to expect that of people. URLs are maddeningly maddling to parse even if you know what is going on, if you don't it's almost impossible to explain it. Why is ebay.com.au different to ebay.com.au.edgesuite.net, should I worry if I see that? Why is edgesuite alright for hosting the images on? It's a rabbit warren of edge cases and exceptions that defied all normal levels of explanations.

Apple Pay 12 years ago

You use your fingerprint to activate the NFC, so they'd have to bash you over the head and cut off your fingers presumably.

Moto 360 review 12 years ago

The square interface on the round watch is pretty weird. I didn't expect to see square interface elements being lopped off the sides. The software seems to be almost a complete afterthought, I would have expected at least some innovative ways of making rounder interfaces.

It doesn't hold up to SSL stripping very well. As we are working under the assumption of a compromised host, the absence of a signature on the Trezor when you don't expect one wouldn't raise any suspicion. The omnipotent host malware can remove all references to the payment request being signed from the payment gateway before the user sees it.

Nothing stops a threat from just lying and waiting for you to expose a large number of passwords. Having one stolen doesn't raise red flags in itself.

I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.

It doesn't matter. If you have malware lurking in your computer it will just snarf your passwords from the wire and then you're owned all the same. If you use some sort of auth signing system, the request can just be intercepted and modified on the fly.[0] The Trezor is next to useless even for bitcoin for this very reason. Sure they can't steal your money directly, but just replacing the addresses you see and send to accomplishes exactly the same thing. If your platform isn't trusted, no amount if smart crypto or hardware dongles can make it safe.[1]

[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.

[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.

There's been stories for a while of massive malware infections sniffing usernames and passwords of infected users. Simply because there's little to give away that such an activity is going on (ie, if you were spamming or mining bitcoin there would be a real-world impact shown immediately) it's extremely hard to confirm or deny if this is happening and at what scale. In my mind it doesn't seem unlikely that would be happening though. Combined with large websites like LinkedIn being compromised, you're looking at a very, very big problem.