HN user

relevant_thing

91 karma
Posts0
Comments13
View on HN
No posts found.
Edgedressing 5 years ago

This is good and clever work, and I applaud the author for looking at a boring feature and seeing in it a potential attack vector that probably wouldn't have occurred to most people. Kudos! That said, I think the security implications are pretty minimal.

(FWIW, iOS and MacOS do the exact same thing, opening captive.apple.com and showing whatever it redirects to if you're on a captive portal network.)

This behavior does incur a security risk, but using public wifi networks is basically impossible without doing this check either automatically or manually, and most users would be completely bewildered if the OS did nothing to prompt them when they needed to click through a page to make the internet work.

Moreover, if you can MITM the network and they're not tunneling their connection, you have lots of great ways to send them hostile code already! You can use classic SSL stripping to just send them whatever you want! (Granted, a lot of traffic goes straight to HTTPS these days, and browsers are getting wiser about this with HSTS and things like the new automatic HTTPS upgrade in Safari).

If you're paranoid enough not to want to run untrusted javascript (fair enough), you shouldn't be connecting to weird public wifi networks anyway.

Wait, this just looks like cryptographically signing pictures. What's so scary about that? You can do it today from your terminal if you feel like it.

I guess I agree that the 'trusted computing' stuff it seems like they're trying to do is a little scary, but the tech isn't really there yet, at least not on the desktop (look at the fiasco that is Intel SGX) and it's happening with or without whatever this CAI thing is.

I guess a world where your iPhone's camera sends signed frames to the processor's secure enclave which processes them and signs them with a key signed by Apple is... a little different from today? They do basically this for Face ID today.

If it's a simple proxy tunneling HTTPS traffic to Google, Apple probably doesn't know anything about the content of the queries, and Google doesn't know who sent them. If each kept records, they could get together and combine them to get the hashed URLs, but still a much better situation than directly querying a single endpoint.

Signal actually uses a similar approach to anonymize queries to GIPHY from users of its app. https://signal.org/blog/giphy-experiment/

False. See 828 F.3d 1068 at 1077 (9th Cir. 2016):

From those cases, we distill two general rules in analyzing authorization under the CFAA. ... Second, a violation of the terms of use of a website--without more--cannot be the basis for liability under the CFAA.

They say this because (Id. at 1076):

"Not only are the terms of service vague and generally unknown . . . but website owners retain the right to change the terms at any time and without notice." [676 F.3d 854 (9th Cir. 2012)] at 862. As a result, imposing criminal liability for violations of the terms of use of a website could criminalize many daily activities. Accordingly, "the phrase 'exceeds authorized access' in the CFAA does not extend to violations of use restrictions. If Congress wants to incorporate misappropriation liability into the CFAA, it must speak more clearly." Id. at 863.

~850 million US-based passenger * flights per year

~15 minutes in TSA waiting per passenger per flight

~80 years in a life

850,000,000 passengers per year * 15 minutes = 12,750,000,000 minutes of passenger time per year ≈ 24,241 years of passenger time per year

24,241 years of passenger time per year / 80 years per life ≈ 303 passenger lives per year.

The TSA effectively kills ~300 people per year just by wasting our time.

Not necessarily. Obviously this argument requires a corporate right to First Amendment protections. But that doesn't imply that corporations (or anyone) should be able to make unlimited expenditures on electioneering. This brief assumes that corporations are (in some sense) people, but not that they are entitled to put political ads on TV.

The current problem in Flint was caused by the Flint River being more corrosive than Lake Huron, not by lead contamination at the water source. The reason lead testing is done in houses instead of just at treatment plants is to make sure that even the water in houses with lead solder is safe.

[...] houses built before 1987, when lead was banned for use in water pipes, often had lead solder joining copper pipes in home plumbing systems. In houses built before 1983, the solder has had time to build up a mineral coating that keeps lead from seeping into the water; in homes built between 1983 and 1986, seepage could occur, so the EPA orders regular testing of their water. [0]

[0] https://www.washingtonpost.com/archive/local/2004/04/04/wssc...