HN user

roastedpeacock

168 karma

contact: $username @ protonmail.com

575C3ADAB97AD331CA41544ABBDE39538C0FDD59

Posts5
Comments98
View on HN

AFAIK Hardware jailbreaking/homebrew tools are fine even in jurisdictions blighted with with DMCA unless they're specifically for circumventing DRM.

Certain Japanese video-game companies would take issue with that interpretation of facts. Of course there is the arbitrary distinction between 'access' and 'copy' control mechanisms. Something arguably made irrelevant by the further integration of general concepts from personal-computing into certain video-game systems.

Granted, this was a university project so we clearly were within the academic context, but we were in no way affiliated with a too big to sue company.

Even without supposed goodwill of AMD and seeing things a different way being a) affiliated with a university b) outside the USA may have changed some of the equation.

Sony omitted OtherOS support with the PS3 Slim hardware revision with seemingly no technical justification and later removed it from existing consoles.

Afterwards several researchers investigated how to execute third-party code on the device and succeeded. [1] In response Sony did attempt to prosecute several people under DMCA and similar claims [2] and were more successful with certain defendants in some countries versus others.

[1] https://media.ccc.de/v/27c3-4087-en-console_hacking_2010 [2] https://en.wikipedia.org/wiki/Sony_Computer_Entertainment_Am...

If you think that the Internet Archive is their own worst enemy and anyone who thinks differently is wrong, then you don't actually support the work of The Internet Archive. Sure, you may like parts of it. But you oppose its core mission.

This is where I stand.

One can support the mission of the Internet Archive (in archiving the public internet) and still express concern over more legally questionable ventures that may threaten their existence (e.g digitising and redistributing owned copies of books) and may be more of a challenge being justified under the first-sale doctrine.

Signal: Will leave the EU market rather than undermine our privacy guarantees

Considering the Lavabit case [1] this reek of grandstanding to anyone else? Not saying Europe is panacea but considering the unaccountability of American intelligence or law enforcement the European position does seem more favourable.

And to those who bring up policies such as Chat Control. The vote for that in Brussels has been postponed after enough outcry. [2] Hopefully it does not come back to life however them trying again under a different banner would not be a surprise either.

[1] https://en.wikipedia.org/wiki/Lavabit#Connection_to_Edward_S...

[2] https://www.patrick-breyer.de/en/chat-control-vote-postponed...

But the whole story is very crazy, I should write a complete blog post on it and what their shady techniques are.

Please do. If you have any new details not in the public-domain and are safely able to disclose them I am certain many other readers would be interested. :-)

Key pinning also can be done independently of the protocol; the SSH client does that, and it is helpful, but it isn't something that necessarily needs the SSH protocol in order to work.

While it was not entirely perfect Google threw in the towel with HPKP and they do not seem to want to reopen the debate. All the meanwhile they utilize static pinning for their own properties in Chromium [1] and 'secure' domain registration (MarkMonitor) that is very difficult to obtain when not a large corporation. Leaving the rest of us as fine pickings against those who can hijack domains and obtain a CA issued certificate to conduct MiTM attacks.

[1] https://source.chromium.org/chromium/chromium/src/+/main:net...

Traffic of onion-services is encrypted. Traffic correlation to deanonymize the client can still be theoretically performed but ultimately you need to draw the line in the sand somewhere.

Regardless, protonmail doesn’t let people register when connecting with Tor unless you use phone number or card to make a payment

Actually if you attempt enough times you will get the option to verify the registration with an e-mail. And they are rather liberal with which options they accept. So it is not exactly a circular dependency.

From there is it an exercise to the reader to create an account not linked to any other identity.

Even if the attacker cant decrypt existing e-mail the concern is by hijacking the account they can intercept future e-mail received such as password resets.

Some searching finds this comment. [1] I would be interested if such a password reset were possible against someone who for instance had 2FA enabled, no recovery information and only accessed their account using the Tor onion-service. ;-)

[1] https://news.ycombinator.com/item?id=19367063

That is a pretty damming accusation. Can you provide more details? This should be the sort of thing you should be hearing from a disclosure or ideally a vendor advisory - not an HN comment thread on a vaguely related article. Failures of randomness are almost always fatal to a cryptosystem.