HN user

spaceboy

1,061 karma
Posts144
Comments38
View on HN
github.com 9y ago

Wickr-Crypto-c: An Implementation of the Wickr Secure Messaging Protocol in C

spaceboy
2pts0
googleprojectzero.blogspot.com 9y ago

Attacking the Windows Nvidia Driver

spaceboy
205pts74
timtaubert.de 9y ago

The future of session resumption – Forward secure PSK key agreement in TLS 1.3

spaceboy
4pts0
www.inverse.com 9y ago

Should Cybersecurity Be a Human Right?

spaceboy
1pts0
phys.org 9y ago

Miniaturized robots can be propelled through biological fluids

spaceboy
2pts0
github.com 9y ago

Credstash – A little utility for managing credentials in the cloud

spaceboy
1pts0
pritunl.com 9y ago

Pritunl – Open Source Enterprise Distributed OpenVPN Server

spaceboy
1pts0
www.dnscrypt.org 9y ago

DNSCrypt – A protocol to improve DNS security

spaceboy
4pts0
www.eurekalert.org 9y ago

Information transport by spin as an alternative to conventional computing tech

spaceboy
1pts0
www.contextis.com 9y ago

Phwning the boardroom: hacking an Android conference phone

spaceboy
1pts0
bugs.chromium.org 9y ago

Windows GDI32.dll Heap Based Out of Bounds Memory Disclosure

spaceboy
2pts0
www.infosecurity-magazine.com 9y ago

Social Media Impersonators Run Rampant and Undetected

spaceboy
2pts0
fee.org 9y ago

The StingRay Is Exactly Why the 4th Amendment Was Written

spaceboy
13pts0
blog.apnic.net 9y ago

The Root of the DNS

spaceboy
1pts0
en.wikipedia.org 9y ago

Virtue signalling

spaceboy
3pts0
beam.ai 9y ago

Beam – Communication for small, distributed teams

spaceboy
1pts0
www.washingtonpost.com 9y ago

FBI needs to explain why Flynn was recorded, Intelligence Committee says

spaceboy
2pts0
www.strongswan.org 9y ago

StrongSwan – IPsec VPN for Linux, Android, FreeBSD, Mac OS X, Windows

spaceboy
141pts74
www.enisa.europa.eu 9y ago

The importance of cryptography for the digital society

spaceboy
1pts0
www.zdziarski.com 9y ago

Protecting Your Data at a Border Crossing

spaceboy
1pts0
securedrop.org 9y ago

SecureDrop – An open-source whistleblower submission system

spaceboy
343pts78
www.wired.com 9y ago

Forget Recounts. Next Election, Encrypt the Vote Instead

spaceboy
1pts0
nakedsecurity.sophos.com 9y ago

SophosLabs report examines Top Android malware

spaceboy
2pts0
medium.freecodecamp.com 9y ago

I’ll never bring my phone on an international flight again

spaceboy
15pts2
itrytech.com 9y ago

The World’s First Apple AirPod Competitor

spaceboy
1pts0
github.com 9y ago

Open Mesh lock down exploit

spaceboy
1pts0
gist.github.com 9y ago

Raspberry Pi VPN Router

spaceboy
1pts1
medium.com 9y ago

Operational WhatsApp (on iOS)

spaceboy
1pts0
blog.cryptographyengineering.com 9y ago

Random number generation: An illustrated primer (2012)

spaceboy
1pts0
www.theregister.co.uk 9y ago

That guy using a Surface you keep seeing around town could be a spy

spaceboy
1pts0

A bit over a week spent trying to make it work, and it never did

I feel your pain. I remember trying to install DNSCrypt[1] on Linux and failing miserably. I was convinced it would work if only I found the right solution online, or if only the right amount of caffeine was in my bloodstream, or if by sheer effort of will I could get it working, but I still failed. I partially got it installed, error messages galore in my terminal, and all my /paths/ were wrong. It was a humbling experience. I quickly uninstalled it as I don't want partially working, broken soft running on my machine.

I guess for this situation a decent OpenVPN client would be ideal like Viscosity[2]

[1] https://www.dnscrypt.org/

[2] https://www.sparklabs.com/viscosity/

I wonder if we can come up with a widely adopt(able|ed) fingerprint that we can mask ourselves with, do any of these identifying bits actually make the web more usable for us?

https://anonymous-proxy-servers.net/en/jondofox.html

JonDofox with JS turned off and uBlock origin installed. There's actually a small pool of users with this config but it needs to be bigger. As you said, as soon as we get consensus on what config to use, we can all switch to it en-masse.

Can't help but bring up the notion of envy these people (technocrats specifically) have for the biological miracle that is the human body. They can simulate the human brain all they want, but they'll never match it, as it's orders of magnitude more complex than any supercomputer they can dream of. And it has free will, which AI does not. AI is impotent at making free decisions because it's deliberately constrained by the programmers to think rigidly and inside their own custom black box. There's no room to roam unless we get to Mars where we can unleash AI and watch it make free decisions, which I suspect Musk is trying to do...Turning planets into giant labs where AI can be less constrained.

Windows doesn't wipe the memory properly though, and the default browser (MS Edge for Win10, and plain old IE for older versions), are awful default browsers, forensically speaking.

I'll leave this link here for those who use Tails and need to wipe files and other data, either there and then, or after the fact of deletion (clearing files from free space):

https://tails.boum.org/doc/encryption_and_privacy/secure_del...

There's nothing about TailsOS that could arouse suspicion if there's nothing persistent on it that could arouse suspicion, or draw more attention to you. TailsOS is strictly a utility like a wrench or a screwdriver. Providing you exit TailsOS properly and watch the screen as it's wiping the memory to ensure it has infact wiped. TailsOS can prove to be an innocuous O.S after you unload it from memory. They might ask questions, but they have nothing on you.

Bringing a Windows OS is stupid as Windows doesn't clean up properly after shutting down and leaves a forensic footprint which is difficult to cleanup unless you use something like Bleachbit[1] or CCleaner after using Windows. You typically want to offload cleaning up to the O.S level and avoid using such tools such as CCLeaner in the first place (Keep in mind, since this is Windows, there are issues with free space on the drive that leave deleted files remaining on the hard-disk, even after explicitly stating they should be deleted).

With TailsOS, In other words, you can browse freely and with peace of mind that you won't leave a forensic footprint behind, giving you an upper-hand over other passengers who have to self-censor their browsing for fear of scrutiny at a later date from border officers.

[1] https://www.bleachbit.org

[2] https://www.piriform.com/CCLEANER

I thought the U.S had better key disclosure law[1] than other countries? Personally I would rather not self-incriminate myself by revealing a key, no matter how draconian and lengthy the sentencing was. Why, you ask? Well I consider all my own personal data likened to an extension of my own mind, and revealing a key is like slicing a thin part of my brain and attempting to pick its contents. Never a gentlemanly thing to do in any circumstance.

In terms of being stopped and searched when traveling, I just carry a TailsOS bootable live USB. My laptop doesn't have a hard-drive and boots entirely from my TailsOS USB stick. I did not enable any persistent storage and any bookmarks I need to remember, I simply remember them by rote, like in that movie The Book of Eli[2]. My threat model is such that I don't want anybody knowing my business when traveling. The intrusiveness should only go so far as one question, like "Business or Pleasure?" and that's all.

[1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_Stat...

[2] https://en.wikipedia.org/wiki/The_Book_of_Eli

Even though web beacons / trackers like Google Analytics are fairly harmless, I still wouldn't trust them in this app because they often sit close to the main app's code and can be MITM'd to do bad things like send back snippets of a recording, or metadata about a recording like the name of the video file. That is, of course if this app has such beacons. I haven't sat between the traffic of this app (ab)using Burp Suite or Fiddler[2] to give a proper opinion

[1] https://portswigger.net/burp/

[2] http://www.telerik.com/fiddler

Apparently this scene from The Labyrinth is based on the heaven/hell logic puzzle he devised: https://www.youtube.com/watch?v=ReFhu8KYbmU

Many of his logic problems are extensions of classic puzzles. Knights and Knaves involves knights (who always tell the truth) and knaves (who always lie). This is based on a story of two doors and two guards, one who lies and one who tells the truth. One door leads to heaven and one to hell, and the puzzle is to find out which door leads to heaven by asking one of the guards a question. One way to do this is to ask "Which door would the other guard say leads to hell?". This idea was famously used in the 1986 film Labyrinth.

According to: https://en.wikipedia.org/wiki/Raymond_Smullyan

Use a VPN and now you're only vulnerable to the VPS service and the NSA

You can always try 'chaining' VPNs together, or stacking them on top of each other so that if one of the VPS servers is compromised, a TLA gets nothing but encrypted traffic and can't see what you're doing. The only caveat here is the 'exit' VPS is always going to have to be unencrypted. This is why it's worth looking into offshore VPS providers in non-five-eyes countries. I'm not sure what countries these are. I haven't done the research.

Typically I achieve chaining by doing the following:

- Hardware VPN that I connect to as normal. Personally I use http://www.pivpn.io/

- Then I connect to another VPN on my host/hypervisor machine

- Then I fire up Virtualbox and run another VPN inside the VM

- The chain now has three hops, and the exit VPN is on a box that I control. I avoid Digital Ocean like the plague as it's a US company.

They really need to make their promoted tweets cheaper. I attached a credit card with $100.00 to spend on ADs and Twitter burned through it in a week for a few paltry 'promoted tweets' that had very little engagement or views.

This is why I use isolated sessions when browsing. I compartment my surfing these days because of this exact type of attack (identities and other browsing artifacts spilling over into serendipitous/casual/random browsing). Mozilla are even going to ship this strategy in Firefox soon[1]. Another strategy to lessen the amount of data collected on you is to outright disable Facebook like buttons and Twitter share buttons, because these widgets track you as you navigate around the web. This can be done in uBlock origin[2] under the '3rd party filters' tab and selecting Fanboy's annoyance filter list alongside Anti-ThirdpartySocial filter list.

[1] https://wiki.mozilla.org/Security/Contextual_Identity_Projec...

Individuals behave differently in the world when they are in different contexts. The way they act at work may differ from how they act with their family. Similarly, users have different contexts when they browse the web. They may not want to mix their social network context with their work context. The goal of this project is to allow users to separate these different contexts while browsing the web on Firefox. Each context will have its own local state which is separated from the state of other contexts

[2] https://github.com/gorhill/uBlock

This account has been terminated due to multiple or severe violations of YouTube's policy against spam, deceptive practices, and misleading content or other Terms of Service violations.

I need something similar to Coinbase where I can attach a card and just buy some BTC without all the KYC BS you see in Coinbase. There has to be something like that which is heavily vetted by the BTC community? I've seen local bitcoins, but I want to keep everything as virtual as possible.