HN user

sr2

877 karma

I apologize in advance

Posts308
Comments60
View on HN
www.itsec.nl 9y ago

Drive-by remote code execution by MAMP

sr2
1pts0
www.wired.com 9y ago

How to Turn Off Snapchat’s Stalkerish Snap Map Feature

sr2
1pts0
www.catapultsoft.com 9y ago

Catapult – Simple, Secure and Fast Data Transfers

sr2
1pts0
lauren.vortex.com 9y ago

By Killing Encryption, Our Leaders Are Delivering Us to the Terrorists

sr2
1pts0
collatenotes.com 9y ago

Collate – A Cross-Platform Markdown Notes App for Windows, Mac and Linux

sr2
2pts0
www.seald.io 9y ago

Seald – Instantly encrypt and manage your documents, messages, contracts, data

sr2
1pts0
support.apple.com 9y ago

About encrypted backups in iTunes

sr2
1pts0
www.electronichouse.com 9y ago

Smart Glass Solutions to Replace Electronic Window Shades

sr2
1pts0
theantisocialengineer.com 9y ago

Overview of the U.K Parliament Attack. Nothing new if you can run Burp Suite

sr2
1pts0
stallman.org 9y ago

What Mary Had

sr2
4pts2
www.asianscientist.com 9y ago

Does China’s Mass Collection of DNA Violate the Right to Privacy?

sr2
1pts0
www.arqbackup.com 9y ago

Arq Backup – Cloud Backup for Mac and Windows

sr2
1pts0
www.torus.sh 9y ago

Torus – A secure, shared workspace for secrets

sr2
120pts25
dev.to 9y ago

Encrypt and check your secrets into git

sr2
1pts0
www.buzzfeed.com 9y ago

Snapchat's New Feature Has Got a Lot of People Worried

sr2
2pts0
www.slashgear.com 9y ago

Instagram testing private sharing with favorite friends

sr2
2pts0
www.csmonitor.com 9y ago

Unbreakable: China doubles down on quantum internet

sr2
1pts0
vvyper.com 9y ago

Instagram doesn't encrypt stories

sr2
3pts0
www.vpnsrus.com 9y ago

What Is a VPN?

sr2
1pts0
hushed.com 9y ago

Hushed Burner Number App – Temporary Phone Number

sr2
2pts0
www.quantamagazine.org 9y ago

In Cryptography, Advances in Program Obfuscation

sr2
2pts0
terbiumlabs.com 9y ago

Sow HN: Matchlight – Keeps an Eye on Your Data So You Don't Have To

sr2
1pts0
w2.eff.org 9y ago

DocuColor Tracking Dot Decoding Guide

sr2
77pts7
futurism.com 9y ago

Why the Ethereum Flash Crash Isn’t Surprising, and What It Means for Crypto

sr2
3pts0
www.bishopfox.com 9y ago

How I Built an XSS Worm on Atmail

sr2
2pts0
theintercept.com 9y ago

Flimsy Evidence and Fringe Sources Land People on Secretive Banking Watchlist

sr2
2pts0
blog.wikimedia.org 9y ago

Wikimedia Foundation v. NSA: Why we’re here and where we’re going

sr2
2pts0
dos.sh 9y ago

Yahoo Small Business (Luminate) and the Not-So-Secret Keys

sr2
2pts0
www.cyberark.com 9y ago

GhostHook – Bypassing PatchGuard with Processor Trace Based Hooking

sr2
1pts0
www.macrumors.com 9y ago

Russia Threatens to Ban Encrypted Messaging App Telegram

sr2
2pts0

So they have publishers by the balls "forcing" them to use AMP to get higher in their rankings.

Except that I don't write blogposts to please the Google search engine. A site can be found via many other ways. News sites like Reddit are a great way to be discovered, aswell as HN. There's also link dumps like Pinboard which are another way to discover, aswell as others. Twitter, etc

What's to stop someone renting an offshore VPS, like say, in somewhere like Hong Kong[0], and that isn't part of the 'fourteen eyes' spying alliance?

[0] https://privacytoolsio.github.io/privacytools.io/#vpn

Also what's to stop someone stacking anonymously-bought VPNs on top of each other (proxy chaining) similar to how onion routing works, and creating their own homebrew Tor? If the VPN provider is peeking at the logs (which it shouldn't be doing), then all they see is another VPN IP. VPNception!

(Something like the SHALON[1] technique is useful for this, for example):

------------

Abstract—In this paper, we introduce a novel lightweight anonymization technique called Shalon. It is based on onion routing, aims to reduce complexity, and delivers high bandwidth. We have, compared to the widely known approach Tor, slightly reduced the level of security in favor for greatly increased performance.

The most significant advantage compared to other approaches is that Shalon is fully based on standardized protocols, which makes our approach highly efficient and easy to deploy. It also makes Shalon easier to understand for normal users, eases protocol reviews, and increases the chance of having several implementations of Shalon available. In this work, we provide a description of the design and implementation of Shalon, a performance and anonymity analysis, and a discussion on the scalability properties.

[1] https://pdfs.semanticscholar.org/6f30/f14ff4972ddd787bf7e859...

Too much emphasis on education and college in this article. Hacking requires 'thinking outside the box'; often called lateral thinking[0]. Formal education in the subject of hacking is nice, but doesn't allow for the creative mind to fully explore systems. There's a phrase:

   Don't Learn to Hack - Hack to Learn
In terms of earning money from hacking, there are tradeoffs made in both whitehat and blackhat hacking. One noticeable tradeoff in blackhat hacking is having no boss, and penetrating a system on your own terms. Whitehat hacking might pay more and be more respectful and a nice little haven where you can avoid jail, but it's often riddled with a rigid framework for getting into systems and doesn't encourage the lateral thinking I previously mentioned. Instead it's a corporate cubicle job where hacking is often automated and routine.

On the other hand, there is grey hat hacking which many fall into at some stage to strike a balance, and often balance criminality with a respectful whitehat job that pays well.

[0] https://en.wikipedia.org/wiki/Lateral_thinking

"Why Tipping Should Be Banned", by Adam Ruins Everything is worth watching if you are of the school of thought that tipping is bad: https://www.youtube.com/watch?v=q_vivC7c_1k

The gist of the video is that if you're tipping, then a waiter/waitress for example is not being paid enough, and tips are deliberately designed to bolster their unfair income.

For those who don't want to click, here's the abstract:

Populism may seem like it has come out of nowhere, but it has been on the rise for a while. I argue that economic history and economic theory both provide ample grounds for anticipating that advanced stages of economic globalization would produce a political backlash. While the backlash may have been predictable, the specific form it took was less so. I distinguish between left-wing and right-wing variants of populism, which differ with respect to the societal cleavages that populist politicians highlight. The first has been predominant in Latin America, and the second in Europe. I argue that these different reactions are related to the relative salience of different types of globalization shocks.

Just make sure your catchall is renewed well into the next five years. Heck, you can do a 'rollover renewal' that lasts 10 years if you wanted.

This is to stop somebody eventually gaining control of the domain when it expires, setting up a catchall on it, and then being able to login to every single account you used with that address.

Some registrars protect a domain after expiration so nobody can hijack it and claim it as their own, but you often have to pay extra for this service.

ProtonVPN 9 years ago

This was before the client even connected for the first time. And the IPs were well known C&C servers used for collecting keystrokes and screenshots of your O.S

ProtonVPN 9 years ago

Yeah and use a decent client like Viscosity, or if your O.S supports OpenVPN config files natively, just use them.

ProtonVPN 9 years ago

I spotted loads of malicious network traffic, and using the Sysinternals Autoruns[0] utility I was able to spot attempts at persistence. I also checked the outbound connections and they were C&C servers. I can't remember if the installer was digitally signed or not, but there was definitely malware in it. I always make sure to opt-out of any AD ware that might be bundled with an installer, but this seems to have been injected surreptitiously, and installed with very little interaction.

Just be careful with the bespoke VPN clients as they are very juicy targets for MITM attacks. I know I would be going after VPN software if I wanted to do ex-filtration for a small subset of users trying to hide their tracks from governments and ISPs.

[0] https://technet.microsoft.com/en-us/sysinternals/bb963902.as...

Even if this site was not a joke, I wouldn't trust an online password generator, especially if the pass is generated on the backend instead of the client. A quick Google for 'password generator' yields hundreds of these sites which are more than likely run by the same outfit and are possibly logging the passes into a database to make cracking various accounts easier.

There's a few PW generators which run on the client only and don't send any requests to third parties, and I use them sometimes. They are typically very JS heavy and use different seeds to generate sufficient entropy, like client fingerprint, mouse co-ordinates, timezone, etc

ProtonVPN 9 years ago

I found malware in the PIA installer. Not sure if it was planted by PIA themselves or I was subjected to a MITM attack, and so I would never use any bespoke VPN software again. Best just downloading the OpenVPN config files and plug them into something like Viscosity[0] (which I trust over the more bespoke VPN clients made by the VPN providers themselves).

[0] https://www.sparklabs.com/viscosity/

ProtonVPN 9 years ago

Some kind of crypto-haven like The Isle of Man or Liberland

Having up to date Android and iOS zero days plus the rootkit / RAT software is not something you can get open source or find easily commercially.

You might be right about not being able to find 0days that target the latest versions of iOS or Android so easily, but there are dark web markets stuffed with 0days that target specific versions, or a range of versions. Not sure about pricing, but they're typically cheaper than the exploits that target the latest and greatest.

It's by pure chance that the owner of a device is using an out-dated O.S on their phone. Others may argue it's not by chance, but by design, and that some phones can't upgrade properly and remain locked to a specific version..You know, because governments sometimes demand that phones are deliberately left unpatched so they can do interception or do ex-filtration on them?

It's entirely possible that one day many years from now, a prospective employer/insurer/whatever finds such a comment and flags me for it

This is why you should use pseudonyms and strive for anonymity. It's trivial to signup to Hackernews under an assumed name, or handle, and start venting on contentious issues. Hackernews might shadow-ban your throwaway account, so you might have to lurk moar and share some interesting links before you can comment without being censored. I know from experience. Last time I checked, HN has no strict policy on multiple accounts and you can do this very easily.

In terms of OPSEC, you obviously shouldn't contaminate your real iden with your anon iden, or contaminate your anon idens with other anon idens. You should also deliberately alter the stylometry of your writing so nobody can link two pieces of text to each other. Anonymouth[0] is my favorite tool for doing just that.

[0] https://github.com/psal/anonymouth

What if you're on some obscure lesser known mobile network and the EU country you're traveling to doesn't support that network? Vodafone (a non obscure network) however seems to be ubiquitous in the EU.

Glad you mentioned Bulletproof. Asprey said once in one of his many videos that Coconut Oil doesn't work when combined with coffee because it contains bad saturated fats which you want to avoid. It does however contain MCT, but not in the ratio you want, hence his Octane oil products which only provide the good fats that you need.

You mean like a Sybil Attack? You might be right about a certain culture of sockpuppetry on places like Reddit where it's actually trivial to setup multiple accounts under different IPs and then upvote all your stuff. It's no secret you can pay for services where people do this for you and 'astroturf' your chosen topic and make it seem more popular than it actually is.

https://en.wikipedia.org/wiki/Sybil_attack

https://np.reddit.com/r/shills/comments/4kdq7n/astroturfing_...

https://www.youtube.com/watch?v=jdaPJLJCK1M