HN user

theEXTORTCIST

75 karma
Posts0
Comments37
View on HN
No posts found.

There is the issue of the TLS connection of images fetched in the app (other things too?) being tied to a domain without a valid cert. In other words, you could MITM the TLS session between the wifi user and the Tindr servers for AT LEAST photos within the app, perhaps more (authentication? other app behavior?).

Because the app isn't strictly enforcing the validation of the cert of the photos domain it's trying to reach to pull photos, your MITM server is free to serve to the app as if it was the server on the Internet.

I agree that you need "both halves" in this scenario to sign the transaction.

At some point during the spend from the wallet, the privkey that matches the wallet pubkey has to touch memory. This privkey can in theory be compromised in a number of ways with malware on the spending system (keylogger, screen caps, process memdump, etc).

I think the safest way to go about this is to generate an entirely new keypair/wallet on an isolated system. Spend from your wallet then transfer the balance to the newly created wallet. This minimizes losses as a result of privkey compromise (unless of course your isolated system isn't so secure)

This seems like a really cool device. One that I would certainly purchase.

What weird stretch goals they have. I wonder if these are jokes? "$8m = Signatures of entire team printed inside the phone case $10m = Free encrypted VPN tunnel service for all backers for 1 year $20m = Candy Crush (clone) available for free"

This is definitely a confusing sentence, especially for a non English speaker. You can reword the sentence and add something in front (e.g. "The researchers"). "The researchers are using psilocybin assisted group therapy for demoralization in long term AIDS survivors."

AIDS surviors have "demoralization in them". The psilocybin assisted group therapy is being used for that demoralization.

The data URL scheme is abusable.

Firefox and Chrome correctly redirect to localhost via javascript

  data:text/html,http://www.mostSecureInternetBankVictim.com/customerLogin.php%2FreallyLoginRandomData=130r193fj02jf-2jf023f23f-f2039f0239jf0a-39j029jg90wgj-9203f092jf0f-90e9f204fh0-9hf2ef8CUSTID=923r9032fdjnnvjddata%3Atext%2Fhtml%2C%3Cscript%3Ewindow.location%20%3D%20%22http%3A%2F%2F2130706433%22%3B%3C%2Fscript%3EValuedGoogleCustomer=?Security=trueEncrypted=trueSecureBrowsingSession=True

I just tried this on Chrome 60.0.3112.90. Both Firefox and Safari throw phishing warnings with these URLs.

http://news.ycombinator.com@1572395042 Chrome takes me to 93.184.216.34 no warning

Then I tried http://security.wellsfargo.com@customerLoginv=ar3351RandomDa...

Which stretches way past my laptops viewable URL bar... and it takes me right to badsite.null (or a valid site like example.com). If you need HTTPs you can redirect on badsite.null's web server. Very wild.

In society we have an endless amount of social warnings, "Don't drink too much, you'll get ill. Don't do drugs, you'll become an addict. Don't drive without your seatbelt, you can die. Don't watch too much TV, it's not good for you."

But we still lack any sort of warning in the greater contemporary society about the risks of overuse of the hyper stimulus that comes along with social media. I am definitely beginning to see this take shape in our society (with people rejecting social media applications, articles like this, the way people speak to the overuse of such platforms)

Was waiting for this comment. I often ask myself, "Do I want any entity to have a copy of the exact dates and amounts of my entire daily consumer activity?". Whether anonymized or not there is a tremendous amount of knowledge that can be gleaned from non-itemized debit card ledgers.

From my comment, the SPECIFIC details of the tool's concepts of operation, implementation, and capability.

The field guide provides great detail on operations and limitations of a specific existing tool (sample GUI screen shots, potential detection threats from personal security products and full crash dumps, detection of cam software process restarts, abilities to stall NIC cards, abilities to BSOD, ability to corrupt existing files, limitations based on cam emulation, limitations of previously saved cam files, the tool's PE names(32bit wscupd.exe, 64bit running outside of system32 wermgr.exe. GUI.exe present in the same folder as above PEs), example of the log.txt file written to the attacking USB, information on differences between winXP requirements vs other systems(scanner.sys driver needs)).

Untrue according to the crabs article interview with the woman "Petra Haandrikman, team leader of the Dutch police unit that infiltrated Hansa."

https://krebsonsecurity.com/2017/07/exclusive-dutch-cops-on-...

"H: Yes, we called them “AlphaBay refugees.” It wasn’t the technical challenge that caused problems. Because this was a police operation, we wanted to keep up with the orders to see if there were any large amounts [of drugs] being ordered to one place, [so that] we could share information with our law enforcement partners internationally."

Using a standard channel for public key exchange is half the battle. The other half is using a trusted channel to verify the public key does indeed match the public key you were originally sent. "Trusted channel" can be broadly interpreted (and is also often subject to tampering as well)

The only reason I mention that this is at all probable is because of the length of a PGP key. How often is the average user of a site like this logging in to verify even the last few bytes of a PGP pub key compared to what is saved in their software? Plus how many users would chalk it up to "oh SellerX just changed their key pair" and continue on encrypting their message with the new key

Law enforcement could have easily MITM'd the PGP. They replace the public key of a vendor with their own public key (on the vendors's page, without the vendor's/buyer's knowledge), then the buyer address gets encrypted with that public key. Then they decrypt and resend the message using the sellers original public key.

I really wonder if this happened at all