I am trying to understand your post. Is it cheaper per yard to hire a concrete truck than to mix concrete (with free aggregate/sand) yourself?
HN user
theEXTORTCIST
There is the issue of the TLS connection of images fetched in the app (other things too?) being tied to a domain without a valid cert. In other words, you could MITM the TLS session between the wifi user and the Tindr servers for AT LEAST photos within the app, perhaps more (authentication? other app behavior?).
Because the app isn't strictly enforcing the validation of the cert of the photos domain it's trying to reach to pull photos, your MITM server is free to serve to the app as if it was the server on the Internet.
I agree that you need "both halves" in this scenario to sign the transaction.
At some point during the spend from the wallet, the privkey that matches the wallet pubkey has to touch memory. This privkey can in theory be compromised in a number of ways with malware on the spending system (keylogger, screen caps, process memdump, etc).
I think the safest way to go about this is to generate an entirely new keypair/wallet on an isolated system. Spend from your wallet then transfer the balance to the newly created wallet. This minimizes losses as a result of privkey compromise (unless of course your isolated system isn't so secure)
The attacker only needs to have compromised the device which spends from the wallet file
I don't think it's "stupid" to C2 via chat API. It would be "stupid" to have no fallback mechanisms
plot twist: active breach investigation on going with all 3 majors
TOR does not protect DNS queries out of the box. You must configure your PC to query through TOR or all of your DNS queries have the potential to leak to your ISP
https://tor.stackexchange.com/questions/8/how-does-tor-route...
Verizon has been adding headers for tracking for some time (probably via Blue Coat ProxySG forward proxy or similar technology) https://www.verizonwireless.com/support/unique-identifier-he...
This seems like a really cool device. One that I would certainly purchase.
What weird stretch goals they have. I wonder if these are jokes? "$8m = Signatures of entire team printed inside the phone case $10m = Free encrypted VPN tunnel service for all backers for 1 year $20m = Candy Crush (clone) available for free"
This is one of the biggest points that I have seen taught in driver training courses and repeated throughout my life. Most of the events people refer to as car accidents are crashes/collisions.
This is definitely a confusing sentence, especially for a non English speaker. You can reword the sentence and add something in front (e.g. "The researchers"). "The researchers are using psilocybin assisted group therapy for demoralization in long term AIDS survivors."
AIDS surviors have "demoralization in them". The psilocybin assisted group therapy is being used for that demoralization.
Interesting... there doesn't appear to be any fire suppression systems pictured in the mining buildings
Report it anonymously to your insurance provider (*not sure if this is possible and/or would actually do anything)
The data URL scheme is abusable.
Firefox and Chrome correctly redirect to localhost via javascript
data:text/html,http://www.mostSecureInternetBankVictim.com/customerLogin.php%2FreallyLoginRandomData=130r193fj02jf-2jf023f23f-f2039f0239jf0a-39j029jg90wgj-9203f092jf0f-90e9f204fh0-9hf2ef8CUSTID=923r9032fdjnnvjddata%3Atext%2Fhtml%2C%3Cscript%3Ewindow.location%20%3D%20%22http%3A%2F%2F2130706433%22%3B%3C%2Fscript%3EValuedGoogleCustomer=?Security=trueEncrypted=trueSecureBrowsingSession=TrueI just tried this on Chrome 60.0.3112.90. Both Firefox and Safari throw phishing warnings with these URLs.
http://news.ycombinator.com@1572395042 Chrome takes me to 93.184.216.34 no warning
Then I tried http://security.wellsfargo.com@customerLoginv=ar3351RandomDa...
Which stretches way past my laptops viewable URL bar... and it takes me right to badsite.null (or a valid site like example.com). If you need HTTPs you can redirect on badsite.null's web server. Very wild.
In society we have an endless amount of social warnings, "Don't drink too much, you'll get ill. Don't do drugs, you'll become an addict. Don't drive without your seatbelt, you can die. Don't watch too much TV, it's not good for you."
But we still lack any sort of warning in the greater contemporary society about the risks of overuse of the hyper stimulus that comes along with social media. I am definitely beginning to see this take shape in our society (with people rejecting social media applications, articles like this, the way people speak to the overuse of such platforms)
I have heard one of these in San Francisco, CA in the USA. The music had a really high pitched note behind it that sounded horrible.. like a cross between a mosquito and the buzzing of an input jack
Forcefully taking private property from individuals to later sell to other private parties for private use sounds like the nightmare version of eminent domain.
to add to your post, that affiliate link stays active on amazon accounts that clicked it for 24hours and pays out to the owner for every product purchased in that time frame
Was waiting for this comment. I often ask myself, "Do I want any entity to have a copy of the exact dates and amounts of my entire daily consumer activity?". Whether anonymized or not there is a tremendous amount of knowledge that can be gleaned from non-itemized debit card ledgers.
Some relevant info: In the USA average consumers are protected by the FDIC for the balances of their deposits up to $250,000. A large number of banks have consumer liability limits in place for protection from fraudulent charges on their credit cards.
this is an interesting application... was linked in the article safestrike.it
Link to the Orin Kerr article: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.
From my comment, the SPECIFIC details of the tool's concepts of operation, implementation, and capability.
The field guide provides great detail on operations and limitations of a specific existing tool (sample GUI screen shots, potential detection threats from personal security products and full crash dumps, detection of cam software process restarts, abilities to stall NIC cards, abilities to BSOD, ability to corrupt existing files, limitations based on cam emulation, limitations of previously saved cam files, the tool's PE names(32bit wscupd.exe, 64bit running outside of system32 wermgr.exe. GUI.exe present in the same folder as above PEs), example of the log.txt file written to the attacking USB, information on differences between winXP requirements vs other systems(scanner.sys driver needs)).
Just because a threat vector is well known and not cutting edge does not make the SPECIFIC information of its existence, implementation, and capability completely worthless
Pretty interesting how many bits of identifying information are available based on system fonts.
if you've never seen EFF's Panopticlick check out https://panopticlick.eff.org
point taken, I had not read it this way originally but your interpretation makes sense
edit: I knew I saw something about this somewhere earlier today. Still, this proves nothing because it's source less.
https://www.politie.nl/en/news/2017/july/20/underground-hans... "Some 10,000 foreign addresses of Hansa Market buyers were passed on to Europol"
Untrue according to the crabs article interview with the woman "Petra Haandrikman, team leader of the Dutch police unit that infiltrated Hansa."
https://krebsonsecurity.com/2017/07/exclusive-dutch-cops-on-...
"H: Yes, we called them “AlphaBay refugees.” It wasn’t the technical challenge that caused problems. Because this was a police operation, we wanted to keep up with the orders to see if there were any large amounts [of drugs] being ordered to one place, [so that] we could share information with our law enforcement partners internationally."
Using a standard channel for public key exchange is half the battle. The other half is using a trusted channel to verify the public key does indeed match the public key you were originally sent. "Trusted channel" can be broadly interpreted (and is also often subject to tampering as well)
The only reason I mention that this is at all probable is because of the length of a PGP key. How often is the average user of a site like this logging in to verify even the last few bytes of a PGP pub key compared to what is saved in their software? Plus how many users would chalk it up to "oh SellerX just changed their key pair" and continue on encrypting their message with the new key
Law enforcement could have easily MITM'd the PGP. They replace the public key of a vendor with their own public key (on the vendors's page, without the vendor's/buyer's knowledge), then the buyer address gets encrypted with that public key. Then they decrypt and resend the message using the sellers original public key.
I really wonder if this happened at all