HN user

tric

545 karma
Posts2
Comments44
View on HN

Only requirement is that the domain the attacker is spoofing is using O365.

This is not true. The paper mentions multiple service providers using more relaxed validation.

Table 3, section 5 in the paper shows which policies need to be in place on the domain they are piggy-backing on.

They reference Postfix:

"Additionally, we note that mailing list software such as Listserv and Mailman require a backend MTA. In our experiments we used Postfix with DMARC turned on, a configuration which follows good security practice. However, in practice many organizations might not use this configuration because many MTAs (including Postfix) do not enforce DMARC by default. In these cases, the attacker can spoof email from any target domain, regard- less of its DMARC policy, much like the attack against Gaggle."

I read this to mean that if you actually enable DMARC in Postfix, piggy-backing on another domain's policies results in rejection.

No mention of results for receiving at ProofPoint, Mimecast, Trellix, or Cisco's email appliance.

This is not a UX problem.

They are demonstrating a problem with managed providers, and their opinionated configuration. You give up a lot of control as an admin when you use 365 as your front-end. This further proves that.

Your domain may have a policy of reject or quarantine, but does the receiving host correctly act on that policy?

I can understand if free email providers are more permissive with narrow authentication scenarios. Users aren't usually able to contact support.

As someone suggested in this thread, this is a UX problem.

Policies need to appease a large number of users. A gov/corp org receiving these messages can be more strict. Even in these orgs, people complain about not receiving an email that was appropriately rejected.

The diagram demonstrating the attack shows DMARC fails. All they have shown is that everyone should have DMARC configured properly, and use a reject or quarantine policy. This has been best practice for a long time now.

They use the example of state.gov. That domain's policy is currently set to Reject, which is what all Federal government services have been using for years now.

Here's CISA's requirements: https://www.cisa.gov/news-events/directives/bod-18-01-enhanc...

Microsoft also uses their own auth mechanism in addition to DMARC. It's called composite authentication. In my experience, comp-auth is more strict than DMARC alone.

https://learn.microsoft.com/en-us/microsoft-365/security/off...

What am I missing? Why is this noteworthy?

EDIT:

After reading more of the paper, my conclusion is mentioned in a later reply:

"They are demonstrating a problem with managed providers, and their opinionated configuration. You give up a lot of control as an admin when you use 365 as your front-end. This further proves that. "

I'm surprised there isn't some way for gamers to rent out use of their GPU's when idle.

https://rendernetwork.com/

"The Render Network® Provides Near Unlimited Decentralized GPU Computing Power For Next Generation 3D Content Creation."

"Render Network's system can be broken down into 2 main roles: Creators and Node Operators. Here's a handy guide to figure out where you might fit in on the Render Network:

Maybe you're a hardware enthusiast with GPUs to spare, or maybe you're a cryptocurrency guru with a passing interest in VFX. If you've got GPUs that are sitting idle at any time, you're a potential Node Operator who can use that GPU downtime to earn RNDR."

Geez, TikTok (basically) content on HN...

The aggression, quick cuts, single word subtitles...

I don't understand the appeal of this style. I wonder how people will look back at this era of video editing in 10 years.

Probably that it’s very centralized. Or at least that the price is able to be highly influenced by a few individuals/groups.

The article and the parent comment are about Ordinals. Your comment appears to be an opinion about Bitcoin the asset and/or network itself.

Update on Sharing 3 years ago

I have premium at the moment ...and the ads are still getting out of hand.

Do you mean promos for other Netflix shows? Or are these ads for products/services unrelated to Netflix?

I was looking into getting a new toyota, but was hesitant because of this tracking "feature."

I searched online for how to disable it, and found this question:

https://carkiller.com/scottykilmer/qa/how-to-permanently-dis...

These responses are typical:

"But you're still going to be traceable by your phone."

"...everyone, EVERYONE, on the planet has their information out there. There is no such thing as "off the grid." "

"your phone has sent more than enough info about you to every advertiser on Earth mord than the DCM will ever do."

Many people just don't care....

916 Days of Emacs 3 years ago

Emacs wants you to hit the meta/alt key a lot, which is difficult for a touch typist.

hmm.... I wonder if this is the reason Mac OS uses the option key for things like 'kill word' (ctrl+backspace on other OSes or ctrl+w in vi). I have a hard time typing quickly using option/command instead of ctrl.

I also prefer vi-like keybindings.

not to invest all your savings in high risk investments

FTX's failure was due to fraud. Not "high risk investments." They literally didn't have the assets they claimed to have. The same investments held at other centralized exchanges or via self-custody (e.g. Bitcoin) would have lead to a different outcome.