HN user

zerognowl

1,401 karma
Posts104
Comments99
View on HN
blog.adafruit.com 9y ago

Barbie Electronic Typewriter Toys Contains MASC Cryptographic Capabilities

zerognowl
3pts0
www.crypto101.io 9y ago

Crypto 101 – Introductory course on cryptography

zerognowl
919pts140
www.justinmccandless.com 9y ago

Setting Up HTTPS on Node for Free with Let's Encrypt

zerognowl
3pts0
googleprojectzero.blogspot.com 9y ago

Breaking the Chain

zerognowl
101pts17
www.cryptomuseum.com 9y ago

Barbie Typewriter Alphabet substitution cipher

zerognowl
3pts0
cryptodesign.org 9y ago

Crypto Design Awards

zerognowl
3pts0
www.cryfs.org 9y ago

Cryfs – A cryptographic filesystem for the cloud

zerognowl
4pts0
blog.webinista.com 9y ago

Enable HTTPS with AWS Certificate Manager, CloudFront, and S3

zerognowl
4pts0
realm.io 9y ago

Building a User-Centric Security Model in iOS Applications

zerognowl
2pts0
blog.cryptographyengineering.com 9y ago

Zero Knowledge Proofs: An illustrated primer

zerognowl
5pts0
moxie.org 9y ago

A Crypto Challenge for the Telegram Developers (2013)

zerognowl
77pts9
www.contextis.com 9y ago

Manually Testing SSL/TLS Weaknesses

zerognowl
2pts1
whispersystems.org 9y ago

Open Whisper Systems – The XEdDSA and VXEdDSA Signature Schemes

zerognowl
1pts0
www.ssllabs.com 9y ago

SSL Server Test (Powered by Qualys SSL Labs)

zerognowl
2pts0
blog.golemproject.net 9y ago

Golem  –  Building the World’s Most Powerful Supercomputer On The Blockchain

zerognowl
2pts0
cryptoreport.websecurity.symantec.com 9y ago

Check your SSL/TLS certificate installation

zerognowl
2pts0
swizec.com 9y ago

Backbone with ES6

zerognowl
2pts0
brennan.io 9y ago

Tutorial – Write a System Call

zerognowl
198pts16
z.cash 9y ago

Zcash – The Design of a Secure Ceremony

zerognowl
2pts0
www.davidegrayson.com 9y ago

Practical Windows Code and Driver Signing

zerognowl
2pts0
practicalcryptography.com 9y ago

Practical Cryptography

zerognowl
93pts20
spoofer.caida.org 9y ago

The State of IP Spoofing

zerognowl
1pts0
hyperform.js.org 9y ago

Hyperform – Capture form validation back from the browser

zerognowl
1pts0
stripe.com 9y ago

Service discovery at Stripe

zerognowl
2pts0
hstspreload.appspot.com 9y ago

HSTS Preload List Submission

zerognowl
2pts0
eprint.iacr.org 9y ago

A Formal Security Analysis of the Signal Messaging Protocol [pdf]

zerognowl
2pts0
www.cryptocoinsnews.com 9y ago

Here's What Crypto Decentralists Think about the Block Size Debate

zerognowl
1pts0
www.nomoreransom.org 9y ago

Crypto Sheriff, by the No More Ransom Project

zerognowl
1pts0
en.wikipedia.org 9y ago

James while John had a better effect on the teacher

zerognowl
3pts0
neverssl.com 9y ago

NeverSSL – helping you get online

zerognowl
3pts0

Every site which uses the Reddit upvoting model is subject to this type of attack. The correct name for it is a Sybil Attack[1]

I suspect a large portion of Reddit accounts are sockpuppet[2] accounts, alongside Product Hunt.

It's the Law of Manipulatable Numbers where if you put a number next to somebody's name online, then the person sometimes (not often) tries to manipulate the number.

[1] https://en.wikipedia.org/wiki/Sybil_attack

[2] https://en.wikipedia.org/wiki/Sockpuppet_(Internet)

Also noteworthy:

http://www.dailydot.com/layer8/trump-clinton-debate-online-p...

Millennials don't exist, according to Adam Conover: https://www.youtube.com/watch?v=-HFwok9SlQQ

I'm careful using the word "Millennial" these days and increasingly skeptical of online articles with the word "Millennial" in the title. Thanks to shows like Adam Ruins Everything[1], I am more informed on a variety of topics. (I learn visually and prefer to watch his videos instead of read an article).

[1] https://www.youtube.com/watch?v=gX2R0b_mqrQ&list=PLuKg-Whduh...

If the sites are on a root domain, then you can put ADWords on the site and get paid, but not much. Typically a thousand impressions is a dollar. Depending on how long the URL stays on the frontpage, you could be looking at 20,000 - 50,000 impressions which roughly translates as USD 20-50.

You get paid even more when ADs are clicked on.

To be honest this is a rather dated way to monetize a site now with the sudden surge of visitors using ADBlockers, and you might want to look into other ways to monetize, such as

- Affiliate links

- Premium/paywalled articles / content

- Donation buttons, using PayPal / Bitcoin/Litecoin

Also keep in mind that since getting frontpage on HN is so rare, then it can't be a sustainable source of income

In typical UK surveillance state fashion they pander to base fears and unforgivably overlook how bad censorship and surveillance is in places like China.

It's not that the UK GOV "doesn't understand how the Internet works" as claimed by many on this topic, but that the citizenry don't care enough to encrypt. The citizenry aren't scared enough to encrypt.

Education is the key here, and it needs to be bashed into a citizen's skull that The Internet is not a black box, and that traffic moving en clair is fair game by Governments, even criminal threat actors in Starbucks with their fake Free Wifi.

We need to keep building abstractions on top of The Internet to make it expensive for spying to take place. The usual solutions apply; TOR, VPNs, TLS/SSL, PGP, et al.

I agree with others that homeopathy is woo-woo.

One of the oft-cited claims by practitioners is that water has memory[1]

[1] https://en.wikipedia.org/wiki/Water_memory

This sounds cute and it's probably true that water has some subtle hard-to-reproduce property of retaining certain configurations, but even if this were true, what's so great about it?

I'm not entirely convinced that a hard-to-reproduce configuration of water will affect my physiology, and if it does, then this would have to be put through scientific rigeur, which it is not, it's performed on blind faith that it works.

Because their crawler is so monolithic that it would be expensive and annoying overhauling it for IPV6.

There is a great use-case for IPV6 for IOT where each device gets its own IPV6 address. IPV6 addresses are appearing more like MAC addresses at this rate as IPV6 is not exhausted yet.

Is it so bad that productivity grinds to a halt like this? I can understand if your employer has Henry Ford posters on the wall to keep workers productive, but sometimes the best work is done when a worker gets home, as if home is some precious thing that is forcibly denied, because it represents a reward, and that the reward of work is only represented as enjoying the spoils of your labor at home.

This is, for want of better phrasing, the rat race, and quickly being swapped out for better work-life balance, increasingly being lambasted, and seen as generally not ideal for more and more people.

Burnout is such a catch-all term these days and is usually a word associated with the more negative aspects of 9 to 5 culture. It's not a word in the vocabulary of high-performing people. High performance is not especial to 9 to 5 culture, or especial to those who have grit. High performance can be seen in unpaid work, or in work that feels more like work, simply because, there are different types of work, like body work, mind work, etc

If you mean Be the change you want to see then OP simply has to post to HN with a strong bias towards his/her topic of interest?

I can't see that by merely choosing a topic you are passionate about, that it gets more up-votes, but this is the tactic I do see because by being passionate, by virtue, you post more, and so more upvotes are guaranteed?

"Program or be programmed" - Rushkoff said it best.

In a world where your Rushkoffs[1] go unread, we are spiraling into some sort of local maxima where social media is realized for what it is, and the problems associated with social media are epidemic.

The crux of the issue lies in the fact that nobody knows what social media is, or indeed cyber. "Cyber" as it stands now is some far off place, in a William Gibson fantasy, but infact operates in the world seemingly un-noticed by the smartphone equipped masses.

As I said; it's not long until people realize they've been played and their eyeball hours and data exhausts are being sold to the highest bidder for hard cash. It makes me wonder why smartphones even cost so much. Surely they should be 'free' given how much data can be gleaned from a smartphone owner?

[1] https://en.wikipedia.org/wiki/Douglas_Rushkoff

I'm a proud generalist too. One thing I've been investigating recently is the concept of so called 'microdegrees', also called nano-degrees:

https://en.wikipedia.org/wiki/Microdegree

Open Badges is also a neat idea: http://openbadges.org/

Open Badges looks even more promising if combined with blockchain tech so it's impossible to forge your ability / qualification, unlike today where a large portion of 'degrees' can be bought and sold on the black market for very little money.

Put your parents on a VPN, great idea, instead of the other way around where I am the sole VPN user and pay more for my Internet connection because surfing without a VPN just feels weird these days. Also five minutes of OSINT on Google tells me I share my ISP-Issued IP with at least 1000 other paying subscribers, whereas a VPN can run into the millions of users, albeit not all using that VPN-Issued IP at the same time.

Frontend development has come along leaps and bounds since the days of document.layers and MSIE6 alert() debugging, it seems to be slowly coming out of a renaissance period lately as many devs have reached a consensus that they are spoiled for choice and now all that's left to do is, well, build.

There is this trend of developers feeling just as you described: overwhelmed. But rather than feel that, I try to embrace it. Like anything on the web, if you're not building on strength, then you must be in it for other reasons, like trying to impress employers, or trying to learn code because apparently it pays the bills better than other gigs.

I would start small, and treat everything like an experiment. If an experiment works well, you can build on top of it, and import what you learned from experiments into full blown (hopefully paid for) development.

I sometimes have to remember to use <em> instead of <b> but only because I didn't think such things were above me. Indeed it's a miracle a visitor to your site can even read the content with the temptation that exists to include another slider widget, or inaccessible web component.

That DNS is decentralized does not really mean anything when you consider how easy it is to uncover where a site is hosted, and understand which points you need to hit to take a site down. Whilst we can do interesting things at the network level to mitigate (think Cloudflare, anycast, mirroring, etc), the services sitting behind DNS are still exposed like a sitting duck.

I mean if we really wanted to DDOS Cloudflare, we just exhaustively gather all the raw APEX/Naked IPs of their edge nodes then stress them, but I imagine Cloudflare doesn't advertise their list of IPs and they're closely guarded, so attackers are left in the dark. But such an attack is plausible.

What we do need are antifragile protocols like BitTorrent/IPFS/Bitcoin which infact reward swarm behavior, instead of punish it.

What struck me about the Snowden leaks, as opposed to previous (much smaller) leaks regarding the NSA is the fine grained insight into the apparatus, the machinery, and the scope of the spying. Whereas previously we only knew of vague scenarios like tapped undersea cables, we now know the specifics, mechanics, and even operational details of the NSA.

I think fine grained insight into what an intelligence service looks like on the inside is enough to compel people to change their behavior. I know for me, I was skeptical of claims the NSA even could do half the things people were purporting they could do, and having confirmation like this was the real game changer.

Now that people are aware that we are being spied on at a massive scale

Here's an EFF.org press conference video detailing NSA wiretapping, from 10 years ago, as of writing:

https://www.youtube.com/watch?v=dqEfMMUbfQw

Whilst the efforts of the NSA were known for some time, the Snowden leaks were very aggressive and a lot more information could be gleaned from them. It's not enough to casually mention Echelon and then dismiss these revelations as trivial. There is an enormous trove of details in the Snowden Archive that describes the apparatus and machinery used to spy, not just some vague reference to "Tapped Undersea Cables" which is an oft-used scene people use to describe the NSA. I just wish the leaks had more detail, like code samples, or even pictures of the facilities used to spy. (You'd be surprised how much can be gleaned from just one picture or a line of code).

but the effect was minimal beyond crypto heads and maybe enterprise users.

Security/privacy on the Internet is known for being hard, and it used to be, if you wanted privacy you had to withdraw slightly from society, and learn Linux, read about TOR, learn how to harden your web browser, or otherwise attempt to 'go dark' from the prying eyes of governments or sophisticated criminals.

Now it can be said with certainty that many of the things we take for granted, have come along leaps and bounds due to Snowden, and are a lot less complicated to Install and setup.

Now a privacy-conscious teenager can install TOR browser bundle, Signal, uBlock, or any number of things you can find on sites like PrivacyTools[1] with relatively little trouble compared to the Internet pre-Snowden.

UX continues to dominate all other market factors in computing by a huge margin

It might come at some cost, like reduced UX, as you mention, but that's called a security tradeoff or a privacy tradeoff and it's a well-known hard fact of protecting your communications and traffic.

[1] https://www.privacytools.io/

In a world where your Rushkoffs[1] go unread, we are spiraling into some sort of local maxima where social media is realized for what it is, and the problems associated with social media are epidemic.

The crux of the issue lies in the fact that nobody knows what social media is, or indeed cyber. "Cyber" as it stands now is some far off place, in a William Gibson fantasy, but infact operates in the world seemingly un-noticed by the smartphone equipped masses.

As I said; it's not long until people realize they've been played and their eyeball hours and data exhausts are being sold to the highest bidder for hard cash. It makes me wonder why smartphones even cost so much. Surely they should be 'free' given how much data can be gleaned from a smartphone owner?

[1] https://en.wikipedia.org/wiki/Douglas_Rushkoff

A few things with this:

- It doesn't work with JS disabled :(

- I typically want applications like this client-side only because I could use this for creating diceware-like passwords, and I don't want any of this logged on a remote server.

It's making remote requests here which is annoying

    /api/suggestion_service;word=xxx?returnMeta=true
How's My SSL? 10 years ago

Agreed. The onus is not only on the user to respond to threat landscapes, but also on the site owners. Shunting all the responsibility to the site owner typically does not work in your favor.

+1 for the Nanny State reference. In typical UK surveillance state fashion they pander to base fears and unforgivably overlook how bad censorship is in places like China. Where it not for censorship I think the thrill of surfing the Open Web would be dampened, just like when drugs instantly become more exciting when they are outlawed and regulated.

I am certain outlawing base primal urges, like the right to ingest what one desires into one's own body makes such primal urges even more favorable, often to the point of detriment to the State who then have to feverishly invent something inverse to people's actual needs like Alcohol, or bromides like Sugar to pacify their citizenry.

So many bootloader fixes, this is awesome! For those using FDE, read this: http://spaceisdisorienting.com/when-fulldisk-encryption-goes...

I tend to use FDE for non mission critical working environments, like casually surfing the web, or just messing around with code. FDE can go wrong at the worst of times, and can undo years of work if you let it.

That's why if you're using FDE for anything important, you should be backing up crucial data to containers, or otherwise preparing for the entire disk to be scrambled beyond repair and or bricked.