HNHacker News
TopNewBestAskShowJobs

HackinOut

140 karma · joined May 5, 2014

Benjamin Guesneau

Twitter: @HackinOut

submissionscomments
HackinOut··on Wifiphisher: Fast automated phishing attacks against WPA networks
WPS push button and WPS PIN are two separate features. If you only have WPS Push Button enabled you are not vulnerable.
HackinOut··on Wifiphisher: Fast automated phishing attacks against WPA networks
Yes, that is why this password is called a Pre-Shared Key.
HackinOut··on How My Mom Got Hacked
Yes, I meant try to delete... My first impression about CryptoWall is that it was hacked together quicker than CryptoLocker. It doesn't bother with generating a symmetric key per file but rather seems to use a single asymmetric key. It also apparently make a copy of the file before encrypting and doesn't zero-out after deleting the plain text file (see another of my comment in this thread)
HackinOut··on How My Mom Got Hacked
You only need to decrypt once the payment has been received, so the private key doesn't need to be sent to the infected machine before that. Encrypt/Decrypt, it seems to be a moot point.

The "decrypt one file for free" feature seems to be specific to CryptoWall which, some have reported, do not use symmetric encryption like CryptoLocker. CryptoLocker stores symmetric keys for each file on the infected machine, encrypt those with a public key and when the payment is received, send the private key from the C&C Server. I would say it's very unlikely CryptoWall would store remotely a private key per file. That could mean a lot of information to be transferred over the wire. Probably because of using only asymmetric (slow) encryption, CryptoWall apparently only encrypt small files completely, and only a piece of the larger ones. One way the "decrypt one file for free" feature might work is by actually uploading the file (or the the encrypted piece of file) to the C&C Server, decrypting it remotely and sending it back. But the feature is definitely worth investigating.

https://blog.fortinet.com/post/cryptowall-another-ransomware...

http://stopmalvertising.com/malware-reports/cryptowall-behin...

HackinOut··on How My Mom Got Hacked
CryptoWall apparently delete shadow copies with a simple vssadmin command.

http://stopmalvertising.com/malware-reports/cryptowall-behin...

HackinOut··on How My Mom Got Hacked
I wouldn't be so sure this would help: CryptoLocker was using symmetric encryption (AES) for the files while CryptoWall apparently solely use RSA (which creates problems for the pirate, like slow encryption, thus encrypting only small files (.jpeg, .doc...)?). Only the public key seems to be downloaded when the malware installs. (http://stopmalvertising.com/malware-reports/cryptowall-behin...)

If this is the case, I would surprised if they would download the private key for the one free decrypt feature. If they encrypt only small files they might do the decryption on the remote C&C Server?

It's worth investigating anyway.

HackinOut··on How My Mom Got Hacked
Apparently CryptoWall does a dumb copy of the files before encrypting them and do not zero-out after deleting. If it still proceeds this way, that makes it fairly easy to do some recovery.

Source: http://www.wyattroersma.com/?p=108

HackinOut··on HSTS Super Cookies
Same code for Chrome 39.0.2171.95 on Windows...
HackinOut··on One day left to help Internet Archive reach its donation goal
"make our cultural treasures accessible to everyone. Forever."

They're stating their mission and then asking for donations. At least that's how I see it. There is no endeavor that is guaranteed to succeed. Money isn't the only problem they are facing.

I personally greatly prefer that statement to something like "if the money runs out, we'll have to close IA. Please donate." which somehow sounds like blackmailing. EDIT: The former doesn't feel like marketing to me, might lead more people to donate and I would expect most of us (like you and me) to understand that they do not make any promises, except doing their best.

HackinOut··on Politician's fingerprint 'cloned from photos' by hacker
Testimonies can by themselves end up into a conviction. I am not sure this is comparable. When a crime is committed any evidence is welcome to try and solve it. Investigators are not "choosing" their type of evidences like you can choose a type of digital protection.
HackinOut··on Politician's fingerprint 'cloned from photos' by hacker
Yesterdays's HN discussion about this: https://news.ycombinator.com/item?id=8806394
HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
OP mentioned using biometrics as a username in combination with a password. [1] seems to imply you can add a password or pass code on xbox and I think you can do that too on a Galaxy S (?)

[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in

HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
OP mentioned using biometrics as a username in combination with a password. [1] seems to imply you can add a password or pass code.

[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in

HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
Agreed, but I personally think it shouldn't be a general public feature, but rather reserved to the initiated. The cost lessen quickly with time (a point made by this article) and people have trouble understanding the limitations of a particular protection.
HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
"Something you have, something you know, something you are"

Fingerprints are neither. As several people mentioned in this thread, the only thing I see a fingerprint suitable for is replacing a username.

HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
This was done from an "index finger [...] lifted from a water glass" while we are discussing a copy made from a "few photographs"
HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
I think Samsung does it with facial recognition on the Galaxy S's lock screen. Should work better and better and you don't need an additional sensor.

EDIT: So does Kinect for Xbox one.

HackinOut··on German Defense Minister's Fingerprint Copied by Chaos Computer Club
Although I have no doubt it could work, I guess they didn't try the copy? Couldn't find the video of the conference. He probably demo'ed using a copy of his own fingerprint from a photo?

It's great work, I hope the fact that you can make a copy from a simple HD photo will bury people's ideas about fingerprints security for good.

HackinOut··on Quantum Random Number Generator Created Using a Smartphone Camera
The article is from May 9th. HN Discussion here: https://news.ycombinator.com/item?id=7728043
HackinOut··on Google has now ‘forgotten’ more than a quarter-million URLs
Some details from Google: https://www.google.co.uk/policies/faq/
HackinOut··on Backlit e-readers 'damage sleep and health'
Thanks for the reference. I am not sure that backlights are the problem though. Just imagine shining a light behind the page of a book (although it's hardly comparable to the level of transparency of Liquid crystals). I would rather bet on the color of the light (warm vs cold). Maybe it's all in my head but when it's sleep time, I hate cold bulbs (and LCDs) while I am not bothered by warm light like a candle or a warm bulb.

Furthermore, it seems to me that with the Paper White's light guided "on the surface of the display", the light shines as much in towards your eyes as it does towards the screen...

HackinOut··on Backlit e-readers 'damage sleep and health'
Yes but they are totally usable with ambient light with the built-in light turned off as opposed to non-reflective LCDs. As a side-note, if I remember correctly, the built-in light in the Paperwhite is not a backlight but runs on top of the screen, thus using the reflective nature of the e-ink display.

EDIT: I probably should have said "without the built-in light" but wanted to include devices that do not have one to begin with. I am still using one of these :)

HackinOut··on Backlit e-readers 'damage sleep and health'
The well accepted definition of an e-reader is "a mobile electronic device that is designed primarily for the purpose of reading" (from wikipedia) and most (all?) of those devices are reflective as opposed to LCDs which are backlit.

"They spent five days reading from a paperback and five days from an iPad.". If only iPads were used, I don't believe the word e-reader is appropriate.

If you use an e-ink display without a built-in light, there are no reason this would be any different then using a book (as mentioned in the article but it's not only about "the original kindle"). Also there were tons of studies about the effect of light on sleep and especially blue light emitted by LCDs, most e-reader makers use a warmer light if I'm not mistaken.

EDIT: elaborating

HackinOut··on Maximally Powerful, Minimally Useful
Also relevant is D. Knuth's literate programming.
HackinOut··on Maximally Powerful, Minimally Useful
Do you have a language in mind?

If you ban (for your whole program) some components then I guess you would loose some expressiveness.

Also I don't know if you can categorize "components" as more or less readable. For some problems a "component" might be highly readable while totally inappropriate for another problem. I see some cases where using more components makes the code more readable.

This is an art of using language features (paradigms etc...) and design patterns that will be the most readable while powerful enough to solve your problem. I love doing it with Lisp or Ruby which are languages with a very modular syntax. But it's time consuming so I'm doing it only for substantial projects I really care about. It's much more efficient to use conventional well established programming style (think RoR for example) and less bug-prone (more secure etc...) because it's well tested by many.

HackinOut··on Maximally Powerful, Minimally Useful
This trade-off is also why I love Lisp. Although you can easily write something totally incomprehensible, people well versed in Lisp manage to be very expressive with a very powerful language. Of course lisp macros are the key.

It's extremely easy to do LOP with Lisp thanks to s-expressions (all those parenthesis :). But you can be much more expressive with LOP.

EDIT: elaborating

HackinOut··on Maximally Powerful, Minimally Useful
For programming languages, a paradigm allowing to be "as expressive as necessary" is LOP[1] (Language Oriented programming).

With it you can basically choose your level of expressiveness while you develop your program (with different levels for different parts of your program). The frustrating trade-off between expressiveness and readability[2] is the main reason I love this paradigm. Unfortunately LOP has never been really trendy. Hope it will change soon.

[1] http://en.wikipedia.org/wiki/Language-oriented_programming

[2] For programming languages I would rather speak of readability (as opposed to analyzability) because a program is often not written in stone but "alive" (it's modified, enhanced over time...). It probably does not apply to the other fields discussed in the article though.

HackinOut··on Page load fail makes it difficult to cook cornbread in the woodstove
Thanks! I think I saw they were showing the screen at CES but I didn't know they were selling this thing!
HackinOut··on Page load fail makes it difficult to cook cornbread in the woodstove
Pixel Qi (discussed in another reply) was funded by Mary Lou Jepsen, a former CTO of OLPC.

The screen you are referring to probably uses the exact same technology (designed while she was CTO?). It's not e-ink but indeed amazing. Too bad we don't yet put a lot of resources into this kind of projects.

HackinOut··on The Tale of Studio Ghibli
Thanks. I am sure I have seen at least a part of this but I had (purposefully?) forgotten all about it. One nice thing about not being Miyasaki is that my reverie about Ghibli can remain whole. :)
← PreviousPage 2 of 4Next →