HNHacker News
TopNewBestAskShowJobs

HackinOut

140 karma · joined May 5, 2014

Benjamin Guesneau

Twitter: @HackinOut

submissionscomments
HackinOut··on LessPass: sync-less open source password manager
That is either by using the "connected version" or loosing the multi devices ability. BTW shouldn't the "connected version" be the one detailed on the home page? Sure sounds more attractive to me.
HackinOut··on LessPass: sync-less open source password manager
I wouldn't use a password manager system that doesn't have the ability to change the master password.

EDIT: You can't change any password really, without changing all of them (or having a separate master password). Seems unpractical as soon as, for example, site X gets its database hacked.

HackinOut··on UK votes to leave EU
I can't believe Nigel Farage and a lot of pro Brexit campaigners have been calling it UK's "Independence day". Apart from being a very bad (purposeful?) analogy, it's seems to me pretty disrespectful to their own and to US history. I'm not from USA (or UK) but would love to hear how US and UK people feel about it?
HackinOut··on Wi-Fi hack creates 'no iOS zone' that cripples iPhones and iPads
Not aware of anything from Apple about this issue. It was just an assumption, sorry. What I did is test up to date devices (i think i even tested an up to date iOS 6) and couldn't get any specific SSID. The probe requests were still there, but SSID parameter was always set to Broadcast.

However I did see a lots of probe requests WITH a SSID parameter set but those were not coming from my devices :). I assumed they were not up to date.

I am very interested to know if the probe requests you're seeing are also coming from unknown devices: if they aren't, could you provide us with the iOS version you're using/testing with?

HackinOut··on Wi-Fi hack creates 'no iOS zone' that cripples iPhones and iPads
It doesn't seems to be iOS 8 only. Recent versions of iOS 7 seem to be fixed as well. (Tested my phone earlier this week)
HackinOut··on Wi-Fi hack creates 'no iOS zone' that cripples iPhones and iPads
My iPhone do connect auto-magically to FreeWifi_secure networks which is the preloaded SSID for the other french operator listed by Skycure.

However it's supposed to connect with EAP-SIM [1]. Skycure mentions that "some of [those] bundles include SSID passwords". Do they mean that only those would make devices vulnerable? Could you let us know if SFR uses EAP-SIM or a basic PSK?

It could be that iPhones connect automatically only to EAP-SIM preloaded networks.

[1] https://mobile.free.fr/assistance/262.html

HackinOut··on Wi-Fi hack creates 'no iOS zone' that cripples iPhones and iPads
> (because iOS devices broadcast this when scanning for networks IIRC?)

Not anymore, Apple fixed that in recent iOS versions. Probe requests are not divulging SSIDs anymore. However WifiGate uses common SSIDs and network operators preloaded ones as honeypots.

HackinOut··on MacBook Pro Repair Extension Program for Video Issues
Good point for Apple. But I wouldn't call having your computer fixed 4 times in ~2 months lucky... Every brand seems to be having reliability problems with their products nowadays (in software as well as hardware). More than in the past. Or maybe it's just me, unlucky as you are... I really have no idea what my next laptop will be...
HackinOut··on Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs
Double standards are also seen in their "Removal Instructions" post on their forum. When uninstalling SuperFish, it seems suddenly important to remove the root certificate...

"It is very important to delete the certificate even though the application itself has been removed."

http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

Didn't seem that important earlier today: https://web.archive.org/web/20150219151726/http://forums.len...

"files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. "

HackinOut··on Lenovo Caught Installing Adware on New Computers
Komodia, the company behind the tech contracted by the maker of SuperFish, actually (tries) to makes sure invalid and self-signed certificate do generates a warning in the browser. And then they password protect the private key with... the name of their company?!?

http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...

"Also the module tries to verify that the certificate is indeed signed by an approved signer, it will use the CA store of the browser used to verify that (for Internet Explorer the Windows store will be used, and for Firefox the NSS store will be used), if the certificate isn't legit, the created certificate will be created in a way it would raise an alert to protect the user."

A huge ugly hack...

HackinOut··on Lenovo Statement on Superfish
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."

http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."

This was just edited in, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...

So, Lenovo, why should we remove this certificate after all? Any security concerns perhaps?

HackinOut··on Lenovo Caught Installing Adware on New Computers
Wow...

Now Lenovo is "soon" going to explain how to remove this certificate after the "uninstall" in a buried forum post...

http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

HackinOut··on Lenovo Statement on Superfish
"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."

This was just edited, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...

HackinOut··on Lenovo Caught Installing Adware on New Computers
Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...
HackinOut··on Lenovo Caught Installing Adware on New Computers
Except if the adware just modify OS proxy settings, like madeofpalk mentioned. Firefox does not take those into account.
HackinOut··on Lenovo Caught Installing Adware on New Computers
It does not. Firefox has it's own implementation, which is pretty great (supports all kind of proxies/socks).
HackinOut··on Lenovo Caught Installing Adware on New Computers
"Someone will extract the private key in the next few hours, and then HTTPS will be basically completely broken for all Lenovo users -- anyone will be able to spoof any site to them."

Do you mean the proxy is remote? That is not the impression I have (otherwise having the private key locally makes no sense).

If it's local, then even with the private key extracted, and considering a lot of website force https nowadays, we should still have standard crypto between the lenovo computer and the website. EDIT: As long as the adware checks the website certificate AND doesn't trust it's own self-signed certificate in the store... yeah... a lot of ifs...

Anyway, thanks for the additional details, more helpful than "[...] the certificate allows the software to decrypt secure requests[...]", found in the article...

HackinOut··on Lenovo Caught Installing Adware on New Computers
TheNextWeb does a poor job at reporting technical facts:

"[...] its own self-signed certificate authority which effectively allows the software to snoop on secure connections [...]"

"[...] the certificate allows the software to decrypt secure requests[...]"

As kentonv reported, it's actually the local proxy, installed by the ad(Mal?)ware which is at the center of the MiTM attack. The root, self-signed certificate is installed in order for the attack to be transparent to the victim (i.e. no warning in browser).

HackinOut··on I am the fold
Before this went down, the highest recorded fold was at 987654px. Somebody had fun with the experiment or has a nice 1755K screen :)
HackinOut··on Breaking antivirus software
Most viruses are identified by their signature only, because most of them are dumb. Heuristics for unknown threats are often there purely for marketing.

AVs have all more or less the same signature database due to the same reason as above, most viruses are dumb and well known (most can't even be called viruses, think adware & co). IMO this the best reason for not having multiple AVs. I personally do not trust an AV for anything more than dumb signature checking (which are easily circumvented with polymorphism or sometime encryption alone) and targeted heuristics.

I also don't even want to start thinking at the mess that could be created by several AVs's injection/hooking mechanisms on the same machine.

HackinOut··on SpaceX CRS-5 Launch
"Grid fins worked extremely well from hypersonic velocity to subsonic, but ran out of hydraulic fluid right before landing."

"Upcoming flight already has 50% more hydraulic fluid, so should have plenty of margin for landing attempt next month."

https://twitter.com/elonmusk/status/553963793056030721

https://twitter.com/elonmusk/status/553964281025548289

HackinOut··on GoGo does not need to run “Man in the Middle Attacks” on YouTube
I would expect that even if it wasn't mentioned, I mean it's a freaking internet access in a fast moving object 30,000 feet above ground! I don't like what Gogo just did, but kudos for undertaking this challenge. barnaby mentioned they have in-flight paid media services, of what sort/diversity/quality? I suppose it's a selection of movies stored on a server in the plane.
HackinOut··on GoGo does not need to run “Man in the Middle Attacks” on YouTube
1) They are not blocking (completely) Youtube. But still plausible.

2) Then why would they be doing it only on video streaming websites? [1] Also, if they are so obvious about their methods from now on, one nice thing is that we won't need whistleblowers anymore.

[1] https://news.ycombinator.com/item?id=8839733

HackinOut··on Kickstarter switches to Stripe
Sounds like good news. I can understand why they would choose amazon payments since amazon has more credit cards on file than anybody else including Paypal. But Amazon payments or Paypal (I am not referring to their gateway offering) is often something you use to complement a more classical credit card processor (i.e. users are able to input their CC infos directly on your site) like Stripe or Authorize.net. I really do not understand, until now, their choice of going exclusively with Amazon Payments for all this time. Preferred rates maybe?
HackinOut··on Onewheel [video]
Back to the Future was slightly off :)

I love electric vehicles of all sorts, let's enjoy them to the fullest, the hoverboard will be there soon enough.

HackinOut··on Gogo injects false SSL certificates for google.com domains
According to tweet author[1], this happened only with Youtube, and was not related to captive portal mechanism whatsoever. So I would side with her on the why: Poor plane internet access was overloaded by videos streamed from Youtube and somebody hacked together a very ugly solution that's going to have bad consequences...

[1] https://twitter.com/__apf__/status/551132865555996673

https://twitter.com/__apf__/status/551096550516994048

HackinOut··on Gogo injects false SSL certificates for google.com domains
Well they would be facing the unforeseen consequences while not even filtering the HTTP host header (the youtube page is displayed). Unless they forgot to disable the MITM once the user is granted full internet access...

EDIT: Those are two nice insights about what Gogo does behind the scene, but I would bet the fact Google is involved with both is a coincidence (or is it considering the multiplicity of Google's Services?)

HackinOut··on Gogo injects false SSL certificates for google.com domains
it doesn't redirect to the signup page. i believe it's to throttle streaming, but there are better ways to do it

https://twitter.com/__apf__/status/551132865555996673

EDIT: Still from same author:

no, had already been logged in for hours; and only happened on YouTube

https://twitter.com/__apf__/status/551096550516994048

HackinOut··on How My Mom Got Hacked
* asymmetric key pair
HackinOut··on Wifiphisher: Fast automated phishing attacks against WPA networks
I think "Phase 3" is indeed too much. I would think this tool would be more useful for "simple" MITM than for PSK phishing.
Page 1 of 4Next →