HNHacker News
TopNewBestAskShowJobs

InitialBP

293 karma · joined May 5, 2020

submissionscomments
InitialBP··on Show HN: I made a privacy friendly and simple app to track my menstruation
Agree with you if privacy first is the goal then open sourcing it is absolutely the right move. However, it IS still possible to MITM these days - although more difficult.

frida.re has a ton of useful features and community tooling built around it including scripts that will let you "un-pin" certificates by hooking and rewriting the functions that verify whether cert pinning worked or not.

https://frida.re/

https://codeshare.frida.re/@masbog/frida-android-unpinning-s...

InitialBP··on Price fixing by algorithm is still price fixing
I don't think this is entirely true. If people who are currently renting move into homes then their apartments will be rented to people who are looking for housing.

It seems like if you add supply to one area of the housing market like the one above, there is a group of people ready to take advantage of that supply. 3bdroom apartment renters buy a home, then 2bdroom apartment renters get a bigger place that's affordable and meets their needs.

Assuming this works exactly like intended, that 1 family with two or three houses now only owns one and 2 other families get a house, then you're freeing up supply across the whole range of properties.

InitialBP··on Price fixing by algorithm is still price fixing
That seems like a super obvious conclusion, the fact that it isn't what is actually happening is a good indication that it isn't as straightforward as you'd think.

This might be true for an individual that only owns one or two properties, but for a company that owns tens or hundreds of properties they can let stuff set empty to drive up prices on all of their other properties.

InitialBP··on I looked through attacks in my access logs
Bit of a rambly reply:

There are different types of web security vulnerabilities and the attacks you see from automated scanners are likely to be far less sophisticated than targeted web attacks. Specifically these scanners are going to spam out widespread and common CVE's that might grant privileged access to the server or dump credentials in some fashion.

The more sophisticated attack you described is essentially an overflow, and most modern web servers are usually written in memory-safe languages making it very unlikely to see that type of attack on the web. More often it's the underlying OS, servers, or communication stacks (bluetooth, TCP, nginx, etc) that have these types of vulnerabilities since they are often written in low level non memory safe languages like C and C++.

Attacks that exploit the HTTP and HTTPS protocol are a little more interesting. Request smuggling lets you trick certain load balancers and webservers by sending an HTTP request "smuggled" inside of another HTTP request.

Here is a blog by James Kettle's about some request smuggling vulnerabilities and the impact they can have. https://portswigger.net/research/http2

There's really a lifetime's worth of knowledge on web security and the type of stuff you see in scans is just trying to hit the low hanging fruit. Portswigger has loads of free challenges and information about different web security topics.

https://portswigger.net/web-security/all-topics

InitialBP··on I looked through attacks in my access logs
> ancient exploitation strings from 30 years ago that haven't worked on any serious webserver since that time

Unfortunately, there are plenty of serious (business critical) servers that _ARE_ vulnerable to these types of attacks. I've found and remediated things like this all the time. One very common example I've seen of the `.env` issue is Django servers that are exposed to the internet in with debug=True. There's probably thousands if not tens of thousands of servers leaking credentials this way on the internet now.

Beyond that, companies often have internal systems that do not meet the same security standards that external systems require, and sometimes those systems get shifted around, maybe it's moved to a new subnet, maybe a third-party needs access and the CIDR range gets fat fingered in the firewall. Regardless - now that "internal system" is exposed to the internet with all the dangerous configuration.

InitialBP··on Passwordless: a different kind of hell?
Think about motivations for a moment.

The seller is motivated to make the buying process as easy, fast, and uncomplicated as possible. This is a direct correlation with how many things they sell, and in response how much money they make.

On the other hand - consumer opinion and regulation forces them to ensure that the buying process is secure, that someone else isn't buying things on your account, that they have proper logging of what goes on, etc.

The seller shouldn't "Fix" the buying experience by removing the security aspects of it. They should fix the buying experience by using modern authentication like passkeys and ensuring that their applications and sites support password managers.

InitialBP··on Passwordless: a different kind of hell?
1Password can do this for you, and I assume many other password managers as well.

https://support.1password.com/one-time-passwords/

InitialBP··on Passwordless: a different kind of hell?
Business don't want online shopping to be high-friction, but Thankfully consumer opinion is pushing more for security and less for making it as easy as possible to buy stuff online.

I'll happily take this shit-show cacophony of various 2fa methods and authentication types if nobody is stealing money from my bank account or ordering stuff on ebay on my behalf.

The flip side of this - is that if companies properly setup auth and allow you to use username+password (or passkeys) and a TOTP method then this is all basically copy/paste from your password manager or verify on your phone and the process is super easy.

InitialBP··on datetime.utcnow() is now deprecated
If this was something used only by your company or a specific project, then I’m absolutely on board. However, this is in a library used in thousands (millions?) of projects. Since it’s potentially a breaking change you can’t just change it and expect everyone to know.

Many people won’t know it’s deprecated until the code fails to run, and having new functions rather than changing the functionality of existing functions makes it much easier to identify what is actually happening.

InitialBP··on Ask HN: Why did Visual Basic die?
From a security angle...

.net webapps written in asp.net behave similar to PHP in that any file with a .aspx extension that is within the web root will execute by default. This means that asp (and php) webservers are particularly vulnerable to RCE attacks because the default configuration of the server turns an "arbitrary file upload" into a remote code execution instead.

Where an asp.net server would handle front-end and api and they would be tightly coupled, we've moved on to where the most common configuration is a separate API and frontend. I believe you lose a lot of the benefit of using asp.net to try and decouple them.

On a totally personal note, as a penetration tester I've proxied requests from a LOT of different APIs on a lot of different technologies and asp.net is hands down one of the worst to test, the way it handles requests under the hood is unruly and ugly. Some might say that's a positive in terms of security, but IMO it makes it harder to identify vulnerabilities in your system.

InitialBP··on Amazon cancels my account after exposing account lockout for “racist doorbell” [video]
This already IS a huge problem in the medical/health vertical. You should NEVER order supplements, makeup, or medicines/chemicals from Amazon for this reason.

I think there have been a few different noteworthy events where issues have popped up. I'll link to a couple of articles I've found on the topics.

https://themedicinemaker.com/business-regulation/amazons-fda...

https://www.sitejabber.com/resources/counterfeit-cosmetics-t...

InitialBP··on Google doesn’t want employees working remotely anymore
I think most people would agree that you should support the local version of a business over the financial district version because you want to keep people employed in your community, but at the same time I personally would rather support locally owned and operated restaurants over chains and franchises.

Businesses fail and are replaced with other businesses all the time, it's part of the normal flow of capitalism. Within a specific community, as businesses come and go, as long as the old one is replaced with a new one then employment opportunities are still around. Eventually something will open up that is a home run and then that store will flourish in the community, which will likely create even MORE employment opportunities and if it's a local store then a lot of that money will stay local in the hands of employees, owners, local government (taxes).

InitialBP··on Flipper Zero Self Destructs an Electricity Smart Meter
Definitely agree with you here. The parent has a very valid point about not always over-securing things that don't need to be secured, but physical line cutting and wireless shutoff are very different threats.

Someone walking around your neighborhood cutting every single electric line on the side of a house, risking electric shock and trespassing on your private land is much more likely to get caught than somebody rolling through your neighborhood with a flipper zero and a high power antenna turning off all of your meters.

If someone had a grudge against you, and they started to "release the magic smoke" from your meter once a week and the power company is upset with you and your HVAC system doesn't work anymore, in addition to the fact that the compressor in your AC is toast because of someone energizing and de-energizing the circuit so rapidly. Now you are out thousands of dollars and, on top of all that, no matter how many cameras you put up, you'll have a hard time figuring out who's doing it.

InitialBP··on The simplicity of single-file Golang deployments
If you want to do deployments with single-file apps or other "whole stack in a single process" type of deployments there are other options to do it with zero-downtime.

One good option would be to spin up a second server/instance/container, run binary on new system, ensure it's good, once comfortable then swap DNS entry to the new system.

InitialBP··on FTC cracks down on companies that impose harmful noncompete restrictions
That's true of many illegal things. Trespassing is illegal, but people still put locks, gates, fences, etc on their property because people will still trespass if they want to. The purpose of the law is to dissuade people from doing it because there are consequences for that action.

If you're talking about trade secrets, I believe if there is evidence in the product/products that a former employees company is releasing that seems to be operating or working in a similar product they could gather publicly available evidence, hire a PI, and ultimately attempt to subpoena additional information if there is sufficient evidence that the employee is actually sharing trade secrets from a previous company.

InitialBP··on FCC commissioner says government should ban TikTok
If you removed it from the app stores, a humungous percentage of people would no longer install the app. There will certainly be some tech literate folks who do so, but most people have very little tolerance for technical challenges outside of the norm and would stop at, it's not in the app store anymore.
InitialBP··on Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities
According to the report, the replay attack is only valid for 1 hour for login links, and 1 week for sign up links. I agree that there's some risk here, but the fix is probably straightforward (adjust timing to something more realistic or just invalidate them after use).
InitialBP··on Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities
I'd go a step further and stay the author is really making security researchers look bad.

Can't really blame anyone for being concerned about corporate retaliation, but there are most certainly institutions that would send an email on your behalf to disclose vulnerabilities to a security@ email if you wanted to remain anonymous out of a sense of caution.

On top of that you've made some inflated comments on the general security practices about this company with no real evidence and the vulnerabilities listed best-practices at best and inconsequential at worst.

I question the motives behind a post like this:

Does the author have some financial incentive to attempt to discredit Stytch? Does the author want to cause some panic/concern by making scary claims about Stytch? Does the author not truly understand the impact of their vulns and thing that this is a serious issue when it's not?

I can't say but the whole situation really sits wrong with me.

InitialBP··on Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities
Either I'm missing something here or the login CSRF explained in the report is a very weird and not exceptional impactful vulnerability. As described the author is talking about using a CSRF attack to force someone to authenticate to a service that uses Stytch.

Regardless this is a HUGE stretch to say "has no CRSF-protection in their authentication API". You've shown one instance where they don't have CSRF protection on an endpoint that could be argued it's not necessary. Do they have CSRF protection on endpoints that let you adjust your account, perform actions in an app, or other legitimately concerning endpoints?

InitialBP··on Show HN: I made an open-source Bitly alternative
Unrelated recommendation - 1Password will scan QR codes and can store TOTP 2fa tokens for you. I assume other password managers also have similar features.
InitialBP··on Show HN: I made an open-source Bitly alternative
You can't put a hyperlink on a magazine, the tv, or the radio. There are definitely reasonable applications of shortened URLs that apply outside of the normal day-to-day web browsing and applications.
InitialBP··on An app can be a home-cooked meal (2020)
I'm fully in agreement with all of your downsides (although ads aren't necessarily a dealbreaker for me).

The pain point for me is that my family/friends circle isn't willing to try and use new software especially stuff that might be custom or have some lack of features.

It took me a year or more to get my dad to send me pictures and videos over FB Messenger instead of SMS (he has an iphone and I have an android). Maybe I just need some new persuasion tactics but the idea of putting energy and time into building a custom app for my family and then dealing with pushback and a reluctance to use it just sounds exhausting to me.

InitialBP··on Ask HN: Why Adobe still can’t figure out Flash on WASM?
It's worth noting that there was a lot of pressure from the major browsers to deprecate flash due to security issues throughout the years. Flash produced a lot of great media but in the end it wasn't built with security in mind, and security is much more important today than it was 10 years ago. I don't know what it would take to revamp and then port flash over to some other platform, but I imagine that they'd be better off to just build a new system from scratch and aspire to capture a bit of that old flash magic.

List of CVEs for flash player - lots of 10s in there. https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...

InitialBP··on An app can be a home-cooked meal (2020)
Just to play devils advocate, what if you just made a private subreddit for your family?

While I also struggle with the android/apple divide in my family I feel like getting them all to agree to use an existing social platform would be exceptionally difficult, but it would be orders of magnitude easier than getting them to use a custom or relatively unknown app for comms unless it did something really special or novel.

InitialBP··on NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
Maybe not "essential" but I'm willing to guess that a huge percentage of the modern web communicates over HTTP or HTTPS.

"Essential" is interesting because you could definitely argue that HTTP isn't essential, but I don't think there is any feasible way of denying that the formalization and acceptance of early internet protocols (UDP, TCP, HTTP, FTP, etc) have played a significant role in shaping our modern technology world.

In a similar way, having reasonable standards makes it easier for everyone that isn't an expert in a particular field to just use something that is likely to work reasonably well while they worry about some other special part of their idea.

InitialBP··on I spent a year designing a low profile, minimal mechanical keyboard
Tex also makes keyboards with a trackpoint. I haven't personally used them but have seen some great looking custom builds.

https://tex.com.tw/collections/keyboard

InitialBP··on The Zoom installer let a researcher hack his way to root access on macOS
I'm not sure about all languages but this actually caught me by surprise. When you do a 'mv' command (tested on macos) it does not retain file permissions by default. You actually need to pass a special flag in order to do so.

Objective C does retain perms by default using some common move techniques.

InitialBP··on NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
Standards are for people who are not experts in the field or don't have the time and energy to research the existing crypto and actually sift through them to try and decide what to trust and what not to trust.

Lack of standardization might just make it harder for Joe to filter through the google searches and figure out what algorithm to use. He may just pick the first result on Google, which is an ad for the highest bidder on some keywords which may or may not be good.

InitialBP··on The Dangers of Microsoft Pluton
Out of sight, out of mind.

You are totally right that open source is powering countless things people use regularly but I expect most people don't even know what open source software is, much less care about it.

InitialBP··on FCC fines Charter, LTD Broadband more than $3M for RDOF defaults
Starlink is a god send for my hometown in West Virginia.

Current internet service there is provided by Frontier Communications. They offer "advertised" speeds of 6 Mbps but for years my parents internet came in around 1 or 2 on a good day. Service is abhorrent and they are still using phone lines that will likely never be replaced. They've taken serious advantage of the state of WV and even after a class action lawsuit in 2015 that they settled on I doubt it will ever improve.

My parents finally got starlink setup ~3 months ago, it's around 100 mbps (roughly 100x as fast) and way more reliable even though it's satellite.

← PreviousPage 2 of 5Next →