HNHacker News
TopNewBestAskShowJobs

MajesticHobo

155 karma · joined February 22, 2016

CS student, not affiliated with MajesticHobos elsewhere on the net.
submissionscomments
MajesticHobo··on Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
What is a cyber weapon? Knowledge of a vulnerability? Exploit code? How do you propose regulating it? Much of this has been tried before and ended up hurting rather than helping.
MajesticHobo··on Go Language – Web Application Secure Coding Practices
I don't disagree with sanitizing data at output time when it's clear that A) the input won't affect anything else and B) output is going to happen. But realize not all input winds up in a SQL database, not all input will be considered valid in all contexts, and not all input eventually becomes output.

Sometimes, data really does need to be sanitized at the point of submission. If you disagree, that's more of a point about application design than appsec.

MajesticHobo··on Go Language – Web Application Secure Coding Practices
If you allow binary uploads, you're going to be a malware distributor whether you scan or not. AV just introduces complexity and attack surface and doesn't really belong in a guide about Golang secure coding practices.
MajesticHobo··on Go Language – Web Application Secure Coding Practices
You've said nothing that contradicts my post.

As long as the data is sanitized before it can affect the storage/transport mechanism for its content type, you're good.

MajesticHobo··on Go Language – Web Application Secure Coding Practices
Yes, really. Otherwise, you must take extra care not to reflect any input data back in any response to the user, whether it's in the HTML body or not. See: HTTP response splitting.
MajesticHobo··on Go Language – Web Application Secure Coding Practices
This guide still has some issues. It's missing common classes of web app vulns I've seen in Go code (e.g. CSRF, SSRF) and has some weird advice here and there (scan uploaded files with AV? Really?)
MajesticHobo··on Google Will Stop Reading Your Emails for Gmail Ads
WhatsApp doesn't read your conversations for ads because it can't. Message content is end-to-end encrypted. You must have leaked your plans through some other medium inadvertently.
MajesticHobo··on A Backdoor in Skype for Mac OS X
>further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic

Of course they do. You may disagree with the logic, but it's there. Vectors of intelligence gathering have to be both sufficiently covert and useful for an agency to consider. This vulnerability is neither.

MajesticHobo··on Daniel Ellsberg, Edward Snowden and the Modern Whistleblower
The notion that he "lacked the ability to leak carefully and strategically" because he was an outsider. I'm fairly sure he was more than capable of selecting only documents related to domestic surveillance if he wanted to -- that just wasn't his broader goal. However, I would definitely appreciate the argument that his status as an outsider rendered him opposed to the idea of leaking selectively. I think the author hinted at this when he contrasted "hackers" and "leakers", but it's still quite different from what you're saying.
MajesticHobo··on Daniel Ellsberg, Edward Snowden and the Modern Whistleblower
> It's not just that Snowden wasn't an insider, but that he lacked the ability to leak carefully and strategically --- and so the public outcome was inferior to the Pentagon Papers.

This is hard to believe. I find it much more likely that Snowden had a broad agenda he wanted to cover, and simply decided to delegate the work of sifting through documents relevant to the public interest to journalists. How successful this strategy was is another issue entirely.

Also, the direct comparison between the material Ellsberg had to work with and what Snowden had is misleading. Ellsberg leaked a study from RAND literally designed to assess and document the history of the Vietnam War, including past failures. It's easy to look at that and go, "Wow, this is a careful, strategic disclosure." But Ellsberg couldn't have had an easier choice about what to leak!

In contrast, Snowden had access to a much more disparate set of documents that required lots of interpretation and technical parsing on journalists' part. There wasn't a single PowerPoint presentation that summed up NSA's abuses so conveniently.

That doesn't necessarily justify scraping as much as possible and passing it over to journos, but we have to keep the two men's access to material in context.

MajesticHobo··on Lifting the Shadows of the NSA’s Equation Group
> Can we trust this information? The answer is: not fully, because the link timestamp can be altered by the developer in a way that’s not always possible to spot. However, certain indicators such as matching the year on the timestamp with the support of technology popular in that year leads us to believe that the timestamps were, at the very least, not wholly replaced. Looking at this from the other side, the easiest option for the developer is to wipe the timestamp completely, replacing it with zeroes. This was not found in the case of EquationDrug.

https://securelist.com/blog/research/69203/inside-the-equati...

MajesticHobo··on iMessage's 'End-To-End' Encryption Hardly Better Than TLS
It is. The title is a little misleading; here's an explanatory excerpt from the actual paper:

> In this work we analyze the iMessage protocol and identify several weaknesses that an attacker may use to decrypt iMessages and attachments. While these flaws do not render iMessage completely insecure, some flaws reduce the level of security to that of the TLS encryption used to secure communications between end- user devices and Apple’s servers.

MajesticHobo··on iMessage's 'End-To-End' Encryption Hardly Better Than TLS
Uh, no. Implementation bugs don't mean a protocol is broken.
MajesticHobo··on Running I3 Window Manager on Ubuntu for Windows
There's always Icedove, which gets updates from Debian.
MajesticHobo··on The Tor Project: Building the Next Generation of Onion Services
> offering complete untraceable anonymity

Your argument falls apart the moment you claim this.

MajesticHobo··on Snowden calls for whistleblower shield after claims by new Pentagon source
Yes, that is what I meant. That's what I get for being a pedant.
MajesticHobo··on Snowden calls for whistleblower shield after claims by new Pentagon source
A valid point of view, but the US is technically a constitutional republic, not a true democracy. Certain values and principles are written into our DNA via the Constitution, and I contest your assertion that they can simply be voted away by the majority.
MajesticHobo··on How the Pentagon punished NSA whistleblowers
> Whenever a story about Snowden is in the news, some people complain that some of the documents he released were "off topic".

Which is odd, because I personally have not found any of the Snowden publications off topic or unnecessary. When I press these people about what they think shouldn't have been published, they always give me vague answers about "military secrets" and the like without citing anything specific.

MajesticHobo··on Save Firefox
I was under the impression that you are generally allowed to record content for your own personal use, as long as you don't distribute it to others.
MajesticHobo··on Save Firefox
> something that DRM isn't preventing you from doing something you're otherwise not supposed to be doing anyways.

And what would that be?

MajesticHobo··on WhatsApp, Used by 100M Brazilians, Shut Down Nationwide Today by a Single Judge
WhatsApp is the most popular end-to-end encrypted chat app in the world. Shutting it down for 100 million people not suspected or charged with any crime is an incredibly disproportionate, privacy-thwarting response to not being able to access user data in one criminal investigation.
MajesticHobo··on Firejail now supports X11 sandboxing
Okay. So it's a protection against browser exploits, not overreaching web APIs.
MajesticHobo··on Firejail now supports X11 sandboxing
Aren't those already sandboxed browser-local filesystems?
MajesticHobo··on Unmasking the Men Behind Zero Hedge
ZH's response: http://www.zerohedge.com/news/2016-04-29/full-story-behind-b...
MajesticHobo··on WhatsApp Rolls Out End-To-End Encryption to Its Over 1B Users
It's not that easy. Due to toolchain and platform differences, there is no guarantee that your compiler will produce the same binary as the official distribution. This is why deterministic, reproducible builds are a growing area of interest right now.
MajesticHobo··on What It’s Like to Almost Get Executed
A couple points:

> the practice of allowing brutal murderers and rapists to live out their lives and die in peace

Unless I'm misreading you, that's a huge misrepresentation of what death penalty abolitionists advocate. I don't want violent criminals to have zero repercussions for their actions, and no present-day society I've ever heard of allows them to.

But I agree with (what I perceive to be your greater) point about differences in personal moral code. I was merely speaking contextually about the general trend Western society has followed for the past few centuries -- like fewer, more lenient punishments and more respect for civil rights, among others.

MajesticHobo··on What It’s Like to Almost Get Executed
Call it what you want. IMO, any society that recognizes the problems with capital punishment and accordingly outlaws it has at least some liberal tendencies.
MajesticHobo··on What It’s Like to Almost Get Executed
Why not? Some practices are totally abhorrent and have no place in any liberal society.
MajesticHobo··on More Encryption, More Notifications, More Email Security
Why would Google implement e2e crypto? Doesn't that violate their business model?
MajesticHobo··on RandomDNS – aims to improve the security, privacy and anonymity of DNSCrypt
What about a system that uses a different server for each separate lookup?
Page 1 of 2Next →