HNHacker News
TopNewBestAskShowJobs

adn37

186 karma · joined March 30, 2010

Software engineer. Background in web dev, Android dev, embedded systems and win32 IT security.
submissionscomments
adn37··on The Bit Short: Inside Crypto’s Doomsday Machine
> The first red arrow on the chart points to April 25th, 2019: the announcement of the OAG’s investigation. Notice how, as the investigation progresses, the issuance rate of Tether begins to rise — initially in large single blocks, of around $1B, every few months.

The below is an analysis of printed tethers vs known institutional buyers for 2020. I find a ratio of 4 to 1.

Tether market cap for 2020: march: 4.6B$, april: 6.3B$, may 8.8B$, july: 9.9B$, 29August: 10B$, 1stSept: 13B$, 28Sept: 15B$, Jan21: 24B$

Compared to known institutional buyers:

Grayscale: march: 500M$, april: 600M$, may: 1B$, july: 1.4B$, 31August: 1.8B$ (approx), 28Sept: 2B$

Microstrategy: 1.1B$ average price (august to september, as per https://bitcointreasuries.org/)

Difference: between march-september 2020, Tether printed 10B$ while the biggest known institutional buyers spent 2.6B$ (grayscale+microstrategy=1.5B$+1.1B$=2.6B$)

That is to say, Tether prints appear to be 4 times the big buyers amount.

ref for grayscale buy amounts: https://hackernoon.com/grayscales-gbtc-pump-effect-means-202...

adn37··on Faceniff: Cookie snatching for Facebook on Android
I was curious about the technique used under the hood, so I decided to have a closer look.

-- What it does to intercept network trafic:

1/ The app spawns an android (java) service that, that performs the following as root when it starts:

# echo 1 > /proc/sys/net/ipv4/ip_forward

# iptables -t nat -I POSTROUTING -s 0/0 -j MASQUERADE

# iptables -t nat -I OUTPUT -j DNAT -p tcp --dport 1337 --to 127.0.0.1

# iptables -t nat -I PREROUTING -j DNAT -p tcp --dport 1337 --to xxxunclearherexxx

My understanding is that it redirects outgoing packets (targetted at port 1337) to loopback, where the native daemon listens (2/)

This is not visible in the video, but when the user clicks to use a caught Facebook profile, it seems to trigger an android Intent to actually go to Facebook on port 1337 instead of 80, so it gets caught by the iptables hook.

2/ It then execs the faceniff binary to go native (unpacked from resources) with some params (stealth/passive mode, license check), and polls its status every 1s.

-- Native part: I believe it handles most of the logic. Looking at the strings contained, it seems to deal with libpcap to intercept and forge headers on the fly.

Some interesting strings: libpcap version 0.9.8

new user found but the app is locked!

Unable to find ssid in cookies [%s]

HTTP/1.1 200 OK Content-Type: text/html Connection: close

Set-Cookie: %s=%s; expires=Fri, 14-Jul-2017 04:40:00 GMT; path=/; domain=.%s

<meta http-equiv='refresh' content='0;http://%s/>

HTTP/1.1 200 OK Content-Type: text/html Connection: close

Date: Wed, 02 Feb 2011 01:51:18 GMT

<li><a href='http://%s:1337/%s>%s</a></li>

client asking for: [%s]

Technically speaking, this is interesting. Please feel free to add info if you are familiar with the technique.

adn37··on My Android app (1.6M dloads, 4.5 rating) was suspended from Market
Developers have to come a long way to build an user base and good ratings, so it would have been fair to give a warning notice prior to removing the app, ihmo.

(speaking as an Android app dev; and yes it is too intrusive)

adn37··on Programmer salary in mainland Europe?
Care to elaborate please? (FIX engine?)
adn37··on (Android) Developer Income Report #8
Indeed, thanks.

Also, about publishing eCPM/fill rate/CTR: as interesting as it is, it might be a problem regarding Admob's terms of service.

adn37··on What Makes Entrepreneurs Entrepreneurial?
Link to pdf (better quality, no notes): http://ki.se/content/1/c6/06/45/23/Sarasvathy.pdf

Thanks!

adn37··on How do I create a topmost window that is never covered by other topmost windows?
Code injection (SetWindowsHookEx, WH_CBT) and API hooking allows to filter out other programs requesting topmost display.

But this is intrusive. And it can be bypassed by other vendors, whether they workaround it by using other APIs/tricks or unhook their own process' APIs at runtime themselves.

As said here in this thread, the only way to ensure full control is to patch the kernel (Window management related syscalls). And even there it's tricky to be exhaustive.

VM is the safe way to go.

adn37··on "You've angered the hive"
Indeed.

I am speechless because they (started?) monetize going after the 'bad guys', while they have been publishing grey/black hat stuff on Rootkit.com for many years.

The trust is gone.

adn37··on "You've angered the hive"
The most astonishing info here is that this is HBGary that is involved.

Come on, we are talking about the rootkit.com guys. Not taking side is one thing, taking the opposite side is a completely different one.

Pretty much everything I learned for fun about rootkits, I learned it thanks to these guys.

I am speechless.

adn37··on Android Patterns
Adding code samples (java & layouts) would be even more awesome. Very interesting, still.
adn37··on The code injected to steal passwords in Tunisia
Attacker sits at network / ISP level, and can therefore inject any (js, ...) payload in non-https web pages, on the fly.
adn37··on Why we’re really happy with AppEngine (and not going anywhere else)
> We've also developed our own Django-like templating system for Java

Any chance you could list viable alternatives, please? (I'm considering GAE/Java). Thanks for this interesting thread.

adn37··on To code quickly, you must quit coding
I used to do that at work with a software timer. Sprints of 20 to 40. The thing is, you still need to pace yourself.
adn37··on Facebook Finds A New Way To Liberate Your Gmail Contact Data
I do agree. Some people have referrer turned off, but afaik, they are the minority and this should do the trick. Google surely though about it.

This also works the other way. If you rely on FB assets (images, ...), they can shut your access down immediately the very same way. Can't say I like it.

adn37··on Ask HN: Coding Mistakes = Bad Coder?
The true mistake is the one you do not correct.

Testing and code review should give you the opportunity to do so, among others. Also, there's always a trade off between bullet proof and time to market.

adn37··on How to Get More Clicks by Testing Titles
I'd love to use such a service, but for free. Ex: you get karma by giving your A/B preference, that you can then spend later in getting feedback yourself.
adn37··on Live video stream of Startup School today 9:30AM - 5:30 Pacific
Would anybody know how to download them? (apart from 1x recording) I'd like to listen/view them while I'm in the subway, as they are pretty long.
adn37··on Ask HN: Most popular server-side high level languages?
I've been using CakePhp for about 3 years, on sideprojects.

Planning to learn a Java/Scala based 'equivalent'.

adn37··on Reddit hacking for votes and profit
More info on the technical side would have been far more interesting, ihmo.

command control system implementation, software stack, coupling the capta with a captcha filling service...

(I do not support this kind of scheme)

adn37··on How I Built A $600/mo Product In One Day
Insightful, thanks. Please drop us a thread/article in a few months, so we may see the sales curve.
adn37··on The Clean Coder: The Craftsman 62, The Dark Path.
I have no problem calling Sensei a particular great coder/architect. I even used to do it for the fun of it. But when it comes down to management asymmetric relationships, I do my best to avoid biasing it more ("master").

Could be a great way to practice office theater, though.

adn37··on The Clean Coder: The Craftsman 62, The Dark Path.
My martial-arts self died a little at the Kata word used for such things.
adn37··on Ask HN: What's Java used for?
More on banking software: works from backoffice intranets / middleware (J2EE) to low latency trading (core J2SE).

The plus I see, is not having to worry too much about errors (wrt C++). Makes working with large codebases / multiple collaborators easier. Great IDEs too.

Still, coding in Java is quite boring (overdeclaration, lack of pointers/unchecked sections, ...).

adn37··on A blackhat social engineered me by posing as an early adopter of my startup
The former case happens when the attacker challenges himself to just do it. Motivation may increase with time. This is the attacker mindset.

The latter is when any host would do the trick (relay, host platform, whatever).

adn37··on Being Poor by John Scalzi
It's much more complicated than that.

There's so much to say about your post that I'm not even going to start.

adn37··on Why are so many programmers arrogant?
Arrogance is about the way they deliver the feedback. For some, diplomacy is hard since they can't understand why others fail to meet their technical/knowledge/... expectations.

At work, I'm surrounded by smart people. They often outsmart me but a common trap they fall into is not doing enough meta thinking. They seem stuck on level 1 of things.

adn37··on Why are so many programmers arrogant?
I've noticed it countless times, from underground scenes' irc chans and meetups, to the office. Each case is different, that's the beauty of it.

At least, they will judge you on ideas, not on appearance. (edit: only if they consider you worth their time, which isn't easily earned.) So are they really to blame?

adn37··on Your Credit Cards Will Never Be the Same Again: Meet Card 2.0
'Consequences' will never be the same. (bring the down votes, or just enjoy)
adn37··on Ask HN: Developing the developers
It really depends on what they do on a daily basis. Care to elaborate? (language, target app style, complexity, environment, ...)
adn37··on An Open Discussion Of My Personal Business Strategy
Zach, you might want to buy that domain (Webconf...) you are talking about, like right now.

Nice article.

Page 1 of 2Next →