HNHacker News
TopNewBestAskShowJobs

algorithm_dk

681 karma · joined February 9, 2014

51d544
submissionscomments
algorithm_dk··on Show HN: Devstream.tv – Watch developers code live
Yes, YouTube will be added next.
algorithm_dk··on Show HN: Devstream.tv – Watch developers code live
devstream.tv showcases developers that stream live on Twitch.
algorithm_dk··on Ask HN: Who wants to be hired? (March 2018)
Location: Bucharest, RO

Remote: Yes

Willing to relocate: Not right now

Technologies: Javascript, ES5/6, Vue.js, HTML/CSS3/SASS/etc, Node.js (+ Feathers, Express, Hapi, etc), PHP, C++, quick to learn new technologies

Resume: https://andreineculaesei.com/

Contact: https://andreineculaesei.com/contact

Github: https://github.com/neculaesei

LinkedIn: https://linkedin.com/in/install

algorithm_dk··on Xeno Kovah: macOS 10.13 EFI firmware integrity check
http://webcache.googleusercontent.com/search?q=cache%3Ahttps...
algorithm_dk··on Ask HN: How do you hire good developers?
Leave some contact information.
algorithm_dk··on Show HN: Roam – Global co-living subscription
$1600 for a month? In Indonesia? In that room? No wonder you decided to hide the price until someone actually wants to sign-up.

EDIT: Just took a quick look at Airbnb for Indonesian rentals. I found this: https://www.airbnb.com/rooms/5021049 It's cheaper than a room from Roam.

algorithm_dk··on Excuse Me Sir, Your WebRTC Is Leaking
I made a LAN scanner based on this in JS: http://algorithm.dk/lanscan
algorithm_dk··on Wire – Modern Communications Network
From my initial investigation they have some <bad> code behind, race conditions and I think I found a place where it's leaking the IP of the guy you're calling. I'll post my findings later. Messages are sent over SSL but not encrypted in any other way, so they can read them :)
algorithm_dk··on Google Inbox
This looks awesome! Now I won't be able to decide between this, myMail and Mailbox :'( Can anyone shoot an invite to andrew(at)algorithm.dk? Thank you!
algorithm_dk··on How to get your idea stolen
We did not abandon the idea, we took a break.
algorithm_dk··on How to get your idea stolen
Ideas are cheap - good ideas aren't. Thanks for the redaction observations - I edited the article.
algorithm_dk··on Anyone can track your mobile phone's location
It didn't raise much interest so I didn't add credits on it.
algorithm_dk··on For sale: Systems that can track where cellphone users go around the globe
The technical part of this article is partially wrong. I will post the real way it works later along with a real demo you can try on your own number. Stay tuned!
algorithm_dk··on RTFM 0day in iOS apps
Great work man! I'm glad we can bring attention to security issues. Maybe we could work together.
algorithm_dk··on RTFM 0day in iOS apps
I never said I agree with Apple, I think it's a extremely bad default.
algorithm_dk··on RTFM 0day in iOS apps
I can't do responsible disclosure when there are tens of thousands of apps using webView. The number of vulnerable apps is way too high for any kind of responsible disclosure.
algorithm_dk··on RTFM 0day in iOS apps
It is not a 0day in the traditional meaning, it's a simple <did not read the manual> and <bad defaults> case. On the other hand I've been waiting to get on Apple's HoF for two years now, reporting cross-site scripting bugs and even a sqli - yet I'm not there. Apple is not getting any responsible disclosure from me.
algorithm_dk··on RTFM 0day in iOS apps
I did my test on WiFi which results in almost instant calls for me. Set your computer to catch the facetime call and answer it automatically (check this: https://github.com/PaperCutSoftware/teleportme/blob/master/t...). Capture your screen continuously and if you might get the first frames of the call. It's all about what people do when their phone starts calling by itself. Most people freeze which results in a successful attack.
algorithm_dk··on RTFM 0day in iOS apps
Thanks a lot! I asked a friend to test it for me on android (wondering if it works) and I was glad that it doesn't. On Android it fills the phone number for you and lets you push the call button, which seems to me a much saner design.
algorithm_dk··on RTFM 0day in iOS apps
This is true, both bad defaults and people not reading documentation. It's just like mongo that start by default with remote access enabled and no password - Shodan "mongo" and you will find thousands of live, not protected databases.
algorithm_dk··on RTFM 0day in iOS apps
Send it using the Facebook Messenger app or GMail app. The fault is in the apps not in the system. Your code is correct.
algorithm_dk··on RTFM 0day in iOS apps
Absolutely an exploitation technique. Or you can facetime them instantly and catch a photo of them in pijamas!
algorithm_dk··on RTFM 0day in iOS apps
Because the apps can initiate a call by just pointing a webview at tel:0000. Another reason is hybrid apps, imagine a contact hybrid app running in something like PhoneGap. You want to click a button and call right away without the phone asking you to confirm your action.

I'm not saying that Apple's design is good, but it is documented.

algorithm_dk··on Show HN: Hemmingwurst – Make your writing bolder and clearerer
Ah.. what's the purpose of this? I don't get it.
algorithm_dk··on Ingress: Google is broadcasting your address to everyone.
Why can another player retrieve my current location just because I posted a chat message? This information is not displayed in the game, but the data is retrieved. Every time the event list or the chat is loaded, along with each post content the location of the player who has been the source of the event is also coming from the server.
algorithm_dk··on Ingress: Google is broadcasting your address to everyone.
I can't understand how they think this is OK.
algorithm_dk··on Hacker's ruinous run ends in capture
Good thing we're all hackers here (hackernews right?)
algorithm_dk··on LibreSSL's PRNG is Unsafe on Linux
We need to stop useless forks.
algorithm_dk··on Hacker's ruinous run ends in capture
That's not what "hacker" means.
algorithm_dk··on Seriously Oracle? Who employs you guys?
Yeah, got used to it. By the way, you can throw anything to the captcha input, it doesn't actually validate it.
← PreviousPage 2 of 3Next →