HNHacker News
TopNewBestAskShowJobs

anjsimmo

47 karma · joined June 24, 2018

submissionscomments
anjsimmo··on Gmail confidential mode is not secure or private
Google (ab)uses the @media print CSS rule to hide the message content and replace it with "Printing is not allowed by the sender of this message."

However, I've found you can print confidential emails if you comment-out/disable all the @media print rules using Firefox developer tools: https://grokprivacy.org/2018/06/24/archiving-self-destructin...

anjsimmo··on Gmail confidential mode is not secure or private
In Outlook's docs, they also refer to it as "IRM-protected mail", which seems clearer to me. https://support.office.com/en-ie/article/mark-your-email-as-...

Both Google and MS provide a disclaimer that explains Information Rights Management can't prevent "malicious programs" from by bypassing the restrictions.

anjsimmo··on Gmail confidential mode is not secure or private
All that's needed is to disable a few browser options https://boingboing.net/2018/07/22/adversarial-interop.html

I actually tried the "wiresharking my own cables" approach, but because it's encrypted, you also need to dump the ephemeral encryption keys. There's a simple guide on how to do this here: https://jimshaver.net/2015/02/11/decrypting-tls-browser-traf...

anjsimmo··on Commandeering Australian citizens to become spies
Yep, Atlassian headquarters are in Sydney, so they could be issued a Technical Assistance Request to covertly undermine any repo they host (or have indirect control over via pushing out software updates).

While they could potentially be asked to change your code stored in Bitbucket, Git will refuse to pull if the commit hashes in Bitbucket don't match your local copy, so I don't think intelligence agencies are likely to request this as it is too easily detected.

I predict altering the binaries would be a better way for intelligence agencies to covertly inject a "capability" into your software. E.g. they could ask Atlassian to introduce a hidden code injection step as part of Bitbucket Pipelines, which would be very difficult to detect unless you have deterministic builds and manually verify the output.

Aside from your code, I expect intelligence agencies would be very interested to read your product's issue tracking database (all those "minor" security vulnerabilities that your team knows they should fix someday but don't have time for right now).

anjsimmo··on Whatever Happened to the Semantic Web?
I think the general understanding of the need for formalized semantics on the web is going to grow when people realize that chatbots think the answer to "name a fruit that isn't orange" is "an orange": https://hashtag.ai/blog/2018/09/23/fruit.html
anjsimmo··on Between You, Me, and Google: Problems with Gmail's “Confidential Mode”
"Making a commercial product that bypasses IRM is a potential felony, carrying a five-year prison sentence and a $500,000 fine for a first offense".

But Gmail works in a web browser that already provides everything you need to edit out the print/copy protection CSS & JS code: https://grokprivacy.wordpress.com/2018/06/24/archiving-self-...