22,018 karma · joined May 30, 2015
https://bsky.app/profile/arkadiyt.bsky.social
https://arkadiyt.com/about
Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting
- It has an internal battery and will keep running for quite a while after pulling the fuse. This is a safety feature in case you get in a crash that disconnects the 12V battery
- It will break your in-car microphone as discussed. Repairing that requires opening up the dash
- That won't do anything for disconnecting the GPS antenna
Also even with no modem, if you use CarPlay on your phone _via Bluetooth_ then the car will just use your phone's internet connection, so I only use CarPlay via a wired USB connection.
Aside from that the car works great, everything is 100% functional. I suppose I don't get OTA updates, which I'm fine with.
1) physically removed the modem (the "DCM") and
2) disconnected the GPS antenna from the head unit
Took a little research but was still an approachable project
For anyone worried, this approach:
1) Breaks the existing phone from receiving WhatsApp messages, so you can notice that behavior
2) Can be prevented by setting up a WhatsApp pin in your settings
If on the other hand you use a FS key exchange (like ECDHE), and the session is recorded, and the server's private key is obtained, the session key cannot be recovered (that's a property of ECDHE or any forward-secure key exchange), and none of the traffic is decryptable.
If the server was using a key exchange that did not support forward secrecy then yes. But:
% echo | openssl s_client -connect rachelbythebay.com:443 2>/dev/null | grep Cipher
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Cipher : ECDHE-RSA-AES256-GCM-SHA384
^ they're using ECDHE (elliptic curve diffie hellman), which is providing forward secrecy.This is bad advice - making a 4096 bit key slows down visitors of your website and only gives you 2048 bits of security (if someone can break a 2048 bit RSA key they'll break the LetsEncrypt intermediate cert and can MITM your site). You should use a 2048 bit leaf certificate here
- 9/10: TDTH
- 9/10: XCH
- 9/12: GLXG
- 9/12: FVN
They could have demonstrated the POC without sending data about the installing host, including all your environment variables, upstream. That seems like crossing the line
- https://www.youtube.com/watch?v=7VWNUUldBEE
Also previous discussion:
> SolarWinds allegedly misled investors by disclosing only generic and hypothetical risks at a time when the company and Brown knew of specific deficiencies in SolarWinds’ cybersecurity practices as well as the increasingly elevated risks the company faced at the same time.
They still get the client ip from the request to the service itself (unless you're using a VPN, but if you're using a VPN then archive wouldn't get your ip from your DNS request either).
Shameless plug: I wrote a project to generate source proto files from binaries called protodump [1] - it regenerates all the message/field definitions (including the original names). It would just require pulling the binary off the AppleTV box