HNHacker News
TopNewBestAskShowJobs

arkadiyt

22,018 karma · joined May 30, 2015

https://twitter.com/arkadiyt

https://bsky.app/profile/arkadiyt.bsky.social

https://arkadiyt.com/about

submissionscomments
arkadiyt··on <input type="password" maxlength="20"> prevents me from logging into Vanguard
bcrypt famously only looks at the first 72 bytes of the input. There are ways around that - don't use bcrypt, or do bcrypt(sha256(password)), or whatever, but it is not the case that "just feed the input to the hash" removes all length restrictions
arkadiyt··on Apple Private Cloud Compute SoC 3 audit reports
For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it.

Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

arkadiyt··on Removing the modem and GPS from my 2024 RAV4 hybrid
This is addressed in the blog :)
arkadiyt··on Removing the modem and GPS from my 2024 RAV4 hybrid
It's from the linked rav4world post
arkadiyt··on Removing the modem and GPS from my 2024 RAV4 hybrid
There's still a fuse for the DCM even in this car but:

- It has an internal battery and will keep running for quite a while after pulling the fuse. This is a safety feature in case you get in a crash that disconnects the 12V battery

- It will break your in-car microphone as discussed. Repairing that requires opening up the dash

- That won't do anything for disconnecting the GPS antenna

arkadiyt··on Removing the modem and GPS from my 2024 RAV4 hybrid
In a perfect world they wouldn't collect it either, but I'd rather Apple have it than the car manufacturer (or rather, only Apple vs both Apple and the car manufacturer)
arkadiyt··on The Car That Watches You Back: The Advertising Infrastructure of Modern Cars
When I removed the DCM the in-car microphone stopped working, but I bought one of these to get it working again: https://www.autoharnesshouse.com/store/AHH-DCM77.

Also even with no modem, if you use CarPlay on your phone _via Bluetooth_ then the car will just use your phone's internet connection, so I only use CarPlay via a wired USB connection.

Aside from that the car works great, everything is 100% functional. I suppose I don't get OTA updates, which I'm fine with.

arkadiyt··on The Car That Watches You Back: The Advertising Infrastructure of Modern Cars
I bought a 2024 RAV4 Hybrid and

1) physically removed the modem (the "DCM") and

2) disconnected the GPS antenna from the head unit

Took a little research but was still an approachable project

arkadiyt··on Do not accept terms and conditions
Apple Health data is end-to-end encrypted, even without using ADP. They don't have access to it: https://support.apple.com/en-us/102651
arkadiyt··on Surveillance data challenges what we thought we knew about location tracking
> intercept SMS including the verification codes sent by apps like WhatsApp

For anyone worried, this approach:

1) Breaks the existing phone from receiving WhatsApp messages, so you can notice that behavior

2) Can be prevented by setting up a WhatsApp pin in your settings

arkadiyt··on Show HN: Real-time privacy protection for smart glasses
I don't need something to protect the privacy of others from me, I need something to protect my privacy from others. The majority of people who use smart glasses are not going to be using this - where is the product that will protect me from them?
arkadiyt··on Why I no longer have an old-school cert on my HTTPS site
If using a non-FS key exchange (like RSA) then the value that the session key is derived from (the pre-master secret) is sent over the wire encrypted using the server's public key. If that session is recorded and in the future the server's private key is obtained, it can be used to decrypt the pre-master secret, derive the session key, and decrypt the entire session.

If on the other hand you use a FS key exchange (like ECDHE), and the session is recorded, and the server's private key is obtained, the session key cannot be recovered (that's a property of ECDHE or any forward-secure key exchange), and none of the traffic is decryptable.

arkadiyt··on Why I no longer have an old-school cert on my HTTPS site
> does a 4096 not give you more security against passive capture and future decrypting?

If the server was using a key exchange that did not support forward secrecy then yes. But:

    % echo | openssl s_client -connect rachelbythebay.com:443 2>/dev/null | grep Cipher
    New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384
    Cipher    : ECDHE-RSA-AES256-GCM-SHA384

^ they're using ECDHE (elliptic curve diffie hellman), which is providing forward secrecy.
arkadiyt··on Why I no longer have an old-school cert on my HTTPS site
> Make an RSA key of 4096 bits. Call it your personal key.

This is bad advice - making a 4096 bit key slows down visitors of your website and only gives you 2048 bits of security (if someone can break a 2048 bit RSA key they'll break the LetsEncrypt intermediate cert and can MITM your site). You should use a 2048 bit leaf certificate here

arkadiyt··on Ask HN: Former employees' RSUs at risk after startup's IPO
185 days before 3/15/2025 is 9/11/2024. There were these IPOs around that time (all Nasdaq) [1]:

- 9/10: TDTH

- 9/10: XCH

- 9/12: GLXG

- 9/12: FVN

[1]: https://stockanalysis.com/ipos/2024/

arkadiyt··on Snyk security researcher deploys malicious NPM packages targeting cursor.com
> If that's the case, then there's not much to see here

They could have demonstrated the POC without sending data about the installing host, including all your environment variables, upstream. That seems like crossing the line

arkadiyt··on Automakers are sharing consumers' driving behavior with insurance companies
If I get a new car I'm just taking the modem out.
arkadiyt··on See this page fetch itself, byte by byte, over TLS
Chrome/Firefox/curl do allow exporting this by setting the `SSLKEYLOGFILE` environment variable, but as another poster points out this would let anyone with access to your hard drive decrypt your historical traffic
arkadiyt··on Tell HN: Equifax free credit report dark patterns
I continue to request my reports via certified mail to the annualcreditreport address, and this time for the first year Equifax just ... didn't reply. Completely ignored my request.
arkadiyt··on GitHub is preparing for IPv6 support for Github.com
It's a common bypass of server side request forgery filtering. Backends will try to validate that a user-submitted url doesn't resolve to an internal IPv4 address, but they'll happily allow an IPv6 mapped version for the same IPv4 address.
arkadiyt··on Who made millions trading the October 7th attacks?
Just turn off javascript and it'll bypass their paywall
arkadiyt··on Travel routers improve your life [video]
We had some employees using travel routers to bypass company policies around working abroad, taking laptops to China, etc. If you want to detect that sort of thing you could consider adding detection rules in your SIEM for connections to your company VPN from an ip address that is itself associated with another/commercial VPN. It won't catch people connecting to VPN servers offered through their home router, but it's something.
arkadiyt··on Kaspersky discloses iPhone hardware feature vital in Operation Triangulation
The authors' Chaos Communications Congress conference talk about these exploits is up now, it was a great watch:

- https://www.youtube.com/watch?v=7VWNUUldBEE

Also previous discussion:

- https://news.ycombinator.com/item?id=38783112

arkadiyt··on How to Escape a Container
Not mentioned: use a kernel N-day, of which there are many. Patch your hosts folks
arkadiyt··on Billionaires amass more through inheritance than wealth creation, says UBS
Here's a chrome extension I wrote to bypass the ft.com paywall if folks are interested: https://github.com/arkadiyt/free-ft
arkadiyt··on SEC Charges SolarWinds and CISO with Fraud, Internal Control Failures
They weren't charged for having deficiencies, they were charged for knowing about their deficiencies and lying about them:

> SolarWinds allegedly misled investors by disclosing only generic and hypothetical risks at a time when the company and Brown knew of specific deficiencies in SolarWinds’ cybersecurity practices as well as the increasingly elevated risks the company faced at the same time.

arkadiyt··on Issues with 1.1.1.1 public resolver and WARP
> it makes me wonder if archive.today wants exact client IP addresses for some other unstated reason

They still get the client ip from the request to the service itself (unless you're using a VPN, but if you're using a VPN then archive wouldn't get your ip from your DNS request either).

arkadiyt··on Geo Guesser identifies the location and seat number from an aerial shot
It's on this reply: https://twitter.com/georainbolt/status/1698554653854826984
arkadiyt··on Tech sector Salaries have fallen up to 15 per cent as fired talent floods market
Just disable javascript and you can bypass 90% of paywalls, including this one
arkadiyt··on Block YouTube ads on AppleTV by decrypting and stripping ads from Profobuf
> without the C++ source proto files

Shameless plug: I wrote a project to generate source proto files from binaries called protodump [1] - it regenerates all the message/field definitions (including the original names). It would just require pulling the binary off the AppleTV box

[1]: https://github.com/arkadiyt/protodump

Page 1 of 15Next →