HNHacker News
TopNewBestAskShowJobs

bobedybobbob

29 karma · joined September 13, 2015

submissionscomments
bobedybobbob··on Alphabet adds patent claim to Uber intellectual property theft lawsuit
I was under the impression Google (or Google Ventures) owned part of Uber - surely this will make things complicated?
bobedybobbob··on Employee sues Google for 'illegal' confidentiality policies
Is that global or just the employees in California?
bobedybobbob··on North Korea claims success in fifth nuclear test
I'm all for the Non-Proliferation of Nuclear Weapons but also find it amazing what their scientists can do working with such limited resources.
bobedybobbob··on How Hired Hackers Got “Complete Control” of Palantir
Phishing is generally 1. run a command or 2. give me your credentials. To prevent these you need good solid technical controls like U2F for password based authentication (which is origin bound). Similarly binary whitelisting will prevent most users from running rogue executables.
bobedybobbob··on How Hired Hackers Got “Complete Control” of Palantir
With time, creativity and motivation a good offensive security team will always win. All we can do as defenders is to find ways to raise the cost of such an attack.

A bit disappointed they seem to have started on the internal network rather then coming in from the outside :)

bobedybobbob··on Two-factor authentication for Apple ID
It'd be nice to see support for U2F
bobedybobbob··on Let Me Get That Door for You: Remote Root Vulnerability in HID Door Controllers
Nearly all door controllers are broken. I hope someone comes out with a secure alternative soon but fear that the cost of installation that comes with these devices will prevent many people from upgrading.
bobedybobbob··on Multiple security vulnerabilities in Rails
Do we really need CVE numbers assigned for all of these? More or less every application out there is vulnerable to some form of timing attack
bobedybobbob··on Timing attack against HSTS to sniff browser history in Chrome and Firefox
The core issue is the same that leads to cross domain search timing attacks [1] (which can be prevented with CSRF tokens)

With timing HTTP->HTTPS redirections maybe the issue is not that the response can be timed but that HTTP exists in the first place? There are other similar timing attacks that can easily be used to identify if a user is logged in to a specific website [2].

[1] https://news.ycombinator.com/item?id=10211306 [2] http://crypto.stanford.edu/~dabo/papers/webtiming.pdf