HNHacker News
TopNewBestAskShowJobs

conformal

449 karma · joined December 18, 2011

submissionscomments
conformal··on Hackers backdoor the human brain, successfully extract sensitive data
if someone's brain is backdoored, does that mean they are likely to enjoy anal sex?
conformal··on Google confirms Java and OpenSSL crypto PRNG on Android are broken
needless to say, android passed its fips certification with flying colors.

just another secure mobile OS. nothing to see here, move along.

did i mention that you should never store anything of actual import on a phone?

conformal··on Encryption is less secure than we thought
the article title is a total troll, thx mit.

for a real world example of failed uniformity assumptions, see cryptocat.

conformal··on How the U.S. and Its Allies Got Stuck with the World’s Worst New Warplane
the F-35 is one of the largest wastes of government money that is publicly known. by the time the aircraft has all the bugs ironed out, it will have cost USD 1 tln and be easily destroyed by much cheaper drones. the entire contract should be converted into drone development, which will actually pay dividends.

trying to argue that we need the F-35 or that it will provide any kind of strategic military value is absurd.

conformal··on More Encryption Is Not the Solution
> Have YOU inspected your CPU/Firmware/OS/Applications for backdoors? Even with the full source code?

this is absolutely spot on, especially the firmware. nobody talks about it and the attack surface is huge.

just to be explicit, hardware backdoors exist as well :)

conformal··on Why Doesn't Skype Include Stronger Protections Against Eavesdropping?
howdy seth. it's nice to see people calling out skype since i think it likely the service has been co-opted for many years, long before they are listed as having participated with PRISM. i stopped using it for anything but "casual" comms back in ~2005.

as you point out, your focus is on the legal nature of improving the encryption. you mention CALEA, which i'm quoting here for clarity

"A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication."

you are right to point out that skype, under the current laws, is not likely to be considered a "telecommunications carrier". however, they do provide a bridge to the PSTN and this may be part of the legal issue. i suspect they are referencing the yet-to-be-public CALEA II, which may very well require services like skype to be preemptively backdoored for the FBI, etc.

i see skype's current backdoor situation and their comments that you cite as more of a PR/damage control dance than anything. none of the companies that participated in PRISM did/can admit their participation. everyone who does cooperate with the intel services is going to concoct some reason they "had" to cooperate, whether it's true or not.

to me, all of this PRISM and CALEA II nonsense is a reminder that unless a software product is open source, you're unlikely to have any kind of guarantee or expectation of privacy.

conformal··on Why Doesn't Skype Include Stronger Protections Against Eavesdropping?
you must have binged it :)
conformal··on Why Doesn't Skype Include Stronger Protections Against Eavesdropping?
i've got another question: why doesn't the EFF have a comments section on their articles? it's fucking irritating that i can't interact with the author of the article and have to do this on HN.

skype uses "supernodes", i.e. machines with fixed ip addresses, to effect its udp hole-punching to get p2p comms links working. iirc, the architecture of skype is such that supernodes also handle the key exchange (kex) between peers, which is more than a bit dodgy imo.

the kex should occur directly between the two hosts independent of the supernode, but i recall that this has been their architecture for many years, meaning skype can eavesdrop on any chat/call they choose by manipulating the supernodes. the main change that occurred when MS bought skype was that the supernodes were moved from being presumably-arbitrary hosts with fixed ips to hosts controlled directly by MS. since MS controls the nodes where both udp hole-punching _and_ kex occur, they can trivially MITM comms.

i wouldn't be one bit surprised if skype has been owned by intel services for many years. being literally owned by MS only makes this process easier and avoids involving foreign nationals.

conformal··on Twilio is erroneously over-billing and suspending accounts
painful reminder that you need to test payment processing code, by hand or however, after updating it.

i've run some ecommerce sites and this is basic stuff - new payment modules, time to test card processing works properly.

conformal··on The Drone that Killed my Grandson
the age-old question of "cui bono?" remains the single best way to nose out what actually happened, and this often flies in the face of what most people regard and record as "history".

NOTE: i'm supressing a serious rant along your vector.

conformal··on Ask HN: Any startups working to capitalize on the coming privacy boom?
i would not count on the canadian government not running a system that is substantially similar to the usg. intelligence services often aren't concerned with laws, so expecting legal protection matters is a very much misguided path.
conformal··on Ask HN: Any startups working to capitalize on the coming privacy boom?
i like the effort guys, but secure web apps is a tall order. the attack surface of a web app is huge and the web was just not built for client-side crypto. the dependency list for most web browsers is gigantic and attacks against even one of the deps could lead to your crypto being blown.

keep in mind that cryptocat had been audited at least once and they totally missed the completely-busted prng. i am betting you guys will do a better job than nadim et al :)

conformal··on Ask HN: Any startups working to capitalize on the coming privacy boom?
i think it's more like 10-20 years ahead, but point taken :)
conformal··on Mission Creep: When Everything Is Terrorism
consider that the FBI considers potential alternatives to the US Dollar to be a matter of "domestic terrorism":

http://www.libertariannews.org/2011/08/30/bitcoin-fbi-admits...

yeah, that seems like a reasonable application of the word "terrorist" :P

conformal··on Mission Creep: When Everything Is Terrorism
but the best conflicts to get involved in are the ones where nobody will ever win, as evidenced by arguing with stupid people on the internet.
conformal··on Mission Creep: When Everything Is Terrorism
a couple quotes come to mind:

- 1984 - "War is Peace, Ignorance is Strength ,Freedom is Slavery"

- Johann Wolfgang von Goethe - "None are more hopelessly enslaved than those who falsely believe they are free."

conformal··on Why you’ll want everyone you know to wear Google Glass
i think most people are unwilling to acknowledge such a problem with their business strategy exists, and if they do acknowledge it, are unwilling or unable to grasp the full extent of the problem. google, like many large organizations, hides malicious actions behind a veil of complexity. "don't be evil" is certainly a matter of perspective.

i will refrain from citing other examples of hiding behind the veil of complexity since i don't want to "poke the bear" :)

conformal··on Why you’ll want everyone you know to wear Google Glass
it is amusing that you mentioned this because google's business strategy is to steadily erode the privacy of all human beings and monetize it at each step. they can try to dance around this all day with marketing and it doesn't matter.

it's only a matter of time before the glass hardware has an attachment that reads your mind so you exert even less effort than currently, e.g. blinking. google will then take that data and sell it to marketers, the USG, and whoever else they can, so everyone knows what you're going to think before you think it. google predictive thinking... so sad.

conformal··on Why you’ll want everyone you know to wear Google Glass
same here! i want nothing to do with the world of pointless media sharing or other people's perception that recording everything is worthwhile.

if i could legally destroy every glass rig that was anywhere near me, i would be a happy person indeed. the unfortunate situation that now arises is a surveillance arms race, wherein it is illegal (in most countries) to undertake destructive or jamming actions against surveillance technology, be it radio or cellular frequency EM waves, a horde of idiots with cameras or the intelligence services that record all internet traffic, including this post. i would rather not participate, but the concept of passive/massive resistance simply will not work against such technology.

i don't want to develop my own countersurveillance to keep the glassholes at bay. however, i and people who care about privacy are left with few options. i would love to see some legit countermeasures for glass.

conformal··on Gotk3: GTK3 the Go way
if you look on github, you'll notice that all the obvious names were taken, e.g. go-gtk, go-gtk3. that was what really drove the project name to be gotk3.
conformal··on SSH Brute Force – The 10 Year Old Attack That Still Persists
seriously, password-based auth... have ppl not heard of public key authentication?

allowing password-based auth in sshd is plain stupid. _always_ use pubkey auth, it's a 1-line change in /etc/ssh/sshd_config.

conformal··on Adam Langley's Pond: Secure Async Messaging
iirc renegotiation in openssl is mad broken, in which case, mad props to adam :)
conformal··on Don't be evil: Moving everything off of Google
i did this several years ago, feels good knowing that google has to work hard to spy on me versus me just giving them all kinds of info about myself via search, etc.

the only thing i use is a throwaway gmail address that is mostly a spam magnet.

conformal··on Crowd steps up to fund 'NSA-proof' app
we've seen what happens when "3rd parties" audit stuff - think cryptocat... encraption :)
conformal··on Crowd steps up to fund 'NSA-proof' app
there is no such thing as a secure cellphone platform, at least for us non-govt folk. expecting your comms to be secure on a cellphone because you use some app is super naive. as dobbsbob points out, your phone is likely ownable/backdoored by (1) the manufacturer, (2) the OS maker, (3) the ISP and (4) the local intelligence services.

the best way to keep anything secure as it relates to your phone is to not use it. in fact, keep your phone well away from where you work and have important conversations. there is a reason certain ppl are not allowed to bring their cellphones to work: it's because they're not even remotely secure.

conformal··on Partial Tesla Model S recall
i can't tell if this partial recall is a Total Recall joke or not.

quaid, start the reactor... FREE MARS!

conformal··on Thoughts on Matasano Security’s Critique of Javascript Cryptography
i could bother to read what nadim has written, but then i would fall in the "successfully trolled" bucket. i consider daeken very kind for reading and systematically disassembling nadim's post. instead, i will make a few rude blanket statements.

- having a misleading wired article (or several) written about you in no way qualifies you as an expert on cryptography. anyone who has any level of knowledge in the subject knows this guy is a total hack.

- everything that is somewhat correct about his products is due to people who _actually_ know stuff about cryptography telling him "no, no, no, you need to do X". the entirety of the architecture is effectively crowd-sourced. people telling you how to be a good carpenter is no substitute for being a skilled woodworker.

- nadim should stop making crypto products because bad crypto _puts people at risk_. if you make one bad product, i can see chalking it up to "well, at least he's trying". instead, nadim has routinely and repeatedly demonstrated his lack of real domain knowledge.

i suggest nadim make some turd-like web 2.0/3.0 driven product where security doesn't matter. he clearly has the tenacity to code but lacks the intelligence and domain knowledge to make security-related software.

conformal··on Btcd: A Full Alternative Bitcoin Implementation, Written In Go
i think there has been some confusion in links and titles: btcd is a full-node alternative implementation of the bitcoin protocol. this was not meant to be misleading and you are right to point out that the btcwire package is far from the entire piece of software.

in another few weeks all the pieces will be public and it will be closer to a full implementation, per my interpretation of your use of the word full.

conformal··on Show HN: I'm building an open-source, high-frequency trading system
if concurrency with C/C++ is bad for you, go makes it very easy. however, it is not very fast either.

doing it in go and then using cgo where necessary will get you pretty close to C speed.

conformal··on Show HN: I'm building an open-source, high-frequency trading system
i believe that is how it works: open source infrastructure, private algos
← PreviousPage 4 of 6Next →