HNHacker News
TopNewBestAskShowJobs

daten

622 karma · joined December 8, 2009

[ my public key: https://keybase.io/daten; my proof: https://keybase.io/daten/sigs/jzFyVWNrj39c9uJJF62Ismw5gbE7DCDLsSGff-Wccu8 ]

Linux, Software Engineering, Rotary Engine Mechanic and experience with petabyte-scale packet capture and analysis

submissionscomments
daten··on An Open Letter to Wired Magazine: We're breaking up
Communications of the ACM http://cacm.acm.org/

Linux Journal http://www.linuxjournal.com/

daten··on The Great Cyberheist
Or "Private Browsing" if I'm using Firefox instead of Chrome? Having noscript installed didn't help. I still got the login page. Does private browsing hide the referrer URL?
daten··on Another Android Market Share Boost
Apart from being a happy Android user with a Galaxy S based phone, I don't follow the mobile OS market very closely. I'm aware of the competition between Apple iOS and Android. I know RIM is being Blackberry phones. But when reading this article I realized I had no idea what "Symbian" was.

Apparently Symbian is the OS on Nokia and Sony Ericsson phones.

daten··on The Great Cyberheist
You can follow the google referral to see the article without logging in.

http://news.google.com/news/search?aq=f&pz=1&cf=all&...

daten··on Sophos Researcher Suggests Password 'Free' to Spur Wi-Fi Encryption
Yes, it is still possible to decrypt WPA if you know the password and capture the beginning of the users' session. You can also spoof a de-auth to cause a user to reconnect if you weren't present for the start of their session.

This doesn't address problems with arp-spoofing, fraudulent DHCP servers or fraudulent access points, but it does raise the bar in the complexity of the attack.

HTTPS with a valid signed certificate would still be necessary to deal with the other attacks. Or maybe a VPN connection to a network you trust.

daten··on TextCAPTCHA: 180 million simple logic questions
I agree. The questions in the example may be easily solved by a technically minded person, but they could also confuse a large part of your audience. I would find it very difficult to generate questions that are appropriate no matter what language, culture, math or literacy background my visitors have.
daten··on Gmail: Trap my contacts now (warning when exporting contacts to Facebook)
There are several apps like this one that claim to export your friends and email address to CSV format.

http://apps.facebook.com/friendstocsv/

daten··on Japan's Latest Rock Star Is A 3D Hologram - Draws Huge Crowds
I previously heard of Hatsune Miku because she did a cover of "Still Alive" from the computer game "Portal".

http://www.youtube.com/watch?v=_12b6Om758Q

daten··on Japan's Latest Rock Star Is A 3D Hologram - Draws Huge Crowds
I would guess that with most pop. music performers the copyright to their songs are owned by the "Record Label" or company that signs their paycheck.

None of the money from current RIAA lawsuits goes back to the artists.

daten··on Two firesheep denial-of-service attacks
I would think using firesheep to access private information in other peoples accounts without consent is illegal. The fact that those people were using an unencrypted link doesn't make it less illegal, at least in my country.

I also think denial-of-service attacks against legitimate services are illegal.

But my question is, what about denial of service attacks against illegal activity such as firesheep when the attack doesn't affect any legitimate users or services? A specially crafted packet that exploits weaknesses in firesheep code doesn't harm anyone else on the network, like for instance a network flood would.

daten··on Placebo buttons: 'door-close' buttons, others, don't do anything
I don't read Slashdot comments because of the repetitive or off topic jokes that add nothing productive to the conversation.
daten··on Placebo buttons: 'door-close' buttons, others, don't do anything
Many buildings with multiple evelators are programmed to return to a stagger position, so all of the idle elevators are at least one floor apart if not evenly distributed across the whole height of the building. The closest idle elevator responds to a call button.

This is easiest to observe in builds with glass elevators.

daten··on Placebo buttons: 'door-close' buttons, others, don't do anything
I agree, I've also noticed the elevators in my office building are on a schedule and behave differently during business hours than evening and early morning hours.

Maybe it's for the convenience of the after-hours cleaning staff, but after 7PM the close door button can even make the door close before it finishes opening upon arriving at a floor.

daten··on Placebo buttons: 'door-close' buttons, others, don't do anything
Removing 2,500 or more buttons throughout the city would require a lot of man-hours, transporting, storing and disposing of the old buttons. There would also be wiring to remove or block off, cover plates to be made, distributed and installed. And hopefully some sort of communication to the entire population of the city including visitors to explain why the buttons are going away.
daten··on Full CSS3 Lightbox - Absolutely no JavaScript
Does that make it "broken" or just incompatible with your expectations? Would other non-technical users have the same expectations? It's possible other users will want to go "back" to the image they last visited.

Consider if this was done just HTML 4 and no CSS or Javascript. You would click a thumbnail and a new page would be loaded with a full size version of the image. You would then click a "close" button that would take you to the page with the thumbnails again. If you hit "back" you would go back to the image.

The way the page currently works follows the "stack" of what I actually visited by clicking links. If I want to reverse my workflow after visiting all 5 images and closing between them, I personally would expect the back button to go through all 5 images. From this perspective, doing the same effect with Javascript that doesn't update the stack might surprise me if after clicking 10 links on this page, a single click of the browser back button skips 10 steps of my workflow and returns me to HN.

daten··on Full CSS3 Lightbox - Absolutely no JavaScript
I always used Ctrl-Left Click
daten··on The Airport Security Grope
I understandthat arguing with the TSA screeners at the ceckpoint is pointless as they have no ability to change policy and you don't have time to miss your flight, but I have also wondered wht kind of person can work for the TSA and be happy getting paid to do this.
daten··on The Airport Security Grope
Too bad the invasions of privacy at TSA checkpoints don't do anything to prevent "attacks". If you're going to cover your ass, at least do it in an effective way that doesn't offend your intelligent voters.
daten··on EPIC Lawsuit to Suspend Deployment of Body Scanners at US Airports
In my experience this works every time at Dulles international (IAD) but never works at Hartsfield-Jackson Atlanta International (ATL). At ATL you get sent to the back of the normal line.
daten··on EPIC Lawsuit to Suspend Deployment of Body Scanners at US Airports
Can both sides play the "think of the children" card in the same fight?
daten··on Opt Out of a Body Scan? Then Brace Yourself
If it's made to bounce off of skin, what about leather clothes?
daten··on Opt Out of a Body Scan? Then Brace Yourself
Your idea reminds me of this story from 2006.

Milwaukee resident Ryan Bird wrote "Kip Hawley is an Idiot" on a plastic bag given to passengers by airport security. As a result he claims he was detained and told that the First Amendment did not apply to security checkpoints.

http://www.flyertalk.com/forum/travel-safety-security/606142...

Kip Hawley was the head of TSA at the time.

daten··on Opt Out of a Body Scan? Then Brace Yourself
Additionally I would feel perfectly safe flying without any security screening at the airports.

No "terrorists" have been attacking schools, churches, malls, buses, trains, bridges, theaters, libraries, office buildings, etc. Either they only attack planes (not even the airports themselves) or there aren't enough terrorists to justify this amount of "security".

daten··on Opt Out of a Body Scan? Then Brace Yourself
Baltimore Washington Intl. airport and Hartsfield-Jackson Atlanta International Airport both recently got body scanners. They both changed their process to close all lanes not equipped with a body-scanner and funnel everyone through the one or two scanners they had.

At BWI they would make every 15th or so person go through the scanner, or anyone who volunteered by walking up to it instead of the metal detector.

At Atlanta the scanners weren't even operational yet and they still only opened the metal detectors with scanners beside them and had an army of TSA screeners standing around doing nothing while a huge crowd of travelers waited in a very long line.

The processes have indeed changed.

daten··on Teenager jailed for refusing to hand over computer password
What you have said isn't true or accurate.

On December 17, 2006, defendant Sebastien Boucher was arrested on a complaint charging him with transportation of child pornography in violation of 18 U.S.C. § 2252A(a)(1). At the time of his arrest government agents seized from him a laptop computer containing child pornography. The government has now determined that the relevant files are encrypted, password-protected, and inaccessible. The grand jury has subpoenaed Boucher to enter a password to allow access to the files on the computer. Boucher has moved to quash the subpoena on the grounds that it violates his Fifth Amendment right against self-incrimination.

The district court held that Boucher could invoke the Fifth Amendment and refuse to comply.

http://cyb3rcrim3.blogspot.com/2007/12/court-upholds-using-f...

They later worked around it by requiring him to provide the decrypted contents of the drive instead of the password itself since a border agent witnessed some of the files on the drive and he wouldn't be providing new evidence.

http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....

daten··on Compared to you, most people seem dumb
I agree. I don't expect people to become experts in cars or computers or anything else they use in their daily life that their job or safety may depend on, but I do have more respect for people that make an effort to learn the basics or try to understand what they're dealing with.

I don't assume someone is stupid for being clueless about technology. I might assume they're at least a little lazy.

When I started using computers in the 1980's I sat down with a 20 minute tutorial and learned the basics about the mouse, keyboard, interface elements, command line and components of the computer. I've met people that have spent years asking others for help with things I took less than half an hour to learn up front.

daten··on Compared to you, most people seem dumb
Knowing that Jupiter is the 5th planet from the sun is practical knowledge for how many people?

edit: (HN wont let me reply again)

I understood your point. I think in the context of the article the only irony is you think the technical fact that astronomers label Earth as a "planet" is necessary knowledge for every field of engineering or anyone with an advanced education.

Yes, I learned about the solar system in elementary school too but I wouldn't judge someone who didn't. It's not much more useful than trivia to most people.

Discussion around another recent article on HN comparing C programming to a carpenter using a hammer demonstrated that even people with computer science degrees and years of experience writing software might no nothing about HTML or SQL.

daten··on Firesheep: Easy HTTP session hijacking from within Firefox
No. Cabled tethering to a cell phone only gives you access to your own packets. It's like a switched network where only packets addressed to you are sent to you.

On 802.11 wireless networks your wireless network card is capable of capturing traffic addressed to other computers. When encryption isn't used or is compromised, you can steal their credentials.

Doing something similar against cellular networks would require a much more sophisticated attack with specialized hardware that's largely illegal in the United States. I would also hope that cellular communications are encrypted these days.

daten··on Firesheep: Easy HTTP session hijacking from within Firefox
This is true but not relevant to the discussion because the attack in question depends sniffing clear-text wireless traffic at the local access point.

Tunneling over SSH protects your traffic for that portion of the network (and out past your ISP as far as the remote end of the SSH tunnel).

An attacker would need different tools and resources to intercept your traffic between remote hosts.

daten··on Firesheep: Easy HTTP session hijacking from within Firefox
While I completely agree, I wouldn't consider personal experience a valid data point for generalizing the whole world.
← PreviousPage 3 of 6Next →