HNHacker News
TopNewBestAskShowJobs

ergot

1,227 karma · joined November 6, 2016

submissionscomments
ergot··on Ask HN: Best online resources for learning web security
There's a fairly comprehensive list here:

https://github.com/sbilly/awesome-security

ergot··on Fake profiles – Facebook not even trying
Facebook is testing a feature that alerts you if someone is impersonating your account: http://mashable.com/2016/03/22/facebook-impersonation-alert/
ergot··on Lavabit accepts Bitcoin now
I'm going to pay with tumbled Bitcoins since there's no zCash, or Monero option
ergot··on I Had My Electronics Seized by U.S. Customs and Border Protection
Quite apart from all the drama surrounding him, I just wanted to share one of his many informative talks.

(I was wondering why it got downvoted and thanks for clarifying)

ergot··on I Had My Electronics Seized by U.S. Customs and Border Protection
Worth listening to Jake Appelbaum's 'digital anti repression workshop' [1]. In this he explains why he takes the hard-drive out of his laptop and just uses a TailsOS thumb-drive for his computing. It would be actually hilarious when staff ask to peruse the contents of your computer for contraband, only to discover the laptop doesn't have a hard-drive.

[1]: part 1 https://www.youtube.com/watch?v=HHoJ9pQ0cn8

[#]: part 2 https://www.youtube.com/watch?v=s9fByRmAHgU

ergot··on Surveillance Self-defense Against The Trump Administration
Thanks for posting that.

Sorry for posting the wrong link to this :(

ergot··on Introducing ProtonMail's Tor hidden service
For those wondering how to create your own custom Tor onion adress, look no further than: https://timtaubert.de/blog/2014/11/using-the-webcrypto-api-t...

And for those who think Protonmail are the only service with a custom address, think again, because Facebook has one too: https://facebookcorewwwi.onion/

You can find a tonne more at this list:

https://github.com/chris-barry/darkweb-everywhere/tree/maste...

And staying on topic, Mailpile has their own .onion

https://raw.githubusercontent.com/chris-barry/darkweb-everyw...

ergot··on Too much sitting, too little exercise may accelerate biological aging
I do yoga for my back and ensure there's good lumbar support on any chair I sit on. They say sitting is the 'new cancer' and prevention is often the way to go. Here's an interesting article on some yoga exercises you can try for back pain: http://www.buzzle.com/articles/yoga-exercises-for-back-pain....
ergot··on Detailed VPN Comparison Chart
> Maybe even subsidising their offering

Yeah there's a few VPNs that look shady because of their pricing. One that springs to mind is LeafVPN[1]. For $5.00 you get to send all your traffic to Mallory. And it even has `LEA` as the first three letters, so you're safe! This is not an endorsement of this service BTW.

[1]: https://leafvpn.com

ergot··on Detailed VPN Comparison Chart
Brilliant list. I always wondered how many commercial VPN providers use code from these. I suspect setting up the VPN is easy enough, but coding the billing backend might be trickier.
ergot··on The Privacy Threat from Always-On Microphones Like the Amazon Echo
Unless it affects them directly, just like how tobacco smokers don't see any immediate bad effects from smoking. But they know somewhere down the line something awful will happen.
ergot··on Show HN: Hidemail.us – Temporary email redirects, easy
I prefer to blackhole everything in a Zoho account with the catchall[1] feature turned on, so I can just type random crap as the username when signing up like:

asdferhgg@generic.domain

The trick is to keep that domain renewed for as long as you're alive so nobody can take new ownership and pwn all your accounts as a result.

[1] https://www.zoho.com/mail/help/adminconsole/catch-all-setup....

ergot··on Hacker Steals 900 GB of Cellebrite Data
This article actually links to the login page:

https://cellevault.cellebrite.com/cas/login?service=https://...

ergot··on We Reverse Engineered 16K Apps
I like to intercept iOS apps' traffic with Burp Suite[1] or Fiddler[2]. The trick is to have two adapters running on the same OS, one for the public Internet, and the other acting as an ad-hoc hotspot. It's simply a case of letting Burp suite sniff the traffic on the ad-hoc network and seeing what 'goodies' you find, like API keys.

[1]: https://portswigger.net/BURP/

[2]: http://www.telerik.com/fiddler

ergot··on Trying to Keep the Internet Safe from Warrantless NSA Surveillance
> But really Google is so much worse than the NSA

Google is one of the many tentacles of the NSA. Worth reading 'How the CIA made Google': https://medium.com/insurge-intelligence/how-the-cia-made-goo...

Also noteworthy: 'DARPA director Regina Dugan takes job as Google senior executive':

http://articles.latimes.com/2012/mar/13/business/la-fi-tn-fr...

ergot··on Ask HN: What is the best Linux distro for a development laptop?
Best giving them all a whirl and making up your own mind. A good starting point is The Live CD List[1] website. If you're switching from Windows to Linux for the first time, Linux Mint will certainly smooth the transition for you. Also for newbies, Ubuntu is a great first option.

I usually test distros in a VM instead of installing them on bare metal. So far I have not found a distro specifically tailored to development though, and the question really should be what tools are best for development?

In that case, Emacs/Vim[2] would be a good start, and being able to develop without an Internet connection helps harden your coding ability too as you're not so reliant on the solutions of others. Go for one day of coding without Stack Overflow/Google and see how you fare.

[1]: http://livecdlist.com/

[2]: https://stackoverflow.com/questions/1430164/differences-betw...

ergot··on Ask HN: Should I blog on Medium for my open-source project, or self-host?
It will eventually end up on Archive.org. Self hosting is not an antidote to this I think, and sometimes the free services like Wordpress/Blogger last longer.

In the end, there is no escape from bit rot, yet things like IPFS[1] are trying to solve this.

[1]: https://github.com/ipfs/ipfs

ergot··on Ask HN: Kicking off 2017, what’s your favourite browser?
I use them all, because I have a 1TB Samsung SSD with the Xen hypervisor running on it, which means I can dedicate whole operating systems to specific browsers. Each browser has its own 'unique selling point' and I use each browser according to my needs.

-Firefox for privacy

-Tor Browser Bundle for enhanced privacy

-Brave for micropayments

-Vivaldi for customization/tweaks and reading the news

-Chrome because it's ultra fast

-Microsoft Edge just because I can

ergot··on Ultrasound Tracking Could Be Used to Deanonymize Tor Users
For those looking for an app which uses this technique (so called data-over-audio technology) look no further than Chirp

https://www.chirp.io/

    Enhance your products by integrating with Chirp™
    - the world’s most trusted data-over-audio technology
    used by the leading brands in more than 90 countries
ergot··on Ultrasound Tracking Could Be Used to Deanonymize Tor Users
No. That would be reckless and would compromise Tor Browser Bundle from the outset. By default, the NoScript plugin disallows JS from running globally
ergot··on Ultrasound Tracking Could Be Used to Deanonymize Tor Users
Oh thanks for that! Does TOR honor the hosts file, specifically Tor Browser Bundle? I haven't tried.
ergot··on Ultrasound Tracking Could Be Used to Deanonymize Tor Users
A physical switch is for surety and peace of mind, whereas a software switch you have to be careful, because I don't trust my machine's OS to keep the speakers muted, no matter how much the chain of trust has not been compromised, there's always a weak link somewhere. Physical switches or death.
ergot··on Ultrasound Tracking Could Be Used to Deanonymize Tor Users
A bit of an edge case this. I know for me I mute my speakers permanently when using TOR in-case I encounter a shock page like Lemon Party or Goatse

[1]: https://en.wikipedia.org/wiki/Shock_site

ergot··on Ultrasound Tracking Could Be Used to Deanonymize Tor Users
Another reason to disable JS whilst surfing with Tor Browser Bundle. This article mentions the HTML5 Audio API - Something that should be stripped entirely from Tor Browser Bundle (TBB), but instead stays because TBB shares too much code with Firefox.

Also there's nothing stopping someone simply muting their speakers, or physically removing the speaker from their system if they can (some BIOS chips allow this, aswell as physically turning off the camera)

ergot··on Ulterior States (2015) Cypherpunks, Bitcoin and changing the world through tech
https://www.youtube.com/watch?v=yQGQXy0RIIo

One of my favorite documentaries on Bitcoin. Worth watching / listening to Andreas M. Antonopoulos talks on youtube too. He's the only person who could describe the inner workings of Bitcoin that I could understand

ergot··on I Know What You Download on BitTorrent
Unreliable Informants: IP Addresses, Digital Tips and Police Raids https://www.eff.org/wp/unreliable-informants-ip-addresses-di...

An IP address is not grounds for proof anymore. It's like saying every citizen is assigned their own IPV4 address, which is likely wrong, as more often than not an IPV4 address is shared by a pool of users.

ergot··on I Know What You Download on BitTorrent
https://en.wikipedia.org/wiki/Carrier-grade_NAT

    Carrier-grade NAT (CGN), also known as large-scale NAT (LSN),
    is an approach to IPv4 network design in which end sites,
    in particular residential networks,
    are configured with private network addresses that are translated
    to public IPv4 addresses by middlebox network address translator
    devices embedded in the network operator's network,
    permitting the sharing of small pools of public addresses among many end sites.
    This shifts the NAT function and configuration thereof from the customer premises to the Internet service provider network.
ergot··on I Know What You Download on BitTorrent
Interestingly despite the advice given by the Tor website 'Don't torrent over Tor', people still do this:

https://check.torproject.org/exit-addresses

ergot··on Encryption App ‘Signal’ Fights Censorship with a Clever Workaround
The idea behind obfsproxy is that you don't want it looking like port 443 on the wire. You can infact mask the traffic using the domain fronting technique providing you setup obfsproxy correctly. I haven't tried it myself, but I have analyzed Tunnelbear's 'ghostbear' feature with wireshark and the traffic looks fairly innocuous which is what we're aiming for.

https://community.openvpn.net/openvpn/wiki/TrafficObfuscatio...

ergot··on Encryption App ‘Signal’ Fights Censorship with a Clever Workaround
Here's a detailed overview of so called 'domain fronting' https://www.bamsoftware.com/papers/fronting/

Some VPNs use a module called obfsproxy which uses the fronting technique. One VPN service I recall using it is called Tunnelbear. You can read more about this feature here: https://help.tunnelbear.com/customer/en/portal/articles/2435...

This is not an endorsement of Tunnelbear, I just thought it would be noteworthy mentioning that VPN services offer this now to thwart censorship.

Page 1 of 2Next →