HNHacker News
TopNewBestAskShowJobs

fname

930 karma · joined July 29, 2009

Based in Northern VA, DC Area
submissionscomments
fname··on Bomb threat causes mass evacuation at DEF CON hacking convention
Allegedly owned by someone that attended the DEFCON Shoot event where gun powder was transferred to the package, tipping a dog doing a random search in the Forums.
fname··on Microsoft has detected nation-state activity associated with NOBELIUM
This might help: https://www.securityweek.com/whats-threat-group-name-inside-...

For Microsoft specifically, we leverage the periodic table of elements when naming nation states.

fname··on Yahoo discloses hack of 1B accounts
Maybe that can get Verizon another $1B discount.
fname··on OS X is now macOS and gets support for Siri, auto unlock
Tabs across all windows, all apps.
fname··on Microsoft Cloud Strength Highlights Second Quarter Results
> Personally, I'd never put a MS project between me and the cloud, or my data and the cloud

Why?

fname··on Apple Unveils the iPad Pro
+ the pencil @ $99 and the smart keyboard at $169. > $1k for the entry level model to be comparable with the Surface Pro 3 at ~$930 (which starts at 64GB, btw).
fname··on “EPIC” fail–how OPM hackers tapped the mother lode of espionage data
> but DISA can't enforce STIGs across the entire government can they?

No, with a small caveat: If that civilian agency (say DHS) is connected to the GIG[1], then DISA has a say-so and can threaten to disconnect them for failing security audits.

Something to keep in mind is that the STIGs are merely implementation guides to secure a system. Therefore, different agencies have different interpretations. In some cases specific secure implementations break systems and applications (mostly legacy ones), so they avoid securing those particular settings all together.

1: https://en.wikipedia.org/wiki/Global_Information_Grid

fname··on “EPIC” fail–how OPM hackers tapped the mother lode of espionage data
I don't disagree. Unfortunately, this all falls on DoD-DISA. The NSA works with DISA to write the policy for how to secure systems (called STIGs) and also has 'Red Teams', but they aren't the arm that certifies these systems before coming online, nor are they the ones the ensure the systems stay secured as new vulnerabilities are found and patched -- that's DISA again.
fname··on Cardinals Face F.B.I. Inquiry in Hacking of Astros’ Network
I'm guessing they mean they had a break-glass list of passwords for accounts to access those systems.
fname··on Hello World: Windows 10 Available on July 29
> Also on whether WinXP users are going to qualify for the free upgrade?

Nope. There is no upgrade path from XP -> Windows 10. You will have to go from Win7/8 to qualify for the free upgrade to 10.

fname··on Hello World: Windows 10 Available on July 29
Yes, both can be disabled. However, I'm not sure if it's dependent upon which 'edition' though. For example, you can turn it off in Enterprise, but not Professional.
fname··on [dead]
That links to the Surface Pro 3, which has been out for sometime now. You wanted: http://www.microsoft.com/surface/en-us/products/surface-3
fname··on Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless
This is really great, but the real question is will users actually see this on a default Lenovo OS build? Can anyone confirm that Defender doesn't get disabled in favor or say... McAfee or Symantec?
fname··on Google discloses another Windows security issue after deadline exceeded
From the comments in the article

Microsoft informed us that a fix was planned for the January patches but has to be pulled due to compatibility issues. Therefore the fix is now expected in the February patches.

So, they met the deadline and fixed the vulnerability, but due to compatibility issues had to pull it before being released through Windows Update.

fname··on Microsoft fixes '19-year-old' bug with emergency patch
Depends on the IE Zone settings. I believe that if you set the a zone to 'Low', a web page can execute a VBSCript code, with or without ActiveX being enabled.
fname··on Microsoft fixes '19-year-old' bug with emergency patch
Completely agree, maybe the mods can fix the link.
fname··on Microsoft fixes '19-year-old' bug with emergency patch
> Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data.

I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] the SChannel vulnerability through an internal audit. To me, it seems the research is talking about CVE-2014-6332[3], which shows the patch as MS14-064. MS14-066 is the patch for the SChannel vulnerability.

Either BBC is confused on which patch they're trying to report on, or I am.

Anyone similarly confused as I am?

[1] http://securityintelligence.com/ibm-x-force-researcher-finds...

[2] http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-...

[3] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-633...

fname··on Apple Watch
Was there any mention of how it connects? LTE? WiFi? Did I miss that part?
fname··on SWAT Team Detains Popular Gamer Who Was Live-Streaming ‘Counter-Strike’
SWATTING. Usually the phone call is spoofed so it seems like the call is coming from the building itself.
fname··on Microsoft defends its right to read your email
I fail to see how the two are even remotely the same. Google continuously scans email content to sell ads; while Microsoft does it once and admits it so they can catch someone stealing trade secrets.

While I agree that the Scroogled campaign does tread slightly into the hyperbole, I can't agree that this the double-standard that most are making it out to be.

fname··on Ex Microsoft staffer arrested for allegedly stealing Win 8 trade secrets
"...also alleged to have stolen Microsoft’s “Activation Server Software Development Kit,” a propriety system used to prevent the unauthorized copying of Microsoft programs."[1]

And another expansion on what the leak could allow:

"According to the reports, not only was Windows 8 leaked, but he also leaked Windows 7 files and the Microsoft Activation Server Software Development Kit which when reverse engineered, could allow hackers to crack the Activation process within Windows, meaning that pirated copies of Windows 7 could continue to function without the nagging presence of popup messages warning users about their copy of Windows."[2]

[1]: http://www.seattlepi.com/local/article/Ex-Microsoft-employee...

[2]: http://www.ubergizmo.com/2014/03/microsoft-employee-responsi...

fname··on Cops find five Indian Ocean practice runways in MH370 pilot’s simulator
I didn't see anything in the news... Was KUL-PEK a normal route for this pilot? Makes a lot of sense to have and practice on runways in the area you take off or land into the most.
fname··on Malaysia Airlines Says It Lost Contact With Plane Carrying Over 200
EDIT: The Guardian has a pretty good live blog feed giving constant updates - http://www.theguardian.com/world/2014/mar/08/malaysian-airli...

Very sad. Only the third crash of a 777 since being introduced in the 90s.

[1]Confirmed 14 nationalities amongst the passengers, including:

    China - 153 (including 1 infant)
    Malaysia - 38
    Indonesia - 12
    Australia -7
    USA - 4 (including 1 infant)
    France - 3
    Canada - 2
    New Zealand - 2
    Ukraine - 2
    Russian - 1
    Italy - 1
    Taiwan -1
    Austria - 1
    Netherlands - 1
[1]: http://www.malaysiaairlines.com/my/en/site/dark-site.html
fname··on Asiana Airlines Flight 214: A Pilot’s Perspective
Because each driver is not responsible for 300 lives in their cars. That's why there is so much attention to plane crashes. It doesn't kill one person at a time.

Right.. and this crash only killed 2 people. Perhaps one if the reports of the girl being hit by a rescue vehicle are believed; so what's your point? The real story is just how better aircraft safety has come over the years. This same accident years ago could very well have killed everyone aboard.

Just like the AF447 crash between Rio and Paris: Pilots incompetence at its best.

...and a week after this accident everyone was blaming the weird weather that happens at the equator for the crash. The point is that everyone is speculating, even you, that this this accident is the pilot's fault, but more often than not it's found to be a combination of mechanical failure and the pilot not being able to respond to it quickly enough -- which just so happens to be the official cause of AF447 crashing in 2009.

fname··on Senator: Firm that vetted Snowden under criminal investigation
They had to!

Not too long ago, there would be a 8-10 month wait just to get an interview with someone to just kick of the individual investigation. The investigations themselves can can many, many more months after that. By allowing contracting firms and outsourcing, they've significantly lessened the wait. Unfortunately, it's coming with the cost of rampant fraud, waste and abuse (at least form what the article is asserting).

fname··on SimCity mod demonstrates the possibility of offline play
Not true. The actual Reddit[1,2] posts the article pulls this from says they have been able to sync their game to the servers. It seems that when offline, it saves it locally and uploads upon reconnect. He was able to remove the 20 minute timeout disconnect, but it still saves things locally and uploads upon reconnect.

1. http://www.reddit.com/r/SimCity/comments/1a9n5j/you_can_edit...

2. http://www.reddit.com/r/Games/comments/1a9t0e/simcity_modder...

fname··on How Lockheed Martin's 'Kill Chain' Stopped SecurID Attack
Totally agreed. A quick search turned up this White Paper written by a few LMCO employees (PDF):

Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains -- https://www.vita.virginia.gov/uploadedFiles/VITA_Main_Public...

fname··on Xbox 360 Sold More Units Than The Nintendo Wii U In November
Not sure how that makes much of a difference, other than the fact that they still chose to purchase a 360 over the PS3 or Wii U after such a hardware failure.
fname··on Microsoft Screwed Up In-App Purchasing on Win8
Do you have a CC tied to your account?
fname··on Under the hood of Windows 8, or why desktop users should upgrade from Windows 7
I see your point, but I would argue that a tablet and PC have more common use cases and would benefit from using the same OS.
Page 1 of 8Next →