43 karma · joined November 9, 2012
The compass in the iPhone for example, does device allow a web server query the phones heading through browser? Offline modes and caching are features not really possible with the browser.
As for the giving something up, open public web access to proprietary apps, this is very true. I don't see big content moving away from the web though, the app ecosystem seems to compliment it.
Some work was done at Columbia University with developing trojanised firmware, i recall a firmware that could transmit CC# over tcp when it saw then in the print stream.
Extreme care must be taken if connecting printers to the Internet. It's at best a horrible idea and I'd say that most of these are unknown to their owners. Hopefully this gets some MSM coverage and people address the connected printer problem forever. (not likely)
Let's assume it was not SQLi but an authorization application logic bug ie: by changing parameter passed by browser allowed access to whole record set. He did the right thing and told the vendor -- but after the fact he ran a tool that probably simulated SQLi on every damn parameter! Like smashing a car window after telling the owner he has left it unlocked.
Even a brain dead sysadmin would notice it In the logs, and likely whatever SIEM would fire a high priority alert.
He did this without auth and the company did the right thing here. In this post aaronsw world we can't just assume that every n00b clown whitehat hacker is totally innocent of all crimes even if done with the best intentions. People need to take responsibility for their actions. An ignorant click can be just as criminally negligent as stabbing a dude in the face.
Also this is a blog post from 2009 you should tag the article title (2009).
He based this his from esr, and the link to esr is now broken. Is there a central clearinghouse for thes documents? A digitally signed will should be far harder to forge and could be legally binding. To see ones digital wishes be fulfilled from the afterlife should set some tormented spirits to rest.
ATI cards have traditionally had better hashing (in general, rainbow table gen, jtr, BTC) because they have a larger number of Execution Units per core, however clocked slower, than the nvidia. Higher number of EU allows better exploitation of parallelism important for the performance of hashing.
This is the fastest damn computer, its not a brand loyalty GM vs Ford, Coke vs Pepsi, Android vs iOS duality. Oh it's got nvidia, not optimized for hashing. It's going to kick the arse of any consumer or professional grade GPU on the market...
Each block generate 25 BTC reward. At ~14.00 USD/BTC on MtGox right now that about $34k.
So the maximum reward in USD if you could totally control the block chain per day is $34,000. Compare hashing rate of your super computer to total mining hash rate of the btc mining swarm and that is your fraction of 34,000.
They did this so boneheads that sniff the traffic will see the phone to server TLS rather than having it encrypted inside the phone to Nokia TLS. That's ignorant "researcher" you actually made it easier for the bad guys now.
Everyone who says "https interception" is hard, you are right. Unless you can install arbitrary trusted root He has presented no evidence of this. All he did was sniff the wire and saw a TLS session to Nokia. It's called an https proxy, genius. Ugh. This mAkes me so mad that people believe this crap.
Nokia is NOT intercepting https. The actual TLS session is run via a https proxy. No interception occurring. The guy who broke this has no understanding of the TLS protocol or PKI in general. He tried to say the root verisign certs in windows were being proof. bullshit.
its 2 TLS sessions -- or TLS in TLS proxy. No problem. Go back to sleep.
Problem being that psd is horribly proprietary, all that matters is the geometry, right? Why not use open graphics formats?
Johns tale grows more epic every day and I am really looking forward to the comic/graphic novel. McAfee is a true adventurer and I hope the injustice of his ordeal is broug to light.
However after using the site and entering my demographics (all public properties) I could see that I was like 56 people in area; their base spending patterns did not reflect me at all and I felt like a snowflake. Sometimes big data makes you feel special.
At no time was I shown transactions, merely aggrigate figures in categories. No privacy issue here, keep being decent and ethical national bank!