HNHacker News
TopNewBestAskShowJobs

hn-miw-i

43 karma · joined November 9, 2012

submissionscomments
hn-miw-i··on Hardening your Web Server's SSL Ciphers
Don't know if I agree re RC4; BEAST is an issue with CBC, not AES. AES-GCM should be ok, if not superior to the ancient RC4.
hn-miw-i··on Evasi0n iOS 6.x jailbreak
The most important part of jb for me is the ability to run an host based firewall, and have per application rules. I use FirewallIP on iOS 5, I hope it works on iOS 6. I block hundreds of ad and tracking servers as global policy. This functionality doesnt exist on android... I've yet to find anything except moxies firmware for the nexus (now MIA) that has this.
hn-miw-i··on No, I'm not going to download your bullshit app
I find the default iOS popup advertising an app the worst part, by large the app offers extra functionality over the web. the popup disrupts the experience and I also have the same feelings of rage on random site for some random stupid bullshit app.

The compass in the iPhone for example, does device allow a web server query the phones heading through browser? Offline modes and caching are features not really possible with the browser.

As for the giving something up, open public web access to proprietary apps, this is very true. I don't see big content moving away from the web though, the app ecosystem seems to compliment it.

hn-miw-i··on Google has indexed thousands of publicly accessible HP printers
One million trees just died. The problem with some of the earlier HP printers was that they would accept unsigned firmware updates, you could literally reflash the thing with an update instruction in postscript.

Some work was done at Columbia University with developing trojanised firmware, i recall a firmware that could transmit CC# over tcp when it saw then in the print stream.

Extreme care must be taken if connecting printers to the Internet. It's at best a horrible idea and I'd say that most of these are unknown to their owners. Hopefully this gets some MSM coverage and people address the connected printer problem forever. (not likely)

hn-miw-i··on Facebook is impersonating users without their consent
If anyone is reading this, and they use facebook, get the hell off there. Delete your account today. They will always take take take. The most egregious of these kind of rights violations 4 years ago is today's standard practice. They will only get worse and drag the rest of the web down to their new lows. "Do be evil" is the motto of Zuckbergs ilk.
hn-miw-i··on Youth expelled from Montreal college after finding security flaw
It's likely to be an application logic authorization bug; the application doesn't check the context to see if it should return that info. Being web it's something silly like the student-id stored in the user cookie is used to to build the (parameterized) SQL statement. It's not arbitrary injection per say.
hn-miw-i··on Youth expelled from Montreal college after finding security flaw
Problem is he used an auditing/penetration testing tool POST disclosure, and did it without authorization. The availability of these tools puts weapon grade exploits in the hands of those with limited understanding of the consequences. I don't have an issue with the availablity -- best we lighten our history with Full Disclosure and provide best of breed tools to simulate attackers -- however, responsibility and individual accountability is at an all time low. These tools will light up the alarms immediately and the user will have limited understanding.

Let's assume it was not SQLi but an authorization application logic bug ie: by changing parameter passed by browser allowed access to whole record set. He did the right thing and told the vendor -- but after the fact he ran a tool that probably simulated SQLi on every damn parameter! Like smashing a car window after telling the owner he has left it unlocked.

Even a brain dead sysadmin would notice it In the logs, and likely whatever SIEM would fire a high priority alert.

He did this without auth and the company did the right thing here. In this post aaronsw world we can't just assume that every n00b clown whitehat hacker is totally innocent of all crimes even if done with the best intentions. People need to take responsibility for their actions. An ignorant click can be just as criminally negligent as stabbing a dude in the face.

hn-miw-i··on Oculus Rift Will Change Your Gaming World
Except for the remake of total recall... That sucked!
hn-miw-i··on MailChimp Annual Report
Ugh mail chimp. Isn't it incorporated in Belize? Former home of John "badass mutherfucker" McAfee? Home of endemic corruption from highest levels of government? And we hand over our email addresses? What?
hn-miw-i··on Your Culture Is Your Brand
Nice sentiment but I might be that 1% that pockets that $2k after 4 weeks of corporate brainwashing.

Also this is a blog post from 2009 you should tag the article title (2009).

hn-miw-i··on If I get hit by a truck...
The need for a digital probate policy seems very important.

He based this his from esr, and the link to esr is now broken. Is there a central clearinghouse for thes documents? A digitally signed will should be far harder to forge and could be legally binding. To see ones digital wishes be fulfilled from the afterlife should set some tormented spirits to rest.

hn-miw-i··on Ask HN: Can use the #1 supercomputer for any project I want. What should it be?
How did you calculate that? Those units don't quite work out. It's a totally different architecture to your standard i7/radeon home mining rig.
hn-miw-i··on Ask HN: Can use the #1 supercomputer for any project I want. What should it be?
Efficency is mostly about the cost of the hardware (purchase and running costs), power usage and performance. Purchase, running cost and power usage are not part of your efficiency calculation.

ATI cards have traditionally had better hashing (in general, rainbow table gen, jtr, BTC) because they have a larger number of Execution Units per core, however clocked slower, than the nvidia. Higher number of EU allows better exploitation of parallelism important for the performance of hashing.

This is the fastest damn computer, its not a brand loyalty GM vs Ford, Coke vs Pepsi, Android vs iOS duality. Oh it's got nvidia, not optimized for hashing. It's going to kick the arse of any consumer or professional grade GPU on the market...

hn-miw-i··on Ask HN: Can use the #1 supercomputer for any project I want. What should it be?
Ok well blocks generate at an average of 1 / 15 minutes, so about 96 blocks a day.

Each block generate 25 BTC reward. At ~14.00 USD/BTC on MtGox right now that about $34k.

So the maximum reward in USD if you could totally control the block chain per day is $34,000. Compare hashing rate of your super computer to total mining hash rate of the btc mining swarm and that is your fraction of 34,000.

hn-miw-i··on Ask HN: Can use the #1 supercomputer for any project I want. What should it be?
Say this to the super computer administrators: "im doing pure compsci research; im attempting to find alternative implementations of one-way trapdoor functions to optimize proof of work validations" then spend the next time tuning your mining bot and pocket the 14.17 USD/BTC you generate. For research!
hn-miw-i··on Ask HN: Can use the #1 supercomputer for any project I want. What should it be?
Bitcoin. Pay off your student loans one Merkle tree at a time.
hn-miw-i··on Nokia: Yes, we decrypt your HTTPS data, but don’t worry about it
Nokia pushed out an update that uses an http proxy for Phone to server TlS. The worst thing about this is that they have diluted their security model (tls in tls is resistant to single interception-- ie tor).

They did this so boneheads that sniff the traffic will see the phone to server TLS rather than having it encrypted inside the phone to Nokia TLS. That's ignorant "researcher" you actually made it easier for the bad guys now.

hn-miw-i··on Nokia: Yes, we decrypt your HTTPS data, but don’t worry about it
Nokia is not intercepting your https! They are doing nothing dodgy here.

Everyone who says "https interception" is hard, you are right. Unless you can install arbitrary trusted root He has presented no evidence of this. All he did was sniff the wire and saw a TLS session to Nokia. It's called an https proxy, genius. Ugh. This mAkes me so mad that people believe this crap.

hn-miw-i··on Nokia: Yes, we decrypt your HTTPS data, but don’t worry about it
http://gaurangkp.wordpress.com has this completely wrong. I wished he had published my comment on his blog (I was first post).

Nokia is NOT intercepting https. The actual TLS session is run via a https proxy. No interception occurring. The guy who broke this has no understanding of the TLS protocol or PKI in general. He tried to say the root verisign certs in windows were being proof. bullshit.

its 2 TLS sessions -- or TLS in TLS proxy. No problem. Go back to sleep.

hn-miw-i··on Patent trolls want $1,000 per employee for using scanners
Powerful and Popular? Oh I see you mean China! Patents don't mean too much there...
hn-miw-i··on StartChart - Growth metrics for 1,724 Australian startups
Is bugmenot and retailmenot Australian? I can find references to an American company whaleshark. The rest I find of dubious value as I am not in their target market. I find the Australian startup scene as mostly a poor copy of US projects from 6m-2y ago. New ideas don't stay down under for long.
hn-miw-i··on The Most Dangerous Equation [pdf]
Really interesting paper but the use of comic sans on the axes labels is a turn off. Why comic sans?? Why? It's a crime against fontology.
hn-miw-i··on Free UI PSDs for Smartphones
I noticed Microsoft was doing this too, publishing psd templates for its smart devices.

Problem being that psd is horribly proprietary, all that matters is the geometry, right? Why not use open graphics formats?

hn-miw-i··on Dear ITU, please don't bill Internet use like phone calls
Despite efforts of the EU and the ITU to put the Internet genie back in her bottle, she grows louder and prouder every day. She is still in her formative days, as the old world money tries to tame her radical free spirit. Let's hope decisions made by old men in new Dubai doesn't keep her from constantly changing humanity.
hn-miw-i··on McAfee’s Third World Travel Guide
Absolutely fascinating. Very helpful advice that you wouldn't read in a mainstream travel guide. Unfortunately corruption is everywhere and knowing how to respond and knowing the local customs is very important if you wish to keep your skin.

Johns tale grows more epic every day and I am really looking forward to the comic/graphic novel. McAfee is a true adventurer and I hope the injustice of his ordeal is broug to light.

hn-miw-i··on You are committing a crime right now
Doesnt have to be transmitted in the clear; that's exactly what TLS does; allows usernames and passwords to be transmitted with encryption so only the other party can recover them.
hn-miw-i··on Australian Bank Anonymizes and Releases Billions of Records
Interesting, as a customer of ubank I was concerned with the concept, especially after the data deanonymization techniques developed post AOL and Netflix.

However after using the site and entering my demographics (all public properties) I could see that I was like 56 people in area; their base spending patterns did not reflect me at all and I felt like a snowflake. Sometimes big data makes you feel special.

At no time was I shown transactions, merely aggrigate figures in categories. No privacy issue here, keep being decent and ethical national bank!