HNHacker News
TopNewBestAskShowJobs

insomniasexx

35 karma · joined August 6, 2010

submissionscomments
insomniasexx··on Detailed audit of Voatz' voting app confirms security flaws
We can't secure banking, there are just a lot of undo processes, holds, and internal processes and cross-comms that make it so people don't lose all their money all at once and potential losses can generally be reversed, insured, bailed out, covered by someone else, or balanced out / hedged against. Even with that, fraud is rampant and heists worth billions do still occur digitally[1]. And these are financial systems that evolve constantly over centuries at this point. And the attackers still win sometimes.

The biggest thing the measures do is significantly decrease the known ROI on a target. For example, a credit card can be cancelled. Even if the bank doesn't notice and the person doesn't notice and you do get 100k off it, the fact attackers don't know that still reduces the value of the stolen credit card and therefore the incentive to steal them. Further the gain of 100k by an attacker may be split amongst cardholder, card issued, insurance, merchants, etc. so no one person actually loses 100k. These things all matter when building and securing new systems.

If you look at the cryptocurrency space in general, you can see what happens when you replace a credit card or swift with transactions that are similtaneously immutable, very valuable, and easily anonymous enough. The monetary value on anyone's Coinbase account, let alone all the Coinbase accounts, is so high that we've seen attacks[2] usually reserved for nation-state actors and by actual nation state actors[3], including sophisticated + targetted zero-days and bgp hijacks and all sorts of fun stuff. Not to mention the very high density of attacks that require lower effort and talent like sim swaps, phishing, spear-phishing, impersonation, typosquatting, on and on.

Regardless, if the potential gains to hack a bank are level 1, and crypto exchanges or private keys are a 10, then voting is 1,000,000.

The zero-sum nature of winning an election coupled with the potential gains from doing so are so large and so unfathomable that we have to assume that the lengths people will go to are unfathomably more than everything else we've ever tried to secure. Bc if you can gaurentee a win for a candidate or choose the candidate or change the candidate, you can do anything. You can own anything. You can control anything. You can make any amount of money. The limit is only your talents, abilities, moral compass, and appetite for risk.

To protect against a huge number of attackers, including nation state ones with essentially unlimited resources and the incentive to use those unlimited resources is…it's never been done. Again, back to Coinbase, they secure their crypto with...wait for it…paper. Generated and printed using randomly chosen, single-time, fully-airgapped machines. In a random location. In a Faraday cage.[4] That's how you secure billions when you don't have an undo button. With paper. While not even trusting the electricity flowing thru the cable.

As we saw in the 2016 election, Brexit, and lesser know elections across the globe, it takes very little to secure a win. With the right data (which is even more accessible today than it was in 2016) you only need to manipulate relatively small amount of voters. I'm too lazy to look it up but the numbers were insane when you looked at who was targeted by VoteLeave and Trump's campaign. They may have served 40m ads but it was only to like 40k people.

And that wasn't hacking anything. And those were huge-scale elections. And we still don't know who gained what from their outcomes, just that a lot of people spent a decent amount of money and a huge amount of effort to do so. And it wasn't selfless.

Small towns make gains more obvious. If small town mayor decides who gets the contract for building the new 10M town hall and if you can build it for 5M, you have 4.9M to spend on winning that contract. (Well 5M - resources to rig election - gain required for you to take the risk and put in the effort.) And, given the size of government contracts and their ongoing nature, the financial gains alone are massive. Military contractors: trillions and trillions.[5]

Even securing a single contract early on can ensure your success down the line. Maximus handles tons of Los Angeles welfare programs and now all sorts of programs around the globe. They have for 40+ years. They have billions in annual revenues from doing so. E.g. "In September 2012, the Illinois Department of Healthcare and Family Services awarded Maximus Health Services a two-year, $76.8 million contract to help the state with its Medicaid program. That same month, Maximus announced a $23.5 million contract with the State of Oklahoma."[6] Most of these contracts are decided not by the president but a random group of 5-7 officials at a meeting no one knows about where there is no competition and no real discussion.

Again, these are just a few very, very, very simple incentives people have to manipulate votes. Again, go look at 2016 Trump election or Brexit in depth to understand truly what is currently known about the number of people and the lengths they went to to get an election won. Without hacking. Check back in 40 years after more details emerge. We just don't even know yet.

The reason I have zero faith in any tech being successful in the nearish term with regards to voting is not that I think programmers suck or that politics is corrupt. It's that it's truly unprecedented on an incentives level and risk level. And, it's not just that the risk and potential loss for society or potential gain for attackers is so huge, it's also that we don't even know what it is, and even if we did, we wouldn't be able to comprehend it. How do you secure that when that's what you're up against?

The scope of what we do know about banking fraud, crypto fraud, and paper voting fraud is so great and we are always one step behind attacks and mitigate risk in millions of little ways because we can't fully reduce it. But you can't hedge against election fraud. There's no insurance. There's no undo button. There's no time travel.

And that means that, very unlike financial services, the amount you have to spend to secure an app of this nature is actually one resource more than the attackers are willing to spend to get their way in an election. Or one resource less than the amount lost if an attacker wins. But what even is the value of people, our future, our literal lives? Society, war, money, peace, contracts, the fed, interest rates, all the markets, all the debt, n95 masks, new buildings, old buildings, corruption, legitimacy? We can't know which of these attackers are going after therefore you have to protect against all. And there literally isn't enough resources in the world for that.

Zooming back down to simple: there isn't enough money to even secure an app for a single small town that has a single contract for $10M and will never have another contract and there is, impossibly, no other possible gain for rigging the election. I mean, there literally is enough money. But why spend $1M or $2M or $5M on that app? Why even spend a dollar? Why do so when it doesn't actually reduce all the other risks of election manipulation and corruption that are currently in practice while adding a whole new variety of known and unknown attack surfaces and exacerbates existing ones? You wouldn't. Period.

Why would a company try to build an app knowing this? Well, either they're optimistic and altruistic as fuck and don't know it. Or, second, they are taking advantage of you. Or, third and most terrifying, is the act of building a voting app itself is actually the way to rig the election.

Voatz, without a shadow of a doubt, is not the first. Perhaps the second. But the third? When you consider the timing of Voatz' fundraise, who they raised money from, the goddamn timing, the fact they didn't die when it was discovered they were using old ass php and plesk in 2018, and the fact the app is actually still this fucking completely worthless and insecure and hasn't improved, well, I can't say that it's not an attempt to rig an election but it's def not the US who's doing the rigging. They would go to far greater lengths.[7]

---

1: https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery or great podcast on it for audio lovers https://www.stitcher.com/podcast/mugshot-podcast/mugshot

2: “Responding to Firefox 0-days in the wild” by Philip Martin https://link.medium.com/x8tNj2rc14

3: https://blog.chainalysis.com/reports/cryptocurrency-exchange...

4: https://www.wired.com/story/coinbase-physical-vault-to-secur...

5: https://247wallst.com/special-report/2019/02/21/20-companies...

6: https://en.wikipedia.org/wiki/Maximus_Inc.

7: https://archive.nytimes.com/www.nytimes.com/interactive/2013...

insomniasexx··on Is SHA-3 slow?
The encryption actually is KECCAK-256, not SHA-3. However, if you are using a library built for Ethereum it'll be called SHA-3.

When Ethereum was being developed, the spec for SHA-3 wasn't finished or something: https://ethereum.stackexchange.com/questions/550/which-crypt...

It sounds like you have it under control but I typically point people to Dave @ https://walletrecoveryservices.com/ for the less tech-savvy. He's pretty good. You can look at his site for what he can and can't crack. I know he's super super busy but it never hurts to give him a shout and ask him if he has any pro-tips or open-source code somewhere. A ping from someone who has a basic understanding of encryption might be refreshing.

Here are a random assortment of links I have saved regarding recovering presales:

https://www.reddit.com/r/ethereum/comments/46887p/tips_for_r...

https://forum.ethereum.org/discussion/3045/request-post-pass...

https://www.reddit.com/r/ethereum/comments/3g6aw0/i_lost_my_...

insomniasexx··on Stolen Ethers from MyEtherWallet and IG:shanefr0mmaine
Hey eth_vig,

I'm following trailing from this Ethereum Chamber . net scam shit and was googling addresses and found this post.

Can you get in touch with me when you have a second. Would love to compare notes. taylor at myetherwallet com

Thanks.

insomniasexx··on Website with 1000s of live baby monitors, web cams and CCTV feeds has shut down
I used to be part of a forum that had a massive list of the default login and unprotected cams. There were maybe 10k-20k per document, maybe 5 or 6 documents. As far as I could tell, all were working cams but 99% of the time there was nothing happening. Either they were too dark to see much, pointed at a front door, or showing rooms with no one in them. I personally never saw any movement on any of the cams except for a sleeping puppy.

On the rare occasion someone found a not-empty cam, there would be screencaps immediately. It was like crowdsourced voyeurism before crowdsourcing was a thing. The best one was a guy who was using the camera to monitor his weed grow op. Apparently, according to more knowledgable users on this forum, he was using the lights inefficiently. It sparked a massive debate on the intricacies of grow lights and that's when the thread died.

It was creepy but far less creepy or exciting than I imagined when I first stumbled upon the thread. Still, change your passwords people.

insomniasexx··on The greatest juggler alive quit to open a construction business
This article is much more about the journey of his life and the journey of a journalist to answer the question. The final answer means very little; there are a myriad of reasons he quit. Perhaps you should read the article. It's very enjoyable.
insomniasexx··on A New Online Commmunity: Hubski
I'm on OSX Chrome V 29.0.1547.57 and they are loading. Do you want to upload a screenshot and I'll pass it on to the smart programmer guys to see if it can be fixed?

Is it from Hubski or the linked site? (http://www.astro.uvic.ca/~alexhp/new/figures/starrynight_HST...)

insomniasexx··on A New Online Commmunity: Hubski
Look below the "You are not following anyone yet" and click a name to follow them.
insomniasexx··on Sean Parker Sees a Bright Future for Chatroulette
Chatroulette is too notorious. It would be easier to build a new site with the same basic concept and advertise as SFW.

Plus, instant bans for anything inappropriate. That is what tinychat.com had to do when they wanted to new advertisers. Don't know how they did it but you get IP banned within a minute of getting naked.

insomniasexx··on [dead]
Get him a 12 step book? Be there for him. He can't and won't quit until he wants to. He must make the decision. Aside from throwing him in rehab (like some do here in the US) there isn't much you can do. All you can do is let him know that you love and support him and want him to get better.

Therapy might help him work out his other personal issues which in turn might help curb the binges.

insomniasexx··on Why everyone loves coming up with ideas in the shower
Jeez, the Apple haters around here. When I was 12 I used to poop and play my gameboy color.
insomniasexx··on What Shamu Taught Me About a Happy Marriage
I think I learned more about elephants than relationships. It might have been because I couldn't get past the author's condescending tone and found myself wondering what the husband thought when he read his wife's article in the NYTimes. Did he notice how inferior she makes him seen? The non-witty the comparisons to animals just made it hilarious.

I'm young, I'm female, I don't have the answer to what makes relationships work, but thinking you are better than your partner isn't desirable in a relationship. My man lived a successful life before I came around. Hopefully we make each other better people, but nagging about shaving or talking down to them when they lose the car keys isn't how to improve your spouse.

edit: Am I just being immature and stupid and grouchy that I didn't get anything out of the article?

insomniasexx··on Ask HN: What Sucks About Facebook?
In my opinion, Facebook has some time left but not much. I would guess that a new site will take over within the next 12 months. The transition will be similar to the one we saw a few years back when everyone made the shift from Myspace to Facebook.

Even though I am 20 and in college and am friends with everyone I know in real life, everyone I knew growing up and from summer camps, and many of my internet friends as well, I rarely go on anymore. It used to be a daily activity.

What went wrong? I think it just became so popular, had so many people that it wasn't not interesting anymore. We all have a little hipster in us - once everyone you know and their mother and their grandmother is using something, it starts to lose its appeal.

Lastly, Facebook had too much change. They could have updated it once or twice with fairly big changes and been fine. I noticed that I hated hearing about facebook or going on facebook when they were rolling out new privacy agreements and rearranging the site layout once a week.

There is a big potential for anyone developing the next social networking site. Who knows what aspects will make it popular though.