HNHacker News
TopNewBestAskShowJobs

jwcrux

2,276 karma · joined January 3, 2013

Website: http://jordan-wright.com Twitter: https://twitter.com/jw_sec
submissionscomments
jwcrux··on I don't like passkeys
How do you see passkeys as a walled garden but not 2FA? You presumably store your 2FA seed in a password manager.
jwcrux··on RAG Logger: An Open-Source Alternative to LangSmith
How is this a replacement for LangSmith? I browsed the source and I could only find what appear to be a few small helper functions for emitting structured logs.

I’m less familiar with LangSmith, but browsing their site suggests they happen to offer observability into LLM interactions in addition to other parts of the workflow lifecycle. This just seems to handle logging and you have to pass all the data yourself- it’s not instrumenting an LLM client, for example.

jwcrux··on Working with PaloAlto to identify CVE-2024-2550
I feel like I’m missing something.

Isn’t this blog post effectively “we patched our firewall, things broke, we made a support case, and the vendor investigated and filed a CVE”?

jwcrux··on Schwab users are unable to log in
Vanguard is also affected for me.
jwcrux··on Solar
Oh wow, gridstatus is super cool!

I noticed that you have a page on records that have been set. It looks like Ercot released this data today that might be of interest: https://www.ercot.com/news/release/2023-09-14-ercot-provides...

I’m curious why there appears to be a pretty significant delta between their data and yours.

Also, if you’re open to suggestions, I had trouble finding the pricing for gridstatus. Entirely possible I was missing something obvious, but I wanted to see how much it might cost to get the long term Ercot generation-by-source dataset and couldn’t seem to get a clear answer.

Regardless, building things like this takes a ton of effort, and I appreciate all you’re doing. Keep up the great work!

jwcrux··on Launch HN: Gravitl (YC W22) – VPN Platform Based on WireGuard
Congrats on the launch! Could you expand a bit on how you differentiate your product from other products in the space like Tailscale and Nebula?

Edit - I see you mention that Tailscale uses userland WireGuard. Is that the biggest difference between the two? Do you foresee yourselves running into issues by not using the userland implementation?

jwcrux··on Hospital exec says employees are walking off the job
> - Healthcare staff have great animosity towards the unvaccinated patients.

In addition to this, I’ve also heard anecdotally that many of the unvaccinated (by choice) patients have animosity towards the healthcare workers themselves because the patients see this virus as politicized.

Overall I can imagine that it’s resulted in a more-hostile-than-average working environment which is bound to be stressful.

jwcrux··on Poll: Will you take the Covid vaccine?
We also don't know what the effects of covid are in 10 years.
jwcrux··on Hunting for Malicious Packages on PyPI
> "So I need to check for-"

That's the thing. If we're watching syscalls, we see these checks. These would be things like attempted file-reads. Would they be enough to set off alarms? Maybe, maybe not.

This is generally the cat/mouse game of malware detonation in general. There are attempts to make sandboxes appear realistic, but I'd argue that our use case is even simpler since running commands or making network connections during installation is not a normal thing. It might be benign, but it's abnormal enough to warrant investigation.

There will always be ways to try and get around the system, but I'm pretty firm that this will significantly raise the bar which is a Good Thing.

jwcrux··on Hunting for Malicious Packages on PyPI
So there are two things to consider here:

1) The “observable window” is the entire installation time. If they make installs take forever, that’ll affect everyone which should raise alarms pretty quick.

2) The conditional execution is possible but the installation is done using a vanilla alpine container which will match many legitimate hosts too. And any fingerprinting activities that involve syscalls would be detected in the process.

All this to say, there’s always room to continue raising the bar!

jwcrux··on Hunting for Malicious Packages on PyPI
I've been in touch with folks from the Open Source Security Foundation [0] who is interested in making this a centralized service.

I'm a big believer that functions like this should be centralized under a foundation like that, and have really close connections to package manager maintainers so that we can work together towards solving the problem.

[0] https://openssf.org/

jwcrux··on Hunting for Malicious Packages on PyPI
Hey friends! Author here.

If you're looking for a tl;dr you can find one on Twitter (with pictures!) [0]

This research was a blast to do, and I learned a ton. Happy to answer questions!

[0] https://twitter.com/jw_sec/status/1326908628411047937

jwcrux··on Go in Production – Lessons Learned
You almost certainly don't need a web framework. Over the long term, it's easy to find yourself boxed in with how opinionated many of them are.

Instead, if you build on the standard library, you can compose your application from there- a good muxer, some standard middleware that are generic http.Handler's, a session library, etc.

jwcrux··on SRE Teams: Hash
> Hash is a Brazilian fintech building the next-generation of payments infrastructure.

In general I agree with the point you're making, though.

jwcrux··on Crypto scammers piggybacking Trump’s Twitter, cloning Medium, stealing crypto
This is a scam that has been going on for years that has adapted its techniques over time.

We used this botnet as a case study back in 2018 when doing analysis on finding Twitter bots at a large scale. You can find the paper here [0] - the cryptocurrency scam botnet starts on page 28. You can also find the talk here [1] where we go into a little more detail. In full irony, someone tried sharing our research on Twitter, and one of the bots replied to the thread trying to spread the scam.

[0] https://duo.com/assets/pdf/Duo-Labs-Dont-At-Me-Twitter-Bots....

[1] https://www.youtube.com/watch?v=bQsRg0VsYoo

jwcrux··on Cloudflare One
You can find details on it here [0]

> S2 Systems NVR technology intercepts the remote Chromium browser’s Skia draw commands, tokenizes and compresses them, then encrypts and transmits them across the wire to any HTML5 compliant web browser (Chrome, Firefox, Safari, etc.)

[0] https://blog.cloudflare.com/cloudflare-and-remote-browser-is...

jwcrux··on I asked an online tracking company for all of my data (2018)
Nice! I did the same recently, where I requested my data from 14 different location data companies. [0] One company returned my data. Part of the difficulty was making the CCPA requests since I live in Texas, but the majority of responses were along the lines of having no way to identify the person behind the device identifier.

https://duo.com/labs/research/data-companies-are-watching-me

jwcrux··on How HTTPS Works
I love seeing comics like this that aim to show concepts in simple ways. Kudos!

Worth noting that "The Handshake" episode [0] covers the key exchange using RSA. This has the downside that it doesn't support forward secrecy, meaning if an attacker ever compromises the server's private key they can retroactively decrypt traffic they previously captured.

It's more common these days to use an ECDHE exchange in which the client and server exchange keys that are generated just for this session (or at least, they should be [1]) and use those to generate the "shared secret".

In fact, in TLS 1.3 ECDHE is the only key exchange mechanism. [2]

The server then uses its long term keypair corresponding to the certificate to sign all the handshake messages that were seen previously [3].

[0] https://howhttps.works/the-handshake/

[1] https://raccoon-attack.com/

[2] https://blog.cloudflare.com/rfc-8446-aka-tls-1-3/

[3] https://tools.ietf.org/html/rfc8446#section-4.4.3

jwcrux··on Twitter hides Donald Trump tweet for “glorifying violence”
It is low. Estimates [0] put the number closer to 500M/day.

[0] https://www.internetlivestats.com/twitter-statistics/#source...

jwcrux··on Ask HN: What were the things you did that made the biggest impact at your work?
You’d love _The Unicorn Project_ if you haven’t read it. I highly recommend it, and it’s a story around roughly the same journey.

https://www.amazon.com/Unicorn-Project-Developers-Disruption...

jwcrux··on Building a Simple VPN with WireGuard with a Raspberry Pi as Server
I run both on my Pi4 and still have plenty of resources to spare.
jwcrux··on Gophish: An open source phishing toolkit
When I first launched Gophish a few years ago, I sent an email to a reporter I'm a fan of basically saying "Hey, I made this thing, I think your readers would benefit from it".

Their response was lightheartedly asking me if I really just sent them an email about a phishing simulation toolkit and expected them to click the links in the email :D

jwcrux··on Gophish: An open source phishing toolkit
You're absolutely right, and I highly recommend Duo Insight! While I developed Gophish, I also work at Duo so I'm happy to discuss the differences between the two. :)

While my experience with Gophish was one of the things that brought me to Duo, Insight is not based on Gophish at all. I had the privilege of working with the team of engineers who built Insight and they are amazingly talented. It's a really high-quality product from an incredible team.

You hit the nail on the head as to why someone may prefer Insight to Gophish. Gophish, while being easy to set up, still requires _some_ setup and hosting. With Insight, everything is managed for you. This has significant time savings and infrastructure savings.

The downside to this is flexibility, which is what Gophish offers. Insight offers a good few pre-built templates while Gophish lets you create your own. You control everything and have the ability to tailor phishing campaigns exactly how you want them. Gophish was also built from the ground-up to be driven by an API, and has other features that may useful in more red-team scenarios (such as credential capture).

The other benefit to Gophish that you mentioned is that, since you control the infrastructure, you control all of the data end-to-end.

So while they're in a similar space, they're pretty different products with different strengths and weaknesses. If you're just starting to look into running a phishing simulation, I'd lean towards giving Insight a shot since it's super quick and easy to get a campaign out the door. Once you need more flexibility and power, Gophish is an easy transition. :)

jwcrux··on Gophish: An open source phishing toolkit
I think I can still do a better job of pointing people who hit the repo first back to the website for more information. Right now, it’s linked, but it could be more clear.

I’ll take that as an opportunity for improvement. Thanks so much for taking the time to type out that feedback!

jwcrux··on Gophish: An open source phishing toolkit
Thank you for the feedback! It’s really appreciated.

Just out of curiosity, does the copy on the main website [0] give a better indication or does that still not make for a clear description?

I ask because, while the repo was linked in this case, the main website is where most people land.

[0] https://getgophish.com

jwcrux··on Gophish: An open source phishing toolkit
Guilty as charged :) in this case, I thought it made for a nice name, giving a nod to the old card game “Go Fish”.
jwcrux··on Gophish: An open source phishing toolkit
Nice! While Gophish is a personal project, as part of $dayjob I do security research.

Recently, I did some analysis on phishing kits at a pretty large scale that sounds like it’d be of interest to you [0]

[0] https://duo.com/assets/ebooks/phish-in-a-barrel.pdf

jwcrux··on Gophish: An open source phishing toolkit
Thank you so much!

I view Gophish as a way to volunteer and give back to the larger security community. I love engaging with the Gophish community and seeing people use the software to measure their own exposure to phishing.

That said, there aren't any plans to monetize Gophish. It will always stay free and open-source so that anyone can use it. :)

As far as support, I try and respond to every issue as fast as possible. It's a best effort, but I managed to pass 1k closed issues recently, which I was pretty proud of! And I'm fortunate that there are so many amazing people in the Gophish community who are willing to jump into issues, help out, and bounce great ideas around.

jwcrux··on Gophish: An open source phishing toolkit
Hi everyone!

What a happy surprise to see my project on HN :)

My name is Jordan, I've been developing Gophish [0] for a few years now. The goal of the project is to let companies of all sizes perform high-quality phishing simulation regardless of their security budget.

Happy to answer any and all questions!

[0] https://getgophish.com/

jwcrux··on The Bell System Technical Journal
I highly recommend reading The Idea Factory. It's a fascinating historical account of Bell Labs and how they performed research.
Page 1 of 8Next →