HNHacker News
TopNewBestAskShowJobs

lessnonymous

560 karma · joined May 27, 2012

submissionscomments
lessnonymous··on Obama administration asks Supreme Court to allow warrantless cellphone searches
I don't see the problem. If I'm selling drugs out of my car and the police have the right to search it, then they have the right to search the paper notebook on the seat next to me. If there's a phone number in there then they can do what they want with it under the law: which could include working out where I live from it.

To search my home they need a warrant. Which means they need probably cause.

How is a cell phone any different? The law shouldn't be about storage capacity! If it is, then you're saying that they can search the 48 page notebook on the passenger seat, but the 128 page is off limits. That's ludicrous.

Now under the 5th, he should have the right not to unlock it for the police. But they certainly have the right to seize it.

The headline seems to be sensationalist and trying to surf the Snowden saga for readers. It's not related.

Edit: I'm ignoring the sanity of prohibition laws, but just comparing this story to common sense.

lessnonymous··on Facebook vulnerability 2013
It's pretty freaking obvious there was a language barrier problem here. He knew of the whitehat program, but not the ability within it to create test accounts: he asks the security team to set up a test account so he can post to it to show them the problem.
lessnonymous··on Hyperloop
2.8/km² Australia

And here you can travel from most parts of Melbourne to most parts of Sydney with just two train changes. One at a Melbourne hub to the interstate trains and one at Sydney to the local system.

Even so, we feel our train systems suck too.

lessnonymous··on Mega to run ‘cutting-edge’ encrypted email
The 'to' header isn't required to deliver email. You could essentially encrypt the entire header block if you're changing the protocols. What actually delivers the email is the 'RCPT TO' command on the SMTP transaction.

At the moment, SMTP requires that you also give it a 'MAIL FROM' command that tells who the sender is. Most servers also require a HELO that identifies the sending server, but you can basically get away with putting anything in there.

But now you're left with an authorization problem.

Currently the combination of these three fields is what determines whether an SMTP server will accept the message for delivery or relay. If all you get is the 'RCPT TO' command, then you have no idea who's sending the message until it's decoded.

This puts the authorization task on to the recipient's computer. So the 90% of all email that's spam will now need to be parsed on the desktop.

One solution here would be to include another section above the encrypted email header+body that is the authorization block. Now the recipient's server holds then entire encrypted message using the RCPT TO as the destination. The recipient downloads a list of auth-blocks addressed to them and issues back a DENY if they don't want the message.

The authorization block would identify the sender who has signed their identity in a publicly identifiable way. BAM! There goes spam.

Unfortunately the BIGGEST problem in all this is Microsoft. They could have added simple-to-set-up PGP to Outlook years back. So how likely do you think it is that they'll switch to any new protocol. (The anti-spam industry really lives in fear of Microsoft waking up and working on implementing any of the new protocols that would instantly stop spam.)

In all this, I'm ignoring web-based email for all this: that's a much bigger security nightmare as you have to trust your private keys to the third party

lessnonymous··on Mega to run ‘cutting-edge’ encrypted email
Again, you're trusting something that isn't yours. In this case you're trusting the state's server.
lessnonymous··on Mega to run ‘cutting-edge’ encrypted email
From my comment:

> At some point, you'll have to either give up ... security (you'll have to trust something you're not in control of).

The anonymous remailer must be trusted for this to work. And this doesn't get around the fact that email is broken generally. Companies wont start using anonymous remailers.

lessnonymous··on Mega to run ‘cutting-edge’ encrypted email
You can already encrypt email bodies end-to-end using PGP.

The unsolved problem is the (queue dramatic music) METADATA!!!

For an email to get from your computer to the recipients, it has to have metadata that the intermediate computers understand: The SMTP protocol is designed to deliver your email by relaying it any which way it is set to. So when you send it, it goes to your office SMTP server, which then might relay it to your head office SMTP server, which then might relay it to the recipient's spam filtering service, which might then relay it to the recipient's head office, which might then relay it to your recipient's office from where the recipient retrieves the email when they're good and ready.

SMTP is not ever going to be secure. Even if you use TLS (which most mail servers do by default these days) you're only encrypting the message-in-transit so any of the myriad of systems between each SMTP server can't read it.

All it takes for the NSA to read your metadata (and cache your encrypted message) is to compromise one of the SMTP servers it passes through. Then they can compel you to decrypt it using any method they have at hand.

The secure way to send email is to have your computer connect directly to your recipient's computer over an encrypted transport layer (TLS) and possibly for your recipient to authenticate to accept that connection (so AFK means no email). You'll have to know your destination point's IP address somehow. (DNS sounds fine, after all it's just a phonebook. However requesting an IP address could easily be logged and so you've leaked metadata again)

This means you can't send an overnight email and expect someone to get it in the morning when they switch on their computer. If you want to do that it needs to sit on a server somewhere. And that server is subject to attack.

So for convenience, we could build a server designed to accept any of these messages from anywhere. But it also needs to accept messages to anywhere as it can't be allowed to know who the recipient is. That's metadata.

The problem now is how do I get my messages from my server? The server isn't allowed to have my key, so it can't go and attempt to decrypt every waiting message (or decrypt every envelope).

At some point, you'll have to either give up convenience (can't get email unless you're both online) or security (you'll have to trust something you're not in control of).

I'd be stocking up on tin cans. And string.

lessnonymous··on A self-published riff on Hamlet broke every Kickstarter record.
The article asks

> Is it a good book? Is it $580,905 good?

The point it misses, I think, is that it doesn't have to be "$580,905 good". It just has to be $15 or $20 good to each independent backer. If I put up $20 to get a physical copy, then the worth of my copy has absolutely nothing to do with everyone else's copy.

This is, of course, the "work smarter, not harder" concept proven.

Contracting, consulting, and anything else where our time is the product on sale is a low return product. We can't create more time to increase our returns.

Instead we need to find our own "Hamlet" that for some finite effort on our part we can be rewarded by tens, hundreds or even thousands of customers. All of whom receive the value they pay for and all of whom have no interest in every other customer and whether our effort (time) is worth the total we've been paid by all customers.

lessnonymous··on Yahoo Gets A New Logo
GAHHHHH!! They kept the stupid "!". Not just in the logo, but in all their copy. It makes it SO HARD to read!
lessnonymous··on Kickstarter Should Do More to Protect Backers
It annoys me that this is going to gain traction.

The only thing that should happen is that to fund something you have to click some really plainly worded opt-ins. But I'm betting regulators will get involved and remove this funding option for those who can't afford lawyers who specialize in crowd funding. Or can't then afford the discovery that will need to be done before they can request (crowd) funding.

[ I understand that I may lose all my money and that I have no recourse ]

[ I can afford to lose this money and not get anything in return ]

[ I understand that this is speculation and that only X% of projects deliver ]

lessnonymous··on Why I willingly handed over my credit card and PIN to a fraudster
I challenge my bank all the time. The answer I get is "Certainly sir. The best way to validate is to find our free-call phone number in a place you trust - the phone book, or anywhere else you trust - then call it and type in the following number: X X X X X. That will route the call directly back to me".
lessnonymous··on Google doesn't understand what iGoogle does. Offers unrelated 'alternatives'.
None of their suggestions is an actual replacement (or 'alternative') to iGoogle's dashboard.

Nothing else I've looked at seems to work the same way. There's about a bajillion RSS readers. Even some that allow a dashboard layout. But I can't find anything (useful) that provides the same service as iGoogle.

lessnonymous··on Yahoo Mail is not catching up anymore
I run roundcube on my server for webmail access. It's a web-based IMAP client. I'm not sure what you want from a server that isn't already available in the existing open source IMAP servers.
lessnonymous··on Email exchange between Edward Snowden and former GOP Senator Gordon Humphrey
This is my belief.

Spread the password and access details to two people without keeping it yourself. Those two people split their in half without keeping it themselves. The four people who now have the password are the 'kill switch' required to monitor Snowden's location. Snowden has no idea who they are.

Should he be tortured, all he can do is reveal his first two contacts. The torturer will now have to abduct those two people to get the key.

All these second level people know is the two people THEY spoke to. So you need BOTH of the second level to get all four of the third level people.

And then you'll have to abduct another FOUR people to get the key. All before these four people realize Snoden has disappeared.

He knows he can't resist torture. But he doesn't have to. He LITERALLY cannot be coerced.

lessnonymous··on Ask HN: I'm quadriplegic – can you help me with my security?
Totally off topic, but why don't laptops come with twin cameras already?!?!?
lessnonymous··on Show HN: I hacked my microwave with a Raspberry Pi
This is an awesome project. But by far this is the most amazing and innovative part of the article:

> If cooking instructions are posted for a 1000W microwave, you can request the instructions for a 700W microwave, and the cooking times will be automatically adjusted

lessnonymous··on Why is nobody using SSL client certificates?
Anyone know of a good tutorial for using client certificates for (2nd factor) authentication? A quick Google search brings up nothing useful.
lessnonymous··on Google Reader Founder: I Never Would Have Founded Reader Inside Today's Google
I think Google would be wise to offer a discontinued product to the creator. If they have no interest in Reader any more, then Wetherell should be offered the product.

Possibly he would need to pay something for it (preferably over a long term) or he would be given the source, but absolutely no users / user data.

That way they get innovators to dream big ideas like AdSense, but if those ideas are rejected or later shuttered, the innovator gets to keep his idea.

lessnonymous··on HTML5 Genetic Cars
deep man.
lessnonymous··on Pink Floyd: Pandora's Internet radio royalty ripoff
If you get hired to build a bridge, there's a fair chance people are going to be using it.

If you get hired to create music, there's a fair chance nobody will ever hear it. (Other than your mum).

I can't see how we could possibly pay musicians up front.

lessnonymous··on Pink Floyd: Pandora's Internet radio royalty ripoff
85% cut on some arbitrary digital radio fee .. or ∞ increase on AM/FM.

In another universe: "Pink Floyd gets paid for every person listening to their music on Pandora. Band claims it's a win over traditional broadcast from which they received nothing"

lessnonymous··on Senators skip classified briefing on NSA snooping to catch flights home
Foxtel on Fox Classics. It's about 5 months behind (I think) and the Friday ep is always out of sequence for some reason.
lessnonymous··on Your idea sucks Why don't we be more honest when networking at startup events?
The funny thing is, according to the ACS, 20% of Australia's workforce is in IT! Go figure!
lessnonymous··on Australia gets 'deluge' of US secret data, prompting a new data facility
I guessed this exchange of data was happening earlier in the week: https://news.ycombinator.com/item?id=5861516

Though I said ASIO rather than DSD:

> But what if the NSA gave the PRISM tech and data feed to ASIO so ASIO could spy on Americans and answer any question the NSA asks (and vice versa).

> Now neither intelligence service has an 'illegal wiretap' on their own citizens. They just receive 'foreign intelligence' from each other.

lessnonymous··on Senators skip classified briefing on NSA snooping to catch flights home
Ooh, that's an interesting one. Thanks! I've used a system before (no idea what it's called) that gives each voter a number of points (say 10) that they can distribute among the candidates. They can give all 10 points to one person, or spread them out. Of course, your average voter would find this way too confusing.

From the Wikipedia article: > FairVote [argues Approval Voting] can result in the defeat of a candidate who would win an absolute majority in a plurality system, can allow a candidate to win who might not win any support in a plurality elections

This sounds like a good thing. You end up with an elected official that satisfies most of the population.

51% of voters think Alice would be the best person to lead, they'd be OK with Bob but think Carol and Dan are morons. 49% think Carol would be the best person to lead, they'd be OK with Bob but think both Alice and Dan are morons.

So now if we use normal majority voting, Alice wins and 49% of voters have an elected official they think is a moron.

With Approval Voting, Bob will win. Sure, he might have been everyone's second choice, but he's EVERYONE's second choice. So now we're all reasonably happy.

lessnonymous··on Senators skip classified briefing on NSA snooping to catch flights home
Re Gambit: Learned this on an episode of Jeopardy screened in Australia this week. Never knew that it originated in Chess.
lessnonymous··on Connecting the PRISM Dots: A New Theory on How PRISM Works
Aaaaand BINGO!

http://www.itwire.com/it-policy-news/govenrment-tech-policy/...

lessnonymous··on NSA admits listening to U.S. phone calls without warrants
Why is Snowden a traitor but Nadler not? Did Nadler not just go to the press with information that was part of a secret NSA briefing?
lessnonymous··on What's Wrong with the iOS 7 Icons?
After reading the article, the last thing I wanted was dynamic icons. But your take on it makes sense.

I don't want 'photos' to show me the latest photo I took as that could have been days ago and now finding the photos app is really difficult.

But if just part of the icon changed to indicate something, like your stock folio position (without the red/green background idea) then it works both ways. The icon always looks generally the same - it's a graph - but it changes to indicate some data point that may save opening the app.

That said, how would the icons update if you don't open the app. Each app's developer would either have to send out an icon update notification or would have to provide some level of running the app on a regular basis to regenerate the icon.

lessnonymous··on PRISM fears give private search engine DuckDuckGo its best week ever
Do they need to MITM? If they have a copy of the private key, can't they just use it to decrypt the data .. even old data for which they've only just acquired the key?
← PreviousPage 3 of 8Next →