HNHacker News
TopNewBestAskShowJobs

mdp

996 karma · joined December 27, 2010

Partner at 1984 Ventures

m@mdp.im mdp@1984.vc

https://github.com/mdp https://twitter.com/mdp https://1984.vc https://apply.1984.vc

submissionscomments
mdp··on Android user locked out of Google after moving cities
I had a similar problem. There's literally NO solution other than opening up a new account.

It was a wake up call. I've since moved most of my digital life onto other services.

mdp··on Paperless: Scan and index paper documents
Why is this a facepalm? Privacy advocacy is about giving people the option to decide what they share, not preventing them from sharing. I don't have a problem at all if someone voluntarily decides to share their private information with Google. Why does it matter to you what he does with his data?
mdp··on Walmart Pay
That page is specifically talking about EMV in the US, and for whatever reason, I've never seen a EMV 'dip' that takes less than 5-10 seconds here. Target for example has consistently been around 10 seconds every time I've used EMV there and I doubt they are using dial-up.
mdp··on Grooveshark co-founder, 28, found dead in home
Still in jail awaiting trial - http://www.pcsoweb.com/InmateBooking/SubjectResults.aspx?id=...
mdp··on The Secret Goldman Sachs Tapes
I think this is actually missing the point. Her boss may have been right, and I think he was. But as a regulator she's entitled to file her opinion and have him override it. Then it's all in writing.

The fact that they refused to do this and instead bullied her into their own opinion is remarkable. If they'll do this for something so minuscule, imagine what they'll do for bigger issues.

The tapes aren't exposing that Goldman got away without a conflict of interest policy, they're exposing that the Fed is still refusing to let staff stand by their independent opinions.

mdp··on German Artists Say They Put White Flags on Brooklyn Bridge
Think about this for a second. You can literally go "crawling all over the Brooklyn Bridge consequence free" anytime you like. It's a bridge you can walk on. You can even drive your car on it. In both cases you're far more likely to be a threat there than on the top of the bridge.

The immediate reaction was that this might be terror related - "NYPD bomb technicians spent several hours checking the bridge for explosives but found none."

They even subpoenaed a parody Twitter account for claiming it "signal[ed] our complete surrender of the Brooklyn Bridge bicycle path to pedestrians"

Not our proudest moment.

mdp··on Putin Goes to War in Crimea
I think it's the same strategy as Georgia/Abkhazia. You go in to "defend" the ethnic Russians. You don't take it over, you simply "Keep the peace" and make them a separate country. Congrats, now you have a very important military port in a country that you control.

Remember the consequences Putin faced for Georgia in 2008? Neither does he, because there really weren't any.

mdp··on US makes Bitcoin exchange arrests
This is simply not true.

'In some of the documents, prosecutors allege that HSBC intentionally flouted the law. The bank created an operation that was a "systemically flawed sham paper-product designed solely to make it appear that the Bank has complied" with the Bank Secrecy Act and is able to detect money laundering, wrote William J. Ihlenfeld II, U.S. Attorney for the Northern District of West Virginia, in a draft of a 2010 letter addressed to Justice Department officials.'

'In one email exchange submitted as evidence in that case, employees debated whether the bank should help a Miami client get around U.S. sanctions by moving the client's business to HSBC's Hong Kong office. "I believe that the best outcome would be for the customer to open a relationship with Hong Kong just for leters (sic) of credit purposes. He travels there all the time," private banker Antonio Suarez wrote in a 2008 email. Suarez has since left the bank and couldn't be reached for comment.'

http://mobile.reuters.com/article/idUSBRE8420FX20120503?irpc...

mdp··on Ask HN: Is it legally enforceable for your company to own your IP?
I can actually answer this decisively.

Don't take legal advice from anyone but a lawyer that you are paying.

Seriously, this depends on a variety of factors and is especially dependent on your local laws, the specifics of the contract and most importantly, precedent.

Find a lawyer, give them your contract, detail your side project and get an opinion.

mdp··on iMessage for Android
It looks a bit obfuscated, but there might be some useful finds. I'm going through it and looking for hardcoded strings that might not be in the resource files.

I posted the APKTool output on Github for anyone that wants a quick look - https://github.com/mdp/iMessageChatDecompile

mdp··on How to get Gogo in-flight wireless internet for free
Yep, yet another Gogo "exploit" disclosure. This one is actually quite pathetic.

Here's my security disclosure for the day:

You can walk out of most stores without paying for their merchandise if you hide it in your pocket.

Which vendor do I talk to about getting paid for this information?

mdp··on Encrypt your Google chats and make the NSA sad
It's definitely a questionable javascript library, I wrote it back in 2008 after reading the wikipedia article :)

It was designed to interop with OpenSSL's default command line AES crypto, which has some weak points, mostly around the IV selection.

That being said, the biggest weakness will always be that it's running in the browser and open to injection attacks.

But while I think there's definitely better crypto chat solutions out there, it's nice to see people taking an interest in the subject. And let's not kid ourselves, the vast majority of NSA data collection is probably less about sophisticated encryption attacks, and more about the clever application of political/police powers.

mdp··on My crazy idea to piss off spammers
Yeah, I've only had this happen a couple times, and it does make you trust your spam system less.

That being said, it's seems to be getting better as more companies embrace SPF.

mdp··on My crazy idea to piss off spammers
Look at the IndieGoGo header image he's using. It's a screencap of Gmail's spam folder with 5,048 messages. Hasn't this clearly been solved?

I get MAYBE 2 spam emails a month that gets through the filter, and my address is pretty easy to harvest.

So is this still a problem?

mdp··on Evernote doesn't really care about security
Yeah, this is an entirely valid criticism. It was more of a nitpicky point that they weren't flipping to HTTPS automatically, but from a practical standpoint it's no more secure if they did since they lack HSTS.

Struck it from the post.

mdp··on Evernote hacked
They've never really been focused on security in the past. Honestly, I love the service, but their lack of concern about keeping it secure has never sat well with me.

I wrote up a post with some of my security concerns. http://news.ycombinator.com/item?id=5311010

mdp··on Michelin Guides forgets to renew domain name, becomes "Michel in Guides"
I always just assumed you split your time between writing and running a Volkswagen dealership in Southampton.

http://www.petercoopergroup.co.uk/

mdp··on Mitmproxy - an SSL-capable man-in-the-middle proxy
This looks very cool. I've been working on a similar project built on top of Node.Js and Connect (https://github.com/mdp/middlefiddle)

It lets you use Connect compatible middleware to alter the request or response - (https://github.com/mdp/middlefiddle/blob/master/.middlefiddl...)

There's a bunch of these proxies out there, and they all provide something different, but if you're just looking to inspect the HTTPS request, I'd also recommend the excellent Charles Web Proxy - http://www.charlesproxy.com/ - I bought a copy years ago, and it's been invaluable.

mdp··on Simple Two-Factor SSH Authentication
"* OP double-protects the SSH key. It means you need the key's passphrase and another factor (Google authenticator) to decrypt the ssh key. Then the ssh key is used to auth with the server. => the authentication with the server is still one factor auth, compromising the key at any level still grants access."

This is not correct. You can't decrypt a key with a one time password.

The OP is requiring a the second factor(the OTP) after the key is sent to the server and authenticated.

mdp··on Slicehost accounts will be converted to Rackspace cloud accounts
Actually, I made the switch from Slicehost to Rackspace because it was cheaper. It's pay for what you eat pricing, so you don't get a free allotment of bandwidth, but it's around ~$11 for a 256 meg instance.

My biggest concern is that the Rackspace Cloud product doesn't seem as polished as Slicehost. Slicehost was a great service for newer users, with great documentation and help resources.

mdp··on Vico Editor (Mac text editor)
Yes, but I'm extremely lazy :) The less time I spend learning a new editor is more time I can spend learning a new technology.
mdp··on Vico Editor (Mac text editor)
Yes, but what happens when development on this closed source editor dries up?

It looks like a great app, but I'm still leery of basing something as important as my editor on a closed code base again.

There are also some great alternatives out there, notably Redcar, which is both open and full of Textmate like features.

mdp··on Introducing Druid: Real-Time Analytics at a Billion Rows Per Second
I'm more impressed by those UK click through rates on bieberfever.com
mdp··on Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb
Yeah it's easy, just convince everyone you're too big to fail and have the American taxpayer pay it off.
mdp··on Do a startup or travel around the world?
I'm typing this from my iPhone in a bar in Siem Reap, Cambodia, so forgive my brevity and spelling.

Wifi might be prevalent in most places but quality and reliability will always be am issue. I've found it to be ubiquitous is SE Asia, however I've had days where slowness could cause even SSH to bog down to a few characters a minute.

Bigger issue, do you mean travel or live in a foreign country? Because yes, you can very easily find a cheap country with good internet, but traveling itself can be a full time job when you're only spending a week at a time in one place.

If it were me, I'd just travel, and do the startup later.

← PreviousPage 2 of 2