HNHacker News
TopNewBestAskShowJobs

melville_X

77 karma · joined April 29, 2014

security researcher, systems deconstructor, programmer.

https://twitter.com/melville_x

submissionscomments
melville_X··on Kevin Mitnick Now Selling Zero-Day Exploits
I mostly disagree with arguments to rationalize the sale of exploits, they create a massive power balance towards bad actors, but we have to be honest with ourselves, and like drugs, 0days are not going away.

Our only proper response is secure software development practices, employment of security reseachers, and adoption of security-centric practices in critical systems... such as the Linux kernel. Which is embarassingly not the case at the moment. For ex: http://unix.stackexchange.com/questions/59020/why-are-the-gr...

melville_X··on Kevin Mitnick Now Selling Zero-Day Exploits
Governments are almost always the market for zero-days. Private security companies also buy them, but guess who their primary market is? Look at FinFisher's customer list.

There is nothing libertarian about the defense industry or their actors. Unless you mistake neo-liberalism as libertarianism as far too many people do.

melville_X··on Kevin Mitnick Now Selling Zero-Day Exploits
Agreed. Most people I know look at him with amusement. He's hardly an idolizing figure, besides some alright books about past exploits long ago.
melville_X··on Google and Apple Won’t Unlock Your Phone, but a Court Can Make You
Same with Canada... 5 years for contempt of court if you refuse to reveal password.
melville_X··on Use other DNS servers than your ISP's
That's why VPNs exist. A VPN without an external DNS service is pretty pointless if you're concerned about ISP snooping.
melville_X··on No more ads
A good free alternative is Comodo (8.26.56.26), I trust them slightly more than Google and they have security features such as malware detection.

http://www.comodo.com/secure-dns/

melville_X··on Hacker Who Helped Disrupt Cyberattacks Is Allowed to Walk Free
France temporarily made undercover police work illegal until the mid 2000s. That would be an interesting study.

But either way, there are obvious risks in this type of law enforcement. The vast, vast majority of humans are capable of committing crimes. This is why thought-crimes are so dangerous when they start being enforced because everyone is guilty. People flirt with the idea of crime but that capability is rarely utilized. The line one has to cross to commit a crime is high for most people, but there is a significant portion of the population where it is much smaller (poor people or people with lesser intelligence).

LE is overly consumed with making their careers on the back of latter portion of the population to the point where they covertly push them hard to commit crimes. While the intelligent criminals conducting sophisticated plots usually get away with it because noone wants to do the legwork involved.

(deleted my other comment which was not-HN quality).

melville_X··on Hacker Who Helped Disrupt Cyberattacks Is Allowed to Walk Free
Yes that's the definition of entrapment as interpreted by American courts. Very challenging for lawyers to use as a defense. Which is exactly why law enforcement loves using informants and undercover agents for everything these days. In heavily bureaucratic agencies like the FBI, the only thing that matters is looking good to management by getting arrests and 'foiling plots'. So why not go for some easy prosecutions? You'll be upper management in no time.

Plus there are a ton of dumb people and nearly everything is a crime these days, so all you have to do his handout a crime on a platter and fill prisons with the incompetent criminals who take the bait.

Why hunt down criminals when you can fish for dumb ones.

melville_X··on Hacker Who Helped Disrupt Cyberattacks Is Allowed to Walk Free
For anyone who wants to see a preview of Sabu's entrapment of anonymous members, one of his chat logs were leaked:

http://cryptome.org/2012/09/sanguinarious-sabu.htm

> Why is an informant going around throwing out a location to a claimed cache of classified documents concerning SCADA systems? So this is like a textbook attempt at entrapment, its akin to giving someone a key to a door but telling them its legal to open it with, someone being an informant, to take them down after. It also does not appear the FBI gives not one fuck about the security of critical infrastructure as long as it entraps another kid. Nothing at all wrong here is there? Full transcript: http://cryptome.org/2014/05/sabu-m45t3rs4d0w8-2012-0330-0524...

Perfect example of the FBI looking for easy arrests using morally-vague methods of entrapment, instead of doing the hard work and stopping real criminal conspiracies. This is a technique they perfected in domestic terrorism cases where they find dumb criminals with no skill, financing, or strong motivation, then give them all of the resources and information they need to do conduct a real scheme. While holding their hand along the way.

Makes great headlines when they arrest someone "domestic terrorist caught by FBI!" but hardly a good use of resources when they keep missing real terrorist attacks.

Bruce Schneier nailed it in 2007: https://www.schneier.com/essay-174.html. None of the 'foiled plots' were ever a real threat until the FBI showed up. People could argue these people should be in jail anyway but they are hardly worth the skill and resources of the most advanced investigators in the country.

melville_X··on From Gmail to Fastmail
This is a good reason for all of us to keep switching away from GMail. It benefits us all via network effects.
melville_X··on Bitcoin Foundation hit by resignations over new director
I'd support a software focused Bitcoin foundation, not a politically focused one such as the current one. Somewhat like Linux foundation but more decentralized by design.
melville_X··on Isambard Kingdom Brunel
http://torrentz.eu/search?f=ISAMBARD+KINGDOM+BRUNEL
melville_X··on Square Finally Gives Up on Square Wallet and Bets on New Order-Ahead App
/switching bags/switching pants/switching jackets/

Happens all the time. I almost never forget my smartphone somehow.

melville_X··on Bob – A Tarsnap GUI client for OS X
I fought the urge to want a GUI for Tarsnap and hand-wrote cronjob scripts that I'm very happy with now. It was part of the fun. Definitely non-ideal for everyone but I recommend it to any hackers to attempt the same.

One thing I learned as a result is becoming intimately with the unix/linux folder structure and being able to backup an entire OS deployment, reinstall the OS and just pull an old backup to recreate most of the important configs.

There might be a reason why there are a lack of good scripts, even on Github.

melville_X··on Fedora 21 To Have DNSSEC Validation Enabled By Default
The NSA uses Fedora as their standard laptop distro. There will definitely be influence on Fedora from that direction.
melville_X··on OAuth 2.0 and OpenID Redirect Vulnerability
Most important is this line which demonstrates not only does the attacker need to social engineer a user, it has to be done via a vulnerable website:

> The patch of this vulnerability is easier said than done. If all the third-party applications strictly adhere to using a whitelist. Then there would be no room for attacks. However, in the real world, a large number of third-party applications do not do this due to various reasons.

Facebook, etc aren't insecure directly, their 3rd party partners are for not implementing a URL whitelist. This website chose to bury that fact. This explains why Facebook is aware of the issue and did not address it.

melville_X··on OAuth 2.0 and OpenID Redirect Vulnerability
From the Q&A:

> Covert Redirect is based on vulnerability Open Redirect. An open redirect is an application that takes a parameter and redirects a user to the parameter value without any validation (OWASP). So Covert Redirect is an applicaiton that takes a paramter and redirects a user to the parameter value with improper validation. Usually this is the of result of overconfidence of its partnership.

Seems like a known flaw in OAuth2.

melville_X··on Lulzlabs AirChat: Free Communications For Everyone.
Topiary aka Jake Davis from Lulzsec had funnier and more tasteful writing than this. HN back in their defacement days always commented on the quality of the writing. This sounds a bit wannabe, which is a shame since 4chan tends to be obsessed with not rehashing tired content.
melville_X··on DarkMarket: The Silk Road successor police can’t shut down
Great point. They federal level infrastructure is pretty far from having that capability at the moment. As long as systems like one linked in the article are coming, the only natural response by the state is to establish an large-scale NSA-style hacking and network forensic agency working domestically.

There is no way they'll let digital black markets exist without creating a super-expensive heavy handed machine to attempt to stop it. Whether it is practical or not.

melville_X··on DarkMarket: The Silk Road successor police can’t shut down
They cherrypicked a few out of thousands and Silk Road was a tiny tiny percentage of the drug market. What will happen when they are 10x the size? Will that type of law enforcement scale?
melville_X··on DarkMarket: The Silk Road successor police can’t shut down
The point is that hunting people down protected by TOR and privacy laws in the postal mail system, one of the few practical privacy laws left, is still technically possible, yes...but it is expensive, time consuming and requires sophisticated police work.

The drug war is already failing without these huge roadblocks. It will always still be possible to exploit endpoint security. Given the resource limitations of law enforcement, maybe we should focus those resources hunting down important crimes such as creators of child porn or people engaged in violence crime?