HNHacker News
TopNewBestAskShowJobs

michaellosee

50 karma · joined October 9, 2013

submissionscomments
michaellosee··on Defcon 22 videos and slides
+1 to this. During the presentation they scan the entire internet for open VNC ports that do not require authentication. There were many found (thousands?), the most surprising being a mainframe that looked like it controlled a railway interchange. I was the guy who gave them the iPhone backdoor port ;-)
michaellosee··on IBM’s Watson Analytics platform is now open to everyone
It seems that error code may not involve data input format but rather indicates DB2 is out of resources[1].

Honestly this release might be a little early for IBM as well. Any sort of verbose error message is at least a low risk information disclosure finding on a pentest and a verbose database error message is a strong indicator the application is vulnerable to SQL injection. Even if not vulnerable, it's blood in the water and should be fixed before hitting production.

[1]http://www-01.ibm.com/support/knowledgecenter/SSATW2_7.3.0/c...

michaellosee··on ArrayFire, a general-purpose GPU library, goes open source
GPUs love hashing things, do you think ArrayFire would make that easy to do? I would LOVE to use the library to create an opensource GPU cracking program. Hashcat is amazing but is closed source. I am giddy with excitement at the prospect. Thanks!
michaellosee··on The FBI Is Wrong: Apple’s Encryption Is in the Public Interest
Thank you, I knew I was missing something. Also, I found that iOS 8 (mostly) fixed the backdoor:

http://www.zdziarski.com/blog/?p=3820

michaellosee··on The FBI Is Wrong: Apple’s Encryption Is in the Public Interest
>(iOS 8) virtually eliminates the possibility that the encrypted data can be unlocked without the passcode.

I am not the first to point out that it is stupidly easy to bruteforce passcodes that are based on digits (like many phone passcodes are). The FBI lamenting unbreakable phone encryption and the accompanying media buzz borders on farcical and is disingenuous given that there is still a backdoor on the iPhone[1] on port 62078. Am I missing anything?

[1]https://news.ycombinator.com/item?id=8057470

michaellosee··on The Emails Snowden Sent to First Introduce His NSA Leaks
There are several symmetric encryption algorithms to choose from, the default is CAST5 (according to this[1] random mail post). This would only be used to encrypt the private key on disk.

Now I'm curious of the methods of decrypting data in transit. Does the NSA have the tools to break PKI based encryption at 1 trillion guesses/sec? I have some wild guesses, but if anyone knows I'd love to hear it.

[1]http://lists.gnupg.org/pipermail/gnupg-users/2010-October/03...

michaellosee··on The Emails Snowden Sent to First Introduce His NSA Leaks
When I saw 1 trillion guesses per second I immediately wondered what algorithm was being referenced. My single GTX 780 hash performance varies wildly by algorithm. A few numbers:

  NTLM - 1.2 billion/sec
  MD5(Wordpress)- 600 million/sec
  bcrypt - 1,000/sec
1 trillion hashes/sec on a key stretching algorithm like bcrypt would be pretty horrific and might require quantum computing, while the same performance on MD5 might be achieved with <50k in hardware (very rough estimates).

I've heard rumors of storage technology that can store thousands of petabytes in a home appliance form factor. With that can kind of storage it would make sense to just start making salted rainbow tables. Even without fabled hardware, the Bluffdale NSA facility might have the capacity for it. I haven't even done napkin-based calculations yet to see if this is possible, so if anyone has some idea please speak up :-)

edit: formatting

michaellosee··on Asset seizures fuel police spending
That statement was made tongue in cheek, mostly to illustrate that 1) police are only protecting and and serving themselves when seizing our stuff and 2) removing the incentive would help reduce the problem (along with other points made by you and AnthonyMouse).
michaellosee··on Asset seizures fuel police spending
Good point. This has me thinking more about the root of the problem. It seems like the justification they use most of the time is related to drugs. Perhaps asset forfeiture is a another example of how the war on drugs undermines our civil liberties, and yet not even John Oliver has framed it that way.
michaellosee··on Asset seizures fuel police spending
There is an amazing correlation between how much money police seize and what percentage of that money they can keep. The states that allow police to keep a high percentage of the money take in many millions per year, and the opposite is true when that percentage is low. California averaged 24 million in asset forfeiture per year between 2002-2008, after the feds took their 35% cut, in spite of offering better than average protection from the law[1].

With this in mind I've wondered what would happen if,say, 100% of the proceeds from asset forfeiture went to ALS. I expect ALS would benefit very little but at least it would save thousands of people from having their assets stolen by the police. It turns out I'm not the first person to have this idea. The Fifth Amendment Integrity Restoration Act (FAIR)[2] seeks to remove the profit incentive and conflict of interest from civil asset forfeiture (along with some other good ideas). There have been other attempts for reform in various states, but FAIR has a lot of potential to change things at the federal level.

1-https://www.ij.org/asset-forfeiture-report-california 2-https://www.govtrack.us/congress/bills/113/s2644

michaellosee··on DEFCON Router Hacking Contest Reveals Major Vulnerabilities
That is true. Those first two recommendations are good bang for your buck (for the newbies), I guess I forgot I have a technical audience here :-)

Now that I'm thinking about it transparent bridge mode might do the trick as well.

michaellosee··on DEFCON Router Hacking Contest Reveals Major Vulnerabilities
They gave the exploit a "1337 compromise" award, so it is almost as bad as it gets.

While you still have the Q1000, be sure that you have the remote interface disabled and use the NoScript browser plugin. Those two items will mitigate a lot of the risk.

I replaced my Actiontec Q1000 with a used Zyxel Q1000Z I got for $30. I haven't had time to assess the Q1000Z yet, but it does not have any known 0-day vulnerabilities.

michaellosee··on DEFCON Router Hacking Contest Reveals Major Vulnerabilities
I demonstrated the Actiontec Q1000 exploit on Track 0. As a security professional I am very interested in responsible disclosure, and had already reported the vulnerability to Century Link 6+ months before Defcon (slight correction to the article, the ISP is not Verizon). I first read about the SOHOplessly broken contest on HN the week before Defcon and figured I'd apply since I already had a 0-day in my back pocket.

As the article says the manufacturer has acknowledged the vulnerability, but I have not heard from them for quite a while. I've begun to wonder how much time has to pass without a fix before it would be irresponsible of me not to fully disclose the vulnerability. Lately I've been thinking that full disclosure may be the only responsible way to disclose a vulnerability. But I am still conflicted.

michaellosee··on Making Mistakes
> So how do we get as comfortable looking at recent mistakes as we are looking at the ones in the distant past? We probably can't - there's too much baggage.

Self Determination Theory (SDT, http://www.selfdeterminationtheory.org/) has a few ideas on how to answer this question. SDT provides some tools to deconstruct the concept of self esteem.

Traditional self perception is mainly concerned with a healthy self esteem. Under this paradigm it is only natural for people to regularly evaluate themselves by looking at past success/failures and by comparing themselves to others.

SDT provides an alternative to the traditional "self as an object" approach with a "self as a process" approach. While someone operating under the "self as an object" approach may ask themselves "Am I a good person? Am I worthy?", under SDT other questions like "Am I making good choices?" are much more important. This allows a person to view their own actions more objectively. Past mistakes are more readily available to be acknowledged and used to inform the future since they do not implicate an individual's self worth.

The book Mindset (http://www.amazon.com/Mindset-How-Fulfil-Your-Potential-eboo...) by Carol Dweck draws on a lot of SDT foundational concepts. The premise of the book explores and contrasts two mindsets: the static mindset and the growth mindset. If someone with the static mindset gets easy A's in school they take it to mean that they are smart. If someone with the growth mindsets get's easy A's it feels like a waste of time because it's not challenging. The author also discusses the benefits of praising a child's effort rather than just telling them how smart they are. It's a huge topic and I'm barely scratching the surface, but I think I've shown the top of this particular rabbit hole.

I still struggle with leveraging my failures constructively, but I have found learning about these concepts has enriched my life and helped me discover a hacker's mindset.

michaellosee··on Ask HN: Why do you think vulnerable code is still being released today?
Some thoughts. In my experience, the lack of vulnerable code in a secure application is not the product of savvy developers who never make mistakes. A hardened web app usually gets that way because someone took the time to find and fix some of the exploitable vulnerabilities that could be found. Unfortunately, that usually doesn't happen until they get hacked pretty hard and come to see the business value of investing in the people, process, and tools required to create a robust security program which is augmented by quarterly $10,000 PenTests.
michaellosee··on Time to end the war against saturated fat?
+1 for keto. The wife and I have lost 20 lbs each in the last 3 months.