HNHacker News
TopNewBestAskShowJobs

mnordhoff_

23 karma · joined October 9, 2013

https://news.ycombinator.com/user?id=mnordhoff
submissionscomments
mnordhoff_··on Sources: We were pressured to weaken mobile security in the 80's
Matthew Green wrote about GSM and LTE a few months ago:

http://blog.cryptographyengineering.com/2013/05/a-few-though...

TL;DR: GSM security is a joke. LTE is okay, except for two critical issues: One, an attacker can jam LTE and cause a downgrade to GSM. Two, it doesn't offer forward secrecy, so an attacker can record your traffic, obtain the private key from your carrier, and decrypt it. It's a reasonable assumption that NSA and your local sigint agency routinely make copies of your carrier's key database.

Edit: Reword last sentence.

mnordhoff_··on NSA infiltrates links to Yahoo, Google data centers worldwide
IIRC, Poland was the EU country that was the focus of attention.

Skimming Wikipedia's most definitely totally truthy article on the subject [1] (actually, it has a lot of citations, so it should be easy to verify), the UK's only alleged black site was the US base on Diego Garcia, which is "UK", but not "basement in London".

[1] https://en.wikipedia.org/wiki/Black_site#Suspected_black_sit...

Edit (T+18 minutes): Wikipedia lists numerous other European countries as possibly being involved. Information is really sketchy -- they are called "black" sites. Another question is which officials in the lucky host countries even knew about it.

mnordhoff_··on Ask HN: Buffer got hacked - does anyone know details?
Public Service Announcement: "SHA1(password+salt)" is an extremely unsafe way to store passwords. Use PBKDF2, bcrypt or scrypt.

Edit (T+7 minutes): Rewritten to not be a jerk.

mnordhoff_··on Why Android SSL was downgraded from AES256-SHA to RC4-MD5 in late 2010
Nginx has an equivalent preference, ssl_prefer_server_ciphers on. (Scroll down a bit on evmar's link.)