HNHacker News
TopNewBestAskShowJobs

nwh

5,848 karma · joined December 5, 2012

submissionscomments
nwh··on CVE-2014-7284: Lack of randomness in Linux kernel network secrets
For something like CloudFlare which in itself is designed to be a security filter as well as a CDN, having people able to touch the origin server (if they can find it) would be highly undesirable.
nwh··on Immigration Crackdown on Digital Nomads in Chiang Mai, Thailand
An Australian one is fine in the UK, you can even drive using one.
nwh··on I built a custom keyboard for iOS 8
http://i.imgur.com/bSIhNOP.png

Big scary warning, I like it. Swiftkey does badger people to enable it though, so presumably it's sending a lot of data back to their servers as a business model. Nasty.

nwh··on I built a custom keyboard for iOS 8
Can users see this flag?
nwh··on I built a custom keyboard for iOS 8
I didn't mean to suggest that at all, I was commenting on the concept of having executable keyboards outside of the usual application sandbox rather than yours in particular.
nwh··on Material Design for Bootstrap
That front page renders horribly in FireFox.

http://i.imgur.com/kfYvuiX.jpg

nwh··on Material Design for Bootstrap
So "Material Design" is "Flat Design" with shadows?

I'm not sure I can quite get used to this particular theme at all. The colors are pretty gaudy, the main action buttons (brown and purple) particularly are almost unreadable to me. I couldn't find the input boxes at all even though they had a header, they just parse as horizontal rules rather than something I can click on an add text. I respect the effort that has gone into creating this, but on a fundamental level I don't feel this is a good step in interface design.

nwh··on I built a custom keyboard for iOS 8
iOS8 keyboards still make me very uncomfortable. How many of them contain keyloggers?

It's not even if I have one installed, the people I communicate with will be using them too, and they can compromise me.

nwh··on [dead]
Ⓘ ⒽѦ℣Є Ѝ☺ ⒾℶⒺѦ ШℍΛṮ ⑂Оμ'℞Ⓔ ⓉⒶℓĹĸⅠИҀ ѦβⓄⓊŦ
nwh··on Show HN: 123D Catch by AutoDesk – Create 3D scans of virtually any object
They also publicly display everything you do with it.
nwh··on Bash 'shellshock' scan of the Internet
Especially as it's actually executing code on other people's computers, you can't even really say it's just observation at that point.
nwh··on Manual – Custom exposure for your iPhone camera
The "instructions" at the start of the app are a bit baffling. I spent a good few minutes looking at a screen that told me to tap and drag and a weird orange circle that keys popping up above the capture button. In fact the entire selection with the ISO and shutter speed are a little on the janky side, I'm having a good deal of trouble seeing what I'm actually selecting. It's more completely random than anything with the shutter speed as my thumb obscures the entire view. Weird control usability aside it seems fairly functional, I've wanted something like this for a while.

Do you have a privacy policy somewhere with details about the information you collect from the application? I was unable to find any on your website.

nwh··on MIT Students Battle State's Demand for Their Bitcoin Miner's Source Code
The purchasing of this product presents a high risk of potential thought-crime.
nwh··on MIT Students Battle State's Demand for Their Bitcoin Miner's Source Code
Under that definition a lot of things are too dangerous to own. That libc you're packing? You're heading for jail for that, you potential criminal.
nwh··on EBay under pressure as hacks continue
It's unreasonable to expect that of people. URLs are maddeningly maddling to parse even if you know what is going on, if you don't it's almost impossible to explain it. Why is ebay.com.au different to ebay.com.au.edgesuite.net, should I worry if I see that? Why is edgesuite alright for hosting the images on? It's a rabbit warren of edge cases and exceptions that defied all normal levels of explanations.
nwh··on “We've been acquired and Twitpic will live on”
That's correct. Archive Team was working on it but their crawlers got banned. TwitPic said something along the lines of them having a better solution, which I suppose was this.
nwh··on CircuitMaker: a free PCB design tool powered by Altium
It's free as in "freemium". Unusable unless you spend a tonne of money on lots of little in-app purchases.
nwh··on Canon printer hacked to run Doom
What's the driver support for dot matrix printers like in linux these days?
nwh··on A JPEG that becomes a PNG after AES encryption and a PDF after 3DES decryption
People are going to be mighty confused if they try to use that, imgur re-encodes all of it's images uploaded.
nwh··on Apple Pay
You use your fingerprint to activate the NFC, so they'd have to bash you over the head and cut off your fingers presumably.
nwh··on Apple Says It Will Add New iCloud Security Measures After Celebrity Hack
That's mine too, an iCloud backup is pretty much keys to the kingdom. Could also just have been that they had access for a very long time and downloaded data multiple times in that period without being detected.
nwh··on Apple Says It Will Add New iCloud Security Measures After Celebrity Hack
2FA does not protect iCloud data at all, it would have done nothing here.
nwh··on Dell Previews 27-inch ‘5K’ UltraSharp Monitor: 5120x2880
I mainly play games rather than watching filmed content, which it seems makes my use case a little bit more sensitive than other people's.
nwh··on Moto 360 review
The square interface on the round watch is pretty weird. I didn't expect to see square interface elements being lopped off the sides. The software seems to be almost a complete afterthought, I would have expected at least some innovative ways of making rounder interfaces.
nwh··on Dell Previews 27-inch ‘5K’ UltraSharp Monitor: 5120x2880
I looked at 4K TVs recently, and if you look through the advertising they're all 4K at 30hz (ie, totally worthless for viewing anything on) due to the limitations of HDMI 1.4.
nwh··on Notes on the Celebrity Data Theft
It doesn't hold up to SSL stripping very well. As we are working under the assumption of a compromised host, the absence of a signature on the Trezor when you don't expect one wouldn't raise any suspicion. The omnipotent host malware can remove all references to the payment request being signed from the payment gateway before the user sees it.
nwh··on Notes on the Celebrity Data Theft
Double check it against what information source? The malicious software has altered the one shown on both devices. They will of course match, but not with the one you're actually meant to be paying to.[0][1]

[0]: http://www.reddit.com/r/Bitcoin/comments/23sjle/chrome_exten....

[1]: http://www.reddit.com/r/Bitcoin/comments/1vrium/a_google_chr...

nwh··on Notes on the Celebrity Data Theft
Nothing stops a threat from just lying and waiting for you to expose a large number of passwords. Having one stolen doesn't raise red flags in itself.

I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.

nwh··on Notes on the Celebrity Data Theft
It doesn't matter. If you have malware lurking in your computer it will just snarf your passwords from the wire and then you're owned all the same. If you use some sort of auth signing system, the request can just be intercepted and modified on the fly.[0] The Trezor is next to useless even for bitcoin for this very reason. Sure they can't steal your money directly, but just replacing the addresses you see and send to accomplishes exactly the same thing. If your platform isn't trusted, no amount if smart crypto or hardware dongles can make it safe.[1]

[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.

[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.

nwh··on Urgent security warning that may affect all internet users
There's been stories for a while of massive malware infections sniffing usernames and passwords of infected users. Simply because there's little to give away that such an activity is going on (ie, if you were spamming or mining bitcoin there would be a real-world impact shown immediately) it's extremely hard to confirm or deny if this is happening and at what scale. In my mind it doesn't seem unlikely that would be happening though. Combined with large websites like LinkedIn being compromised, you're looking at a very, very big problem.
Page 1 of 34Next →