HNHacker News
TopNewBestAskShowJobs

paddlesteamer

503 karma · joined January 4, 2013

submissionscomments
paddlesteamer··on Ask HN: The government of my country blocked VPN access. What should I use?
Years ago, I created a very basic HTTP proxy using Google Cloud. The idea relies on Google Cloud wouldn't be blocked because the industry in that country probably also needs Google Cloud to function, so the government couldn't touch it.

You can see it here: https://github.com/paddlesteamer/gcrproxy. I don't know whether it works or not (maybe something has changed; it is very old code), but the idea beneath it remains. And I think it is also applicable to other cloud services, too. Cheaper (even free to some point) than having your own VPS.

paddlesteamer··on Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.

I wish I could see those files in action...

paddlesteamer··on Firefox 85 cracks down on supercookies
I wish there could be a way to see which root site set those cookies. For example I wish we could see twtracker.com supercookies are set in some iframe in twitter.com.
paddlesteamer··on NRF52 Firmware Readout and Reverse-Engineering Now Possible
With this, devices that use NRF52 chips are now open to investigators. I think we'll learn of more vulnerabilities of BLE devices whose shitty implementations are hidden in those SoCs. I'm more than excited about the next post about Logitech Pro G mouse.

Making things open is a good thing on society's security.

paddlesteamer··on Blur Tools for Signal
Other than Signal, I also recommend Threema. It doesn't rely on mobile numbers, possible to configure to run on your private server, etc. It's just not free (as in beer). Also, it's from Switzerland, a country respects your privacy more than the USA[0].

[0]: https://www.reddit.com/r/privacy/comments/gukg5z/threema_win...

paddlesteamer··on Show HN: Print a WiFi Login Card
I like how it ignores WEP. Don't use WEP.
paddlesteamer··on Image Scrubber: tool for anonymizing photographs taken at protests
Since the Antifa will be designated as a terrorist organization[0], I don't suggest you guys to trust github pages, google photos, drive, etc. Tomorrow there may be a subpoena for the IP addresses who use this tool. It may not be enough proof but it'll cost you a lot of money and time. I'd be using local tools like exiftool or gimp.

[0]: https://twitter.com/realDonaldTrump/status/12671296442282475...

paddlesteamer··on MacOS Catalina: Slow by Design?
I hate bloated OSs and unfortunately Mac OS is one of them. I know how everyone wants everything to work out of the box and I know it's very natural to want so but I cringe if I find out my OS doing something behind my back. That's why I'd never use Windows, Mac OS, Ubuntu, etc. They all violate my privacy and slow my system to do so.

I use Debian, I like Debian. When I run Wireshark I don't see unknown requests destined to debian.com. That is the definition of simplicity for me. And yes, it doesn't always work out of the box, you have to install some drivers, change configurations but it's getting better and easier. Yet, I'm a software developer so I understand and like that stuff.

> Linux was always a disaster in terms of user experience and isn't improving.

No, you can't define it as a disaster, it's not. If you're an end-user that understands nothing of computers maybe you can but otherwise it's not a disaster. It's just harder and getting easier by day.

paddlesteamer··on Why Is This Website Port Scanning Me?
Actually , I'm pleased ebay is doing this. It wasn't a new issue but now ebay doing it, it took a lot of attention. It's like disclosing a security issue in WebSocket protocol. Now I'm sure next releases of the most browsers will fix it.
paddlesteamer··on Show HN: Raspberry Pi garage door opener
Very nice! I only have one question: I see there are pull-up resistors connected to push buttons. Aren't there built-in pullups on RPi GPIOs? Maybe you can enable them and use fewer elements on the breadboard.
paddlesteamer··on Teensy 4.1 Development Board
Every time I ran across these boards, I always think of "Apollo Guidance Computer"[1] which is used on Apollo spacecrafts.

They have 16KB ram 2000MHz cpu freq so I feel like I can build a spaceship witha couple of teensies :D

[1] https://en.m.wikipedia.org/wiki/Apollo_Guidance_Computer

paddlesteamer··on Teensy 4.1 Development Board
There is even a hearing aid using teensy board and the modified version of teensy audio library[1]!

[1] https://shop.tympan.org/

paddlesteamer··on Teensy 4.1 Development Board
Teensy audio adapter has SGTL5000[1] running on the board and in my opinion it is highly customizable. It provides up to 96KHz sample rate (44.1 KHz with teensy's clock I guess) with 16bit sample size for ADC and DAC so I don't think it's low quality.

[1] https://www.nxp.com/products/audio/audio-converters/ultra-lo...

paddlesteamer··on China starts major trial of state-run digital currency
This is very interesting. It's hard to find information about underlying technology but according to this link[1]:

"Payments via the e-RMB could be contactless and transactions can be conducted via bluetooth and encrypted NFC when two mobile phones with electronic wallets get close to each other. This is different from Alipay and WeChat Pay, that rely on cellular networks, and one can use the e-RMB without the internet, just like paying physical cash."

and

"Meanwhile, the PBoC’s Digital Currency Research Institute that is tasked with the research and development of the e-RMB, advised against a blockchain-based approach to digitalizing the currency or related payment systems, stressing that blockchain’s decentralized and distributed digital ledger that records transactions across many computers runs counter to the PBoC’s role of centralized bookkeeping and administration."

So, it'll be able to work offline. It'll basically act like cash but it's also centralized. How are offline transactions implemented? What happens when you do an offline transaction and then drop both phones into the water? (Schrodinger's transaction?) Is it a surveillance tool on cash payments? I'd definitely like to get my hands on that app.

[1]: https://asiatimes.com/2020/04/china-trials-digital-payments-...

paddlesteamer··on Finding Radio Frequency Side Channels
I also like this approach: https://www.wired.com/2017/02/malware-sends-stolen-data-dron...
paddlesteamer··on When in doubt: hang up, look up, and call back
How do these scammers hide their identities? Is there a tor network or some kind of proxy for gsm?
paddlesteamer··on ICQ New
Why someone would need another messenger? Especially without E2EE?

I think tomorrow I'll bring back myspace.

paddlesteamer··on HTTPS Is a Privacy Nightmare
I remember in the past Moxie Marlinspike developed something called Convergence. It's not alive now. He defined it as

"An agile, distributed, and secure strategy for replacing Certificate Authorities."

in his website(https://moxie.org/software.html). I don't remember how it worked but maybe we can develop something like that.

paddlesteamer··on HTTPS Is a Privacy Nightmare
Sorry, I should have written more clearly.

- Government forces state-issued certificate on all computers:

The government doesn't hide that it's MitM'ing all traffic. The traffic it can't read is blocked. All citizens must install a state-issued certificate to reach any content. There's nothing to do against it. This is what's happening in Kazakhistan now. If another country's government passes a bill, then they can enforce their certificates too. CAA and OCSP are irrelevant here.

- Website X issued a certificate from CA Y. CA Y is in government Z's jurisdiction. Government Z forces CA Y to issue that same certificate for itself. Because government Z make the laws fuck you:

This time the government hides that it's MitM'ing website X's traffic. No way to detect. The government decrypts traffic on the air. CAA and OCSP are irrelevant here.

- Stolen certificate:

Somebody stole the root certificate or stole a certificate given to specific website X. Now that somebody(maybe government) doesn't use this certificate widely but use it to attack to a specific target. It may be detectable but if the attacker uses it cleverly, it may also works. CAA and OCSP are relevant here.

- We deploy a new decentralized mechanism for TLS:

The government doesn't have a company or an organization to ask for a copy of a certificate. That authority is distributed among peers. Since the internet is built on this decentralized certification system, the government couldn't force its citizens to install a state-issued certificate because now the internet doesn't work that way. Now we can use this to secure DNS too.

Think it like this: The governments can't go and ask Open Whisper Systems to decrypt Signal messages, it would be ridiculous. We have to build HTTPS in a way that it would be ridiculous for a government to go to an organization and ask for certificates/keys.

I hope I made myself clear now.

paddlesteamer··on HTTPS Is a Privacy Nightmare
But what if it became like the situation in Kazakhistan where you can't connect to internet without installing state-issued certificate? Or a government forces that CA(assuming CA is in the same country) to sign another certificate? Or a stolen certificate is used in a MitM attack on specific individual?
paddlesteamer··on Pi-hole Remote Code Execution
I think it's more than 'pretty low issue'. Someone already connected to the LAN may just sniff the login credentials since the Pi-hole web interface doesn't use https and then gain root access where all LAN clients trust with their DNS queries.
paddlesteamer··on I had to build a web scraper to buy groceries
Actually, it depends on where do you live. In OP's country elder people have been given rights to call social services and even police to get their shopping done. Other than that, in Turkey family relations are similar to Italy: the old people and younglings usually live together. So there is always a risk to get the disease in the market and then pass it to an elder back at home. OP's doing the right thing keeping his head down and order online.
paddlesteamer··on A detailed look at the router provided by my ISP
Yep, I tried. No luck there
paddlesteamer··on A detailed look at the router provided by my ISP
Hi, OP here, actually it's not true. Think the scenario as this: you don't have the CLI root password, you just do a MitM attack and learn about root password when your ISP attempts to change it. This applies my situation, also I could learn about the default password just by looking into the firmware.
paddlesteamer··on A detailed look at the router provided by my ISP
Hello, OP here, I've actually spent considerable amount time to find a code execution. I know you'll want to learn details of FUN_004122c0 but here is the decompiled version of iptables part from ghidra:

undefined4 FUN_004045a0(int param_1,int param_2)

{ int iVar1; int iVar2; char pcVar3; char cVar4; code pcVar5; undefined auStack544 [256]; undefined auStack288 [260];

  FUN_00412530(auStack544,0,0x100);
  FUN_00412530(auStack288,0,0x100);
  if (param_1 == 0) {
    FUN_004122c0(auStack288,0x100,"iptables > %s 2>&1","/var/IptablesInfo");
  }
  else {
    iVar1 = FUN_00412210(0x100);
    if (iVar1 == 0) {
      return 0x40010009;
    }
    cVar4 = '\0';
    while ((iVar2 = *param_2, iVar2 != 0 && (cVar4 != '\x10'))) {
      if (cVar4 == '\0') {
        FUN_004122c0(iVar1,0x100,0x412c84,iVar2);
      }
      else {
        FUN_004122c0(iVar1,0x100,"%s %s",iVar1,iVar2);
      }
      cVar4 = cVar4 + '\x01';
      param_2 = param_2 + 1;
    }
    FUN_004122c0(auStack288,0x100,"iptables %s > %s 2>&1",iVar1,"/var/IptablesInfo");
    FUN_00412660(iVar1);
  }
  FUN_00412330(auStack288);
  iVar1 = FUN_004123c0("/var/IptablesInfo",0x414f68);
  if (iVar1 == 0) {
    pcVar5 = FUN_004126e0;
    pcVar3 = "Fail\r";
  }
  else {
    while (iVar2 = FUN_00412470(auStack544,0x100,iVar1), iVar2 != 0) {
      FUN_004126b0(0x412c84,auStack544);
      FUN_004121a0(0xd);
    }
    FUN_00412520(DAT_0042b010);
    FUN_004123a0(iVar1);
    pcVar5 = FUN_00412500;
    pcVar3 = "/var/IptablesInfo";
  }
  (*pcVar5)(pcVar3);
  return 0;
}

Any ideas?