HNHacker News
TopNewBestAskShowJobs

passfree

166 karma · joined August 8, 2010

submissionscomments
passfree··on Extracting the SuperFish certificate
Well done :)
passfree··on HTML5 Security Cheat Sheet
The problem with your approach is that you are assuming that people are fine that scan for in production for security issues. While it is true that everyone does it, this arguments falls flat because there are plenty of systems which will avoid the risk and for good reasons.
passfree··on JUniversal: A new, Java-based approach to cross-platform mobile apps
Well, those who have done some iOS or Android development know that any good app requires extensive hacking. Unfortunately this doesn't work in a cross-platform manner. For the simplest applications having a cross-platform framework is fine but if you really want to make an immersive app for iOS or Android you need to go native. Now this is not to say that some applications will work perfectly fine under this framework.
passfree··on Presenting the Most Over-Engineered Blog Ever
Yes it is over-engineered. Heck, even WordPress is engineered. Blogs are essentially static pages with the comments as a moving part (i.e. dynamic). Most blogs can happily leave on a static web folder if bound to something like Disqus or whatever you decide to use.
passfree··on Show HN: Building terminal dashboards using ASCII/ANSI art and JavaScript
This is kickass.
passfree··on Bitcoin crashes over 25% in 24 hours, under $180
Oh simply invest into more tangible things, like companies, land and properties, etc. Unless communism becomes modern again it is safe to say that your assets should be secured.
passfree··on Blood Work: Scientists Uncover Surprising New Tools to Rejuvenate the Brain
Futurama anyone?
passfree··on Everything we know Google is working on for the new year
After a certain point I don't think money matters even for Google. :)
passfree··on Everything we know Google is working on for the new year
It is not about the ads any more. Information is far much more important and they do a fine job at taking over every information stream they can get to. In the long run this will play a huge role.
passfree··on 300,000 WordPress hacking attempts and 5 observations
Just in case someone wants to check "their own" wordpress deployments, there is a free, friendly wordpress security scanner here: https://suite.websecurify.com/market/wpscanner
passfree··on Why HTTPS Everywhere isn't on addons.mozilla.org
HTTPS is a good idea but it really doesn't work for me. I am one of those paranoid people who want full end-to-end SSL without exceptions. HTTPS Everywhere doesn't fill the bill.

This is why the company I work for created PanicMode (https://chrome.google.com/webstore/detail/panic-mode/lamdafc...).

PanicMode is ridiculously simple extension. Once activated, it will swap HTTP for HTTPS without leaking even a single packet. Not even pre-flight requests are spared.

PanicMode is not good for general purpose browsing mainly because 99% of the site break badly, i.e. they do not support SSL at all. That is very telling and sad reality. The way I use it is with profiles. I have a bunch of chrome profiles that I use for different purpose. One of my profiles is just for social browsing - facebook etc. I have another one for company stuff. Those profile have panic mode installed and activated. Because I care about security in those profiles I don't mind if I click on a facebook link and it doesn't open up because at least I know that I am protected against side-channel attacks.

It is a very simple mechanism but works well when used effectively.

passfree··on Ask HN: Where do you see web and desktop apps in 5 years?
I think this is a ridiculous thing to say. Don't think of the web as dev platform. Think of it as OpenGL or any other GL language. To create a game you need to use a graphics card which provides a primitive set of instructions but they can be empowered with the help of libraries. The web is the same. It provides a primitive set of functions that can be represented in a common way. They are still usable on their own but much more useful as part of frameworks.

Web technologies is for UI what opengl is for gaming.

passfree··on Ask HN: Where do you see web and desktop apps in 5 years?
Really? Web technologies are much easier to work with and make a much better UI toolkit. Just look at the share amount of developers doing Web stuff and compare them with the amount of developers doing iOS.

And btw, iOS development is easy for as long as you do not want to customize things. Once you start changing the standard controls you are entering the land of no return.

Now compare this with web technologies which are designed to be customizable.

passfree··on Less.Mail – An email assistant that makes you work less
Interesting concept. I did sign up to test it out. However, I think that voice control is not practical with the amount of email we receive on daily basis. Some people will receive more than 100 messages per day that needs to be answered and a voice activated software will not cut it.

However, looking beyond this challenge, the idea is still cool and having an AI assistant to sort out your inbox will be certainly a breakthrough technology. Besides web, email is perhaps one of the greatest innovations of the 20th century but it needs to be brought in the 21st, i.e Email 2.0.

passfree··on Passwordless authentication: Secure, simple, and fast to deploy
A similar idea was discussed here (http://www.gnucitizen.org/blog/simple-universal-authenticati...) in 2008.
passfree··on Tamper: Chrome devtools extension for capturing and editing HTTP requests
Interesting idea. There is also a similar tool over here: https://suite.websecurify.com/market/httpview
passfree··on ShellShock exploited in the wild: kernel exploit with CnC component
As a best practice, you should use it in a separate profile but this is the only way to benefit from this technology.
passfree··on ShellShock exploited in the wild: kernel exploit with CnC component
This test is for public sites. The vulnerability effects web apps too in a big way.
passfree··on CVE-2014-7169: Bash Fix Incomplete, Still Exploitable
Hi everyone,

We just published this tool to test for Shellsheck. https://suite.websecurify.com/market/shellshock

Do a scan over before it is too late.

passfree··on ShellShock exploited in the wild: kernel exploit with CnC component
In case you want to test for ShellSheck https://suite.websecurify.com/market/shellshock
passfree··on Node.js Best Practices
I have one word: CoffeeScript.
passfree··on Chromeos-apk – Run Android APKs on Chrome OS, OS X, Linux and Windows
The Android emulator is terrible. It is one of those things that will speed up Android adoption if made better. iOS simulator is so much nicer to work with.
passfree··on Chromeos-apk – Run Android APKs on Chrome OS, OS X, Linux and Windows
There are no limitations of what you can do via a web browser. My company personally developed and delivered projects otherwise thought not possible in browser environments. With the help of extensions and solid JS and HTML, everything is possible. Of course super low level stuff are out of the picture but this is not normal users will be concerned about.
passfree··on Writing Extensions for Firefox Is Barely Worth the Trouble
Btw, we debug a lot of JS code and although Chrome has better developer tools they do crash... a lot and are unresponsive too. Chrome/Webkit should have native tools not the one written in JavaScript because this is a mess. They are still better than Firefox's dev tools.
passfree··on Writing Extensions for Firefox Is Barely Worth the Trouble
I have also experienced this sad situation with Firefox. XUL was my biggest disappointment because mozilla was not willing to invest any time to make it better. Instead they shipped this monstrosity called addon-sdk. You need python to develop JS applications? This is stupid.

I would love to see firefox converging with NodeJS but given mozilla's attitude towards developers lately I seriously doubt that it will ever happen.

Firefox has a very rich history and the technology is fantastic but sadly it is not made to be easy to the developer.

passfree··on My iOS Indie-Game Numbers
$0.99 for an App is not sustainable pricing unless your product is mass-marketed in order to make up the numbers. My company have several products in iOS and Mac App Stores and none of them are near this price. In fact, one of our products (Websecurify for iOS) is $16 which you may say is an expensive app for iOS but this is a more realistic pricing. I doubt we would have achieved any effect if we had priced it $0.99. Btw, the next version of our app will probably cost twice as much because even $16 is barely sustainable.

I think it is time for iOS developers get their strategy checked up. I know a lot of people want to get their app/game to a lot of people but unless you have evidence that you app is reaching millions of people, it is not going to work.

passfree··on Discovering private APIs with Charles.app
Proxy.app from Websecurify is native Mac proxy and it is pretty good too.
passfree··on Discovering private APIs with Charles.app
You can use Proxy.app (http://www.websecurify.com/desktop/proxy.html) which does that. As for the certificate pinning - it makes proxying a very difficult.
passfree··on XSS in TweetDeck
It is unknown because nobody checked. Why nobody checked? Because it is too simple so nobody thought that it will work until now.
passfree··on UK government's password checker sends plaintext password in the URL over HTTP
This is so wrong in some many levels.

1. They should not ask for any password first of all 2. They post the password to their server when they could have checked it on the client 3. The password is sent as GET meaning that it is in the URL and it will be recorded in your history and perhaps anything else that keeps log of the URLs you visit

100% fail

Page 1 of 3Next →