HNHacker News
TopNewBestAskShowJobs

pedro84

1,930 karma · joined August 12, 2013

submissionscomments
pedro84··on Why does zsh start so slowly?
RE: #2, would "wait $(jobs -rp)" work for you?
pedro84··on Crush: A command line shell that is also a powerful modern programming language
$ ls -l /usr/bin | awk '$5 > 50000000'

-rwxr-xr-x 1 root root 51859776 Jan 26 2018 pandoc

pedro84··on OpenSSH to deprecate SHA-1 logins due to security risk
http://www.openssh.com/txt/release-8.3

To check whether a server is using the weak ssh-rsa public key algorithm, for host authentication, try to connect to it after removing the ssh-rsa algorithm from ssh(1)'s allowed list:

ssh -oHostKeyAlgorithms=-ssh-rsa user@host

If the host key verification fails and no other supported host key types are available, the server software on that host should be upgraded.

pedro84··on An introduction to data processing on the Linux command line
This is a little more awk-ish:

awk -F, '$2 == "F" {$0=(($1-32)*5/9)",C"} {print}'

pedro84··on The Return of the WIZard: RCE in Exim (CVE-2019-10149)
Qualys re-posted their writeup and included the details that had previously been left out:

https://www.openwall.com/lists/oss-security/2019/06/06/1

pedro84··on More Productive Git
> We then tell git bisect to run the command lein test on each commit until the command exits with a 0 exit code, indicating that we’ve found the first broken commit.

According to git-bisect(1), "the script should exit with code 0 if the current source code is good, and exit with a code between 1 and 127 (inclusive), except 125, if the current source code is bad."

pedro84··on How to Analyze Billions of Records per Second on a Single Desktop PC
I learned from The AWK Programming Language:

https://news.ycombinator.com/item?id=13451454

pedro84··on Breaking Signature Verification in Pass (Simple Password Store) (CVE-2018-12356)
The project's response is here:

https://lists.zx2c4.com/pipermail/password-store/2018-June/0...

pedro84··on XNU kernel heap overflow due to bad bounds checking in MPTCP
https://twitter.com/i41nbeer/status/1004130737174515712

""" The trigger is here: https://bugs.chromium.org/p/project-zero/issues/detail?id=15... … If you're in to iOS exploit dev take a go at it and blog about it! I'll publish what I have soon, hopefully this week. """

pedro84··on Speculative execution, variant 4: speculative store bypass
Additional vendor info:

https://developer.arm.com/support/arm-security-updates/specu...

https://blogs.technet.microsoft.com/srd/2018/05/21/analysis-...

https://www.intel.com/content/www/us/en/security-center/advi...

pedro84··on Detangle automatically separates your browser into multiple browser profiles
https://twitter.com/svblxyz/status/958314262270705664

Detangle is now open-source. You can specify a list of "internal sites" to be opened in your main browser, while other sites get opened in contained / separate profiles (or Incognito mode). Great for added protection against UXSS and other threats.

pedro84··on How “Exit Traps” Can Make Bash Scripts More Robust and Reliable
I've used a variation of this that catches other signals as well:

  trap 'rc=$?; trap "" EXIT; cleanup $rc; exit $rc' INT TERM QUIT HUP
  trap 'cleanup; exit' EXIT
pedro84··on Game Over We Have Obtained Fully Functional JTAG for Intel CSME via USB DCI
blog post with more details from the tweet's author: http://blog.ptsecurity.com/2017/10/how-to-obtaining-full-sys...
pedro84··on Remotely Compromising Android and iOS via a bug in Broadcom's WI-FI Chipsets
Apple released fixes for both macOS and iOS last week:

https://support.apple.com/en-us/HT207923 https://support.apple.com/en-us/HT207922

pedro84··on Enter 30 to Shell: Cryptsetup Initram Shell [CVE-2016-4484]
Same team found a similar vulnerability last year in grub:

http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-by...

pedro84··on Sweet32: Birthday attacks on 64-bit block ciphers in TLS and OpenVPN
From the article: "But the take-away is this: triple-DES should now be considered as “bad” as RC4."

OpenSSL developer Mark Cox says: "tldr: "Low", Don't Panic!" https://twitter.com/iamamoose/status/768431734547484672

The researcher site is https://sweet32.info/

And RedHat has a nice writeup as well: https://access.redhat.com/articles/2548661

pedro84··on Microsoft: 0Day Exploit Targeting Word, Outlook
"First, our tests showed that EMET default configuration can block the exploits seen in the wild."

http://blogs.technet.com/b/srd/archive/2014/03/24/security-a...

pedro84··on Bitcrypt broken
Ransomware crypto fail:

  The number has 128 digits, which could indicate a (big)
  mistake from the malware author, who wanted to generate
  a 128 bytes key.
  Finally, we simply deal with RSA-464 encryption, which
  can easily be broken on a standard PC in a matter of hours.
pedro84··on ISeeYou: Disabling the MacBook Webcam Indicator LED
I think there's more here than what can be fixed with tape. Your computer has computers in it that can be re-programmed in ways that the OS doesn't tell you about. From the pdf:

  The same technique that allows us to disable the LED, namely 
  reprogramming the firmware that runs on the iSight, enables
  a virtual machine escape whereby malware running inside a
  virtual machine reprograms the camera to act as a USB Human
  Interface Device (HID) keyboard which executes code in the host
  operating system.
pedro84··on Ask HN: Moving from PHP to Django, setup & host advice?
There's a walkthrough of some of those sysadmin-y things here:

  http://ponytech.net/blog/2013/09/10/django-deployement-ubuntu-upstart-nginx-gunicorn-and-virtualenvwrapper/
pedro84··on Hosting backdoors in hardware
On linux:

  echo 1 > /proc/sys/kernel/modules_disabled

  http://www.outflux.net/blog/archives/2009/07/31/blocking-module-loading/
pedro84··on Square open-sources its Vim repo, Maximum Awesome
Is the Keyboard Repeat Rate or Delay Until Repeat set to low? (System Preferences -> Keyboard)
pedro84··on Obama administration asks Supreme Court to allow warrantless cellphone searches
Seems pretty clear that it's time for the next generation (cyber-citizen party?) to start running for office.

/me writes in tptacek / cperciva