[1] : http://blogs.msdn.com/b/nikolait/archive/2013/04/23/introduc...
[2] : http://www.evosuite.org
347 karma · joined April 15, 2013
[1] : http://blogs.msdn.com/b/nikolait/archive/2013/04/23/introduc...
[2] : http://www.evosuite.org
Devices without tokens or with unrecognised tokens would need user approval, those with the correct one would be trusted. That still doesn't solve the problem of deciding if a device should be trusted or not though.
Indeed it can. Bunnie & xobs recently showed how to get code running on the controller chips of SD cards [1]. With your own implementation you could have the card present alternative files (clean vs infected) to different machines based on read patterns [2] or just a mount count. Without an exploit for the kernel, you'd still need the user to click on one the files, however.
That's not to say your suggestion isn't safer; SD cards don't present a threat to HID attacks (where a USB stick pretends to be a keyboard and is trusted to send inputs), but as with anything, it's not totally safe.
[1] : http://www.bunniestudios.com/blog/?p=3554
[2] : http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.h...
However, it seems not everything is kept on the TOR network. I would've assumed that if someone were using TOR for criminal purposes, they wouldn't expose themselves to monitoring by accessing resources off TOR, but that doesn't seem to be the case.
There's a great example of exploiting simple person-person interaction graphs to generate this information here: http://kieranhealy.org/blog/archives/2013/06/09/using-metada...
[0] : http://www.keynote.com/solutions/testing/mobile-testing
I'd be interested to see how much of the breakdown in revenue for their compute cards is for academia, government and industry though.
To me it seems more plausible that the verification answer was a series of spaces. Perhaps the bounty was paid for noticing insecure verification answers weren't rejected?
I'd suggest Nokia's Symbian permission model was better, if a little annoying. It asked each time the app tried to use a given permission (until you permanently allowed/disallowed it).
[1] : http://www.burns-stat.com/pages/Tutor/R_inferno.pdf [PDF]
This is clear evidence that filtering is a terrible way to block "objectionable" content, that it won't make anyone safer; any confidence in it is baseless so the whole thing is just a waste of customers' money.