HNHacker News
TopNewBestAskShowJobs

red0point

635 karma · joined March 23, 2015

submissionscomments
red0point··on TinyCheck: Easily capture network communications coming from a smartphone
If you don’t want to change SIM cards, you cold go to 2G and easily create a fake base station and disable 3G/4G on the phone. For 4G, it‘s a bit more tricky as you need to do a relay attack (https://alter-attack.net/) and even then only do some DNS redirection if you know what host is being looked up, or some fingerprinting based on the size of the traffic.

Of course, you can also just check if the phone sends something by looking at the RF energy or even build an uplink decoder, but I doubt that this is very useful information by itself for this use case.

Finally, what I propose instead, is to use a private LTE network, which you can create using a SDR and srsLTE and some programmable SIM cards, which you need to insert into the phone. This way, it‘s easily possible to view any traffic leaving the phone on any connection. Plus, srsLTE has been shown to work on Raspberry Pi as well (I think).

red0point··on TinyCheck: Easily capture network communications coming from a smartphone
Well not easily, because once the outer TLS has been set up, you can‘t see the contents of the second TLS handshake. You could maybe deduce it via packet sizes and timings, but certainly not pretty easily.
red0point··on TinyCheck: Easily capture network communications coming from a smartphone
When cellular data is disabled (assuming it really is, not just faked to the user), then the corresponding radio bearers for user plane data habe not been established, thus no data-stream can travel with it. You can only communicate with the eNb and MME in this stage, and even this isn’t exposed directly to the OS but embedded in the Chipset.
red0point··on TinyCheck: Easily capture network communications coming from a smartphone
Not directly, as the flight mode really prevents any radio communication (it takes a bit to shut down as it sends a NAS Detach Request first and waits for a reply for a few seconds).

However, there is also WiFi Calling - in that sense, your phone establishes some connection with the cell network. However, I don‘t think any user data may travel on this bearer, but there might be some edge case where this is possible.

red0point··on Scion EPIC: a path-aware clean-slate internet architecture
Their research group actually went down a similar road, and explored a possible design of an anoymous communication network on top of SCION, called HORNET - check this out:

https://netsec.ethz.ch/research/anonymity.php

red0point··on Scion EPIC: a path-aware clean-slate internet architecture
As addressed by the author, Dr. Markus Legner, these points are not true for SCION, as it is a path-aware routing system. Especially the paths cannot be spoofed, as their MAC is checked at each router hop (an extremely efficient operation, much faster and energy efficient than big router table lookups).

And exactly this tradeoff is examined in the blog post (and their EPIC paper).

red0point··on Ubooquity: Free home server for your comics and ebooks library
Cool solution, however, what does CC stand for?
red0point··on Control Legacy Electronic Devices via the Internet
While it's a cool result, I think the security of this is really lacking. The author mentions to not want to expose the Rasperry Pi to the internet due to security reasons, but then does so anyway through a reverse proxy, which doesn't even add any authentication.

To exploit this, you can simply do: 1. Search in AWS networks for open ports 6000. Tools like masscan help, but if you give it time it will also show up on shodan.io 2. Connect and send a GET request to the /switch/on path and check if you get a 200.

red0point··on I reverse engineered McDonalds’ internal API
I don‘t know about 3G, but I just checked for LTE [1] and the timing is broadcasted in SIB16, which is not encrypted, so theoretically anything could pick it up.

[1] https://www.etsi.org/deliver/etsi_ts/136300_136399/136331/11...

red0point··on Controllable Video Sprites That Appear Like Professional Tennis Players
No need to think that far. Just calculate the hash of the video file stored on camera (or segments of it during e.g. live stream) and authenticate this using a private key stored in a secure element on the camera. Do you trust this secure element enough (see the breach of Intel’s CPU Private Keys via SpecEx, maybe you can do so by loading a custom firmware as well?).

Assume the secure element is in fact secure, the issue then, as with any public/private key scheme, lies with establishing trust of the keypair. Do you trust the manufacturer that he will not be breached?

And more pressing even; How do you prevent someone modifying their internal camera video stream such that they may send any data to the authentication chip/mechanism?

And if all this is implemented, it can be done even more low level - just direct the camera e.g. to your screen (I assume solutions would then crop up to increase the fidelity of such a solution).

I am not saying such a solution would not provide ANY benefits, I am just pointing out that these issues prevent it from becoming a silver bullet.

red0point··on A ride that takes 10^20k years to complete in Roller Coaster Tycoon 2 [video]
Sure you can use Big O, just look at it as the expected runtime. For example, QuickSort is O(n^2) in worst case, but expected O(nlog(n)).
red0point··on New ‘Meow’ attack has deleted almost 4k unsecured databases
I‘m not sure why you‘re bringing concurrency to the table.

My point still is that looking something up in a stack (did I visit this node?) costs O(n) time, so the BFS will degrade from O(m+n) to O(m*n+n).

To come back to the concurrency, if you can index your edges in some way, you can also store the visited flag in a separate datastracture to support concurrent access (one „flag store“ for each access).

red0point··on New ‘Meow’ attack has deleted almost 4k unsecured databases
1) If it‘s a tree, it ain‘t got no loops 2) The stack isn‘t to deal with loops, the „visited“ flag at each edge is there for that. The stack (for DFS, BFS would be a queue) is there to keep track of which nodes have been visited such that you can construct a path from the starting node to the one you‘re looking for.

Obviously there are variants to this, depending on what you‘re actually trying to achieve with it. My point is that a stack would be a very inefficient way to deal with loops.

red0point··on DIY Video Hosting
May I ask from which provider you are getting this VPS? 20USD for unlimited 10Gbit/s bandwidth sounds a bit too good to be true.
red0point··on Ask HN: How can I quickly trim my AWS bill?
For the ML models you can also switch to dedicated server providers, such as: https://www.dedispec.com/gpu.php

For storage, there‘s always Wasabi / B2 with S3 compatible interfaces. If the data itself is not changing that much, so regular backups are possible, just use some dedicated storage servers with hard drives and install MinIO. Do not rely on S3 for outgoing data (much too expensive), use a caching layer on another provider (OVH , Hetzner, ...), or if it fits your workload, Wasabi („free“ egress).

red0point··on NHS rejects Apple-Google coronavirus app plan
Valid point. DP3T (in one configuration) adresses this and lets you filter out certain parts that you do not wish to disclose. Thus, this then requires you to upload all broadcast identities used in the relevant timeframe, but because of space-related issues is then „compressed“ using a Cuckoo-Filter. This, however, yields false-positives. To eliminate those to a managable amount, it further requires more space.

So, this has a tradeoff. Personally I don‘t think that linking multiple IDs in a day is a big intrusion of your privacy (and remember, it‘s only disclosed to anyone for the timeframe that is epidemologically relevant) - full de-anonymization still requires some second channel, such as cameras or the like - which can be linked together without those Broadcast IDs anyways.

red0point··on CryptoCam: Privacy Conscious Open Circuit Television
Great insight.

Additionally, an attacker could gain long-term visibility of the cameras footage, simply by continuously capturing the broadcasted keys via a covertly placed device, either in close proximity to the camera or further away with high-gain directional antennas.

red0point··on Show HN: Easily move between cloud storage (S3, Backblaze, OneDrive, etc.)
I bet they‘re using exactly your tool internally ;)
red0point··on Universal, reusable virus deactivation system for respiratory protection (2017)
They are airtight in this study. From the abstract:

When tested with tightly sealed sides, salt-coated filters showed remarkably higher filtration efficiency than conventional mask filtration layer, and 100% survival rate was observed in mice infected with virus penetrated through salt-coated filters.

red0point··on You can now make horcruxes out of your confidential files
Just use regular Reed-Solomon for the data and Shamir's Secret Sharing for the key (an implementation is for example http://point-at-infinity.org/ssss/).

If you choose the same parameters for both algorithms, you can freely assign any key with any data shard and store those.

red0point··on You can now make horcruxes out of your confidential files
This is unsafe and should not be used.

This is simply splitting the key in multiple pieces, thus for every piece you have, you gain additional information about the key, allowing for exponentially easier brute-forcing of the remaining key.

Example: Assume someone creates 3 horcruxes and you can get your hands on 2 of them. This gives you 85 bits of the full 128 bit key, thus you only need to brute force 43 bits for the rest. Of course you don't have the full data anyways, but you still learn about 2/3 of it.

A better tool is ssss which uses Shamir's Secret Sharing. http://point-at-infinity.org/ssss/

red0point··on “move fast and break things” almost killed our startup on arrival
And how will you monetize it when all premium features are free? Will there be premium-premium features that require payment?
red0point··on What Stress Does to the Brain
Original Source:

https://ethz.ch/en/news-and-events/eth-news/news/2019/07/wha...

red0point··on Driverless Congestion
In Zurich, the maximum base fare is 8 CHF, while the maximum price per kilometer driven is 5 CHF [1]. UberX currently costs 1.80 CHF per kilometer [2]. It's not all that unrealistic to assume that this cost will go down to 56 Rp. when letting autonomous vehicles drive.

[1] https://www.stadt-zuerich.ch/content/dam/stzh/pd/Deutsch/Sta... [2] https://www.uber.com/de-CH/blog/zurich/preise-zurich/

red0point··on Why Do Buses Bunch?
But what if I (or all passangers) want to get off at the next stop?
red0point··on Ask HN: Is Google Compute down?
Yes there is an approach out there, solving many problems of the internet at once. It‘s called SCION and is being used in production at large swiss banks today.

https://www.scion-architecture.net/

red0point··on ESNI: A Privacy-Protecting Upgrade to HTTPS
https://blog.cloudflare.com/encrypted-sni/

The Cloudflare blog for details.

red0point··on Getting Started with DNS over HTTPS on Firefox
Essentially, you're now not only trusting 1 entity but 6 - if any of those 6 will log / leak data, you're offering them 1/6th of your traffic. The probability of that happening is significantly larger than using only a single provider (if you want to calculate it, there's the Binomial Distribution).

That being said, if any of those providers would then leak your traffic patterns, all the attacker would get is your VPN IP address and not your home IP address. So essentially, you're making it even harder to correlate DNS queries to you.

red0point··on The Data Transfer Project
Let me shout from the back so you can hear:

BUT THEY HAVE AN INTER-COMPATIBLE DATA MODEL?!

Or at least they're trying to create one. They talk about it in their overview: https://datatransferproject.dev/dtp-overview.pdf

And the actual implementation of the model is on Github as well:

https://github.com/google/data-transfer-project/tree/master/...

red0point··on Getting Started with DNS over HTTPS on Firefox
Cool project! I'd wish I had so much dedication for implementing this at home :)

You could also take inspiration from the NSA and actually perform random DNS queries & HTTP requests to various sites to disguise the true queries.

Another improvement would be actually offloading the resolver to another location via a VPN and querying from there.

← PreviousPage 4 of 5Next →