HNHacker News
TopNewBestAskShowJobs

shallot_router

289 karma · joined April 24, 2017

submissionscomments
shallot_router··on Uber Paid Hackers to Delete Stolen Data on 57M People
It's not related to this particular breach, but given this and Uber's other issues, it's not out of the realm of possibility that at some point they had a more serious breach involving loss of password hashes or interception of credentials at login.

(But in all likelihood the poster's account was just compromised through the usual means, otherwise there would be more reports of hacked accounts.)

shallot_router··on Uber Paid Hackers to Delete Stolen Data on 57M People
It's very common, but there are lots of ways of addressing it.
shallot_router··on The Tories have voted that animals can't feel pain as part of the EU bill
This is in some ways more despicable than almost everything the Trump administration has passed so far.
shallot_router··on The Parity fallout: Which ICOs are affected?
Not sure why you're being downvoted for this. Seems like a valid concern for such a system.
shallot_router··on How Sentry Receives 20B Events per Month While Preparing to Handle Twice That
Serving a static web page 8-50k times per second and doing some really complex processing 8-50k times per second are worlds apart.
shallot_router··on Parity Wallet security alert
If they don't fork, everyone affected by this will lose all of their ETH.

Many would argue the correct thing to do is to not fork and say that people knew the risks beforehand, etc. But that's what people said last time and they still forked, with no (apparent) severe consequences other than complaining about integrity. Two forks may be harder to justify.

shallot_router··on Experiments to identify potential neural mechanism in “feeling of presence”
As a general trend, I don't think so, but this thread seems to be an anomaly. This is the first HN thread in a while where I felt like I stumbled into a default subreddit or something.
shallot_router··on www.reddit.com/etc/passwd
https://www.reddit.com/r/ProgrammerHumor/comments/78aa07/red...

That's a pretty funny easter egg.

shallot_router··on Google Docs Is Randomly Flagging Files for Violating Its Terms of Service
In terms of user security, that's just not a good idea. Google has likely prevented an absurd number of account compromises (and therefore identity theft, fraud, personal information leakage, espionage...) by recognizing logins from new devices and unfamiliar locations. Google's user account security practices are pretty much the best in the business.

It's silly to think Google doesn't already know everything about every device you log in from, so that horse is already out of the barn and running on the highway privacy-wise. They might as well use that information to actually protect their users since they're already using it for advertising.

shallot_router··on Magic mushrooms may 'reset' the brains of depressed patients
The key point from the paper [1]:

>Decreased depressive symptoms were observed in all 19 patients at 1-week post-treatment and 47% met criteria for response at 5 weeks.

Small sample size, but definitely an interesting result. I was hoping they'd test again after a few months have passed, though.

[1] https://www.nature.com/articles/s41598-017-13282-7

shallot_router··on Equifax website hacked again, this time to redirect to fake Flash update
WHOIS history on that domain shows the registration changed hands on November 15, 2016. Before that, it was owned by "Digital River, Inc.":

    Registrant Name: Digital River, Inc.
    Registrant Organization: Digital River, Inc.
    Registrant Street: 10380 Bren Road West
    Registrant City: Minnetonka
    Registrant State/Province: MN
    Registrant Postal Code: 55343
    Registrant Country: US
    Registrant Phone: +1.9522531234
    Registrant Email: hostmaster@digitalriver.com
Digital River appears to be an online commerce company: https://www.digitalriver.com/cloud-based-ecommerce-solutions...

They were probably the legitimate owners. The domain registration expiration date at that time was set for 2017, so it doesn't look like a registration lapse. It's unclear how and why the ownership was transferred.

shallot_router··on Russian Hackers Stole NSA Data on U.S. Cyber Defense
In practice, this isn't really possible, though. The binary is usually going to be slightly different. In theory you could RE the differences and potentially disprove a backdoor, but it's not easy.

Also, it's not necessarily that hard to slip a very subtle backdoor into the source.

shallot_router··on Lessons from France's first cyber-attack, nearly two centuries ago
This seems more like a "hack" in the general tech sense than the security sense (even though it's probably technically illegal). I even think it'd be something YC would love to see on an application.
shallot_router··on Russian Hackers Stole NSA Data on U.S. Cyber Defense
>There are also things like Kaspersky previously volunteering to provide complete source access to the government. Our government declined the offer. How does this make sense?

First, even if they were giving access to their genuine source code repository, there's absolutely no guarantee that the binaries aren't backdoored by Kaspersky, FSB, or both. Alternatively, they could just hand over a phony copy of the source.

It's kind of a pointless offer. There's no real reason to deny, but there's also no reason to accept. If the fear is that their products might be influenced or backdoored by hostile intelligence agencies, the only reasonable solution is a total boycott.

(And yes, I very much understand the exact same could be said of the NSA and a lot of US-made software.)

shallot_router··on Hedge Funds Flip ICOs, Leaving Other Investors Holding the Bag
What % of ICOs are seemingly legitimate? I see advertisements for ICOs on reddit and other tech websites all the time, and I have yet to find one that doesn't look incredibly shady.
shallot_router··on Yahoo Triples Estimate of Breached Accounts to 3B
I'd be pretty surprised if an attacker could actually get away with a lot of sensitive, actionable bulk user data from Facebook. DMs would probably be way too big in total, unless they just looked for DMs of high-profile people.

As for passwords, they're probably not stored in a very crackable format (probably some kind of super-bcrypt-esque algorithm with a pepper). Of course, they could hijack the login procedure and harvest passwords in real-time until they're detected. That would still be really bad depending on how long they can evade detection - maybe millions of passwords - but at least it wouldn't be retroactive. And the password dump could still be bad for people looking to target individuals within the dump.

Maybe advertising data could be trimmed down enough to dump the whole thing? Every ad that accounts have clicked?

shallot_router··on Yahoo Triples Estimate of Breached Accounts to 3B
I'm not too surprised at the 3 billion. I'm just wondering how many of those correspond to real people.
shallot_router··on Fully driverless cars could be months away
How could a driverless car ever truly be tamperproof, though? At some point we'll just have to accept it as a potential risk.
shallot_router··on Cloudflare Workers: Run JavaScript Service Workers at the Edge
Technically, yes, but as I understand it, they frown upon it and could potentially terminate your account. See this section of their ToS (https://www.cloudflare.com/terms/):

>SECTION 10: LIMITATION ON NON-HTML CACHING

>You acknowledge that Cloudflare’s Service is offered as a platform to cache and serve web pages and websites and is not offered for other purposes, such as remote storage. Accordingly, you understand and agree to use the Service solely for the purpose of hosting and serving web pages as viewed through a web browser or other application and the Hypertext Markup Language (HTML) protocol or other equivalent technology. Cloudflare’s Service is also a shared web caching service, which means a number of customers’ websites are cached from the same server. To ensure that Cloudflare’s Service is reliable and available for the greatest number of users, a customer’s usage cannot adversely affect the performance of other customers’ sites. Additionally, the purpose of Cloudflare’s Service is to proxy web content, not store data. Using an account primarily as an online storage space, including the storage or caching of a disproportionate percentage of pictures, movies, audio files, or other non-HTML content, is prohibited. You further agree that if, at Cloudflare’s sole discretion, you are deemed to have violated this section, or if Cloudflare, in its sole discretion, deems it necessary due to excessive burden or potential adverse impact on Cloudflare’s systems, potential adverse impact on other users, server processing power, server memory, abuse controls, or other reasons, Cloudflare may suspend or terminate your account without notice to or liability to you.

I think in practice, unless you have a very popular website or are abusing it in some way, they probably wouldn't care or even notice. But you'd still be taking a gamble.

(I don't work at Cloudflare though so take whatever I say with a grain of salt.)

shallot_router··on Cloudflare Workers: Run JavaScript Service Workers at the Edge
This seems like it has a ton of potential. I'm already thinking of the possibilities for my own Cloudflare-proxied sites.

I hope it's not priced too harshly. Hopefully an added monthly flat rate rather than per-request pricing?

shallot_router··on WeChat confirms it makes all private user data available to Chinese government
They're stupid if they're just saying something everyone already knows. It'd be like saying "the US government assassinates civilians with unmanned airborne vehicles" or something.
shallot_router··on Facebook is 'silencing' Rohingya Muslim reports of 'ethnic cleansing'
Or a lot of tribalism?
shallot_router··on Facebook is 'silencing' Rohingya Muslim reports of 'ethnic cleansing'
I never thought I'd see the day where a Buddhist monk in robes is calling for the genocide of "Muslim vermin". (I don't think he literally said "vermin", but that's basically the analogies he's using.)
shallot_router··on Facebook is 'silencing' Rohingya Muslim reports of 'ethnic cleansing'
Yep. People complain about the "adpocalypse" and censorship from YouTube and Facebook, but they're really stuck between a rock and a hard place.

That said, I think they should always err on the side of free speech wherever possible.

shallot_router··on W3C abandons consensus, standardizes DRM, EFF resigns
I believe they were being sarcastic.
shallot_router··on Announcing CoffeeScript 2
I wish someone could take the best parts of TypeScript and CoffeeScript and put them together.
shallot_router··on S3 was down
Definitely not. If HTML caching were enabled by default, I would've run into all sorts of weird issues with a lot of my Cloudflare-protected sites.
shallot_router··on Forget Equifax. Facebook and Google Have the Data That Should Worry You
Ah sorry, I did misunderstand. Yes, no one is safe. Not Google, not Facebook, and not NSA or CIA or any agency or organization on Earth. A good defense is much harder than a good offense when it comes to infosec.
shallot_router··on DHS Issues BOD Banning Kaspersky from Federal Government
Nginx isn't a security company and doesn't make client-side software, so probably not. (Of course, theoretically nginx could be backdoored to give valuable information to intelligence agencies, but it's harder due to the fact it's open source, and even if it was closed source the escalation in response to banning nginx could start a new Cold War. Imagine the US and Russia mutually banning use of any of the other side's software and actually trying to implement it.)
shallot_router··on DHS Issues BOD Banning Kaspersky from Federal Government
Of course that's what the Russian officials said, but who knows how accurate that is or what might be omitted from that statement?
Page 1 of 4Next →