HNHacker News
TopNewBestAskShowJobs

theEXTORTCIST

75 karma · joined February 7, 2017

submissionscomments
theEXTORTCIST··on How to build a house alone [video]
I am trying to understand your post. Is it cheaper per yard to hire a concrete truck than to mix concrete (with free aggregate/sand) yourself?
theEXTORTCIST··on Tinder's lack of encryption allows spying
There is the issue of the TLS connection of images fetched in the app (other things too?) being tied to a domain without a valid cert. In other words, you could MITM the TLS session between the wifi user and the Tindr servers for AT LEAST photos within the app, perhaps more (authentication? other app behavior?).

Because the app isn't strictly enforcing the validation of the cert of the photos domain it's trying to reach to pull photos, your MITM server is free to serve to the app as if it was the server on the Internet.

theEXTORTCIST··on How I recovered cryptocurrency from a broken laptop
I agree that you need "both halves" in this scenario to sign the transaction.

At some point during the spend from the wallet, the privkey that matches the wallet pubkey has to touch memory. This privkey can in theory be compromised in a number of ways with malware on the spending system (keylogger, screen caps, process memdump, etc).

I think the safest way to go about this is to generate an entirely new keypair/wallet on an isolated system. Spend from your wallet then transfer the balance to the newly created wallet. This minimizes losses as a result of privkey compromise (unless of course your isolated system isn't so secure)

theEXTORTCIST··on How I recovered cryptocurrency from a broken laptop
The attacker only needs to have compromised the device which spends from the wallet file
theEXTORTCIST··on How Cybercriminals Can Abuse Chat Platform APIs as C&C Infrastructures [pdf]
I don't think it's "stupid" to C2 via chat API. It would be "stupid" to have no fallback mechanisms
theEXTORTCIST··on Reported difficulties getting help on Equifax's phone lines
plot twist: active breach investigation on going with all 3 majors
theEXTORTCIST··on How does FreedomPop make money?
TOR does not protect DNS queries out of the box. You must configure your PC to query through TOR or all of your DNS queries have the potential to leak to your ISP

https://tor.stackexchange.com/questions/8/how-does-tor-route...

Verizon has been adding headers for tracking for some time (probably via Blue Coat ProxySG forward proxy or similar technology) https://www.verizonwireless.com/support/unique-identifier-he...

theEXTORTCIST··on The Librem 5: A Matrix-Native FLOSS Smartphone
This seems like a really cool device. One that I would certainly purchase.

What weird stretch goals they have. I wonder if these are jokes? "$8m = Signatures of entire team printed inside the phone case $10m = Free encrypted VPN tunnel service for all backers for 1 year $20m = Candy Crush (clone) available for free"

theEXTORTCIST··on A glut has used-car depreciation accelerating
This is one of the biggest points that I have seen taught in driver training courses and repeated throughout my life. Most of the events people refer to as car accidents are crashes/collisions.
theEXTORTCIST··on Psilocybin-assisted group therapy for demoralization in long-term AIDS survivors
This is definitely a confusing sentence, especially for a non English speaker. You can reword the sentence and add something in front (e.g. "The researchers"). "The researchers are using psilocybin assisted group therapy for demoralization in long term AIDS survivors."

AIDS surviors have "demoralization in them". The psilocybin assisted group therapy is being used for that demoralization.

theEXTORTCIST··on Inside one of the world’s largest Bitcoin mines
Interesting... there doesn't appear to be any fire suppression systems pictured in the mining buildings
theEXTORTCIST··on 'Body Brokers' Get Kickbacks to Lure People with Addictions to Bad Rehab
Report it anonymously to your insurance provider (*not sure if this is possible and/or would actually do anything)
theEXTORTCIST··on URL obfuscation (2002)
The data URL scheme is abusable.

Firefox and Chrome correctly redirect to localhost via javascript

  data:text/html,http://www.mostSecureInternetBankVictim.com/customerLogin.php%2FreallyLoginRandomData=130r193fj02jf-2jf023f23f-f2039f0239jf0a-39j029jg90wgj-9203f092jf0f-90e9f204fh0-9hf2ef8CUSTID=923r9032fdjnnvjddata%3Atext%2Fhtml%2C%3Cscript%3Ewindow.location%20%3D%20%22http%3A%2F%2F2130706433%22%3B%3C%2Fscript%3EValuedGoogleCustomer=?Security=trueEncrypted=trueSecureBrowsingSession=True
theEXTORTCIST··on URL obfuscation (2002)
I just tried this on Chrome 60.0.3112.90. Both Firefox and Safari throw phishing warnings with these URLs.

http://news.ycombinator.com@1572395042 Chrome takes me to 93.184.216.34 no warning

Then I tried http://security.wellsfargo.com@customerLoginv=ar3351RandomDa...

Which stretches way past my laptops viewable URL bar... and it takes me right to badsite.null (or a valid site like example.com). If you need HTTPs you can redirect on badsite.null's web server. Very wild.

theEXTORTCIST··on Why our outdated brains are making us unhappy
In society we have an endless amount of social warnings, "Don't drink too much, you'll get ill. Don't do drugs, you'll become an addict. Don't drive without your seatbelt, you can die. Don't watch too much TV, it's not good for you."

But we still lack any sort of warning in the greater contemporary society about the risks of overuse of the hyper stimulus that comes along with social media. I am definitely beginning to see this take shape in our society (with people rejecting social media applications, articles like this, the way people speak to the overuse of such platforms)

theEXTORTCIST··on US diplomats mysteriously go deaf, Cuba suspected of using sonic weapons
I have heard one of these in San Francisco, CA in the USA. The music had a really high pitched note behind it that sounded horrible.. like a cross between a mosquito and the buzzing of an input jack
theEXTORTCIST··on Baby Boomers Who Won't Sell Are Dominating the Housing Market
Forcefully taking private property from individuals to later sell to other private parties for private use sounds like the nightmare version of eminent domain.
theEXTORTCIST··on Amazon owns a whole collection of secret brands
to add to your post, that affiliate link stays active on amazon accounts that clicked it for 24hours and pays out to the owner for every product purchased in that time frame
theEXTORTCIST··on Why Germans pay cash for almost everything
Was waiting for this comment. I often ask myself, "Do I want any entity to have a copy of the exact dates and amounts of my entire daily consumer activity?". Whether anonymized or not there is a tremendous amount of knowledge that can be gleaned from non-itemized debit card ledgers.
theEXTORTCIST··on Why Germans pay cash for almost everything
Some relevant info: In the USA average consumers are protected by the FDIC for the balances of their deposits up to $250,000. A large number of banks have consumer liability limits in place for protection from fraudulent charges on their credit cards.

https://www.fdic.gov/consumers/banking/facts/

theEXTORTCIST··on Blackwater Founder Wants to Provide “Turn Key” Mercenary AF for Afghanistan
this is an interesting application... was linked in the article safestrike.it
theEXTORTCIST··on Arrest of WannaCry researcher sends chill through security community
Link to the Orin Kerr article: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.

theEXTORTCIST··on Dumbo: CIA system to take over webcams, microphones
From my comment, the SPECIFIC details of the tool's concepts of operation, implementation, and capability.

The field guide provides great detail on operations and limitations of a specific existing tool (sample GUI screen shots, potential detection threats from personal security products and full crash dumps, detection of cam software process restarts, abilities to stall NIC cards, abilities to BSOD, ability to corrupt existing files, limitations based on cam emulation, limitations of previously saved cam files, the tool's PE names(32bit wscupd.exe, 64bit running outside of system32 wermgr.exe. GUI.exe present in the same folder as above PEs), example of the log.txt file written to the attacking USB, information on differences between winXP requirements vs other systems(scanner.sys driver needs)).

theEXTORTCIST··on Dumbo: CIA system to take over webcams, microphones
Just because a threat vector is well known and not cutting edge does not make the SPECIFIC information of its existence, implementation, and capability completely worthless
theEXTORTCIST··on It is easy to expose users' secret web habits, say researchers
Pretty interesting how many bits of identifying information are available based on system fonts.

if you've never seen EFF's Panopticlick check out https://panopticlick.eff.org

theEXTORTCIST··on Underground Hansa Market taken over and shut down
point taken, I had not read it this way originally but your interpretation makes sense

edit: I knew I saw something about this somewhere earlier today. Still, this proves nothing because it's source less.

https://www.politie.nl/en/news/2017/july/20/underground-hans... "Some 10,000 foreign addresses of Hansa Market buyers were passed on to Europol"

theEXTORTCIST··on Underground Hansa Market taken over and shut down
Untrue according to the crabs article interview with the woman "Petra Haandrikman, team leader of the Dutch police unit that infiltrated Hansa."

https://krebsonsecurity.com/2017/07/exclusive-dutch-cops-on-...

"H: Yes, we called them “AlphaBay refugees.” It wasn’t the technical challenge that caused problems. Because this was a police operation, we wanted to keep up with the orders to see if there were any large amounts [of drugs] being ordered to one place, [so that] we could share information with our law enforcement partners internationally."

theEXTORTCIST··on Underground Hansa Market taken over and shut down
Using a standard channel for public key exchange is half the battle. The other half is using a trusted channel to verify the public key does indeed match the public key you were originally sent. "Trusted channel" can be broadly interpreted (and is also often subject to tampering as well)
theEXTORTCIST··on Underground Hansa Market taken over and shut down
The only reason I mention that this is at all probable is because of the length of a PGP key. How often is the average user of a site like this logging in to verify even the last few bytes of a PGP pub key compared to what is saved in their software? Plus how many users would chalk it up to "oh SellerX just changed their key pair" and continue on encrypting their message with the new key
theEXTORTCIST··on Underground Hansa Market taken over and shut down
Law enforcement could have easily MITM'd the PGP. They replace the public key of a vendor with their own public key (on the vendors's page, without the vendor's/buyer's knowledge), then the buyer address gets encrypted with that public key. Then they decrypt and resend the message using the sellers original public key.

I really wonder if this happened at all

Page 1 of 2Next →