75 karma · joined February 7, 2017
Because the app isn't strictly enforcing the validation of the cert of the photos domain it's trying to reach to pull photos, your MITM server is free to serve to the app as if it was the server on the Internet.
At some point during the spend from the wallet, the privkey that matches the wallet pubkey has to touch memory. This privkey can in theory be compromised in a number of ways with malware on the spending system (keylogger, screen caps, process memdump, etc).
I think the safest way to go about this is to generate an entirely new keypair/wallet on an isolated system. Spend from your wallet then transfer the balance to the newly created wallet. This minimizes losses as a result of privkey compromise (unless of course your isolated system isn't so secure)
https://tor.stackexchange.com/questions/8/how-does-tor-route...
Verizon has been adding headers for tracking for some time (probably via Blue Coat ProxySG forward proxy or similar technology) https://www.verizonwireless.com/support/unique-identifier-he...
What weird stretch goals they have. I wonder if these are jokes? "$8m = Signatures of entire team printed inside the phone case $10m = Free encrypted VPN tunnel service for all backers for 1 year $20m = Candy Crush (clone) available for free"
AIDS surviors have "demoralization in them". The psilocybin assisted group therapy is being used for that demoralization.
Firefox and Chrome correctly redirect to localhost via javascript
data:text/html,http://www.mostSecureInternetBankVictim.com/customerLogin.php%2FreallyLoginRandomData=130r193fj02jf-2jf023f23f-f2039f0239jf0a-39j029jg90wgj-9203f092jf0f-90e9f204fh0-9hf2ef8CUSTID=923r9032fdjnnvjddata%3Atext%2Fhtml%2C%3Cscript%3Ewindow.location%20%3D%20%22http%3A%2F%2F2130706433%22%3B%3C%2Fscript%3EValuedGoogleCustomer=?Security=trueEncrypted=trueSecureBrowsingSession=Truehttp://news.ycombinator.com@1572395042 Chrome takes me to 93.184.216.34 no warning
Then I tried http://security.wellsfargo.com@customerLoginv=ar3351RandomDa...
Which stretches way past my laptops viewable URL bar... and it takes me right to badsite.null (or a valid site like example.com). If you need HTTPs you can redirect on badsite.null's web server. Very wild.
But we still lack any sort of warning in the greater contemporary society about the risks of overuse of the hyper stimulus that comes along with social media. I am definitely beginning to see this take shape in our society (with people rejecting social media applications, articles like this, the way people speak to the overuse of such platforms)
Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.
The field guide provides great detail on operations and limitations of a specific existing tool (sample GUI screen shots, potential detection threats from personal security products and full crash dumps, detection of cam software process restarts, abilities to stall NIC cards, abilities to BSOD, ability to corrupt existing files, limitations based on cam emulation, limitations of previously saved cam files, the tool's PE names(32bit wscupd.exe, 64bit running outside of system32 wermgr.exe. GUI.exe present in the same folder as above PEs), example of the log.txt file written to the attacking USB, information on differences between winXP requirements vs other systems(scanner.sys driver needs)).
if you've never seen EFF's Panopticlick check out https://panopticlick.eff.org
edit: I knew I saw something about this somewhere earlier today. Still, this proves nothing because it's source less.
https://www.politie.nl/en/news/2017/july/20/underground-hans... "Some 10,000 foreign addresses of Hansa Market buyers were passed on to Europol"
https://krebsonsecurity.com/2017/07/exclusive-dutch-cops-on-...
"H: Yes, we called them “AlphaBay refugees.” It wasn’t the technical challenge that caused problems. Because this was a police operation, we wanted to keep up with the orders to see if there were any large amounts [of drugs] being ordered to one place, [so that] we could share information with our law enforcement partners internationally."
I really wonder if this happened at all