HNHacker News
TopNewBestAskShowJobs

w3rhn2j34oh5o

61 karma · joined June 3, 2019

submissionscomments
w3rhn2j34oh5o··on Google SVP Hardware: I'd disclose smart speakers before guests enter my home
Last time I was in a Silicon Valley Hotel, I had to sign a waver that I accepted that there was an Alexa in my room. Of signed it, and unplugged it (as well as the TV). I will not have these horrible things near me. The hotel claimed they would charge if you unplugged it. They didn't.
w3rhn2j34oh5o··on Visa, Mastercard, Others Reconsider Involvement in Facebook's Libra Network
There are several things going on here -- Today, banking controls the monetary supply through creation of new dollars to be loaned. Being fully backed has less meaning in a continuously inflating fiat currency world. Being backed by gold, by computation, by proof-of-stake -- these are all much stronger measures than JP Morgan Chase's core banking database.

Libra is control over monetary flows. Offend zuck, watch your public key added to the block list. Watch the balance drained from your account as the producers use 'admin' transaction powers to remove funds. Maybe the ledger maintainers simply block your transactions from being committed.

And then we have currency controls in places other than the US, like India and China. Suddenly 'stablecoin's are more useful than bank account backed dollar holdings (outside the US). This is a power grab for the future currency of developing nations. The endgame is control of planet Earth's M1 currency supply.

w3rhn2j34oh5o··on Federal Prosecutors Conducting Criminal Probe of Juul
It really isn't killing kids, and I would challenge that they are 'targeting them'. As an adult vape user, I love the fruit flavors. They are for my (adult) use only. I would never let someone under 21 get access to this. Why should I be penalized because lots of kids are breaking the law?

The recent (adult) deaths from Vaping are due to black market THC cartridges filled with vitamin e acetate. It is very likely the kids are obtaining (safe) retail product, which is a failure in retail process, not the manufacturer. While it is a bad thing that school aged children are illegal acquiring Juul -- how is this different (or even worse) than Alcohol? We should investigate alcohol vendors for making tasty beverages too. Can't have flavors that adults might like...

There is a combination of events occurring simultaneously that is making it hard for folks to objectively understand the problem, and if there is actually a problem at all.

w3rhn2j34oh5o··on A deep dive into iOS Exploit chains found in the wild
There was no Apple data breached. User endpoints were attacked, using various well crafted exploits against their software. This isn't a GDPR (privacy) issue, no company data was leaked, its end user data from their device. Apple tries to protect your data on their devices, but all software has bugs. Bad guys will try to exploit these bugs to reach their goals.

Google does research into making it hard for attackers to compromise user devices. That is the purpose of PZ team. There are no numbers because nobody has these numbers except for the attacker. I am guessing Google has some ball park numbers based on search traffic or web analytics.

If you want to know if you were affected, you need to ask yourself if powerful adversary wants access to your data, possibly because of civil unrest occurring in their territory; and if you visit strange websites related to this. Only the adversary knows for sure, not Apple, Not Google.

w3rhn2j34oh5o··on Facebook scans system libraries on Android and uploads them to their server
Grabbing rootkit artifacts that could be on the device?

Its just that its not Facebooks place to do this. I wouldn't expect a app linux binary to upload the contents of /usr/lib, or a windows app to start sending system32 dll's off system.

FB can try to sell this as a 'lite-AntiVirus' type service, but that is not its place. There is no indication the app is doing this. Its FB being creepy as usual.

If Google did it, it would be less creepy, just like how Microsoft can grab malicious files detected by Defender -- but they write, support and protect the OS! FB is just an app. It shouldn't be harvesting its users operating system files!

w3rhn2j34oh5o··on The Myth of Consumer-Grade Security
Or whomever has hacked the source control / build environment to replace the "5 magic HSM public keys" with one or more of their own public keys -- See Juniper Incident with Dual-EC DRBG (https://eprint.iacr.org/2016/376.pdf)

This story should be repeated whenever anyone brings up 'solutions' involved with key escrow. Bruce warned us in 2006 this was a backdoor, ten years later, we find that not only was it implemented by Juniper, the backdoor was backdoored by unknown (and potentially malicious) actors. Really, this should be the last word on why this key escrow and general cryptographic backdoors are a terrible terrible idea.

w3rhn2j34oh5o··on The Myth of Consumer-Grade Security
The point, yes, but it is not the case in reality:

2015: https://cryptosense.com/blog/the-untold-story-of-pkcs11-hsm-...

2017: https://cryptosense.com/blog/infineon-rsa-key-generation-bug...

2019: https://cryptosense.com/blog/how-ledger-hacked-an-hsm/

Stop trying to build scenarios where key escrow solutions are technically sound. They are not. This is an intractable problem that is not solved by these half cocked technical measures. Key escrow cannot by definition be secure, and wasting time trying to invent solutions just confuses the matter, weakens security and leaves us all vulnerable. Basically, Sssssssh, or the politicians might actually believe this fantasy.

w3rhn2j34oh5o··on Delivery apps like DoorDash are using tips to pay workers’ wages
they say 'tip in cash', but I never have the physical cash to tip. This always brings me anxiety when I dont have the physical small bills to provide. I would ensure I use a platform (as mentioned in the article, like grubhub or seamless) that doesn't garnish the electronic tips for pay.
w3rhn2j34oh5o··on Authentication and the Have I Been Pwned API
I don't think it is that clear -- he is selling access to a data set containing PII (email address or account names). Its stolen data. One can make a case that free and open access to this data set is a common good, however once money is involved, one is conducting business with data that one did not legally obtain. It is not 'perfectly legal'.
w3rhn2j34oh5o··on Authentication and the Have I Been Pwned API
And the local pawn shop has expenses too. Just because they have to pay rent and electricity costs does not make selling a stolen item legal.
w3rhn2j34oh5o··on Authentication and the Have I Been Pwned API
He can try to justify it however he likes -- its selling stolen goods. Just because you sell stolen goods under their value, or under your costs to provide does not suddenly make it ok.
w3rhn2j34oh5o··on Authentication and the Have I Been Pwned API
So fencing stolen goods is not illegal if someone else stole it? I don't think so. Stolen is stolen -- nobody has any right to sell it.
w3rhn2j34oh5o··on Google takes another run at social networking with Shoelace
I'm not following your logic? Are you saying I should join FB because everyone else is? Everything in life is ephemeral. Trends and apps come and go. This too shall pass.

My goal is to get people to question the relevance, time drain and impact to humanity that FB imposes on the world. I believe that if people did the calculus they would see the horror for what it is.

w3rhn2j34oh5o··on Google takes another run at social networking with Shoelace
I don't think you can make this claim without understand the motivation or threat models of the billions of non-facebook users. I use Google services, I do not use Facebook services. Am I the exception to the rule? How many are in this exception group?
w3rhn2j34oh5o··on Google takes another run at social networking with Shoelace
I just don't understand why on earth would anyone defend this platform. Yeah I don't own a TV either. Enjoy your zuckbucks!
w3rhn2j34oh5o··on Identifying Risky Counterfeit Intel Gigabit CT Network Adapters
And thats the challenge, you can't ever really know that the firmware, or even the logic implemented in silicon is identical. You don't need evidence that it is different, it is impossible to know, one must assume it could be, thus a security risk.
w3rhn2j34oh5o··on Google takes another run at social networking with Shoelace
'everyone'. Ive never used FB in my life, and never will. More people are ditching ZuckNet every day because it is so awful. Good to have alternatives.
w3rhn2j34oh5o··on Identifying Risky Counterfeit Intel Gigabit CT Network Adapters
A PCI express card can use Bus Mastering to gain read/write access to main memory, bypassing the CPU. Counterfeit hardware running arbitrary code that has Direct Memory Access can do anything. Its much worse than running an arbitrary binary on the Operating System. If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk!
w3rhn2j34oh5o··on Fall of Certificate Authorities
IdenTrust crossigned the LetsEncrypt root. LE is def the number one player in this space today. Its not technically correct to sat IdenTrust is no#1 as LetsEncrypt is its own root. This article fails to mention LE at all.
w3rhn2j34oh5o··on Apple Sign In
My angle is stopping folks using and recommending telegram. Where are my facts wrong?
w3rhn2j34oh5o··on Apple Sign In
Granted, there are no known weaknesses with their protocol -- however, Telegram leads the user to believe their conversations are encrypted, which, unless they opted in to secret chats (and this is not supported on desktop ), its all in the clear.

So if you are using it on desktop, all your messages belong to Telegram, and whomever they are sharing it with.

w3rhn2j34oh5o··on Apple Sign In
Signal also does historical synchronization between devices. It bootstraps the history from another device. It also has search which can be done locally. Telegram is, by design, capable of being accessed by 3rd parties (beyond governments). iMessage is capable of being accessed by 3rd parties via iCloud backups, which is an opt-in situation.

Be aware, wechat sends every message with geolocation to the authorities in real time. It is more critical than ever that we be aware of the mechanisms in the systems we build and use -- else dystopia awaits.

w3rhn2j34oh5o··on Apple Sign In
then use signal. friends don't let friends use telegram. Signal gives you all of this without the snake oil that telegram is selling you.
w3rhn2j34oh5o··on Apple Sign In
Telegram is unencrypted by default. All standard messages are stored on the server. Telegrams secret chat mode (end-to-end encryption) uses home made cryptography, and has been panned by experts in past. All group chat is in the clear and stored on the server. This is not the case with imessage. Comparing Telegram to iMessage, telegram is not in the same league as Apple. I don't trust either from TLA's or well funded adversaries.