HNHacker News
TopNewBestAskShowJobs

wwwv

67 karma · joined March 27, 2017

submissionscomments
wwwv··on Google: Security Keys Neutralized Employee Phishing
That would be useless, as the key could just be passed through.
wwwv··on ESLint compromised, may have stolen your credentials
Critically, it also doesn't leave a trail by running a server anywhere.
wwwv··on ESLint compromised, may have stolen your credentials
That's why they're using two different stats engines.
wwwv··on ESLint compromised, may have stolen your credentials
They are linked as HTTP referrer, so they can get the tokens out of the stats page later on.

It's using a popular and well known domain to evade detection.

wwwv··on Hackers send silent commands to speech recognition systems with ultrasound
"Hey Siri" is.
wwwv··on Hackers send silent commands to speech recognition systems with ultrasound
Siri recognises the "hey siri" bit unique to the owner, further commands aren't validated.
wwwv··on US Navy collisions stoke cyber threat concerns
> There are also military specific parts of GPS that civilian receivers can't access. I don't know if military receivers are ignoring civilian signals, though.

For all intents it's a different system, the packets are encrypted, the right receiver hardware gives you vastly superior accuracy. There's civilian hardware which can use the packets without decrypting them for better accuracy, there's some patents on doing this amusingly.

wwwv··on US Navy collisions stoke cyber threat concerns
The US military uses encrypted GPS, not the civilian one.
wwwv··on Filecoin Suspends ICO After Raising $186M in One Hour
I'm not really in this world, but you'd save more power by recycling aluminium cans (%5+ of US power consumption) than by killing off cryptocurrency mining.
wwwv··on What is an Initial Coin Offering and How Does it Work?
The answer is a little unfortunate, even though things are said to be worth $xxxxM market cap, but the depth of the market is so shallow that the true value is near zero.
wwwv··on What is an Initial Coin Offering and How Does it Work?
It's worthwhile to note that not a single once of the thousands of "ICO" things that have been launched in the last year have actually done anything of value. They all generate hype, raise money, and then give up and go to work on other things. It happens over and over again with no memory of the past failures, apparently.

That said I wouldn't fault you for believing that a lot of the $xM raised in x ICO just turned out to be largely the creator seeding the pot and a minority of other people buying into something "big". You could even take out a loan, there's nearly zero risk other than the operator of the ICO running with the scratch.

wwwv··on Ubuntu Systemd Vulnerability
TCP or UDP transports.
wwwv··on Attempt to Reverse a $55 Million Ether Heist
Should be easy to describe then.
wwwv··on Attempt to Reverse a $55 Million Ether Heist
All obfuscation around a central controlling group that have the ability to reverse any transactions they don't like or negatively financially impact them, in other words.
wwwv··on Attempt to Reverse a $55 Million Ether Heist
The principle of Ethereum is that code is law, the "hacker" followed the law to the letter and acted in a prescribed manner. What's the crime here exactly?
wwwv··on Is SHA-3 slow?
If your concern is an attacker that can do 128 bits of work, you've got other problems (like reality).
wwwv··on Is SHA-3 slow?
SHA3 is a hash function, not a KDF.
wwwv··on Laptop Ban a Reaction to X-Ray Equipment Stolen by ISIS
There's beyond HDR, you can switch between multiple penetration levels and do automatic detection of materials even with ones made 2 decades ago. None of this is really new, insightful, or particularly revolutionary.
wwwv··on Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
In general yes, invisible things can burn your eyes but it's probably of no concern here. The more common thing you'll run into is things like cheap DPSS green lasers that output a large amount of IR, you don't have a blink reflex for things outside of your visible range and these will cause damage on the higher end.
wwwv··on Laptop Ban a Reaction to X-Ray Equipment Stolen by ISIS
They are not opaque to X-Rays, much less the ludicrous penetrating power used in baggage inspection. Baggage X-rays can happily penetrate inches of metal, nothing short of lead brick will obscure contents and that's going to raise other questions. Where did you get that nonsense from?
wwwv··on Show HN: Kryptonite – a new home for your SSH private key
How does this handle SSH session re-keying, does that need further authentication from the device? openssh does this pretty infrequently, I can't immediately remember if that needs participation with the asymmetric key or not.

ED: Seems it's just as if you re-did the cipher negotiation, so no asymmetric interaction.

wwwv··on Show HN: Kryptonite – a new home for your SSH private key
So, capture the auth and use it for the malware, show the user some failure and allow their retry to pass. Stupid dodgy Yubikey fails half the time.
wwwv··on The TSA's Selective Laptop Ban
Completely transparent as far as a luggage X-ray is concerned, they're very high power because they don't have to care about exposure limits like medical imaging would. They usually have multiple attenuators and detectors so they can do neat tricks like detection of organic materials.
wwwv··on The TSA's Selective Laptop Ban
No, luggage X-rays are extremely powerful, think 120kV or higher. They can easily penetrate inches of steel on the low end.