Viewing profile — MajesticHobo
MajesticHobo
HN member- Joined
- Mon, Feb 22, 2016, 9:58 PM UTC
- HN karma
- 155
- Public activity
- 42 items
- HN profile
- View on Hacker News ↗
About MajesticHobo
Recent public activity
-
comment
Comment #14664878
What is a cyber weapon? Knowledge of a vulnerability? Exploit code? How do you propose regulating it? Much of this has been tried before and ended up hurting rather than helping.
-
comment
Comment #14623236
I don't disagree with sanitizing data at output time when it's clear that A) the input won't affect anything else and B) output is going to happen . But realize not all input winds…
-
comment
Comment #14622930
If you allow binary uploads, you're going to be a malware distributor whether you scan or not. AV just introduces complexity and attack surface and doesn't really belong in a guide…
-
comment
Comment #14622313
You've said nothing that contradicts my post. As long as the data is sanitized before it can affect the storage/transport mechanism for its content type, you're good.
-
comment
Comment #14622186
Yes, really. Otherwise, you must take extra care not to reflect any input data back in any response to the user, whether it's in the HTML body or not. See: HTTP response splitting.…
-
comment
Comment #14621979
This guide still has some issues. It's missing common classes of web app vulns I've seen in Go code (e.g. CSRF, SSRF) and has some weird advice here and there (scan uploaded files …
-
comment
Comment #14621659
WhatsApp doesn't read your conversations for ads because it can't. Message content is end-to-end encrypted. You must have leaked your plans through some other medium inadvertently.…
-
comment
Comment #13170695
>further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic Of course they …
-
comment
Comment #13163460
The notion that he "lacked the ability to leak carefully and strategically" because he was an outsider. I'm fairly sure he was more than capable of selecting only documents related…
-
comment
Comment #13163213
> It's not just that Snowden wasn't an insider, but that he lacked the ability to leak carefully and strategically --- and so the public outcome was inferior to the Pentagon Papers…
-
comment
Comment #12294570
> Can we trust this information? The answer is: not fully, because the link timestamp can be altered by the developer in a way that’s not always possible to spot. However, certain …
-
comment
Comment #12281826
It is. The title is a little misleading; here's an explanatory excerpt from the actual paper: > In this work we analyze the iMessage protocol and identify several weaknesses that a…
-
comment
Comment #12281817
Uh, no. Implementation bugs don't mean a protocol is broken.
-
comment
Comment #12024946
There's always Icedove, which gets updates from Debian.
- story
-
comment
Comment #11763214
> offering complete untraceable anonymity Your argument falls apart the moment you claim this.
-
comment
Comment #11751313
Yes, that is what I meant. That's what I get for being a pedant.
-
comment
Comment #11749675
A valid point of view, but the US is technically a constitutional republic, not a true democracy. Certain values and principles are written into our DNA via the Constitution, and I…
-
comment
Comment #11749421
> Whenever a story about Snowden is in the news, some people complain that some of the documents he released were "off topic". Which is odd, because I personally have not found any…
-
comment
Comment #11679788
I was under the impression that you are generally allowed to record content for your own personal use, as long as you don't distribute it to others.
-
comment
Comment #11679459
> something that DRM isn't preventing you from doing something you're otherwise not supposed to be doing anyways. And what would that be?
-
comment
Comment #11615571
WhatsApp is the most popular end-to-end encrypted chat app in the world. Shutting it down for 100 million people not suspected or charged with any crime is an incredibly disproport…
-
comment
Comment #11611587
Okay. So it's a protection against browser exploits, not overreaching web APIs.
-
comment
Comment #11611340
Aren't those already sandboxed browser-local filesystems?
-
comment
Comment #11595279
ZH's response: http://www.zerohedge.com/news/2016-04-29/full-story-behind-b...