Live data from Hacker News

Viewing profile — MajesticHobo

MajesticHobo

HN member
Joined
Mon, Feb 22, 2016, 9:58 PM UTC
HN karma
155
Public activity
42 items

About MajesticHobo

CS student, not affiliated with MajesticHobos elsewhere on the net.

Recent public activity

  1. comment
    Comment #14664878

    What is a cyber weapon? Knowledge of a vulnerability? Exploit code? How do you propose regulating it? Much of this has been tried before and ended up hurting rather than helping.

  2. comment
    Comment #14623236

    I don't disagree with sanitizing data at output time when it's clear that A) the input won't affect anything else and B) output is going to happen . But realize not all input winds…

  3. comment
    Comment #14622930

    If you allow binary uploads, you're going to be a malware distributor whether you scan or not. AV just introduces complexity and attack surface and doesn't really belong in a guide…

  4. comment
    Comment #14622313

    You've said nothing that contradicts my post. As long as the data is sanitized before it can affect the storage/transport mechanism for its content type, you're good.

  5. comment
    Comment #14622186

    Yes, really. Otherwise, you must take extra care not to reflect any input data back in any response to the user, whether it's in the HTML body or not. See: HTTP response splitting.…

  6. comment
    Comment #14621979

    This guide still has some issues. It's missing common classes of web app vulns I've seen in Go code (e.g. CSRF, SSRF) and has some weird advice here and there (scan uploaded files …

  7. comment
    Comment #14621659

    WhatsApp doesn't read your conversations for ads because it can't. Message content is end-to-end encrypted. You must have leaked your plans through some other medium inadvertently.…

  8. comment
    Comment #13170695

    >further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic Of course they …

  9. comment
    Comment #13163460

    The notion that he "lacked the ability to leak carefully and strategically" because he was an outsider. I'm fairly sure he was more than capable of selecting only documents related…

  10. comment
    Comment #13163213

    > It's not just that Snowden wasn't an insider, but that he lacked the ability to leak carefully and strategically --- and so the public outcome was inferior to the Pentagon Papers…

  11. comment
    Comment #12294570

    > Can we trust this information? The answer is: not fully, because the link timestamp can be altered by the developer in a way that’s not always possible to spot. However, certain …

  12. comment
    Comment #12281826

    It is. The title is a little misleading; here's an explanatory excerpt from the actual paper: > In this work we analyze the iMessage protocol and identify several weaknesses that a…

  13. comment
    Comment #12281817

    Uh, no. Implementation bugs don't mean a protocol is broken.

  14. comment
    Comment #12024946

    There's always Icedove, which gets updates from Debian.

  15. story
  16. comment
    Comment #11763214

    > offering complete untraceable anonymity Your argument falls apart the moment you claim this.

  17. comment
    Comment #11751313

    Yes, that is what I meant. That's what I get for being a pedant.

  18. comment
    Comment #11749675

    A valid point of view, but the US is technically a constitutional republic, not a true democracy. Certain values and principles are written into our DNA via the Constitution, and I…

  19. comment
    Comment #11749421

    > Whenever a story about Snowden is in the news, some people complain that some of the documents he released were "off topic". Which is odd, because I personally have not found any…

  20. comment
    Comment #11679788

    I was under the impression that you are generally allowed to record content for your own personal use, as long as you don't distribute it to others.

  21. comment
    Comment #11679459

    > something that DRM isn't preventing you from doing something you're otherwise not supposed to be doing anyways. And what would that be?

  22. comment
    Comment #11615571

    WhatsApp is the most popular end-to-end encrypted chat app in the world. Shutting it down for 100 million people not suspected or charged with any crime is an incredibly disproport…

  23. comment
    Comment #11611587

    Okay. So it's a protection against browser exploits, not overreaching web APIs.

  24. comment
    Comment #11611340

    Aren't those already sandboxed browser-local filesystems?

  25. comment
    Comment #11595279

    ZH's response: http://www.zerohedge.com/news/2016-04-29/full-story-behind-b...