Live data from Hacker News

Viewing profile — afreak

afreak

HN member
Joined
Wed, Jan 23, 2013, 7:15 PM UTC
HN karma
1,471
Public activity
226 items

About afreak

Security analyst and researcher based in Vancouver, British Columbia.

https://cariad.keigher.ca

Recent public activity

  1. story
  2. story
  3. comment
    Comment #13100529

    Unless you have access to a mobile phone's baseband source code, you cannot really trust anything about its level of security. This was discussed on HN a while back and comes up qu…

  4. story
  5. story
  6. comment
    Comment #12353811

    (ignore what I said here)

  7. comment
    Comment #12353715

    Not the best link but here's something to chew on: http://www.universetoday.com/15403/how-long-would-it-take-to... >However, despite these advantages in fuel-efficiency and specifi…

  8. comment
    Comment #12353668

    Keep in mind that at best it would take maybe 1,000 years with current technology to get there with a probe or human-supporting ship. It would be highly unpopular however as it inv…

  9. comment
    Comment #12221199

    You're assuming that they have a vested interest in holding their Bitcoins for some greater good.

  10. comment
    Comment #11943781

    PBKDF2 is not for password storage.

  11. comment
    Comment #11941835

    If the server had bcrypt configured to take a second per password, multiple everything by 4. And so on. What I think is needed as a supplement to "use bcrypt / scrypt" is a "and us…

  12. comment
    Comment #11941771

    As part of a presentation I did at a local OWASP chapter, here are some numbers based on just using CPython's Hashlib processing of 14,000,000 someodd passwords: Intel Xeon E5-1620…

  13. comment
    Comment #11941719

    A weak password is a weak password no matter how good the hashing is. I think that you're referring to this bit from last year: http://www.pxdojo.net/2015/08/what-i-learned-from-cr…

  14. comment
    Comment #11941528

    No. You cannot effectively use the techniques you can use against SHA/MD5 to attack the three I mentioned. SHA and MD5 can be calculated entirely in a CPU's registers without havin…

  15. comment
    Comment #11941474

    There are several services (including one run by me). https://canar.io (mine) https://haveibeenpwned.com/ Mine lets you free-form search whereas HaveIBeenPwned is there for searchi…

  16. comment
    Comment #11941410

    Any developer today that is developing an application and isn't using something like Argon2, Bcrypt, or Scrypt should be considering a plan to move away from whatever they're curre…

  17. comment
    Comment #11671646

    > And I think that email is unbeatable, because it is federated, because it's governed by standards and because in spite of all constraints, it's quite adaptable, being the kind of…

  18. story
  19. story
  20. comment
    Comment #11384095

    > A few people will donate bitcoin. A few things can be bought directly with bitcoin. On average, you'd expect that the fraction of your income paid in bitcoin would be similar to …

  21. comment
    Comment #11383724

    > gratipay offers bitcoin payments, which, if they implement it right, would eliminate the middleman [...] when the financee cashes out using bitcoin And tell me, how does one cut …

  22. comment
    Comment #11381904

    > As far as unauthorized use of campus resources, I think the university would be better served by suing AT&T for failing to adequately protect its network. It is not the responsib…

  23. comment
    Comment #11381799

    It should be noted that what weev was doing is nothing new and is really just this: $ cat payload.ps |netcat -q 0 $printer_ip 9100 This is what was originally posted: https://stori…

  24. story
  25. comment
    Comment #11330668

    WIND Mobile. The plan isn't offered any longer but there are similar ones available.