Live data from Hacker News

Viewing profile — bodz

bodz

HN member
Joined
Thu, Sep 07, 2017, 6:31 AM UTC
HN karma
161
Public activity
40 items

About bodz

No profile information was provided.

Recent public activity

  1. comment
    Comment #19315615

    Small but important correction: the chemical is injected into the retina , not the cornea. I was thinking this was cool because if it works in the cornea, it could possibly be inje…

  2. comment
  3. comment
    Comment #15280056

    I think so too, but I wonder about the long term effect that doing everything in the virtual world will have on abilities in the physical world. It's extremely anecdotal, but my li…

  4. comment
    Comment #15279753

    There's something to be said for getting rid of excessive waste and unnecessarily large warehouses of "cheap junk", but it's also worth remembering that toys play a very important …

  5. comment
    Comment #15279176

    I don't necessarily think so. Just because he manages the risk management offering which is sold to other companies doesn't mean he would be aware of or involved in day-to-day risk…

  6. comment
    Comment #15278195

    They had a CISO as well as a CIO. Both have been fired/resigned now, though.

  7. comment
    Comment #15277915

    FYI the "President of US Information Solutions" at Equifax is a role that has nothing to do with their IT/security department. It's not the same thing as the CIO or head of IT, as …

  8. comment
    Comment #15277873

    Having worked on the incident response teams for these types of breaches, the "PR machine" is only part of the reason why companies "sit" on the info. It also takes a long time to …

  9. comment
    Comment #15277825

    None of the managers had anything to do with or were in the chain of command of the security team, so it's entirely possible they had absolutely no idea about the breach until long…

  10. comment
    Comment #15277758

    I don't believe there's any claim that they didn't learn of it until the public announcement, only that they didn't know of it at the time of the stock sale which was on Aug 1st, o…

  11. comment
    Comment #15254934

    Lifted it off a glass/phone/anything else you touched. Or it can be "compromised" in the same way your SSN can be compromised through hacking. The millions of people who were expos…

  12. comment
    Comment #15250140

    > The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get in the security line! Pin will be required on start. As far as …

  13. comment
    Comment #15243392

    > I don't think the average person in their audience has a strong reason to understand the difference. In my experience as a security consultant, one of the biggest problems (and i…

  14. comment
    Comment #15239139

    > They can't be phished because they aren't secrets. And here lies the problem. Apple treats them as if they are. "Your fingerprint is one of the best passwords in the world" - App…

  15. comment
    Comment #15238981

    > You're conflating every fingerprint scanner with the Apple's implementation of TouchID, which is far more secure than the check-the-box-to-win-a-government-contract stuff that's …

  16. comment
    Comment #15235503

    It's worth noting that despite the prosecutors saying "its a foregone conclusion", they have not actually even charged Reynolds with possession of child pornography. It seems to me…

  17. comment
    Comment #15235465

    > Biometrics can't be rotated. But they also can't be phished. Sure they can. Haven't you ever seen a cop show where the detective tricks the suspect into drinking from a cup of co…

  18. comment
    Comment #15235429

    Unfortunately I can't find any archives of Apple's website advertising TouchID when it first came out, but as I remember it was touted as "revolutionary, most secure way to protect…

  19. comment
    Comment #15234575

    > At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the…

  20. comment
    Comment #15233981

    The OPM hack resulted in millions of people's fingerprints and names being hacked, and now are floating out on the internet for anyone to look up. Individuals who had their fingerp…

  21. comment
    Comment #15233756

    No security is going to keep "determined" intruders out. But the point is that you should still strive to achieve "good enough" security. The problem is that while the actual ranki…

  22. comment
    Comment #15233637

    https://arstechnica.com/tech-policy/2017/09/judge-wont-relea...

  23. comment
    Comment #15233319

    > Much the same, they can force you to reveal your fingerprint, but cannot compel you to share a password. Unfortunately this is dependent on your jurisdiction. In Virginia it's be…

  24. comment
    Comment #15233243

    The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you …

  25. comment
    Comment #15233184

    To add more examples to this, Florida courts have also ruled that you can be imprisoned for not giving police access to your phone.[1] The "police can't force you to give up your p…