Live data from Hacker News

Viewing profile — cantfindmypass

cantfindmypass

HN member
Joined
Fri, Dec 06, 2013, 6:04 PM UTC
HN karma
190
Public activity
40 items

About cantfindmypass

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #7748051

    Correct, they cannot compute SHA256() or SHA256(SHA256()) of arbitrary data.

  3. comment
    Comment #7695703

    Someone showed me this a while ago. Apparently it's an actual attack. https://www.youtube.com/watch?v=G50typU3mLg

  4. comment
    Comment #7694948

    > I suspect they have a base OS installation and then have a post-boot encrypted partition which requires manual passphrase entry over ssh or console to unlock, containing all the …

  5. comment
    Comment #7510206

    Being able to rebind the keys would be really nice. The keys are decently intuitive, but it sucks pretty bad if you have a split keyboard.

  6. comment
    Comment #7298879

    Apple has had a working gotofail fix for OS X internally for days.

  7. comment
    Comment #7295708

    the only source of this appears to be the updated whois information...

  8. comment
    Comment #7286560

    The percentage of sites using SHA256 certificate is tiny, and most CAs are still SHA1 based.

  9. comment
    Comment #7284175

    That is a different bug.

  10. comment
    Comment #7284034

    I would be totally happy to put a proper stylesheet and some better copy together if someone wants to send me that (put it in a gist maybe?)

  11. comment
    Comment #7283798

    I am now for informational purposes linking to the OS X patch released by i0n1c. http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.htm...

  12. comment
    Comment #7283695

    I'm not checking for Safari vs OS X. I'm not sure what else to say to vulnerable OS X users - there is not really any effective mitigation besides turning the computer off.

  13. comment
    Comment #7283678

    It became widely known outside of Apple due to the iOS patch.

  14. comment
    Comment #7283675

    Yes, removing one line would fix it.

  15. comment
    Comment #7283538

    The issue is that Apple's security engineers must have realized that there was a good chance someone would reverse engineer the patch, and from there find out the OS X is also vuln…

  16. comment
    Comment #7283255

    Apple still hasn't released a fix for OS X...

  17. comment
    Comment #7283242

    My web logs show lots of systems identifying as 10.9.2 pulling the test image from the bad server.

  18. comment
    Comment #7282531

    I just noticed that his works differently than mine.

  19. comment
    Comment #7282479

    Yes, the bug is a regression introduced in Mavericks.

  20. comment
    Comment #7282369

    I don't know - I can't imagine that nobody on their security team pointed out that someone would promptly reverse engineer the patch and figure out that OS X is also vulnerable.

  21. comment
    Comment #7282290

    There's not a whole lot I can do about that without adding a lot of complexity. You could try downloading https://gotofail.com:1266/test.png I suppose.

  22. comment
    Comment #7282273

    I wanted to make something that gives something a little more useful than an error page if you're safe.

  23. comment
    Comment #7282265

    I started making this before agl released that, though he had that up before I finished. Also, upon closer inspection, mine actually works differently from agl's.

  24. comment
    Comment #7282255

    No OS X patch is available yet. :-( Chrome/Firefox shouldn't be vulnerable.

  25. comment
    Comment #7282239

    There is no patch for Mavericks out yet. :-(