Viewing profile — cantfindmypass
cantfindmypass
HN member- Joined
- Fri, Dec 06, 2013, 6:04 PM UTC
- HN karma
- 190
- Public activity
- 40 items
- HN profile
- View on Hacker News ↗
About cantfindmypass
No profile information was provided.
Recent public activity
- comment
-
comment
Comment #7748051
Correct, they cannot compute SHA256() or SHA256(SHA256()) of arbitrary data.
-
comment
Comment #7695703
Someone showed me this a while ago. Apparently it's an actual attack. https://www.youtube.com/watch?v=G50typU3mLg
-
comment
Comment #7694948
> I suspect they have a base OS installation and then have a post-boot encrypted partition which requires manual passphrase entry over ssh or console to unlock, containing all the …
-
comment
Comment #7510206
Being able to rebind the keys would be really nice. The keys are decently intuitive, but it sucks pretty bad if you have a split keyboard.
-
comment
Comment #7298879
Apple has had a working gotofail fix for OS X internally for days.
-
comment
Comment #7295708
the only source of this appears to be the updated whois information...
-
comment
Comment #7286560
The percentage of sites using SHA256 certificate is tiny, and most CAs are still SHA1 based.
-
comment
Comment #7284175
That is a different bug.
-
comment
Comment #7284034
I would be totally happy to put a proper stylesheet and some better copy together if someone wants to send me that (put it in a gist maybe?)
-
comment
Comment #7283798
I am now for informational purposes linking to the OS X patch released by i0n1c. http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.htm...
-
comment
Comment #7283695
I'm not checking for Safari vs OS X. I'm not sure what else to say to vulnerable OS X users - there is not really any effective mitigation besides turning the computer off.
-
comment
Comment #7283678
It became widely known outside of Apple due to the iOS patch.
-
comment
Comment #7283675
Yes, removing one line would fix it.
-
comment
Comment #7283538
The issue is that Apple's security engineers must have realized that there was a good chance someone would reverse engineer the patch, and from there find out the OS X is also vuln…
-
comment
Comment #7283255
Apple still hasn't released a fix for OS X...
-
comment
Comment #7283242
My web logs show lots of systems identifying as 10.9.2 pulling the test image from the bad server.
-
comment
Comment #7282531
I just noticed that his works differently than mine.
-
comment
Comment #7282479
Yes, the bug is a regression introduced in Mavericks.
-
comment
Comment #7282369
I don't know - I can't imagine that nobody on their security team pointed out that someone would promptly reverse engineer the patch and figure out that OS X is also vulnerable.
-
comment
Comment #7282290
There's not a whole lot I can do about that without adding a lot of complexity. You could try downloading https://gotofail.com:1266/test.png I suppose.
-
comment
Comment #7282273
I wanted to make something that gives something a little more useful than an error page if you're safe.
-
comment
Comment #7282265
I started making this before agl released that, though he had that up before I finished. Also, upon closer inspection, mine actually works differently from agl's.
-
comment
Comment #7282255
No OS X patch is available yet. :-( Chrome/Firefox shouldn't be vulnerable.
-
comment
Comment #7282239
There is no patch for Mavericks out yet. :-(