Viewing profile — cdine
cdine
HN member- Joined
- Tue, Mar 02, 2010, 6:49 PM UTC
- HN karma
- 860
- Public activity
- 28 items
- HN profile
- View on Hacker News ↗
About cdine
Recent public activity
-
comment
Comment #21425786
Thanks! That was the goal. For those who aren't familiar, the original slides and our response blog posts are still up: https://codebutler.com/projects/firesheep/
-
comment
Comment #21425781
Firesheep co-author here. Thanks and agreed :)
-
comment
Comment #8684873
Source: https://github.com/SecurityInnovation/PGPy Documentation: https://pythonhosted.org/PGPy/
- story
- story
-
comment
Comment #3135265
For some time I've ran a box with PF forwarding all TCP ports to an SSH server. That plus a simple nmap connect scan has proved handy for countless annoying networks that try to bl…
- story
- story
- story
-
comment
Comment #1829258
Indeed, Loopt appears to be one of the few high-profile sites to have done this right. SSL for everything, and cookies that are relevant to login sessions are marked secure. This i…
-
comment
Comment #1828602
Most sites don't properly invalidate sessions when you log out, you can't protect yourself as well as you think. See our slide on this topic: http://codebutler.github.com/firesheep…
-
comment
Comment #1828598
It's 100% open source! Please feel free to review it. http://github.com/codebutler/firesheep It doesn't currently do anything with passwords, it's only pulling out cookies from HTT…
-
comment
Comment #1828593
Yup, they're one of our examples of a "good" setup. However, Google leaks iGoogle and some other things (Latitude, address book, reader, ...)
-
comment
Comment #1828583
HTTPS Everywhere only works on a select few sites. You're up a creek for anything it doesn't cover. And Tor, there's lots of cases where operators did bad things. Don't trust it fo…
-
comment
Comment #1828538
This vulnerability (it hurts to even call it such at this point) has been around for years, and the attack has always been easy for a determined attacker to carry out. How else are…
-
comment
Comment #1828496
Well, hopefully it will then convince companies to properly secure their websites and actually protect users.
-
comment
Comment #1828487
I love SSH tunnels, but in regards to this particular problem, it really just pushes the problem off to wherever you ssh tunnel terminates. Do you trust you server operator? ISP? T…
-
comment
Comment #1828010
Sorry if it was misleading somehow, this is definitely not a vulnerability in Firefox. It's a Firefox extension that makes it easy to execute HTTP session hijacking attacks.
- story
- story
-
story
How to Hack Nike+ for Automatic Foursquare Check-ins
Why does HN keep deleting/deading this link?
-
comment
Comment #1486658
They specifically mention that the certificate size (and that of intermediates, among other things) impacts the message size and thus the TCP packet sizes used during handshakes. T…
-
comment
Comment #1449634
Interesting, thanks for the pre-coffee clarification. aka I can't read =] I'm sure people will still mess things up :)
-
comment
Comment #1449056
So, I get it and all that, what are some real world use cases of this and the postgresql equivalent? Who's actually using these things for something other than saying how fast they…
-
comment
Comment #1375793
This link is actually to an article titled "Legal challenge between Palo Alto company, Orange County hospital halts stem cell research"