Live data from Hacker News

Viewing profile — cdine

cdine

HN member
Joined
Tue, Mar 02, 2010, 6:49 PM UTC
HN karma
860
Public activity
28 items

About cdine

my public key: https://keybase.io/crash; my proof: https://keybase.io/crash/sigs/ZhoY4fclRo8oQWagxVf8CIdmfvKP8bITaptnKHZXsSM

Recent public activity

  1. comment
    Comment #21425786

    Thanks! That was the goal. For those who aren't familiar, the original slides and our response blog posts are still up: https://codebutler.com/projects/firesheep/

  2. comment
    Comment #21425781

    Firesheep co-author here. Thanks and agreed :)

  3. comment
    Comment #8684873

    Source: https://github.com/SecurityInnovation/PGPy Documentation: https://pythonhosted.org/PGPy/

  4. story
  5. story
  6. comment
    Comment #3135265

    For some time I've ran a box with PF forwarding all TCP ports to an SSH server. That plus a simple nmap connect scan has proved handy for countless annoying networks that try to bl…

  7. story
  8. story
  9. story
  10. comment
    Comment #1829258

    Indeed, Loopt appears to be one of the few high-profile sites to have done this right. SSL for everything, and cookies that are relevant to login sessions are marked secure. This i…

  11. comment
    Comment #1828602

    Most sites don't properly invalidate sessions when you log out, you can't protect yourself as well as you think. See our slide on this topic: http://codebutler.github.com/firesheep…

  12. comment
    Comment #1828598

    It's 100% open source! Please feel free to review it. http://github.com/codebutler/firesheep It doesn't currently do anything with passwords, it's only pulling out cookies from HTT…

  13. comment
    Comment #1828593

    Yup, they're one of our examples of a "good" setup. However, Google leaks iGoogle and some other things (Latitude, address book, reader, ...)

  14. comment
    Comment #1828583

    HTTPS Everywhere only works on a select few sites. You're up a creek for anything it doesn't cover. And Tor, there's lots of cases where operators did bad things. Don't trust it fo…

  15. comment
    Comment #1828538

    This vulnerability (it hurts to even call it such at this point) has been around for years, and the attack has always been easy for a determined attacker to carry out. How else are…

  16. comment
    Comment #1828496

    Well, hopefully it will then convince companies to properly secure their websites and actually protect users.

  17. comment
    Comment #1828487

    I love SSH tunnels, but in regards to this particular problem, it really just pushes the problem off to wherever you ssh tunnel terminates. Do you trust you server operator? ISP? T…

  18. comment
    Comment #1828010

    Sorry if it was misleading somehow, this is definitely not a vulnerability in Firefox. It's a Firefox extension that makes it easy to execute HTTP session hijacking attacks.

  19. story
  20. story
  21. story
    How to Hack Nike+ for Automatic Foursquare Check-ins

    Why does HN keep deleting/deading this link?

  22. comment
    Comment #1486658

    They specifically mention that the certificate size (and that of intermediates, among other things) impacts the message size and thus the TCP packet sizes used during handshakes. T…

  23. comment
    Comment #1449634

    Interesting, thanks for the pre-coffee clarification. aka I can't read =] I'm sure people will still mess things up :)

  24. comment
    Comment #1449056

    So, I get it and all that, what are some real world use cases of this and the postgresql equivalent? Who's actually using these things for something other than saying how fast they…

  25. comment
    Comment #1375793

    This link is actually to an article titled "Legal challenge between Palo Alto company, Orange County hospital halts stem cell research"