Live data from Hacker News

Viewing profile — cybergibbons

cybergibbons

HN member
Joined
Thu, May 29, 2014, 10:16 PM UTC
HN karma
139
Public activity
42 items

About cybergibbons

No profile information was provided.

Recent public activity

  1. comment
    Comment #27068006

    The problem is, people are using solely what3words for location. Every single call recording to emergency services doesn't use any other information. The odds are around 1 in 24 th…

  2. comment
    Comment #27023171

    Yeah, that's not true. https://cybergibbons.com/security-2/why-what3words-is-not-su...

  3. comment
    Comment #27022579

    Yes, that's pretty much the definition of incorrect.

  4. comment
    Comment #27019744

    Old skool! Those were the days :)

  5. comment
    Comment #27019679

    A design requirement of the app is it works offline.

  6. comment
    Comment #27019671

    Your surface area is totally incorrect.

  7. comment
    Comment #27019664

    Only with a ridiculously long word list containing plurals and words people can't spell.

  8. comment
    Comment #27018276

    Yeah, multiple MRT members have contacted me to say this is a real struggle. If someone is on the move, it's virtually impossible to work out what direction they are going.

  9. comment
    Comment #27017222

    It's promoted for use in search and rescue, so other bands are in use.

  10. comment
    Comment #27017215

    Why 3 words? Why not 4?

  11. comment
    Comment #27016801

    You would still get high densities of cells which share two words being present close together, leading to any issue with the third word causing a confusing location.

  12. comment
    Comment #27016783

    No, I went from the patent and using the API instead: https://twitter.com/cybergibbons/status/1386344576856825858 https://twitter.com/cybergibbons/status/1386393951276609539 https:…

  13. comment
    Comment #27015517

    The word list already is 40k long. That's beyond most people's vocab and includes really awkward to spell words. IMO, if the solution is to use words, then What4Words would have ha…

  14. comment
    Comment #27015181

    Two reasons: 1. It needs to be reversible so you can go from words to lat/lon. 2. They wanted to use shorter words in cities, so the distribution of low n didn't want to cover the …

  15. comment
    Comment #24540807

    Yes, sorry, added that bit on my phone when out and about and made a mistake. Corrected.

  16. comment
    Comment #24537390

    RTCs are actually quite rare, especially in a lot of the lower power RF SoCs. Drift would also be an issue - most move at least 10 minutes a year. That's with good temperatures, no…

  17. comment
    Comment #24536536

    Is CTR more common?

  18. comment
    Comment #24536385

    I've added a section on padding oracle attacks towards the bottom. I don't think there's a significant different in ease of understanding between most of the modes. I used CBC as i…

  19. comment
    Comment #24536199

    I considered using a padding oracle attack in the post, but it's aimed at a very basic level of understanding. I find padding oracles are much harder to describe to newcomers. Also…

  20. comment
    Comment #14085584

    Why do you need to spend money to use HTTPS with IoT?

  21. comment
    Comment #14077005

    Less well tested than OpenSSL, but historically has been relatively secure.

  22. comment
    Comment #14076989

    Specifically, in the case of the firmware running on the Trådfri gateway, it already supports TLS.

  23. comment
    Comment #12251391

    No, unfortunately not. We had to do it all black box as it was on sale or return, so couldn't inspect the firmware to find vulns. It was runnign Tizen, which makes things a lot har…

  24. comment
    Comment #12249115

    I did the work on this. Yes, the much bigger threat is taking control of these devices and using them as a pivot. We've done this for IP cameras, DVRs etc. It doesn't seem to engag…

  25. comment
    Comment #12249113

    I did the work on this. Yes, the much bigger threat is taking control of these devices and using them as a pivot. We've done this for IP cameras, DVRs etc. It doesn't seem to engag…