Live data from Hacker News

Viewing profile — deepbreath

deepbreath

HN member
Joined
Wed, Mar 21, 2018, 12:22 PM UTC
HN karma
55
Public activity
36 items

About deepbreath

No profile information was provided.

Recent public activity

  1. comment
    Comment #39898912

    The knockee PoC should also be straightforward, can use socat + udp-listen + fork with a script that checks that input matches `sha1sum(secret||num)||num` and `num>previously_seen_…

  2. comment
    Comment #39898717

    Don't have to do anything too complicated. Here's the knocker code in a short Bash script, produced by GPT4: ~ % gpt4 'write a very short bash script that takes the number stored i…

  3. comment
    Comment #39898534

    > At the point an attacker has remote code execution The attacker doesn't have remote code execution in the xz case unless they can speak to your port 22. Port knocking prevents th…

  4. comment
    Comment #28785812

    You're right, I guess it depends on what you choose A and B to be. For: A = OP supports Mozilla making money from address bar ads B = Mozilla is honest about making money from addr…

  5. comment
    Comment #28785537

    Except it's not used correctly here. "A iff B" means "A implies B and B implies A". "I'd be willing to entertain, or even support, this way of them making money iff they spelled ou…

  6. comment
    Comment #24817431

    > I don't even know how people can say this stuff with a straight face. It's not too difficult to do so, when there are examples of courts banning satirical poems of a foreign lead…

  7. comment
    Comment #23569400

    I thought I did? The condescending attitude is unnecessary. Happy to clarify my point if my initial comment was confusing: Websites such as http://panopticlick.eff.org/ showcase ho…

  8. comment
    Comment #23567304

    Could you point what you believe to be the issues in the thread?

  9. comment
    Comment #23566954

    If nothing else, it significantly reduces the entropy of your IP when websites are fingerprinting you, especially if your ISP assigns you a static IP. Even if you don't have a stat…

  10. comment
    Comment #22642077

    There are plenty of homeless people in London.

  11. comment
  12. comment
    Comment #21969500

    Honestly, your comments are pretty much an r/wowthanksimcured meme.

  13. comment
    Comment #21664742

    > (Hint: go ahead and start interviewing and have semi-serious job leads before this talk) I think this bit of advice is at odds with OP's statement: "I don’t think I’d come across…

  14. comment
    Comment #20681375

    Makes me think of the gradual increase of identity politics in mainstream media, politics and liberal circles, to the point it's driving me insane. Most people around me seem undis…

  15. comment
    Comment #20679546

    Not thinkpad x1 carbon

  16. comment
    Comment #20621598

    I committed the grave mistake of purchasing a laptop with only 8GB ram and I constantly run out of memory as a result. When it happens, I just repeatedly mash alt+sysrq+f until it …

  17. comment
    Comment #20612659

    https://www.telegraph.co.uk/news/2016/04/07/german-comedian-...

  18. comment
    Comment #16991557

    The server would not be able to verify a changing hash without knowing the password

  19. comment
    Comment #16991550

    It's unclear to me how your random salt would work. From my understanding, you're suggesting smth like: register: send (username, user_salt, HMAC(user_salt, pwd)) login: send (user…

  20. comment
    Comment #16991494

    But the password is only known to the client?

  21. comment
    Comment #16991437

    > meaning old hashes wouldn't be accepted and reducing hash "replay" possibilities How would the server even verify the hash, then?

  22. comment
    Comment #16991368

    I think one of the things I'd really miss is Google Maps. The directions are really good, and the web app is unusably slow

  23. comment
    Comment #16944885

    The last two employees would eat eachother's lunch. The issue is that the last employee has to have the moral integrity to fire himself.

  24. comment
    Comment #16911304

    So then all he needed to do is write his name in addition to his IP address in the comment?

  25. comment
    Comment #16899373

    It's happened before, with Microsoft, too. They've transitioned from an OS where you pay with cash (win7), to a spyware OS where you pay with cash and your data (win10).