Viewing profile — gibsonsecurity
gibsonsecurity
HN member- Joined
- Tue, Dec 24, 2013, 9:46 PM UTC
- HN karma
- 44
- Public activity
- 16 items
- HN profile
- View on Hacker News ↗
About gibsonsecurity
No profile information was provided.
Recent public activity
- story
-
comment
Comment #7003799
They won't see a huge amount of users deleting accounts, but I'm sure future users will think twice before joining. Also, the value of the company.
-
comment
Comment #7003714
This isn't an issue with convenience, this is an issue with Snapchat failing to fix a vulnerability. How relevant is find_friends to Snapchat now? Is it really needed? Are they get…
-
comment
Comment #7003577
We're going to be releasing a statement shortly. Here: https://gist.github.com/anonymous/8231005
-
comment
Comment #6994146
For the record we don't know about SnapchatDB. But it was a matter of time until this happened, the exploit still works with minor modifications, you just have to be smart about it…
-
comment
Comment #6973487
We don't :) (but we'd be happy to take Snapchats money and help them out!) We documented two exploits, which are exploits, because we are exploiting code that has been incorrectly …
-
comment
Comment #6973467
Sorry about that - I thought it was clear from the context of those off-the-cuff estimations that it was 6666 numbers (since that was based off of how many numbers you could scan, …
-
comment
Comment #6965677
He isn't? Sorry that really is a mistake on my part. I thought I saw his name attached to it. I'm probably thinking of someone else, again I apologize to all parties involved.
-
comment
Comment #6964568
Obvious privacy reasons that would probably get Snapchat sued, but otherwise, yes that would probably work.
-
comment
Comment #6964445
We thought about that, and it would be pretty misleading. If they did find out data that way, they should really tell people how inaccurate it can be.
-
comment
Comment #6962850
Definitely, lol. That's a pretty sneaky idea, I'm sure its possible with all the clients now available!
-
comment
Comment #6962805
Hahahaha, I don't think making it harder to reverse would be any better, it would probably motivate people even more (deobfuscation is too much fun and fairly easy!). They should r…
-
comment
Comment #6962794
I'm quite the fan of Steve Gibson, infact I use grsec on my boxes, sadly we only noticed this after our initial release, when it really was too late. If Steve Gibson hears of this,…
-
comment
Comment #6962716
Thanks, and that's totally fine. I agree with you, Snapchats definitely flawed from the start, but as long as we get rid of gaping holes in their security such as the find_friends …
-
comment
Comment #6962682
Hi, I'm one of the authors of the above release [1], and the exploit we primarily talked about (find_friends) isn't really an issue with the protocol as a whole. We understand the …
- story