Viewing profile — iscoelho
iscoelho
HN member- Joined
- Wed, Jan 18, 2017, 10:31 PM UTC
- HN karma
- 653
- Public activity
- 201 items
- HN profile
- View on Hacker News ↗
About iscoelho
No profile information was provided.
Recent public activity
-
comment
Comment #49089377
I don't think iPhone Upgrade Program was ever the best deal to be honest. It's just convenient.
-
comment
Comment #49087741
I stand corrected! This doesn't look too bad then.
-
comment
Comment #49087691
The Apple Upgrade lease model isn't even a replacement as you have to wait 24 months before upgrading. The entire point of the iPhone Upgrade Program was to make it painless to swa…
-
comment
Comment #48825099
You'd be surprised to know that this strategy works quite well! Pixel bots require a hardware fake display when faced with kernel anti-cheat. They also depend on color/pattern reco…
-
comment
Comment #48815760
Aimbot is actually very solvable! 1) When DMA is fully blocked, Aimbot resorts to being a pixel bot. 2) Once you're relying on a pixel bot, all the anti-cheat has to do is "bait" t…
-
comment
Comment #48815712
> "How come replay analysis doesn’t catch more cheaters?" 1) There's too many players. 2) Closet cheaters are extremely subjective: automated & manual moderation would be full of f…
-
comment
Comment #48815644
I feel someone doesn't need to play competitive games to be able to give an honest assessment of the privacy & security risks. I'm sad I'm not seeing that honesty elsewhere in this…
-
comment
Comment #48815544
At least in Valorant, DMA is becoming impossible due to IOMMU / Memory Integrity enforcement. The only option is becoming pixel bots. As for faking the input device: I'm sure it's …
-
comment
Comment #48815429
In my opinion, the debate about kernel anti-cheat on Windows is disingenuous fear-mongering. I'm confused why Hacker News of all places misrepresents the technical details. You can…
-
comment
Comment #48815297
That's a different type of game entirely. Private/community servers cannot be competitive at the scale of modern competitive games.
-
comment
Comment #48815271
This isn't possible in Valorant. Their kernel module is extremely particular about input devices: 1) only allows a single mouse input device at a time 2) completely ignores virtual…
-
comment
Comment #48141010
I don't disagree. Clarifying, I personally don't think this exploit is a backdoor, but rather that the negligence is enough to appear malicious. Just for fun (not saying I believe …
-
comment
Comment #48132130
If the device does not have BitLocker, WinRE already by default provides full Administrator access to the unencrypted disk via Command Prompt. > I think that level of pushback agai…
-
comment
Comment #48132048
If the device doesn't have BitLocker, this exploit is pointless because you can already boot any OS USB and immediately have full access to the unencrypted disk. This exploit is on…
-
comment
Comment #48131914
1) Except that the entire premise behind BitLocker TPM's security relies on the login screen as a hard security boundary, and thus any attack on the login screen is an attack on Bi…
-
comment
Comment #48131723
Considering the researcher had already reported these to Microsoft, and delayed releasing them publicly until Microsoft "pulled every childish game possible" (quote) instead of pat…
-
comment
Comment #48131443
What's with all the replies on these threads downplaying this? Why is it mainly brand new accounts? What's going on here? I've seen every variant of: 1) "this is an authentication/…
-
comment
Comment #48131415
That’s quite a stretch, to say the least.
-
comment
Comment #47429859
But it doesn't. Full authentication bypass exploits are extremely rare and unheard of among tech giants. Maybe account takeover/recovery, sure, but full bypass? It just never happe…
-
comment
Comment #47427311
I knew there was another incident that I was forgetting, insanity... I don't understand how Microsoft keeps getting away with this and everyone just forgets.
-
comment
Comment #47426921
Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was abl…
-
comment
Comment #46621579
I'd use WireGuard in that case. The main reason WireGuard is popular at all is because it is approachable. IPsec is much more complicated and is designed for network engineers, not…
-
comment
Comment #46621447
That's a large packet benchmark, not mixed packet size, and it just barely hits it. If you need consistent 10Gbps for a business use case, I would not consider that sufficient. > "…
-
comment
Comment #46621110
Mikrotik can be popular for CE (Customer Edge) devices, that is correct. Those are not ISPs however, those are customers.
-
comment
Comment #46621094
CE (Customer Edge) is what you are referring to. ISPs would be the PE (Provider Edge). I am aware it can be popular for SMB CE devices, however that is simply not the case for PE d…