Live data from Hacker News

Viewing profile — jamesmotherway

jamesmotherway

HN member
Joined
Sat, May 02, 2020, 9:53 PM UTC
HN karma
70
Public activity
34 items

About jamesmotherway

I'm a proactive cybersecurity professional with a background in IT (among other things).

hn.stoic811@8shield.net

https://www.jamesmotherway.com

Recent public activity

  1. story
  2. comment
    Comment #43174382

    I've used favicons (along with analytics IDs) to identify related malicious sites. You can also apply this to detect brand abuse and phishing pages.

  3. comment
    Comment #43129220

    See the "Data categories and encryption" section: "The table below provides more detail on how iCloud protects your data when using standard data protection or Advanced Data Protec…

  4. comment
    Comment #42571358

    Sorry, I overlooked part of your post earlier - I'm tired. As I previously alluded to, I don't use passkeys due to concerns about their implementation. Whether passkeys are better …

  5. comment
    Comment #42568182

    Hardware keys and passkeys are better because they can't be phished. In the case of hardware keys, one should register multiple to prevent lockout. Most implementations of passkeys…

  6. comment
    Comment #42568108

    If the vault requires a hardware key and master password to access the encrypted password and token, would you still describe it as single-factor authentication?

  7. comment
    Comment #42561025

    China-nexus threat actors tend to be focused on espionage, including intellectual property theft. "Prepositioning" is a more recent observation, but it doesn't mean a war is inevit…

  8. comment
    Comment #42554253

    Is your system configured to share analytics and diagnostics? I disable both, and when a crash occurs, I receive a dialog with an "ignore" option.

  9. comment
    Comment #42554150

    Bad actors frequently use BuyVM's services, also known as FranTech and Ponynet. Their popularity with Tor operators probably doesn't help how their network traffic is perceived eit…

  10. comment
    Comment #42383943

    https://archive.is/NKPrR

  11. comment
    Comment #42278658

    I'm assuming by "significant" you mean an attack on critical infrastructure. That's a strategic capability that very likely requires multiple attack chains, not a single exploit. F…

  12. comment
    Comment #42267311

    The X230 is still relevant for those who want a ThinkPad that supports Libreboot (an alternative firmware without proprietary components). I personally found this demonstration int…

  13. comment
    Comment #42266787

    I'm inclined to believe it. If someone managed to prove Apple's lying about it, there would be serious reputational (and other) risks to their business. I also can't imagine how th…

  14. comment
    Comment #42261825

    "All Apple silicon-based Mac notebooks and Intel-based Mac notebooks with the Apple T2 Security Chip feature a hardware disconnect that disables the microphone whenever the lid is …

  15. comment
    Comment #42210706

    Threat actors don't create malware to impress people; they do it to accomplish their goals. Apparently, this sample was sufficient for them. Security companies attribute activity b…

  16. comment
    Comment #42186799

    The NSA publishes excellent cybersecurity resources: https://www.nsa.gov/press-room/cybersecurity-advisories-guid... I've highlighted advisories that may give you some perspective,…

  17. comment
    Comment #42179519

    I understand where you're coming from, but Apple Intelligence is labelled as a beta feature.

  18. comment
    Comment #41946309

    The alternative in many cases would be to install MDM software on one's personal device, which seems like the worse option to me.

  19. comment
    Comment #41610348

    Banks use various other services such as Early Warning. Still, it's absurd the lengths we need to go to for any level of assurance against fraud.

  20. comment
  21. comment
    Comment #41547873

    Thanks for your feedback. I posted this because I've seen many people stop their analysis when they find a site is on Cloudflare. Were you able to solve the challenge at the end?

  22. story
  23. comment
    Comment #41542775

    Satiety is precisely it, and I would not be so quick to minimize its effect. Reasoning by analogy, most would accept that some people are better suited to extended release medicati…

  24. comment
    Comment #41542290

    It's frightening to think about the implications of this when generalized toward mainstream topics.

  25. comment
    Comment #41542275

    It's certainly interesting, but he's not a hero.