Live data from Hacker News

Viewing profile — supernetworks

supernetworks

HN member
Joined
Sat, Apr 15, 2023, 6:28 PM UTC
HN karma
28
Public activity
28 items

About supernetworks

On a mission to make networking secure and simple. Now we're scaling up manufacturing to make it affordable. Reach out to us and check out our website if you'd like to learn more https://www.supernetworks.org/

Recent public activity

  1. comment
    Comment #47498139

    Another favorite, https://www.synacktiv.com/publications/cool-vulns-dont-live-... the router sniffed plaintext http to grab HTTP User agents to put them into a curl bash command li…

  2. comment
    Comment #47498025

    Not a bot. Anyway if you have questions about router security rather than moderation happy to "delve" into that.

  3. comment
    Comment #47497981

    Supernetworks -- ill update. Our initial comment got moderated for too much self promotion so also apologies there and again for anyone who is offended

  4. comment
    Comment #47497897

    [flagged]

  5. comment
    Comment #47497296

    You can check our comment history https://news.ycombinator.com/threads?id=supernetworks

  6. comment
    Comment #47497129

    Thanks Tom. This whole comment thread is a bit of a dumpster fire of opinions however we have been working on the wifi security problem for a long time and we have a lot to say abo…

  7. comment
    Comment #47496101

    [flagged]

  8. comment
    Comment #47170353

    Yep, unfortunately fuzzy. For enterprise wifi deployments, one amusing thing to do when configuring 802.1X is to test ARP spoofing the upstream radius server after associating, and…

  9. comment
    Comment #47170123

    Some 802.1x have inherent mitm attacks that have been called out since 2004 and never got the v2 ( https://www.rfc-editor.org/rfc/rfc6677.html ). EAP-TLS however is the best practi…

  10. comment
    Comment #47169868

    Hostapd now has support for multi pass SAE /WPA3 password as well. We have an implementation of dynamic VLAN+per device PSK with WPA3 ( https://github.com/spr-networks/super ) we'v…

  11. comment
    Comment #47169817

    This attack exploits multi PSK networks precisely. If it's all one PSK the attacker can already throw up a rogue AP for WPA3 or just sniff/inject WPA2 outright. The back half of a …

  12. comment
    Comment #47169756

    This is mostly accurate, to clarify the association IDs tie into what VLANs will be assigned and that does block all of the injection/MITM attacks. This also assumes that the VLAN …

  13. comment
    Comment #47169623

    EAP TLS provides strong authentication, is much better than the other enterprise authentication options, but will not block these lateral attacks from other authenticated devices. …

  14. comment
    Comment #46278700

    yes understood, the first article isn't the main subject of the article.

  15. comment
    Comment #46278666

    by complexity class that would be consensus, although the argument for building BPP systems is about the energy cost being orders of magnitude less and perhaps also some polynomial…

  16. comment
    Comment #46278449

    yes, this paper is the main subject of the article

  17. comment
    Comment #46277361

    A direct equivalent, no, as stated in the introduction. "Notably, while probabilistic computers can emulate quantum interference with polynomial resources, their convergence is in …

  18. comment
    Comment #46266224

    Some of the properties of fil-c managed heaps are very similar to what CHERI can do with Cornucopia by the way: see https://dl.acm.org/doi/10.1145/3620665.3640416

  19. comment
    Comment #46204562

    tragically, this is exactly what it is

  20. comment
    Comment #45464770

    "given that destroying the correlation between two entangled particles" i think this is the assumption that is easy to make without digging deeper into entanglement. i am still in …

  21. comment
    Comment #45201048

    We have a similar container @juhovh, for a plugin for the router we work on. in case this is helpful for you, feel free to to review https://github.com/spr-networks/spr-tailscale/b…

  22. comment
    Comment #44953461

    A particularly tricky exploit in the linux futex implementation from 2014, by Pinkie Pie, https://issues.chromium.org/issues/40079619 "The requeue-once rule is enforced by only all…

  23. comment
    Comment #44952913

    encrypted DNS goes a long way towards mitigating this as well.

  24. comment
    Comment #44952608

    Novel or not, this seems like it can be actively exploited?

  25. comment
    Comment #44948122

    It is a book, "Underground: Hacking, madness and obsession on the electronic frontier". I seem to recall cross it hosted under mit.edu/~hacker/underground.txt or something like tha…