Live data from Hacker News

Viewing profile — tkems

tkems

HN member
Joined
Mon, Aug 22, 2016, 2:46 PM UTC
HN karma
479
Public activity
59 items

About tkems

[ my public key: https://keybase.io/tkems; my proof: https://keybase.io/tkems/sigs/J855-TsekXzOE90xlOemdLwBwo75MEstw3kzgnlDEbk ]

Recent public activity

  1. comment
    Comment #47401149

    One that I have been experimenting with is using analog phones (including rotary ones!) to act as the satellites. I live in an older home and have phone jacks in most of the rooms …

  2. comment
    Comment #42942513

    I can confirm that Aliexpress doesn't allow me to checkout with a USA address and states that items can't be shipped to my region. -edit: Since this post it seems that I can order …

  3. comment
    Comment #42853776

    I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other…

  4. comment
    Comment #42151261

    From what I've read, myQ is pretty locked down and doesn't support local control (outside of a HomeKit device that I think is no longer supported). I would guess that the cert pinn…

  5. comment
    Comment #41597748

    Yes, RF (radio frequency) remotes I've seen include my garage door opener, some overhead fans in bedrooms, gates, remote outlet/light controllers.

  6. comment
    Comment #41596113

    I would check out the Unleashed firmware [1]. I've had pretty good luck with it so far. [1] https://github.com/DarkFlippers/unleashed-firmware

  7. comment
    Comment #41596086

    As someone in cybersecurity, it is handy as a low frequency RFID reader as Android phones only support higher frequency. Having something compact and in a single unit (compared to …

  8. story
  9. comment
    Comment #40987103

    This is a great run down of the process to extract the firmware from these types of devices without desoldering the flash. I've done a fair amount of reverse engineering and a lot …

  10. comment
    Comment #40906936

    With Google Wallet (the only one I have at the moment), it is not static for the ticket. It has a NFC and barcode option. The barcode changes every 15 seconds for me.

  11. comment
    Comment #40906885

    I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation aroun…

  12. comment
    Comment #40225423

    One issue I have with the Flock cameras installed in my city is that they are installed on public land (right next to the road) and paid for with tax dollars.

  13. comment
    Comment #40225373

    One of the Flock cameras was installed in my city nearby where I live. Once I noticed it, I thought it was a red light camera at first since it was near an intersection. I did some…

  14. comment
    Comment #39853361

    If banks would spend money on this and not enabling support for hard to phish MFA options like hardware keys (FIDO2), I would change banks. We have solutions to most of the phishin…

  15. comment
    Comment #39710744

    Wow, I just submitted the consumer disclosure report this morning after finding out about it from somewhere else. I am VERY interested to see if anything is reported from my car si…

  16. comment
    Comment #39706109

    This sounds like HomeLink and is indeed more complex. My understanding of it is that they partner with lots of companies to support their rolling/fixed codes and remotes so that th…

  17. comment
    Comment #39706057

    The largest garage door manufacture in the US uses the Security+ and Security+ 2.0 algorithms that are rolling, but can be fairly trivially decoded to gain the serial number and ro…

  18. comment
    Comment #39305859

    I would say that money is the root of the problem. I think that most VOIP providers don't want to loose out on unencrypted traffic (both legitimate and spam). Also, why do I seem t…

  19. comment
    Comment #39305793

    This was my thought too. While I do think going after this kind of scam is a good first step, I don't see overseas operators not using this any less. Most spam calls I get don't fo…

  20. comment
    Comment #39257074

    I find this strange but not surprising. I've heard of speed bumps in the past related to 'hackers in town' and I wouldn't be surprised if it comes out later that it had something t…

  21. story
  22. comment
    Comment #39132942

    This seems that Apple went to way too much thought to avoid a simple solution: Just let users sideload apps and put up a few warning messages like Android. Must have had a bunch of…

  23. comment
    Comment #39092204

    From what I understand, cars are a bit more complex now then garages. KeeLoq, from my understanding, is not 'breakable' like garage doors. It does have weaknesses, but more related…

  24. comment
    Comment #39091745

    While rolling codes can be secure (KeeLoq [0] is a more secure example but has it's own issues), this [1] is an example of some of the weaknesses that can happen if a rolling code …

  25. comment
    Comment #39091680

    Just a heads up about the Flippers U2F implementation [0] and the possible weaknesses compared to a Yubikey/other U2F key. [0] https://modusmundi.com/posts/u2f-flipper/