Live data from Hacker News

Viewing profile — xrorre

xrorre

HN member
Joined
Sun, Mar 06, 2016, 4:15 PM UTC
HN karma
144
Public activity
20 items

About xrorre

No profile information was provided.

Recent public activity

  1. comment
    Comment #11753427

    Here's an old XSS exploit for Roundcube from 2013: https://www.intelligentexploit.com/view-details.html?id=1696... I still use RC despite the long history of XSS attacks against it…

  2. comment
    Comment #11729494

    I appreciate the intention of this article. Written for people only starting to change their surfing habits in light of Snowden. But the example of the tools they should use are no…

  3. comment
  4. story
  5. story
  6. comment
    Comment #11707769

    In terms of a threat model, it includes any machine which acts as a hypervisor and as the old saying goes: If you don't trust the hypervisor, how can you trust any machine running …

  7. comment
    Comment #11707694

    Typically we don't want the userspace to be compromised at all. An antilogger works by effectively substituting letters as they are typed. So when I type 'A', it is read as A in th…

  8. comment
    Comment #11706522

    You can counter this by creating a hook to scramble keys as they are typed. There are countless antiloggers out there and they're the first thing I install on any fresh distro. Why…

  9. comment
    Comment #11706448

    Qubes is exponetially superior to this distro. Open that PDF in a disposable Fedora sandbox, and physically disable the network plz

  10. comment
    Comment #11706421

    JPGs are also a lot safer as PDFs can ping remote resources using carefully hidden beacon images. Although that said, I sometimes use this to see who opened my files. I once left h…

  11. comment
    Comment #11700880

    Zemana Antilogger is pretty sufficient for these threats, and also blacklisted by the NSA, so I suppose it works then? I wrote some custom apps that use 'key-interleaving' so that …

  12. story
  13. comment
    Comment #11288957

    The Apple situation annoys me because it's no longer about the web. It's about breaking crypto on a device which is vendor-locked. The same thing as breaking homegrown crypto, or D…

  14. story
  15. comment
    Comment #11266923

    > Well the security they engender is mostly physical security i.e. not getting blown up by terrorists while the security they want to breach is information security. This is exactl…

  16. comment
    Comment #11265840

    Better wording of a back door is donwgraded security. For an institution whose sole purpose is to engender security, they do the opposite. It's like saying they have better, more e…

  17. comment
    Comment #11265786

    The second occurrence is not only inevitable, it refutes the notion of a door in the first place, which is supposed to be fully opened at some stage for long periods, not temporari…

  18. story
  19. story
  20. story