Viewing profile — xrorre
xrorre
HN member- Joined
- Sun, Mar 06, 2016, 4:15 PM UTC
- HN karma
- 144
- Public activity
- 20 items
- HN profile
- View on Hacker News ↗
About xrorre
No profile information was provided.
Recent public activity
-
comment
Comment #11753427
Here's an old XSS exploit for Roundcube from 2013: https://www.intelligentexploit.com/view-details.html?id=1696... I still use RC despite the long history of XSS attacks against it…
-
comment
Comment #11729494
I appreciate the intention of this article. Written for people only starting to change their surfing habits in light of Snowden. But the example of the tools they should use are no…
-
comment
Comment #11708227
asdf
- story
- story
-
comment
Comment #11707769
In terms of a threat model, it includes any machine which acts as a hypervisor and as the old saying goes: If you don't trust the hypervisor, how can you trust any machine running …
-
comment
Comment #11707694
Typically we don't want the userspace to be compromised at all. An antilogger works by effectively substituting letters as they are typed. So when I type 'A', it is read as A in th…
-
comment
Comment #11706522
You can counter this by creating a hook to scramble keys as they are typed. There are countless antiloggers out there and they're the first thing I install on any fresh distro. Why…
-
comment
Comment #11706448
Qubes is exponetially superior to this distro. Open that PDF in a disposable Fedora sandbox, and physically disable the network plz
-
comment
Comment #11706421
JPGs are also a lot safer as PDFs can ping remote resources using carefully hidden beacon images. Although that said, I sometimes use this to see who opened my files. I once left h…
-
comment
Comment #11700880
Zemana Antilogger is pretty sufficient for these threats, and also blacklisted by the NSA, so I suppose it works then? I wrote some custom apps that use 'key-interleaving' so that …
- story
-
comment
Comment #11288957
The Apple situation annoys me because it's no longer about the web. It's about breaking crypto on a device which is vendor-locked. The same thing as breaking homegrown crypto, or D…
- story
-
comment
Comment #11266923
> Well the security they engender is mostly physical security i.e. not getting blown up by terrorists while the security they want to breach is information security. This is exactl…
-
comment
Comment #11265840
Better wording of a back door is donwgraded security. For an institution whose sole purpose is to engender security, they do the opposite. It's like saying they have better, more e…
-
comment
Comment #11265786
The second occurrence is not only inevitable, it refutes the notion of a door in the first place, which is supposed to be fully opened at some stage for long periods, not temporari…
- story
- story
- story