Live data from Hacker News

Phrack Magazine

phrack.org

11–20 of 22 posts

Re: Phrack Magazine

#13

Earlier quoted context omitted.

The problem is that HTTPS has become something of a cult in tech circles. Not every web site needs HTTPS. It matters not at all if some government sees me checking the weather, or reading about the best seeds to plant this time of year. And 99 44/100% of the MITM hype is pure theoretical hysteria. There is a very long distance between "could" and "will" and "can" and "did." I know a lot of people enjoy their paranoia…

Holy shit man, ISPs are notorious for injecting ads and other garbage into web pages. Back when I had Comcast (Xfinity) they'd inject giant pop-up windows in web pages served over HTTP if I was approaching the asinine bandwidth limits. I also noticed an uptick in tracking ads on pages served over HTTP. Your ISP and mobile carriers are not trustworthy neutral carriers of data. Encrypted transports are the only way for…

Have fun injecting pop-ups and JavaScript crap into my Lynx sessions. Which is where nearly all of my HTTP browsing happens.

Re: Phrack Magazine

#14
post #4

Earlier quoted context omitted.

It has immense security implications. Without transport encryption, an adversary performing a MITM attack can, in certain circumstances, completely rewrite the entire HTTP response from the server. That includes everything from adding a tracking pixel to, at the extreme, serving some webasm exploit for your browser, plus a sandbox escape, to get code execution in (your) userland... where they could quickly and easily…

Do you trust certificate authorities? Do you trust the Chinese govt? Russian? While I agree in principal, in practice https is not very resilient to the attacks you mentioned because CAs are demonstrably [1,2,3] not trustworthy despite being baked into your browser. 1: https://en.m.wikipedia.org/wiki/DigiNotar 2: https://therecord.media/mongolian-certificate-authority-hack... 3: https://arstechnica.com/information-te…

I don't trust CA's, but having two points of weakness in this chain isn't better than having one.

Re: Phrack Magazine

#15

Earlier quoted context omitted.

Holy shit man, ISPs are notorious for injecting ads and other garbage into web pages. Back when I had Comcast (Xfinity) they'd inject giant pop-up windows in web pages served over HTTP if I was approaching the asinine bandwidth limits. I also noticed an uptick in tracking ads on pages served over HTTP. Your ISP and mobile carriers are not trustworthy neutral carriers of data. Encrypted transports are the only way for…

Have fun injecting pop-ups and JavaScript crap into my Lynx sessions. Which is where nearly all of my HTTP browsing happens.

Fine and well until someone injects code to exploit some 0day in lynx. Correct me if I'm wrong, but lynx doesn't even have sandboxing the way Chrome & FF do, right? Sure, it's a much smaller attack surface than those presented by traditional browsers, but if I had to hazard a guess, I'd assume it's been far less targeted, and considerably less hardened over the years.

Note: this is NOT an endorsement of Chrome, FF, Webkit, Blink, Gecko, nor is it a suggestion to NOT use Lynx - just a reminder that there are no silver bullets in security.

Re: Phrack Magazine

#16
Any time I'm in Barnes and Noble (in the US) I find the latest copy of 2600 magazine, which is in the same vein as phrack.

With 2600 at least, I can never find anything that interesting to read. Articles are usually about a) the hacker ethos, b) some ancient system and its exploit or c) a current system that's incredibly niche and its exploit, all with wildly varying article quality.

Re: Phrack Magazine

#17

Spoiler for anyone else that got excited: nothing new has been published.

New content is clearly not a requirement for posting old links on hn :). This was a little experiment to see how it compares to the overthewire links which show up every few months. Interesting difference in reactions, the actual hacker content gets a yawn :).

Not new, but it helps.

Or at least some explanation for why you shared it.

Spare us the experiment. Plenty of discussion when the content is fresh https://news.ycombinator.com/item?id=28758486

Re: Phrack Magazine

#18

Earlier quoted context omitted.

New content is clearly not a requirement for posting old links on hn :). This was a little experiment to see how it compares to the overthewire links which show up every few months. Interesting difference in reactions, the actual hacker content gets a yawn :).

Not new, but it helps. Or at least some explanation for why you shared it. Spare us the experiment. Plenty of discussion when the content is fresh https://news.ycombinator.com/item?id=28758486

If the last time HN looked at phrack was 2021, you are welcome for me bringing this gem back for anyone who hasn't seen it, and hey maybe we will get some papers for the next issue

Re: Phrack Magazine

#19

Spoiler for anyone else that got excited: nothing new has been published.

I once hired someone because they got published in Phrack. best decision ever.

Same, and in fact it was Sinan as a consultant because of his smashing the stack article. I was not disappointed with the results.

Re: Phrack Magazine

#20
post #16

Any time I'm in Barnes and Noble (in the US) I find the latest copy of 2600 magazine, which is in the same vein as phrack. With 2600 at least, I can never find anything that interesting to read. Articles are usually about a) the hacker ethos, b) some ancient system and its exploit or c) a current system that's incredibly niche and its exploit, all with wildly varying article quality.

2600 is so bad these days, very sad.
Post reply on HN