Live data from Hacker News

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

wired.com

21–30 of 107 posts

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#21
post #17
post #15

Earlier quoted context omitted.

What's not true? (what's 'it' that you talk about)

The article did not become propaganda.

The article up to that point was great.

However, that sentence "But the government of Iran probably could" made the preceding paragraphs appear to be a vehicle to deliver a meme (like a shaggy-dog story). The rest of the article could have been great, I just stopped reading.

The journalist could have made a neutral statement about what entities have the resources to crack a 768-bit key. But they or their editor chose not to.

Instead, everyone that reads the article will go away with the meme "Iran, if they wanted to, could crack 768-bit keys". Which is, by common definition, propaganda.

It might be unintentional, i.e. the journalist is riding a wave of popular opinion, which they should not do; or it might be an attempt to load the article with link bait.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#22
post #5
post #2

I hope this guy's inbox is full of job offers. That's a heck of a find.

http://www.linkedin.com/in/drzacharyharris Wow, the guy's a monster. Fluent in classical (and Levantine) Arabic, Chinese, Greek; Top Putnam score (twice), teacher, Christian missionary. Sounds like he's got drive.

Nit-picky corrections:

1. Top Putnam score in Colorado. There's a pretty big difference between that, and say, top Putnam score in Massachusetts (which is more likely the same as top overall due to many Putnam Fellows coming from Harvard or MIT).

2. Elementary proficiency in Classical and Leventine Arabic, Mandarin Chinese, and Koine Greek

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#23
post #21
post #17

Earlier quoted context omitted.

The article did not become propaganda.

The article up to that point was great. However, that sentence "But the government of Iran probably could" made the preceding paragraphs appear to be a vehicle to deliver a meme (like a shaggy-dog story). The rest of the article could have been great, I just stopped reading. The journalist could have made a neutral statement about what entities have the resources to crack a 768-bit key. But they or their editor chose…

Hasn't (hackers in) Iran been behind hacking registrars and intercepting social networks etc? I thought it was a nod to that.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#25
post #9

“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.” "But the gover…

> "But the government of Iran probably could"...At this point I stopped reading, as this article became propaganda.

How is that propaganda? You don't think most countries have that kind of computing power?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#26
post #8

DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.

It authenticates the domain of the sender, right?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#28
post #8

DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.

It authenticates the domain of the sender, right?

If you want to impute that much authority to it, sure, but the actual signature verification depends on the insecure DNS anyways. Do not make security decisions based on DKIM. It's an anti-spam mechanism and that's all.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#29
post #14
post #8

DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.

Gmail (possibly Hotmail) put a little lock icon next to DKIM authenticated email from some senders, such as eBay & PayPal and outright reject unauthenticated emails from such domains. They've flaunted this feature in the past So if an authenticated PayPal email pops up in your Gmail inbox saying you must do this and that to unlock your account, you may be more likely to do so due to the legitimacy of DKIM.

The reality is that people will act on "Paypal" mail that comes from "Payapal.ng". Let's not pretend that DKIM has much to do with that decision. I agree, though, that the little lock in the Gmail UI is misleading.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#30
post #22
post #5

Earlier quoted context omitted.

http://www.linkedin.com/in/drzacharyharris Wow, the guy's a monster. Fluent in classical (and Levantine) Arabic, Chinese, Greek; Top Putnam score (twice), teacher, Christian missionary. Sounds like he's got drive.

Nit-picky corrections: 1. Top Putnam score in Colorado . There's a pretty big difference between that, and say, top Putnam score in Massachusetts (which is more likely the same as top overall due to many Putnam Fellows coming from Harvard or MIT). 2. Elementary proficiency in Classical and Leventine Arabic, Mandarin Chinese, and Koine Greek

Wow, #1 sets off my tryhard alarm. Especially at the college level where a huge portion of high Putnam scorers migrate to locations like Cambridge and California.

top 50 or even 200 overall or whatever is far more impressive than #1 in a state that has no reputation for high scores.

Post reply on HN