Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

51–60 of 142 posts

Re: Full-disclosure – Administrivia: The End

#51
post #48

What a shame; I just recently started taking on an interest in computer security and signed up for the list. In just the few weeks I was on there, I learned about a vulnerability in a device I had recently bought. I am cherishing the opportunity (which I haven't found time for yet) to walk through my first exploit! As a newcomer I'm not really sure what John's referring to, though. Too bad...

I'll offer my take on his "industry that shouldn't have become an industry". One of the biggest drivers of cash into information security hires is government regulation. Otherwise, a lot of these companies could give a shit if they lose private data. Enter the information security specialist who has no fucking clue how to program or do anything remotely technical. They went out and got their CISSP cert, and now they…

Wow, that's a harsh view on the CISSP and infosec pros in general. Though I'm not necessarily disagreeing with you.

Re: Full-disclosure – Administrivia: The End

#52
post #49

Earlier quoted context omitted.

Given the list's modus operandi and goals, wouldn't it work well under a format such as the blockchain? No moderation and no chance to delete what's been posted, since the decentralization means it would by then be replicated across lots of machines.

You then can't filter or delete spam, which far outweighs legitimate mail.

You need to pay BTC in order to store in the blockchain(i.e. you can't send 0.00BTC transaction to someone.) That should go pretty far in eliminating spam. Then again it might be too high a barrier for legitimate posters.

Re: Full-disclosure – Administrivia: The End

#54

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…

I floated the idea on bitcointalk.org of a fully anonymous distributed message board that used small bitcoin payments as the cost to post messages ... possibly softened by having a newbie/spam forum where "free" posts are possible but don't get much attention.

It didn't get much traction. (I can understand why bitcointalk.org is staying where they are. It was when theymos was openly asking what to do with all the donated BTC.)

I would, however, be happy to join a public github repo if there's serious interest.

Re: Full-disclosure – Administrivia: The End

#55
post #27

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

Don't trust Tor to provide anonymity against government adversaries. It's likely not secure given Snowden disclosure of anti-Tor tools.

I actually think Snowden's documents support a cautious optimism about Tor.

The techniques they detail all amount to an admission that Tor itself is still quite difficult for the NSA to de-anonymize at scale. They resort to exploits against browsers instead, which is far less scalable and far more risky.

According to Snowden, the NSA doesn't want to waste valuable vulnerabilities on low-value targets (since this risks discovery and disclosure, making the vulnerability useless in the future).

So they can't do mass surveillance of Tor, and can only de-anonymize targeted individuals under optimal conditions.

Re: Full-disclosure – Administrivia: The End

#56
post #39
post #12

Earlier quoted context omitted.

Yes it would seem in the vein of the list to out the 'researcher' who is being the final asshole.

What would be the point, other than nailing that person to a post and having them exposed to various forms of Internet abuse? As you said yourself, this is just the final straw.

That would be the point.

Re: Full-disclosure – Administrivia: The End

#57
First thing I saw in my inbox when I got to work this morning. Sad really, the list has certainly had it's moments.

Can't help but be a little optimistic, at least the "Google Vulnerability with PoC" youtube-upload trollfest chain of emails is done flooding my inbox this month :D

Re: Full-disclosure – Administrivia: The End

#58

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

It's a double edged sword. The primary adversary on a site with anonymous posting isn't a government but the staff of the site itself (as demonstrated by the OP.)

Re: Full-disclosure – Administrivia: The End

#60
Instrumental in this message for me was this part:

There is no honour amongst hackers any more.

10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest feat of all - exit. There's no more moral obligations of the past. Launch at all cost - the rest is an afterthought.

There's a discrepancy between the two cultures. I think this divide is the source of the mailing-list problem and problems with freedom of information and privacy at large we have today.

Post reply on HN