Live data from Hacker News

Stop Hacklore – An Open Letter

hacklore.org

41–50 of 115 posts

Re: Stop Hacklore – An Open Letter

#41
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

To be fair, this letter is about information security, not privacy.

Maximizing privacy is a somewhat different goal, and recommendations for how to do so would differ from person to person. Some people really don't care about privacy. And for some other people, adblocker and tracking-blocker software is sufficient for their privacy needs. Whereas for certain people in certain parts of the world, literally the only way they can browse the Web safely is with Tor running on a temporary TailsOS drive.

Re: Stop Hacklore – An Open Letter

#42

So, since this seems to be relevant im a CISO myself. And i would definitely not agree with everything in this letter. Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices. To take on point as example - the "never scan public QR codes". Apart from the fact that there have been enaugh exploits in the past…

[deleted]

Re: Stop Hacklore – An Open Letter

#43

So, since this seems to be relevant im a CISO myself. And i would definitely not agree with everything in this letter. Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices. To take on point as example - the "never scan public QR codes". Apart from the fact that there have been enaugh exploits in the past…

It's funny your warning about QR codes goes onto warn about PDF exploits. Yet you clicked the link to this article, by your own definition opening you up to "a whole different world of possible exploitations via whatever file is being returned". It's the nature of the internet to follow links, but our updated browsers keep us safe from exploits.

When was the last time you saw an un-targeted mass 0-day exploit campaign? There haven't been any for modern browsers. If we're talking about 0-days, you likely known there have been zero-click iMessage/WhatsApp vulnerabilities in the past. There's no protecting against those, but you're not here warning users to disable iMessage and WhatsApp. What's more realistic is making sure users keep their software updated, and trust that QR codes and links aren't going to waste a 0-day worth a million dollars on you.

Re: Stop Hacklore – An Open Letter

#44
How about these:

- CISOs aren’t actually officers of the company and are typically 2-3 levels below the actual officers

- CISOs only exist to have someone to deflect blame onto after the inevitable breach

- If a company actually cared about security they wouldn’t put it in a silo

Re: Stop Hacklore – An Open Letter

#45
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

> Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

The entire point of end-to-end encryption is that you don't need to trust the server. If your password manager has access to your secrets (i.e. you don't control the secret key/password itself), then you have bigger problems than a potentially untrustworthy host.

Re: Stop Hacklore – An Open Letter

#46
post #38
post #37

Earlier quoted context omitted.

Where do you detect malice? The claims are quite accurate.

Accurate? Lets take the Wifi (Other users already commented the other ones). Open a wifi access point with the name of the restaurant, intercept the DNS requests and serve your filtered stuff. PS: If the text is real and not trolling, the keyword in the text is 'rarely happen', which we could apply to car seatbelts then.

what filtered stuff?

you mean partial web pages?

most browsers use DNS over HTTPS

Re: Stop Hacklore – An Open Letter

#47
post #38
post #37

Earlier quoted context omitted.

Where do you detect malice? The claims are quite accurate.

Accurate? Lets take the Wifi (Other users already commented the other ones). Open a wifi access point with the name of the restaurant, intercept the DNS requests and serve your filtered stuff. PS: If the text is real and not trolling, the keyword in the text is 'rarely happen', which we could apply to car seatbelts then.

And how exactly do you plan to forge the SSL certificates to deliver your filtered contents?

Re: Stop Hacklore – An Open Letter

#50
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

Max browser security levels and a good ad-blocker will not prevent you from getting phished or hacked more than an encryption-audited cloud-based zero-knowledge vault, where server compromise is irrelevant. All competent #1 cloud-based password managers are like that.

Do you have a list of such managers?
Post reply on HN