Live data from Hacker News

O.mg Cable

shop.hak5.org

481–490 of 555 posts

Re: O.mg Cable

#481

Earlier quoted context omitted.

He can defeat just about anything, but he’s also exceptionally skilled. As a consumer of locks, I expect them to be defeatable by a skilled lockpicker. But I don’t expect them to be defeatable by a bic pen or by reaching in the keyhole with an oddly shaped wire to move the locking paul. You can buy locks that don’t have easy bypasses, and can’t be easily drilled, and can’t be picked by beginners.

Which locks don't have easy bypasses? I've been wondering the most sophisticated/effective/secure locks regular consumers have access to. In other words, which locks does the Lock Picking Lawyer himself use in his house to protect his family?

He has specifically mentioned BiLock as one he would consider. As another comment in this thread mentioned, Mendeco is also well regarded.

Re: O.mg Cable

#482

Earlier quoted context omitted.

And let's not forget that many of them are probably browsing HN at this very moment. They could be you, they could be me!

> They could be you, they could be me! Couldn't be me: the private sector pays me waaaaaaaay more. Also, you can't work for the feds if you ever touch the ganja, which is ridiculous. Everyone I personally know in infosec leads a very... alternative west-coast lifestyle which is not conducive to career progression in an east-coast, button-down-shirt environment.

> Also, you can't work for the feds if you ever touch the ganja, which is ridiculous.

Calling it 'ridiculous' removes the debate concerning the pros and cons on such rule. If you consider someone can become vulnerable if they're addicted (to anything, really) then it makes sense to be wary of a drugs addiction. Especially if the resource the person is addicted to is illegal.

That being said, I'd find it reasonable if they OK'ed medical marihuana usage. I hope my gov (NL) does.

Re: O.mg Cable

#483
post #283

Earlier quoted context omitted.

https://www.youtube.com/watch?v=qV8QKZNFxLw

Apparently, picked here: https://youtu.be/ai5Hf-wPXFE but check out this one instead: https://youtu.be/sES_Hbj92BQ - ~2h to open fully (though the author of the video claims impressioning could speed up the thing; anyway, reportedly attacking the door is just easier in this case)

Guy who made the video here. The lock mechanism itself isn't one of the easiest, but also not one of the hardest to pick skill-wise. However, it does take a very long time to pick through which means that the lock is doing its job very well. Also, I have read that this lock is very resistant to destructive attack as well. So combining pick resistance with physical resistance, you have a very good lock as long as it's installed on a good door and the building has all other security measures in place (no ground level unprotected windows, etc)

Also worth noting, Bosnian Bill (a more recognized name) also attempted this lock here https://www.youtube.com/watch?v=tLeiPmfm-2s

Re: O.mg Cable

#484
post #347

Earlier quoted context omitted.

Yes, penetration testers, red teams, blue teams, auditors, and a myriad of other security conscious roles take advantage of these tools. > What prevents a malicious actor from buying and using these tools? Nothing. What prevents any actor from buying and using it maliciously? A significantly deeper question. I rather promote this.

Well, for one, the US government prevents private actors from buying all sorts of things. I am surprised that selling tools which potentially "enable cyber crime" hasn't triggered some overzealous regulator in DC yet. It seems like low-hanging fruit.

What prevents a criminal buying a chef's knife and committing a crime with it?

I am surprised that selling tools which potentially "enable murder" hasn't triggered some overzealous regulator in DC yet. It seems like low-hanging fruit. /s

Pro-authoritarian sentiment keeps going strong. Why is it so normalized these days?

Re: O.mg Cable

#485
post #482

Earlier quoted context omitted.

> They could be you, they could be me! Couldn't be me: the private sector pays me waaaaaaaay more. Also, you can't work for the feds if you ever touch the ganja, which is ridiculous. Everyone I personally know in infosec leads a very... alternative west-coast lifestyle which is not conducive to career progression in an east-coast, button-down-shirt environment.

> Also, you can't work for the feds if you ever touch the ganja, which is ridiculous. Calling it 'ridiculous' removes the debate concerning the pros and cons on such rule. If you consider someone can become vulnerable if they're addicted (to anything, really) then it makes sense to be wary of a drugs addiction. Especially if the resource the person is addicted to is illegal. That being said, I'd find it reasonable if…

Well it's a comparison. Not once on the security clearance paperwork is alcohol mentioned, while if you have smoked/eaten/etc. marijuana at ALL in the past 7 years, it's practically an instant deny unless it was under some exigent circumstance. You can even be denied if you don't partake but are close contacts with other marijuana users.

Obviously if someone is _addicted_ to either, that is a security risk. But the extent to which they reject people for recreational marijuana use is laughable.

Re: O.mg Cable

#486

Wow! Is the trick that we now have powerful microcomputers small enough to fit into a USB plug? That's pretty incredible technology. How many years ago did this become possible? My IT security training is dated, I am aware of the risks of plugging in a random USB key, but just a cable from a helpful "coworker"? Yikes.

In 2008 we had USB flash drives which extended only two millimeters beyond the laptop when you plugged them in, and Wifi dongles in the same form factor.

Re: O.mg Cable

#487
post #482

Earlier quoted context omitted.

> They could be you, they could be me! Couldn't be me: the private sector pays me waaaaaaaay more. Also, you can't work for the feds if you ever touch the ganja, which is ridiculous. Everyone I personally know in infosec leads a very... alternative west-coast lifestyle which is not conducive to career progression in an east-coast, button-down-shirt environment.

> Also, you can't work for the feds if you ever touch the ganja, which is ridiculous. Calling it 'ridiculous' removes the debate concerning the pros and cons on such rule. If you consider someone can become vulnerable if they're addicted (to anything, really) then it makes sense to be wary of a drugs addiction. Especially if the resource the person is addicted to is illegal. That being said, I'd find it reasonable if…

So you don't think any alcoholics work for the NSA?

Re: O.mg Cable

#488
post #420

Earlier quoted context omitted.

Cracking heads. The rest is just PR. They don't work for you. They know they don't work for you.

Tbf oakland is a low bar (as well as sf). Here just 15 mi down the road they investigated and arrested a credit card thief who stole my wife’s card and I didn’t even ask for it. They also regularly capture cat converter thieves with sting operations. Overall I’ve been quite impressed with San Mateo PD

I second this. I even had a local Bay Area PD help me recover a stolen bike after finding it posted.

Re: O.mg Cable

#489

Earlier quoted context omitted.

Not if you replace it with another lock that looks similar

I think when you get home and your key doesn’t work on the lock, it might tip you off.

When I had towers or pizza boxes I pretty much never touched them once it became normal to leave them on all the time, which was as soon as they were always downloading from the internet at 3.3 kbps.

If the case was locked in a cage I wouldn’t notice until I needed to put access the tower to plug in a usb, which might not be for weeks these days.

Re: O.mg Cable

#490

Earlier quoted context omitted.

I've been going to DefCon for many years and the hak5 merch booth is the first stop for all newcomers (myself included). Long lines and people handing over fists-full of cash.

I did my part and purchased something. :P Seems like they get a big chunk of their yearly revenue from Defcon sales. Makes sense as I bet a lot of hackers might just want to do an in person transaction and this is the perfect opportunity to do so.

Totally! Cash only, no CC trail or delivery address. I lived in Charlotte NC for a brief period and I bought some lock picks from a "spy outlet" store in a mall. They scanned my driver's license and said they needed to keep it on file for a year. This was ... 1992 maybe? Yikes today.
Post reply on HN