Hacker Newsnew | past | comments | ask | show | jobs | submit | evilDagmar's commentslogin

A judge would never sign off on a warrant for the kind of searches Flock facilitates. Similar opinions involving cell phones have been rejected by the courts multiple times. Folks desperately trying to workshop some line of reasoning by which everyone should apparently be okay with an Orwellian panopticon is pretty annoying.


Let's not. There's enough overcomplicated nonsense examples of cybersecurity in movies as it is. If you could compromise a device via bluetooth, then you could exfiltrate data via bluetooth just as easily.


It's not completely unrealistic angle, you could pwn the speaker when someone is traveling with it in public and then exfiltrate data when it's plugged in a secure environment and you can't connect anymore


you could but I think the inclusion of lasers would make for a better spy / cyberpunk movie. Most "hacking" in movies are not realistic and for show but it being plausible is just a bonus.


It's not inconceivable to suggest that the people claiming that the CSAM hadn't been removed knew it was still there not only because they'd never actually sent the request for removal, but because they themselves put up the original site and requested the CSAM be indexed in the first place.


"The Feeling of Power" IIRC.


It's amusing how the article says it's "potentially" in violations of US hacking laws.

That practice is _definitely_ a violation of the Computer Fraud and Abuse Act. No employer's IT is going to have it not be a violation for a user to share their password with someone else, which even in the weakest boilerplate immediately revokes their rights to the account. At that point _any_ use of those credentials is very much a violation of the CFAA.


Was Plaid violating CFAA?


I hope so. Asking for your bank account's login is an absurd requirement and breaks all the lessons we work so hard to teach people.


Twitter invented OAuth around 2010 since people were typing their credentials into third-party clients.


IT's policy is more for unauthorized credential sharing to a third party that is not legally acting as a designated data transfer agent. what argyle is doing is legal and fine.


Oh, one of my absolute favorite things is setting ServerTokens ProductOnly, so that scrubs will freak right out when they see their canned vuln scanner get bug-eyed and basically scream that the server might be vulnerable to every possible exploit ever written.


Oh that app did a huge thing just by showing how far the administration is willing to go with its delusional fascist nonsense. The app was _barely_ functional and available on a minority of the smart phones, and yet there the White House was, making hyperbolic claims on a regular basis about the massive "dangers" it posed. They even went so far as to go after the guy's wife since they didn't have any legal means to oppose him.

Things which take minimal effort but produce a massive response are what Trump's fire hose of duplicitous social media posts are all about. It's perfectly fine work to leverage that same asymmetry in response.


Yes, and the fact they responded so strongly shows the app IS definitely effective, and not mere "theater" as the author wants to claim (it may not be as effective as it could be, it might be many things, but it is definitely well above "...sound and fury, signifying nothing").


The "disclosure" was a big waste of time. It was vague and ill-informed, nothing that came after seems to give the impression that they actually knew what they were talking about.

The only serious vulnerability that might have applied would have required the man to be using Apache as a reverse proxy to another server, which is just _extremely unlikely_ considering where it was hosted and what it was being used to do.


Truth. A stripped down configuration of that running nothing but personally-written code on the backend would pretty much render those issues moot (as in "completely mitigated").

Considering how lacking in detail the reports were, I'd probably have just dismissed this man's claims as "AI slop". That he was relying on nmap to tell him the version of something that is easily discovered using openssl s_client (because those HTTP response headers are perfectly human-readable) is kind of telling in and of itself.


They're getting that rate because of the reduced cost to support their connection to the grid per kWh. It's essentially the cost of the "packaging". If this is resulting in a loss of revenue for the utility, the blame for that falls on the utility for not properly measuring costs.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: