besselheim | 9 years ago | on: Virtual machine escape fetches $100k at Pwn2Own hacking contest
besselheim's comments
besselheim | 9 years ago | on: Windows 10 is bringing ads to File Explorer – how to turn them off
besselheim | 9 years ago | on: Virtual machine escape fetches $100k at Pwn2Own hacking contest
Of relevance to Edge exploitation, Microsoft are currently working on a Qubes-like sandboxing model for Edge, based on Hyper-V (though it looks like it'll be aimed towards enterprise customers rather than consumer): https://blogs.windows.com/msedgedev/2016/09/27/application-g.... Will be interesting to see if that's part of the challenge in Pwn2Own 2018. Somewhat surprisingly, Hyper-V wasn't successfully exploited at this year's contest.
besselheim | 9 years ago | on: Multihash – self-describing hashes
besselheim | 9 years ago | on: Bash and Windows Subsystem for Linux Demo [video]
Regarding future work, are there any plans to make the emulated Linux filesystem usable in the rest of Windows e.g. via a drive mapping?
besselheim | 9 years ago | on: NSA contractor indicted over mammoth theft of classified data
Positive news that they caught him anyway, another Snowden-like espionage drama would be highly undesirable.
besselheim | 9 years ago | on: Was Snowden a Russian Agent?
The popular narrative of Snowden's actions and motivations doesn't add up when you look at all the available evidence.
It's quite reasonable for people to suspiciously probe the mythos built up around him.
besselheim | 9 years ago | on: Ask HN: Online Security Tips for Newbie Freedom Activists?
besselheim | 9 years ago | on: Dutch secret service tries to recruit Tor-admin
HN already has something of a negative bias towards the work of the various security services (that is, the mood is largely pro-Snowden and anti-NSA) - having a better balance of views may well be a positive effect.
Similarly for the pro-capitalist bias here, and what almost amounts to a religious veneration for VCs and the very wealthy. Then again, HN is a bit of a chimera in the topics it covers. So we do have some diversity of interests and opinions.
besselheim | 9 years ago | on: Dutch secret service tries to recruit Tor-admin
besselheim | 9 years ago | on: Dutch secret service tries to recruit Tor-admin
besselheim | 9 years ago | on: Stanford historian uncovers a grim correlation between violence and inequality
The filthy rich do enjoy this ego-feeding narrative that it was all just talent and hard work that gave them a disproportionate slice of the world's wealth, but it's not borne out by the facts.
besselheim | 9 years ago | on: Dutch secret service tries to recruit Tor-admin
besselheim | 9 years ago | on: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
besselheim | 9 years ago | on: There is no WhatsApp 'backdoor'
besselheim | 9 years ago | on: TINY: VNC for DOS
Unfortunately the DOS program it was being used to remote was highly picky on the hardware being used, and would refuse to communicate with the PLC if the PC was too new. Due to the harsh environment of the plant, we'd go through two or three computers per year. So there was a lot of digging around for old hardware until we realised it would run reliably in DOSBox with a suitable CPU speed set.
After that, our use case for TINY was no more, and we just used a VNC server for Windows. Saved a great deal of site to site travel and plant downtime while it was set up though.
besselheim | 9 years ago | on: Why HTTPS for Everything?
besselheim | 9 years ago | on: Why HTTPS for Everything?
besselheim | 9 years ago | on: Intel Committee Releases Declassified Snowden Report
The damage to signals intelligence capabilities, through the leaking of classified documents, was deliberately and maliciously done through the actions of Snowden himself, most likely in response to a bruised ego.
In contrast, the engineers involved in the Challenger shuttle did their very best to try to avert disaster - albeit to no avail - through their selfless adherence to professional ethics and engineering safety concerns.
The two scenarios couldn't be more different really.
besselheim | 9 years ago | on: Intel Committee Releases Declassified Snowden Report
> Snowden would later publicly claim that his "breaking point" - the final impetus for his unauthorised downloads and disclosures of troves of classified material - was March 2013 congressional testimony by Director of National Intelligence James Clapper.
> But only a few weeks after his conflict with NSA managers, on July 12, 2012 - eight months before Director Clapper's testimony - Snowden began the unauthorized, mass downloading of information from NSA networks.
Given that Snowden claimed his motivation was seeing Clapper "lie on oath", there's some irony in seeing Snowden caught in a lie about this claim, as at that point not only had he already downloaded and exfiltrated much of what he later leaked, but had already been in contact with Greenwald and Poitras for two to three months.