Hacker Newsnew | past | comments | ask | show | jobs | submit | ergot's commentslogin

There's a fairly comprehensive list here:

https://github.com/sbilly/awesome-security


Facebook is testing a feature that alerts you if someone is impersonating your account: http://mashable.com/2016/03/22/facebook-impersonation-alert/


I'm going to pay with tumbled Bitcoins since there's no zCash, or Monero option


Worth listening to Jake Appelbaum's 'digital anti repression workshop' [1]. In this he explains why he takes the hard-drive out of his laptop and just uses a TailsOS thumb-drive for his computing. It would be actually hilarious when staff ask to peruse the contents of your computer for contraband, only to discover the laptop doesn't have a hard-drive.

[1]: part 1 https://www.youtube.com/watch?v=HHoJ9pQ0cn8

[#]: part 2 https://www.youtube.com/watch?v=s9fByRmAHgU


[flagged]


Quite apart from all the drama surrounding him, I just wanted to share one of his many informative talks.

(I was wondering why it got downvoted and thanks for clarifying)


No problem m8.


Please refrain from certain political posts here when the person you're responding to merely linked videos to technical ways of defending yourself.


[flagged]



He deserved it.


Thanks for posting that.

Sorry for posting the wrong link to this :(


For those wondering how to create your own custom Tor onion adress, look no further than: https://timtaubert.de/blog/2014/11/using-the-webcrypto-api-t...

And for those who think Protonmail are the only service with a custom address, think again, because Facebook has one too: https://facebookcorewwwi.onion/

You can find a tonne more at this list:

https://github.com/chris-barry/darkweb-everywhere/tree/maste...

And staying on topic, Mailpile has their own .onion

https://raw.githubusercontent.com/chris-barry/darkweb-everyw...


For those wondering how to generate vanity Tor onion addresses in a more efficient manner (taking advantage of your GPU): https://github.com/lachesis/scallion


Too bad you have to do it yourself, we can't have a service doing that in the cloud.


Maybe doing that in the cloud would compromise the security of your vanity address. You would not own the private key. Your cloud provider could control your domain.

(Please correct me if I am wrong…)


Correct.

Vanity addresses are popular in bitcoin, but difficulty rises exponentially with each character. Most people don't want crunch random numbers for 6 months. The solution to 3rd party key generation is split keys.

Essentially the addition of keys to get the desired final key.

Generate key X, give X public address to cloud provider, they search for key Y so that X + Y == YourVanityAddress, when found they send you private Y. Private X + Y is your vanity private key.

Vanity address generated by 3rd party in a trustless environment.


I was not aware of that technique, thanks.


Yeah, that's the reason.


Finding an arbitrary 8 character onion with scallion is easy even on a video card from 2009 (ATI 5770). You don't need fancy hardware for this.

That said you could use an Amazon GPU instance for a handful of cents an hour and run scallion there.


>And for those who think Protonmail are the only service with a custom address, think again, because Facebook has one too

facebook, scryptmail, one bitcoin exchange, one bitcoin walled, dozes on blogs and chans, there is GoG instance in Tor as well as GitLab.


For those curious to see a vanity finder written in Go: https://github.com/wybiral/onions


Why does Facebook have a tor address?


So that you can access Facebook without leaving tor through an exit node.


I guess I don't see the point of using Tor with Facebook. So much of your identity is already tracked. It's like trying to sneak up on somebody while wearing those squeaky clown shoes.


The idea is not to hide from Facebook, the idea is to not unhide for Facebook.



And to enable state surveillance.

When you have a very small subset of users who will go through the trouble of trying out Facebook's onion address, it is much easier to be successful with surveillance tools on that small sample.


Not for the Egyptian government.


No, mainly for Five Eyes and friends


That's the point. It makes you more vulnerable for some threats, less vulnerable for others.


Because not everyone uses their real name on Facebook, especially in a Middle Eastern country, I would imagine. And Facebook isn't just for your family and real friends anymore (and hasn't been for years).


so Facebook can spy on users from China too!


Vanity Onion addresses are a bad idea. They teach users to ignore part of the address instead of treating the whole address like an IP address.

The GNU Name System gets this sort of thing correct though.


> Vanity Onion addresses are a bad idea. They teach users to ignore part of the address instead of treating the whole address like an IP address.

This assumes that users aren't ignoring the address anyway. There is a near 100% success rate in tricking users into visiting fake URLs in laboratory conditions. While trying to explain my research to a tenured professor, she literally typed each domain I was spelling out into Firefox's search box instead of punching it in manually.


I do yoga for my back and ensure there's good lumbar support on any chair I sit on. They say sitting is the 'new cancer' and prevention is often the way to go. Here's an interesting article on some yoga exercises you can try for back pain: http://www.buzzle.com/articles/yoga-exercises-for-back-pain....


> Maybe even subsidising their offering

Yeah there's a few VPNs that look shady because of their pricing. One that springs to mind is LeafVPN[1]. For $5.00 you get to send all your traffic to Mallory. And it even has `LEA` as the first three letters, so you're safe! This is not an endorsement of this service BTW.

[1]: https://leafvpn.com


any of this services are safe to use http://vpntrends.com/best-vpn-services/ ? Not that i do anything illegal but don't want to send my information directly to the government.


Brilliant list. I always wondered how many commercial VPN providers use code from these. I suspect setting up the VPN is easy enough, but coding the billing backend might be trickier.


Unless it affects them directly, just like how tobacco smokers don't see any immediate bad effects from smoking. But they know somewhere down the line something awful will happen.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: