Hacker News new | past | comments | ask | show | jobs | submit | more bluetooth's comments login

If GhostMail was compromised, the attacker would be able to read messages as they are being sent. Sending messages as images does not stop them from being copied or held for an indefinite amount of time.


In the unlikely scenario that the app was compromised and stayed compromised, you would be correct. However, if it was compromised and the situation was quickly rectified, only sent but unread messages would be able to be read. If a service like WhatsApp was compromised, however, a much larger amount of messages would be able to be read.


Here's a similar project based on another similar project that's been around for quite some time: http://penturalabs.wordpress.com/2013/04/25/blue-for-the-pin...

Original project: http://hakshop.myshopify.com/products/wifi-pineapple


How did you test for YAML injection? From my past experiences with Ruby (hardly any) YAML injection is difficult to test from a blackbox perspective as you need an understanding of the source code in order to be able to craft the appropriate serialized YAML object to yield code execution.


Couple of methods. For one thing, we test for status codes returned for particularly crafted YAML/XML parameters. Aside from that, we also carefully craft a YAML injection using a timing attack and test blind, that way.


It might also be because this link has been posted at least two times recently:

https://news.ycombinator.com/item?id=5796935

https://news.ycombinator.com/item?id=5807149


Two issues I can see arising from this:

1. You're funding someone who the government most likely has labelled a terrorist. I don't think the government will take too kindly to such a thing.

2. Snowden is in hiding. Not only might it be hard to come into contact with him, but how can we be sure our money will reach him?

I think #1 is not too difficult to solve via ways of bitcoin, but #2 is still a blocker.


Regarding #1:

Why should the government have a say on this at all? The person is doing a favor for the citizens of the whole world which happens to backfire for the government which has things to hide. Just the sole fact that government might be pissed about something transparency advocating like this should be enough of a reason to support it.

It's the government which should be afraid of the people and not the people who should be afraid of the government!


Maybe you're forgetting, but this is the real world. Ideally, the government should be afraid of its people, but the US is in a far from ideal situation right now.


Which is exactly the reason why people should realize that whatever was done by Snowden is good for them. Because what Snowden did is good for them and if the government opposes it in any way then government opposes what is good for the people. Government is the enemy of the people. People should go against their government.

(Besides, I said should be rather than is. :)


You're funding someone who the government most likely has labelled a terrorist

huh? how do you get 'terrorist' from revealing secret information?


Is this serious? This "news" website is making an outlandish claim, yet cites not a single source.

> "The White House can’t order all 20 million of its employees around. Someone will always talk to us, and help us understand the truth behind these troubling, but somewhat ambiguous conversations and other communications. All your PRISM are belong to us, and it’s going to be this way for as long as something like PRISM exists."

Where did this quote come from? Who are they quoting? There is just so much wrong with this article.

Edit: The more I browse, the more this site seems like a less funny version of The Onion. Here are some choice articles chronicle.su has published in the past:

    Stephen Hawking joins Illuminati, snubs Israel
    Amanda Bynes dead at 27, inventor of ‘lol’ signs off [she is still alive]
    Margaret Thatcher, Illuminati leader, dead at 87
    Fascist Zune Conspiracy Exposed


It's almost as if he's speaking to a cult. Might as well have said something along the lines of "Obama is the savior of the US. Let him into your heart and soul and you will know it to be true. Go forth and vote!"


Wait.. are you being sarcastic or you really don't realize that Obama was making a joke when he said that? I remember when he said it and certain media outlets sort of went crazy - but the audience just laughed.


He's making the same joke for years now. Not everybody thinks it's still funny though.


> if government does nothing and we get attacked people will complain

Who says this? Do you honestly think warrantless wiretaps are a valid form of defense?


I saw a comment last week on HN that mentioned how incompetent and generally stupid FBI agents are, and cited as evidence failure to prevent the Boston marathon bombing.


People are blame crazy these days, they have to find someone at fault. Every single thing that happens recently from a Tornado to a bombing has 24 hour media asking who to blame.


For some reason, comments on HN appear with seemingly random font sizes when viewed on mobile. I've seen it on both android and iOS.


+1 i see the same behavior on my android, but don't see the issue on the desktop !


I always thought it was due to a comment being of less than a certain number of characters, as a way of diminishing throwaway comments that may generally not add much to a debate. I guess not?


Got a source? That sounds so incredible I almost want it to be true.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: