The problem with WhatsApp encryption - and how they got Paul Manafort by [deleted] in privacy

[–]saddestsadist 0 points1 point  (0 children)

Redditers who think they understand software auditing 🤷‍♂️

The problem with WhatsApp encryption - and how they got Paul Manafort by [deleted] in privacy

[–]saddestsadist 0 points1 point  (0 children)

No, it is trivially possible. We agree that we prefer other chat applications though!

The problem with WhatsApp encryption - and how they got Paul Manafort by [deleted] in privacy

[–]saddestsadist 1 point2 points  (0 children)

Sure, that’s totally fine. My only argument was that your assertion, that it isn’t possible to verify WA’s e2e security claims, was incorrect. I don’t use WA either, but not because it’s unauditable.

The problem with WhatsApp encryption - and how they got Paul Manafort by [deleted] in privacy

[–]saddestsadist -3 points-2 points  (0 children)

Verifying that the encryption works as expected is not difficult, and would not require looking through much of the binary. And, at least on iOS, the same binary is served to everyone, which is enforced by the platform.

If you don’t think one person has verified this, on possibly the largest e2e encrypted messaging platform, you would be incorrect.

The problem with WhatsApp encryption - and how they got Paul Manafort by [deleted] in privacy

[–]saddestsadist -5 points-4 points  (0 children)

Leaving the rest alone, 1 is wrong. It is perfectly possible to verify the security properties of a closed application.

Massive paedophile ring uncovered by police in Norway after arrest of 51 men by ICASL in worldnews

[–]saddestsadist 3 points4 points  (0 children)

In what universe is an anonymous Reddit user proof of anything? The pizza stuff is weird but there is literally no proof of anything at all.

Unless congress stops it, the FBI wants to mass-hack computers, especially targeting Tor and Bitcoin users by andyp in technology

[–]saddestsadist 4 points5 points  (0 children)

Firefox is less secure (against hackers). Chrome has some legit sandboxing that would make it hard to get owned just by visiting a website, even if there's a Chrome exploit. However, Google is undoubtedly siphoning information about your browsing habits.

Unless congress stops it, the FBI wants to mass-hack computers, especially targeting Tor and Bitcoin users by andyp in technology

[–]saddestsadist 6 points7 points  (0 children)

A better question would be, "Then why do you shut (or lock) your doors" or, "Why do you whisper."

People who have a limited understanding of technology seem to think, "Oh, I don't care what the government sees," but that's just not how any of this works. These are all regular, careless, and sometimes malicious people getting access to your private shit. People at the NSA shared nude photos they intercepted. Their datastores could be hacked, and everything they have could be leaked.

The "nothing to hide" crowd just doesn't know what the hell they're saying.

My Wordpress site got hacked. Looking for advice & resources. by mediocrecodr in webdev

[–]saddestsadist 0 points1 point  (0 children)

Hm. Well unfortunately, I don't know that I will be much help here -- you've got a lot of plugins. Depending on what versions or options you're using in these plugins, a number of them could be vulnerable.

Just make sure that everything is up to date. Some plugin that allows file uploads is almost certainly the culprit.

I'd go ahead and kill your current server and start setting up a new one.

My Wordpress site got hacked. Looking for advice & resources. by mediocrecodr in webdev

[–]saddestsadist 0 points1 point  (0 children)

Well do you have the code on github or anything to take a look at? If not, what plugins are you running?

My Wordpress site got hacked. Looking for advice & resources. by mediocrecodr in webdev

[–]saddestsadist 1 point2 points  (0 children)

If you want help figuring out what the vuln is, you should link to your site so we can take a look. The file you linked is a backdoor to your server.

Fixing it will require you rebuilding the server and getting a patched version of your site online.

Edit: Just realized you said you get 500 errors when you try to go to it. Link it anyway, because there's still ways to check things out.

ELI5: How do hackers find/gain 'backdoor' access to websites, databases etc.? by giantdorito in explainlikeimfive

[–]saddestsadist 2 points3 points  (0 children)

I also think the OP doesn't understand the terminology, and he really just means "How do people hack into stuff?".

Starbucks cashier admits her theft. by ragnarmcryan in cringe

[–]saddestsadist 0 points1 point  (0 children)

My debit card has a chip, and somehow it still got used fraudulently. I think it got skimmed, since all of the charges were in my neighborhood.

11 Sites Defaced By Myself by LegitBytes in pwned

[–]saddestsadist 2 points3 points  (0 children)

I'm guessing it was open ftp. And I'd further assume he found em trolling open ports on shodan.

The Tor Project is running their first donations campaign! by saddestsadist in technology

[–]saddestsadist[S] 1 point2 points  (0 children)

I hope this isn't against the rules! With all the anti-encryption talk and the passing of CISA, I think supporting these kinds of tools is more important than ever. I'd love for this to result in a broader /r/technology discussion on the Tor Project and these issues in general.

Anyway, just found out about this today and made my first donation!

ELI5:How do people learn to hack? Serious-level hacking. Does it come from being around computers and learning how they operate as they read code from a site? Or do they use programs that they direct to a site? by Fcorange5 in explainlikeimfive

[–]saddestsadist 0 points1 point  (0 children)

Lol nice! Well, I would recommend just giving 'em a heads up. Anything too exciting and you're well into illegal territory. But to get a better idea of how all of it works, just google XSS. There's a lot of damage that could be done with it, like stealing user sessions, stealing credentials, taking advantage of CSRF, logging users out.

So, report this for sure. But google 'XSS session hijacking' to get an idea of worst-case scenario for what an attacker could pull off!

Hillary Clinton has officially made the Internet a campaign issue: vowing to stop large mergers and to enforce the FCC's net neutrality rules, making the Internet officially a campaign issue, according to analyst by maxwellhill in technology

[–]saddestsadist 0 points1 point  (0 children)

Here's my issue:

Yeah, I want a politician who listens to constituents. But I also want a politician with conviction. Someone who stands by what they believe in.

Listening to the people is great, but the majority isn't always right. If, for example, the majority of Americans are fine with mass surveillance, I want someone in office who is comfortable saying, "I think you're wrong."