Hacker Newsnew | past | comments | ask | show | jobs | submit | vxxzy's commentslogin

Had to read through all the cruft to get:

"If the network is properly secured—meaning it’s protected by a strong password that’s known only to authorized users—AirSnitch may not be of much value to an attacker."


IIUC the issue is, you could have a "secure" network and a guest network sharing an AP, and that guest network can access clients on the secure network. Someone did mention the xfinity automatic guest network, which might be a pain to disable?

This is likely not a big deal for your home network, if you only have one network, but for many enterprise setups probably much worse.


A feature! Not a bug! Bugs can be undisovered features.


I am going to use this story in place of the "Pot Roast Principle" [0]

[0]: https://www.psychologytoday.com/us/blog/thinking-makes-it-so...


i will now no longer press F3 or / instead i will read.


I don’t recall where, but for some reason I remember learning that if people start to bump into you too many times, that’s a warning shot to get out. It was something like “bumps per second”.


he probably meant: syncing your files across devices should be a feature not a product. a feature of the os (icloud).


Anyone wanting to get a feel for unintended uses of a product should go look at google map reviews of locations in India. It is fascinating and ingenious.


Howso? I took a peek around New Delhi and didn’t notice anything


Go out into more rural areas.


Have this in Maryland. Local sheriff’s office won’t accept it. Bars and Restaurants won’t accept it either. Is this common in other states?


oh wow. I have become fond of pidgin over the years. There is a slack plugin that makes life a lot better. It seems for plugins, extensions, app stores, and general third-party repositories (pip, npm, crates, etc) risks are increasing. Centralization breeds certain risks that are tough to mitigate. So far, mitigating these risks involve trusting a central steward, cryptographic signing, and contributor reputation.I wonder if we can ever truly mitigate the contributor or steward aspects?


Maybe it will have FIDO2/U2F support? There is a use-case here maybe? I’ll stop giving ideas now…


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: