Hacker Newsnew | past | comments | ask | show | jobs | submit | spaghetti-guy's commentslogin

You can view the history (with the line numbers) by typing 'history'. If you have the following set, you can avoid any command prefixed with a space ever getting in this list. HISTCONTROL=ignorespace

I have trained myself, over many years, to hit space automatically before I type rm/reboot/shutdown etc. It's occasionally inconvenient if I need to rerun something but does mean I can't fat-finger anything destructive!


According to the Google support site, all Pixels are encrypted by default. So, this shouldn't even be possible...unless perhaps there was no lock code on the device?


Google has the keys to the kingdom.


Do you have a source for that? I didn't think the phone's encryption key or password was backed up to Google. The help pages say that if you forgot your PIN, you should reset your phone.[1][2]

Of course Drive and Photos files are in Google servers and aren't E2E encrypted, but I don't think that's what you're talking about.

Full disclosure I work at Google but on nothing related to this.

[1] https://support.google.com/android/answer/7663172?hl=en

[2] https://www.techlicious.com/tip/what-to-do-if-you-forget-you...


Maybe, but they don’t give them for average repairman.


No they don't. The encryption keys are stored on the Titan M. It has tamper protection.

The Twitter user most likely has an easy to guess password.


If a tech tries a random 4 digit passphrase on every device they work on, they are bound to get it right occasionally.


If something common/unimaginative like 4444 or 1111, I bet it would be something like 1 in 10.


Pattern unlock. Incredibly insecure.


I think out in the real world they are insecure because it's easy to shoulder-surf and get a peek at the pattern being input. Overall they are probably similar to pin codes... some people just have 0000 as their pins, or draw an L for a pattern.

Sending a phone in for repair negates the shoulder-surf issue but yeah.

Perhaps Google just has a backdoor.


I think it's easy to guess patterns because people all use one of a small number of simple patterns. Everyone uses the geometrical equivalent of hunter2 or 123456, but they irrationally think it's more secure because it's a pattern.


Why?


1. Easy to view & remember. 2. The oil smear is visible in reflected light, and that pattern is not quickly overwritten by using the device. 3. Typical gesture patterns mean gestures start from similar positions (high) and are frequently unoriginal. 4. Gestures are simpler than the equivalent code (e.g. the passcodes 1397 and 1235987 are gesturally identical) 5. In practice the reality of finger sizes mean that join-the-dots encourages users to draw a gesture using only adjacent dots (e.g. connecting dot 1 to 2, 4 or 5, rather than 1 to 6 or 8.)


probably because there are a few "popular" patterns that many people use.


Had a similar issue with CloudTrail logs. These are delivered to your S3 bucket but the objects are owned by AWS's 'CloudTrail account'. This means you can't drop the logs into your security account and then query them with Athena from another account. Took ages to figure that out.


I'm doing/fixing the same thing with the Cost Usage Reports.

It feels like a common pattern to consolidate your logs into a single account for analysis, I wish they made it more straightforward to setup.


We haven't really dug in to analyzing those outside of cost explorer yet but that makes sense.

One workaround I've heard of is S3 replication. I've not tried it yet but apparently the replica has the 'correct' ownership.


Isn’t that one part of what control tower does now?


yep. control tower creates centralized logging, scp rules and more. what used to take a dev a couple weeks to set up can now be done with a few clicks


What you are talking about is 'load bank'. It's basically a massive hair dryer. Many data centres have these on the roof for exactly this purpose.


Signed up to pose two questions :-

1/ I legitimately do not know a lot of my usernames and passwords. I sign up with a unique email that includes the name of the site (I'm not particularly religious about the format of this and usually end up checking previous email to figure it out). Passwords are saved in Chrome and I mostly don't remember them. I'm sure I am not unique. Where would one stand with this scenario?

2/ Wherever I can, I use a U2F device as a second factor. Could one be compelled to provide this along with the passwords (providing I can remember them)? Where would one stand if the key was unavailable - i.e. lost/left at home? Assuming they have a PC nearby for checking your social media accounts, I'd very much doubt it had it's USB ports enabled so, even if I did provide it, I would suggest they probably couldn't use it. Is there any documented precedent for how this is handled?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: