Judge: Stingrays Are 'Simply Too Powerful' Without Adequate Oversight (arstechnica.com)
New submitter managerialslime sends news that an Illinois judge has issued new requirements the government must meet before it can use cell-site simulators, a.k.a. "stingrays," to monitor the communications of suspected criminals. While it's likely to set precedent for pushing back against government surveillance powers, the ruling is specific to the Northern District of Illinois for now.
What is surprising is Judge Johnston’s order to compel government investigators to not only obtain a warrant (which he acknowledges they do in this case), but also to not use them when "an inordinate number of innocent third parties’ information will be collected," such as at a public sporting event. This first requirement runs counter to the FBI’s previous claim that it can warrantlessly use stingrays in public places, where no reasonable expectation of privacy is granted. Second, the judge requires that the government "immediately destroy" collateral data collection within 48 hours (and prove it to the court). Finally, Judge Johnston also notes: "Third, law enforcement officers are prohibited from using any data acquired beyond that necessary to determine the cell phone information of the target. A cell-site simulator is simply too powerful of a device to be used and the information captured by it too vast to allow its use without specific authorization from a fully informed court."
But in the end, these court orders and government actions do little. These organizations are almost clandestine in nature and are just going to do what they want. Props to GNAA.
Crikey!
they were adding much needed oversight on the Chevy Corvette Stingray!
Perhaps it was modded down because it has nothing to do with stingray use by police?
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
G'day mate!!!
Watch me harass this deadly black mamba with a stick!!
Brilliant!!!!
So the three-letter-agencies and the local yokels will have to just continue using parallel construction. Isn't it amazing how many detailed and accurate "anonymous tips" the police receive?
Wow, you have really lost your mind over this, it is lovely to see I am getting to you finally, you are starting to correct some of the issues, though you did still ignore much of my responses yet again. I guess I shouldn't expect too much from you.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Yeah, because Saudi Police won't use Stingrays - at all.
No siree.
Modded down because it's offtopic...
See subject & this (my ware's been verified safe by 1 of the best) http://slashdot.org/comments.p... & this (60++ reputable sources say it's safe too) http://slashdot.org/comments.p... + this (false positives filtering done by my sources for hosts data AND my program too vs. your "MITM" bullshit) http://slashdot.org/comments.p... & lastly this (your lies on AD+DNS I never once said - show us where I did scumbag & YOUR SCREWUPS ON ADMIN PRIVELEGE USE IN MY PROGRAM) http://slashdot.org/comments.p...
* You fucking worm...
(Why'd you run from those, hmmm?)
APK
P.S.=> I am going to annihilate you publicly for those you reprehensible piece of fucking lying malicious libelous trolling trash - & YES I EMAILED Mr. Steven Burn of MalwareBytes today to make a statement that he has indeed seen my code & checked it for safety prior to hosting AND RECOMMENDING IT you disgusting piece of fucking libeling lying trolling mentally damaged goods retarded assburgers crap... apk
APK is my hero,
That is easy, no.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Can anything be done by privacy-concious folks to mitigate being swept up in overzealous use of such devices? Is it possible to control which cell towers your phone communicates with? Maybe a whitelist type thing? Are there crowd sourced maps of 'good cell towers' and known stingray devices?
http://slashdot.org/comments.p...
Why do you keep asking me to repeat myself? Do you have short term memory loss?
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
I'm not the AC, but I'll bite.
Come at me bro.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
http://slashdot.org/comments.p...
Is reading too much to ask? You ask the question, read the freaking answer. Yes, you claimed that DNS wasn't needed by trying to say that it uses more resources to run than a hosts file.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
They truly are the party of death.
Is there any information a stingray can collect that the cellular carriers don't also collect?
The stingray just seems like an end-run around getting a court order to subpoena the information from the carriers.
Better yet, come meet me here - you know where I am!
* :)
APK
P.S.=> You little FUCK - I will put your ass out, GUARAN-fucking-TEED you little cocksucking libelling lying motherfucker mentally damaged good do nothing trolling piece of SHIT... apk
Instead of protecting rights, they need to start thinking about the children.
Is using conventional syntax, capitalization, and conversational tone too much for a venomous, lowlife wannabe-troll like you?
See subject & your lying words again motherfucker:
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Where'd I say it? Show us. I say AD needs internal DNS far back as 2007 http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there on OpenDNS free (I use it) + AD in my security guide.
APK
P.S.=> WTF? Where did I say I don't use DNS too? I do & detailed it for you AGAIN (my std. post on it vs. hosts) -> http://slashdot.org/comments.p... apk
See subject: Anytime you LIKE motherfucker, come on face to face with me and I will END your retarded motherfucking ass... where in Maryland are you pussy?
APK
P.S.=> You're a little piece of fucking shit that needs to get his jaw fucking broken... apk
Any government official who eavesdrops on the communications of US citizens should get the death penalty. No exceptions.
See subject everyone: Hello pussy!
APK
P.S.=> You're welcome to talk shit to my face too pussy... I'll hospitalize you in less than a minute... apk
Judge: Stingrays Are 'Simply Too Powerful' Without Adequate Oversight
The ghost of Steve Irwin agrees!
Someone who gets it!
Without getting stupidly extremist ("Death to eavesdroppers"? Really?!), our law enforcement and judicial systems have gotten off into the weeds and need to be reminded that the spirit of the Constitutional amendments that grant privacy are designed to limit personal exposure down to only what is needed to investigate specific crimes committed by specific individuals. The idea of casting a wide net and picking up everyone doing anything wrong will always be attractive and based on the faulty logic that our judicial system is perfect in discerning proof of offense from misleading and incomplete evidence. The Constitution, on the other hand, assumes the judicial system is imperfect and must be held to a high standard that assumes imperfection.
*** *** You're just jealous 'cause the voices talk to me... ***
I just see this as the same problem: Judges who do not understand technology making rulings on the subject. Sure, it's a good ruling for the privacy side. But it completely fails to understand that while one can choose where they are deployed geographically one cannot choose to deploy them in a way that will not collect inordinate amount of data on the innocent.
Kudos on the ruling, I'd rather see technology misunderstood in favor of privacy (for a change...) But it is still technology misunderstood.
So responding to the question three times is running away...I see...you are deranged aren't you?
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
This is something that as the CEO of a cell phone company you could fight against.
Why hasn't someone simply said "No, the phones we issue will not connect to anything short of a proper registered cell phone tower which WE own, stingrays will be ignored".
Or is that somethign that isn't technically possible? I'm sure there's a way. And I for one would be quite willing to be restricted to the coverage area of a specific network IF that also ensured that I was guaranteed to not be fooled by a stingray.
Alternatively, is there not some way to overload the stingray so that the data it collects is simply useless, or better the stingray device is destroyed?
Perhaps carriers should be forced, by law, to encrypt their traffic such that the police would necessarily be forced to ask for the keys to decrypt the calls from a specific phone?
*** *** You're just jealous 'cause the voices talk to me... ***
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Where'd I say it? Show us. I say AD needs internal DNS far back as 2007 http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there on OpenDNS free (I use it) + AD in my security guide.
* I even proved I use DNS http://slashdot.org/comments.p... albeit REMOTE DNS, not local (wastes too much power, cpu & RAM with all of its parts + has security issues galore)
So where do you get the IDEA I said it's not worth using DNS much less with AD which I easily proved you wrong on ABOVE & with data of me saying it LONG AGO...?
APK
P.S.=> Not your FUCKED UP REASONING (your brain isn't normal assburgers retard) but where DID I SAY THAT which is in quotes above? Show us & answer here scumbag motherfucker... apk
This is something that as the CEO of a cell phone company you could fight against.
If you wanted to be harrassed by TLAs for the rest of your life.
I have a phone that displays the difference between a secure call/data connection and an unsecure (unencrypted) one. It is an ancient Motorola RAZR V3. Now, correct me if I'm wrong, but in the case of more modern phones, this feature has been dropped. And I'd guess that this was at the request of law enforcement.
Have gnu, will travel.
Coren you say apk doesn't run dns so how can you it when he uses it? Where did he say he ran ad minus dns? It's all we want to know.
If I set up a Cell simulator I would be hunted down and arrested. Doesn't the FCC take a very dim vue of such activities?
"We don't use stingrays. Prove to us that we do. Neither ownership nor signing out a stingray constitutes proof. Should you be able to prove it we will issue an NSL and shut you down based upon National Security considerations. Also we have the President, Administration, CIA, NSA and Homeland Security on our side."
Problem solved!
Seriously. We're not talking about the CIA here. You want to build a Stingray? There are plans online. It's not hard. If I was a crook I'd say let 'em use one against me in the way you're suggesting. Without a court order it gets thrown out. If you want to stop worrying about the rest of the bad guys out there then go have a look at what Bernie Sanders is doing...
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
Just because some asshats will still break the law doesn't mean we should give up on enforcing it.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
I first thought 'Wow, a judge who gets it!' then said 'Wait a tic.... Illinois... Chicago... Corruption and Mobsters. Oh, I get it now.'
Does anyone else doubt that this is a self serving ruling intended to avoid 'collateral investigations' of local political/crime figures thanks to savvy abuse of the stingray on a warrant for some small fry who will be in a similiar area to a bigshot who can 'accidentally have his data intercepted'?
While I cheer for the aversion of a rights abuse for the rest of us, I have to wonder who this will really be benefitting in the short term.
This is regulation that I can agree with.
I expect my calls to be private even on the street.
Someone has to make an encryption app for the calls where you exchange keys in person and they are never on the network.
What the Koran says doesn't have nearly as much to do with what most Muslims believe as you seem to think it does.
The relationship is identical to that of Christianity with the Bible. They proffer the book as the authority for their beliefs, but selectively ignore passages they don't like, and liberally interpret (totally change the meaning of) everything else. This happens because the greater part of the believers have socially matured to the point where they can see the evil in a lot of what was written in their ancient scriptures, but they can't yet bring themselves to let go of them (mostly due to the fear of punishment in the afterlife if they do). So, they reinterpret in order to have it both ways.
If you went around saying "Christians hate their families! They hate their siblings and their husbands and their wives, because that is exactly what Jesus told them to do," everyone would recognize you for the idiot you are. Yes, the Bible says that, and no, Christians don't believe that. Same thing here, Yes, the Koran says Jihad is duty, and no, most Muslims don't believe that.
I expect my calls to be private even on the street.
Someone has to make an encryption app for the calls where you exchange keys in person and they are never on the network.
Expectation of privacy needs to be reviewed. Definitions of privacy should not be capricious.
There is privacy in a crowded noisy room.
There is privacy in the middle of an open field.
There is privacy in the home.
There is privacy in the bedroom (hotels have bedrooms).
There is privacy in a special RF shielded, sound deadening special room.
A conversation in a restaurant while on a date has privacy expectation.
There is privacy in the confessional of the catholic church.
To subject the population to privacy rules for NSA secret meetings
is folly.
Truth is stranger than fiction, but it is because Fiction is obliged to stick to possibilities; Truth isn't. Mark Twain.
It's a step in the right direction.
But there's a fundamental problem here.
If the FBI is claiming "that it can warrantlessly use stingrays in public places, where no reasonable expectation of privacy is granted", then it is violating the Bill of Rights.
There are many situations where an expectation of privacy can exist in a public place. For example, if one is hiking on public lands, one might step behind a tree to relieve oneself.
That is reasonable conduct.
An expectation of privacy certainly exists in that situation.
Yet one is on public lands, which are a public place by definition.
The conclusion follows: the FBI's position is invalid. An expectation of privacy can exist in a public place.
Reasonable conduct, in addition to a broad, strong right to privacy, are certainly fundamental rights "retained by the people" under the 9th Amendment, and "reserved to the people" under the 10th Amendment.
It follows that not only is the FBI's position invalid, but it is illegal. Any precedents to the contrary are themselves illegal.
A policy consistent with the Bill of Rights would require a highly specific warrant for any surveillance mechanism involving an artificial enhancement to the human sensory system. Whether or not one is in a public place is irrelevant. We don't want the FBI putting a cloud hidden cameras behind every tree on public lands, or anything equivalent to that.
Time for the government to stop treating the Bill of Rights like toilet paper.
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Where'd I say it? Show us (not your illogic logic but where I literally said that). I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there on OpenDNS free (I use it) + AD in my security guide.
Running from a simple question WHERE I said that specifically that you shoot your mouth off lying about it & me, hmmm?
(OR is it just your mentally damaged goods assburgers brain acting up again w/ illogic logic trying to put words in my mouth I never said? Yes...) ... And
Where did I say I don't use DNS too?
Clue: I do & detailed it for you AGAIN (via my std. post on DNS vs. hosts) -> http://slashdot.org/comments.p...
APK
P.S.=> Con't. in 2/6... apk
"figured out why privilege escalation's a bad thing?" - by Coren22 on Tuesday September 22, 2015
How else can I programmatically update hosts itself?
---
"it requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it!
Even MalwareBytes AntiMalware DEMANDS it or it can't do a job fully like many security tools!
---
"Needing admin privileges every time a program updates is poor design" - by Coren22 (1625475) on Tuesday November 10, 2015
Mine doesn't to get new data to update hosts vs. threats. Only hosts itself updates need it vs. WFP/SFP. Users set it too. It's not programmatic impersonation.
---
"90's tech to fight modern war" - by Coren22 (1625475) on Tuesday November 10, 2015
Ozymandias/Watchmen per a namesake:
"I resolved to apply antiquities teachings" (hosts) "to our world today & began my path to conquest - Conquest not of men but of the evils that beset them: Fossil Fuels (antispyware), Oil (antivir), Nuclear Power (addons) are like a drug & you gentlemen along w/ foreign interests are the pushers"
It works Aryeh Goretsky NOD32/ESET hosts = good security-> http://it.slashdot.org/comment...
Oliver Day (Symantec) too-> http://www.securityfocus.com/c...
MalwareBytes' hpHosts' Admin hosts + RECOMMENDS my APK Hosts File Engine 9.0++ SR-2 32/64-bit-> http://hosts-file.net/?s=Downl...
APK
P.S.=> Con't. in #3/6... apk
"I guess we should avoid your crap, it looks like it is marked as malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
62 reputable sources + /. users say different:
Safe by 57 antivirus programs in 64-bit model https://www.virustotal.com/en/...
+
the 32-bit model https://www.virustotal.com/en/...
&
Per VirScan (installer too)-> http://f.virscan.org/APKHostsF...
---
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl... & MalwareBytes = BEST antivirus per this VERY recent testing of them all http://www.av-test.org/en/news...
(& he certified my source http://slashdot.org/comments.p... - he wouldn't host it, much less recommend it, minus that...) /.'ers say my work is good too:
"his hosts program is actually pretty good" - by xenotransplant (4179011) on Monday August 10, 2015 @03:34PM (#50287195)
"I like your host file system." - by Karmashock (2415832) on Wednesday September 09, 2015 @03:57PM (#50489401)
"APK is kinda right... I've given up on JS based adblocking and gone to blackholing in /etc/hosts, just like it was back in the 90s. The computational load has gotten intolerable for any ad-blocking using JS. I've tried his hosts file generating software. It works." - by bmo (77928) on Thursday October 15, 2015 @11:30AM (#50736071)
"his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources" by alexgieg (948359) on Friday September 25, 2015 @09:57AM (#50596461)
"No complaints from me, I like APK's spam. Reminds me to use a host file. Also, his stuff is free." - by aaaaaaargh! (1150173) on Tuesday November 17, 2015 @09:31AM (#50947415)
APK
P.S.=> Con't in part #4/6... apk
"I guess we should avoid your crap, it looks like it is marked as malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
62 reputable sources + /. users say different:
Safe by 57 antivirus programs in 64-bit model https://www.virustotal.com/en/...
+
the 32-bit model https://www.virustotal.com/en/...
&
Per VirScan (installer too)-> http://f.virscan.org/APKHostsF...
---
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl... & MalwareBytes = BEST antivirus per this VERY recent testing of them all http://www.av-test.org/en/news...
(& he certified my source http://slashdot.org/comments.p... - he wouldn't host it, much less recommend it, minus that...) /.'ers say my work is good too:
"his hosts program is actually pretty good" - by xenotransplant (4179011) on Monday August 10, 2015 @03:34PM (#50287195)
"I like your host file system." - by Karmashock (2415832) on Wednesday September 09, 2015 @03:57PM (#50489401)
"APK is kinda right... I've given up on JS based adblocking and gone to blackholing in /etc/hosts, just like it was back in the 90s. The computational load has gotten intolerable for any ad-blocking using JS. I've tried his hosts file generating software. It works." - by bmo (77928) on Thursday October 15, 2015 @11:30AM (#50736071)
"his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources" by alexgieg (948359) on Friday September 25, 2015 @09:57AM (#50596461)
"No complaints from me, I like APK's spam. Reminds me to use a host file. Also, his stuff is free." - by aaaaaaargh! (1150173) on Tuesday November 17, 2015 @09:31AM (#50947415)
APK
P.S.=> Con't in part #4/6... apk
"His newest post is trying to refute that MiTM attack opportunity his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
I DISPROVED it: Only hardcoded favs users provide themselves are REVERSE DNS verified.
My program filters 5,500++ false positives:
1.) Search engines
2.) Antivirus (e.g. updaters)
3.) Security community sites
4.) Captchas, brower home pages + download pages
5.) Ebay/Amazon (shopper & banking)
(Security community I get hosts data from do false positives filters in current data + removal lists).
---
"won't demonstrate security of his product be exposing the source (someone might steal it!)" - by Coren22 (1625475) on Wednesday November 18, 2015
I don't give away work to be stolen OR misused like GOOGLE CHROME http://it.slashdot.org/story/1...
"the secretary at MalwareBytes took a look at his source code and said it looked all good to them" - by Coren22 (1625475) on Wednesday November 18, 2015
My ware went thru code verification by Mr. Steven Burn of Malwarebytes' hpHosts
http://slashdot.org/comments.p...
A competent coder & BEST security researcher I know of FROM THE BEST ANTIMALWARE THERE IS http://www.av-test.org/en/news...
NOT a secretary!
---
YOU BLEW IT ON ADMIN PRIV TOO: My program doesn't require it hosts does (WFP/SFP): my program protects hosts beyond it!
I.E.-> I run manually minus admin priv & drag result to hosts naming it "hosts" overwriting original.
Only auto update needs it (WFP/SFP) & users set it themselves in program shortcut: Not programmatic impersonation.
---
DNS introduces a SECURITY ISSUE RIDDLED SINGLE POINT OF FAILURE & doesn't secure down to endpoints on a LAN -> http://slashdot.org/comments.p...
How I use DNS-> http://slshdot.org/comments.pl... & what hosts overcome in DNS fails!
APK
P.S.=> Con't in part #5/6... apk
"Virus scanners/Adblock software don't need admin priv to update" - by Coren22 (1625475) on Tuesday November 10, 2015
Neither does my program. AV does to remove threats - Adblock addons = Vastly INFERIOR in abilities + efficiency vs. hosts as I proved & no one proved me wrong to date!
---
"your software does" - by Coren22 (1625475) on Tuesday November 10, 2015
No hosts do (WFP/SFP) - Intake update of new hosts data doesn't!
---
"won't reveal your source code" - by Coren22 (1625475) on Tuesday November 10, 2015
I don't owe you it. I don't give away work to be stolen OR misused like GOOGLE CHROME http://it.slashdot.org/story/1...
---
"What's stopping you from pointing my bank's web site at your private server?" - by Coren22 (1625475) on Tuesday November 10, 2015
I don't keep a server. Security guru (not - you create no ware for security & your forensics skills = non-existent): Put it in a VM, trace it via process monitor + wireshark (don't need code)!
---
"the possibility of being caught, which would be pretty hard to catch w/ such a large hosts file, as no one can go through it manually." - by Coren22 (1625475) on Tuesday November 10, 2015
I put hardcoded fav sites @ top of hosts for speed & reliabilty - spotted easily & bulk of hosts = sorted blocked known bad threats provided by the security community (filtered vs. 5,500++ false positive possibles in my program & by current security community data).
---
"What are you going to do when Windows gets rid of the hosts file completely?" - by Coren22 (1625475) on Tuesday November 10, 2015
Hasn't happened!
---
"They have already taken steps to make it useless in Windows 10." - by Coren22 (1625475) on Tuesday November 10, 2015
It works there!
Telemetry's killed 10 by itself: VISTA = Win10 = Win8 = flops - who're you fooling other than yourself?
APK
P.S.=> Con't. in #6/6... apk
Coren22 'eats his words' vs. me 2x yet again:
"introduces risk you are relying on a 3rd party to update a hosts file potentially opening you up to MITM attacks" - by Coren22 (1625475) on Tuesday November 17, 2015
How?
My prog only puts entries in as non-blocking to hostnames is ones users give it as favs to speed up @ TOP of hosts REVERSE DNS VERIFIED!
(For more speed, & reliability + security - in RAM as 1st resolver queried = faster & more secure vs. remote DNS w/ all its security issues in Kaminsky flaw, DNSChanger malware IP stack settings, routers bushwhacked in DNS settings, rogue DNS, Open DNS servers abused by malware. It aids in reliability vs. redirects).
YOU'D SPOT IT INSTANTLY @ TOP OF CUSTOM HOSTS & can easily edit anything you want out!
(Rest = known bad sites from 10 reputable security community sites for blocking - the MAJORITY of what's in my hosts files!)
+ my sources do removal lists vs. false positives & helped me create a "FP" filter in my program (5,500++ of them)!
---
"maybe one day you can get a score 5 comment" - by Coren22 (1625475) on Tuesday November 17, 2015
See subject & ~ 12 +5 upmods: "Eat your words" (1st one: You tried using what I post there against me to FAIL):
+5 'modded up' posts by "yours truly" (11):
http://news.slashdot.org/comme...
http://tech.slashdot.org/comme...
http://news.slashdot.org/comme...
http://science.slashdot.org/co...
http://tech.slashdot.org/comme...
http://hardware.slashdot.org/c...
http://news.slashdot.org/comme...
http://news.slashdot.org/comme...
http://hardware.slashdot.org/c...
http://yro.slashdot.org/commen...
http://yro.slashdot.org/commen...
"You believe you are getting the better of me" - by Coren22 (1625475) on Tuesday November 17, 2015
YOU GOT THE BEST OF YOURSELF in fails & lies about me. Your immature signatures about me SCREAM you're butthurt - Did it to yourself.
APK
P.S.=> You fail Coren22... apk
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Where'd I say it? Show us (not illogic logic but where I literally said it). I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there in my security guide.
Fact: You shoot your mouth off lying about it & me, hmmm?
(It's your mentally damaged goods assburgers brain acting up trying to put words in my mouth I never said? Yes...)
---
Where did I say I don't use DNS too?
Clue: I do & detailed it for you AGAIN (via my std. post on DNS vs. hosts) -> http://slashdot.org/comments.p...
---
"You must really suck at programming" - by Coren22 on Monday November 23, 2015
What've you programmed? Other /.'ers disagree:
"his hosts program is actually pretty good" - by xenotransplant (4179011) on Monday August 10, 2015 @03:34PM (#50287195)
"I like your host file system." - by Karmashock (2415832) on Wednesday September 09, 2015 @03:57PM (#50489401)
"APK is kinda right... I've given up on JS based adblocking and gone to blackholing in /etc/hosts, just like it was back in the 90s. The computational load has gotten intolerable for any ad-blocking using JS. I've tried his hosts file generating software. It works." - by bmo (77928) on Thursday October 15, 2015 @11:30AM (#50736071)
"his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources" by alexgieg (948359) on Friday September 25, 2015 @09:57AM (#50596461)
"No complaints from me, I like APK's spam. Reminds me to use a host file. Also, his stuff is free." - by aaaaaaargh! (1150173) on Tuesday November 17, 2015 @09:31AM (#50947415)
APK
P.S.=> Con't. in 2/6... apk
"figured out why privilege escalation's a bad thing?" - by Coren22 on Tuesday September 22, 2015
How else can I programmatically update hosts itself?
---
"it requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it!
Even MalwareBytes AntiMalware DEMANDS it or it can't do a job fully like many security tools!
---
"Needing admin privileges every time a program updates is poor design" - by Coren22 (1625475) on Tuesday November 10, 2015
Mine doesn't to get new data to update hosts vs. threats. Only hosts itself updates need it vs. WFP/SFP. Users set it too. It's not programmatic impersonation.
---
"90's tech to fight modern war" - by Coren22 (1625475) on Tuesday November 10, 2015
Ozymandias/Watchmen per a namesake:
"I resolved to apply antiquities teachings" (hosts) "to our world today & began my path to conquest - Conquest not of men but of the evils that beset them: Fossil Fuels (antispyware), Oil (antivir), Nuclear Power (addons) are like a drug & you gentlemen along w/ foreign interests are the pushers"
It works Aryeh Goretsky NOD32/ESET hosts = good security-> http://it.slashdot.org/comment...
Oliver Day (Symantec) too-> http://www.securityfocus.com/c...
MalwareBytes' hpHosts' Admin hosts + RECOMMENDS my APK Hosts File Engine 9.0++ SR-2 32/64-bit-> http://hosts-file.net/?s=Downl...
APK
P.S.=> Con't. in #3/6... apk
"I guess we should avoid your crap, it looks like it is marked as malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
62 reputable sources + /. users say different:
Safe by 57 antivirus programs in 64-bit model https://www.virustotal.com/en/...
+
the 32-bit model https://www.virustotal.com/en/...
&
Per VirScan (installer too)-> http://f.virscan.org/APKHostsF...
---
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl... & MalwareBytes = BEST antivirus per this VERY recent testing of them all http://www.av-test.org/en/news...
(& he certified my source http://slashdot.org/comments.p... - he wouldn't host it, much less recommend it, minus that...) /.'ers say my work is good too:
"his hosts program is actually pretty good" - by xenotransplant (4179011) on Monday August 10, 2015 @03:34PM (#50287195)
"I like your host file system." - by Karmashock (2415832) on Wednesday September 09, 2015 @03:57PM (#50489401)
"APK is kinda right... I've given up on JS based adblocking and gone to blackholing in /etc/hosts, just like it was back in the 90s. The computational load has gotten intolerable for any ad-blocking using JS. I've tried his hosts file generating software. It works." - by bmo (77928) on Thursday October 15, 2015 @11:30AM (#50736071)
"his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources" by alexgieg (948359) on Friday September 25, 2015 @09:57AM (#50596461)
"No complaints from me, I like APK's spam. Reminds me to use a host file. Also, his stuff is free." - by aaaaaaargh! (1150173) on Tuesday November 17, 2015 @09:31AM (#50947415)
APK
P.S.=> Con't in part #4/6... apk
"His newest post is trying to refute that MiTM attack opportunity his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
I DISPROVED it: Hardcoded favs users provide themselves are REVERSE DNS verified & my program filters 5,500++ false positives:
1.) Search engines
2.) Antivirus (e.g. updaters)
3.) Security community sites
4.) Captchas, brower home pages + download pages
5.) Ebay/Amazon (shopper & banking)
(Security community I get hosts data from do false positives filters in current data + removal lists).
---
"won't demonstrate security of his product be exposing the source (someone might steal it!)" - by Coren22 (1625475) on Wednesday November 18, 2015
I don't give away work to be stolen OR misused like GOOGLE CHROME http://it.slashdot.org/story/1...
"the secretary at MalwareBytes took a look at his source code and said it looked all good to them" - by Coren22 (1625475) on Wednesday November 18, 2015
My ware went thru code verification by Mr. Steven Burn of Malwarebytes' hpHosts
http://slashdot.org/comments.p...
A competent coder & BEST security researcher I know of FROM THE BEST ANTIMALWARE THERE IS http://www.av-test.org/en/news...
NOT a secretary!
---
YOU BLEW IT ON ADMIN PRIV TOO: My program doesn't require it hosts does (WFP/SFP): my program protects hosts beyond it!
I.E.-> I run manually minus admin priv & drag result to hosts naming it "hosts" overwriting original.
Only auto update needs it (WFP/SFP) & users set it themselves in program shortcut: Not programmatic impersonation.
---
DNS introduces a SECURITY ISSUE RIDDLED SINGLE POINT OF FAILURE & doesn't secure down to endpoints on a LAN -> http://slashdot.org/comments.p...
How I use remote filtering DNS combined w/ hosts is there showing many DNS security issues hosts overcome.
APK
P.S.=> Con't in part #5/6... apk
"Virus scanners/Adblock software don't need admin priv to update" - by Coren22 (1625475) on Tuesday November 10, 2015
Neither does my program. AV does to remove threats - Adblock addons = Vastly INFERIOR in abilities + efficiency vs. hosts as I proved & no one proved me wrong to date!
---
"your software does" - by Coren22 (1625475) on Tuesday November 10, 2015
No hosts do (WFP/SFP) - Intake update of new hosts data doesn't!
---
"won't reveal your source code" - by Coren22 (1625475) on Tuesday November 10, 2015
I don't owe you it. I don't give away work to be stolen OR misused like GOOGLE CHROME http://it.slashdot.org/story/1...
---
"What's stopping you from pointing my bank's web site at your private server?" - by Coren22 (1625475) on Tuesday November 10, 2015
I don't keep a server. Security guru (not - you create no ware for security & your forensics skills = non-existent): Put it in a VM, trace it via process monitor + wireshark (don't need code)!
---
"the possibility of being caught, which would be pretty hard to catch w/ such a large hosts file, as no one can go through it manually." - by Coren22 (1625475) on Tuesday November 10, 2015
I put hardcoded fav sites @ top of hosts for speed & reliabilty - spotted easily & bulk of hosts = sorted blocked known bad threats provided by the security community (filtered vs. 5,500++ false positive possibles in my program & by current security community data).
---
"What are you going to do when Windows gets rid of the hosts file completely?" - by Coren22 (1625475) on Tuesday November 10, 2015
Hasn't happened!
---
"They have already taken steps to make it useless in Windows 10." - by Coren22 (1625475) on Tuesday November 10, 2015
It works there!
Telemetry's killed 10 by itself: VISTA = Win10 = Win8 = flops - who're you fooling other than yourself?
APK
P.S.=> Con't. in #6/6... apk
Coren22 'eats his words' vs. me 2x yet again:
"introduces risk you are relying on a 3rd party to update a hosts file potentially opening you up to MITM attacks" - by Coren22 (1625475) on Tuesday November 17, 2015
How? My prog puts entries in as non-blocking to hostnames on ones users give it as favs to speed up @ TOP of hosts REVERSE DNS VERIFIED!
(For more speed, & reliability + security - in RAM as 1st resolver queried = faster & more secure vs. remote DNS w/ all its security issues in Kaminsky flaw, DNSChanger malware IP stack settings, routers bushwhacked in DNS settings, rogue DNS, Open DNS servers abused by malware. It aids in reliability vs. redirects).
YOU'D SPOT IT INSTANTLY @ TOP OF CUSTOM HOSTS & can easily edit anything you want out!
(Rest = known bad sites from 10 reputable security community sites for blocking - the MAJORITY of what's in my hosts files!)
+ my sources do removal lists vs. false positives & helped me create a "FP" filter in my program (5,500++ of them)!
---
"maybe one day you can get a score 5 comment" - by Coren22 (1625475) on Tuesday November 17, 2015
See subject & ~ 12 +5 upmods: "Eat your words" (1st one: You tried using what I post there against me to FAIL):
+5 'modded up' posts by "yours truly" (11):
http://news.slashdot.org/comme...
http://tech.slashdot.org/comme...
http://news.slashdot.org/comme...
http://science.slashdot.org/co...
http://tech.slashdot.org/comme...
http://hardware.slashdot.org/c...
http://news.slashdot.org/comme...
http://news.slashdot.org/comme...
http://hardware.slashdot.org/c...
http://yro.slashdot.org/commen...
http://yro.slashdot.org/commen...
"You believe you are getting the better of me" - by Coren22 (1625475) on Tuesday November 17, 2015
YOU GOT THE BEST OF YOURSELF in fails & lies about me. Your immature signatures about me SCREAM you're butthurt - Did it to yourself.
APK
P.S.=> You fail Coren22... apk