Readit News logoReadit News
graystevens commented on Ask HN: Could you share your personal blog here?    · Posted by u/revskill
graystevens · 2 years ago
https://grh.am

A combination of cyber security, project ideas, and general ramblings.

Dead Comment

graystevens commented on Ask HN: What Are You Working On? (May 2023)    · Posted by u/david927
graystevens · 3 years ago
A project I posted a few years back on HN for an invisible full-lid sticker for MacBooks, so that you could both protect them _and_ keep your stickers once you get a new laptop. I finally found a cost effective manufacturing solution, so setup a shop for them!

LidLayer - https://lidlayer.com

graystevens commented on Show HN: LidLayer – Preserving Laptop Stickers on MacBooks   lidlayer.com/... · Posted by u/graystevens
graystevens · 3 years ago
Some of you may remember something similar from a few years ago: https://news.ycombinator.com/item?id=20405957

Well, I'm back, and this time I've managed to turn this into an actual physical product! It all started with a simple blog post back in 2019, which gained enough traction on various websites that it seemed worthwhile pursuing. So, a Kickstarter[0] was, well, started – but it never gathered enough momentum to get it across the line (and looking back, rightly so), and so everything got put on hold.

Then the pandemic happened, and I’m kind of glad the idea hadn’t taken off. I did however continue to get a trickle of messages and DMs asking what happened to LidLayer, and if there were any plans for the future…

Fast-forward a year or two, and I get the opportunity to go to a conference for work – the beautiful Objective by the Sea (ObtS)[1], where I am surrounded by stickered MacBooks! The idea of LidLayer immediately pops back into my head, and I can’t help but take another look at it, to see if I can make it work (it must be good if I keep coming back to it, right?).

So, I managed to find a supplier who can accurately cut the LidLayers way more cost-effectively than I ever could, meaning I could finally bring this whole thing back to life. And, what that also means is that because the cost of producing these has gone down, I can pass that saving on to you! Win win win!

[0] https://www.kickstarter.com/projects/grham/lidlayer-protect-...

[1] https://objectivebythesea.org/v5/index.html

graystevens commented on CanaryTrap: Detecting data misuse by third-party apps on online social networks   arxiv.org/abs/2006.15794... · Posted by u/massacre
mahmoudimus · 5 years ago
This is a great idea and in my opinion should be a best practice for any company. We're actively working on enabling this functionality for our core data aliasing engine at the company where I work.

The idea is pretty cool when you start to think about adding self-destructing properties to individual pieces of data, so reasoning about data type and entropy becomes a risk modeling problem.

A concrete example: imagine if bank account numbers, credit card numbers, emails etc have self-destructing properties where there exists an outer shell "pointing" to the data but the underlying data is destroyed (using techniques like crypto-shredding et al.). The outer shell would have canary properties that work in real-word systems but since the underlying data is destroyed, all we would be left with are canary properties without the underlying data leak.

A good example of some companies that offer something similar:

- https://canarytokens.org/generate

- https://github.com/thinkst/canarytokens

- https://canary.tools/

Pretty cool technology that can really go far.

graystevens · 5 years ago
We started something similar with BreachInsider (https://breachinsider.com) to allow businesses (or I guess individuals?) to do this themselves with minimal overhead or resources. The idea being that they sprinkle these ‘users’ throughout their databases and see where they show up, and be alerted if they ever get contacted or show up somewhere unusual (Pastebin etc.)

We ran something similar, firing ‘insiders’ across many of the top 100 sites and services, to spot breaches (either in the traditional sense of security incidents, or lapses in privacy for end users).

graystevens commented on Preserving Laptop Stickers – A Post Factum   grh.am/2019/preserving-la... · Posted by u/graystevens
graystevens · 6 years ago
This is a retrospective on the original post here: https://news.ycombinator.com/item?id=20405957

It got enough attention that it only seemed fair to give this a real chance, and for that, I decided to try out Kickstarter.

u/graystevens

KarmaCake day851May 29, 2014
About
[ my public key: https://keybase.io/graystevens; my proof: https://keybase.io/graystevens/sigs/_4qVvqrHehM0x3Xm0Iw5bXNk1N-BsvIXcn6C9FAVe3U ] findkismet: 7aa1f72a72193c6baa62b247c4dce3bd441fe4a01aaf341be66dff13e1574334

Email: graham@grh.am

View Original