Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
CyberRage
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
CyberRage
5y ago
Actually it makes a lot of sense. Some of the reasons include: - Stable\known CPUs, most vendors are used to Intel. - Infrastructure\Support, Intel has a lot more infrastructure to support customers\contracts - Long cycles, servers are more
92.
▲
by
CyberRage
5y ago
I see, definitely valid criticism. Cannot edit my comment now. My point wasn't the specific incident that was linked but more about the fact that updates are a threat for extensions as they update automatically without user input
93.
▲
by
CyberRage
5y ago
Just to prove my point that extensions have a wide attack surface. authentication bugs: https://blog.lastpass.com/2017/04/lastpass-2fa-bug-reported- resolved/ Information leaking bugs: https://hack
94.
▲
by
CyberRage
5y ago
The point is(just gave a couple of examples for issues in the past related to web based PM's) that extensions have tremendous attack surface and lots of complicated little things you have get perfectly right. kbuck made it seem like th
95.
▲
by
CyberRage
5y ago
It's not just content scripts, I've seen vulnerabilities from information leaking(not necessarily creds) to authentication bugs. Connecting the application that manages your secrets to the most exposed application on your PC is a
96.
▲
by
CyberRage
5y ago
Tavis is an amazing researcher that I respect and look up to. However, I would still advocate for a web based password manager for regular people. The benefits overpower the possible risks which are more targeted than generic. For security
97.
▲
by
CyberRage
5y ago
Any extension based PM has potential risks. Bitwarden had multiple vulnerabilities reported in bug bounty and there are likely to be more. The most secure solution is a local PM.
98.
▲
by
CyberRage
5y ago
You're wrong. you can exploit browser extensions without escaping sandbox. In fact, LastPass and others had some pretty embarrassing vulnerabilities that can be exploited due to being an extension. There's no question that a local
99.
▲
by
CyberRage
5y ago
Also Android\iOS in general as a platform is more secure, Android\iOS are far more restrictive when it comes to users. narrowing the attack surface for casual users. For instance, rooting in order to install custom drivers\software is very
100.
▲
by
CyberRage
5y ago
You can clearly see that from data. looking at 0-day disclose, black market exploit prices and attacks in the wild. 0-day exploits for both iOS and Android are 3 times as costly as windows. You're looking at linux as it is but linux as
101.
▲
by
CyberRage
5y ago
Respectable linux distros(not just android!) use SE, sandboxing etc. Windows lags far behind OS's like Android, iOS and even ChromeOS when it comes to security.
102.
▲
by
CyberRage
5y ago
Initial access is part of the day-to-day these days. you can't cover all entry points, it's a matter of time for someone to make a mistake. the fact that the adversary showed these extreme levels of proficiency and dedication tell
103.
▲
by
CyberRage
5y ago
Windows is a mess. I don't expect it to be any secure in the following years. It is unlikely that non-admin permissions were able to stop the attack. the amount of 0-day EOP's within windows is ridiculous, truly unbelievable.
104.
▲
by
CyberRage
5y ago
You don't get this kind of attack because you had an exposed FTP server. The attack implanted malicious code into their code, learning the tooling, process and responsibilities of the personal. They then reversed engineered the protoco
105.
▲
by
CyberRage
5y ago
Well, usually highly targeted attacks are orchestrated with a reason. You want to leverage your access to perform actions because you got get revealed\blocked even not intentionally. Once you act, let's deploy some ransom, wipe some da
106.
▲
by
CyberRage
6y ago
True that. maybe I'll rephrase, was Rust specifically chosen to address memory concerns? I don't think it is too common in Android.
107.
▲
by
CyberRage
6y ago
Is this because of memory bugs\vulnerabilities that target the stack or just because it was too old and junky?
108.
▲
by
CyberRage
6y ago
The link includes players with vastly lower winrate and players with high winrates but for extremely low number of games. We need sufficient quantities to claim 99% winrate, for highly ranked players even with 200 games(which is still a low
109.
▲
by
CyberRage
6y ago
https://www.youtube.com/watch?v=Di-yRj6TIK8
110.
▲
by
CyberRage
6y ago
You're beautifully showing the human nature which can be problematic in my opinion. First of, no human player achieves 99% winrate against diamond players. there are many cheeses, one miss-step and you lose. GM's can lose to Diamo
111.
▲
by
CyberRage
6y ago
But that could be fixed technically. Deepmind's goal was not to create an "unexploitable" agent but to prove that ML algorithms can cope with complex, dynamic environments such as StarCraft. It seems to you weird but the same
112.
▲
by
CyberRage
6y ago
What amazes me at the end of the day is that brute-forcing seem to do much better than I initially thought it would do. Trying random stuff just sounds stupid but with enough compute and data, I guess it could overpower smart creatures like
113.
▲
by
CyberRage
6y ago
Training requires millions of games. playing against humans is only for evaluation purposes, not for training. In both cases, it was indeed a static model but more recent work which is called MuZero is not static and achieves great results
114.
▲
by
CyberRage
6y ago
StarCraft is built in such a way that you can't create a perfect, 100% winrate agent. Since there is hidden information, you could always miss a corner of the map where the enemy hidden some units and you lose the game. Is Alphastar &q
115.
▲
by
CyberRage
6y ago
Interesting blog-post. I found some similarities with what occurred with Deepmind's Alphastar AI. One of the weaknesses that seem to manifest in this piece too is the handling of unfamiliar scenarios. The AI is very confused once it ex
116.
▲
by
CyberRage
6y ago
You're looking at thing as they are now. Now, as I've said, there's demand\need since the EU scaled up the vaccination efforts however, look back 3-5 months. EU was discussing just how to split\manage the vaccines among the u
117.
▲
by
CyberRage
6y ago
France, a while back, was receiving good numbers but were failing to keep up in terms of demand\infrastructure. I think now EU is far more active when it comes to the efforts but initially, they were not. It seems like there is more resista
118.
▲
by
CyberRage
6y ago
Wow, you almost make it seem like Israel has done something wrong. Nope, it was EU. the EU wanted to wait for final, concrete results before mass adoption. The EU was very skeptical regarding the vaccines. the EU wanted to perform bulk orde
119.
▲
by
CyberRage
6y ago
AMD's success is great for the industry. x86 and GPU competition is much needed with complete dominance from Intel and Nvidia.
120.
▲
by
CyberRage
6y ago
Packaging and inter-connect are definitely going to become more and more important. Pushing silicon fabrication is becoming a real limit for hardware, smart packaging\stacking will play a big role in the following years. AMD\Apple already p
More ›