Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DorothySim
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
1.
▲
by
DorothySim
9y ago
> For example, IIRC NetBSD required new developers to meet with one or two existing developers in person to verify their identity. (Pretty much like a regular PGP WoT.) Debian also requires OpenPGP keys and WoT for all developers.
2.
▲
by
DorothySim
9y ago
> What I'd really like to see is a JS implementation of the "dynamic" features like diffing That's possible. I've made something like that (dynamically fetching git info via dump HTTP server protocol) using Git.j
3.
▲
by
DorothySim
9y ago
But if you don't provision the device yourself how can you be sure it hasn't been tampered with in a way that just displays "bootloader OK, everything good" but in the mean time it was rooted? Or is that a risk calculate
4.
▲
by
DorothySim
9y ago
Interesting design. As far as I understood from old papers client certificates are used only to identify the device while user authentication is handled differently. Could you elaborate on the technical details on user authentication? (If t
5.
▲
by
DorothySim
9y ago
They also take into account the state of the machine you're working on. So locked bootloader and probably a client cert in TPM-like component, plus "device health". Client certs alone are good for authentication (don't w
6.
▲
by
DorothySim
9y ago
I think the only restriction is working on Google approved hardware so no BYOD there. (Disclosure: not a Google employee).
7.
▲
by
DorothySim
9y ago
For people interested in specs, here's the link: https://www.greenbytes.de/tech/webdav/draft-ietf-httpbis-cac...
8.
▲
Linux kernel: stack buffer overflow with controlled payload in get_options()
(lkml.org)
1 points
by
DorothySim
9y ago
|
0 comments
9.
▲
by
DorothySim
9y ago
The "Online Demo" button brings me to the download page. Is this a bug?
10.
▲
by
DorothySim
9y ago
I suggest returning 404 Not Found instead of 422 Unprocessable Entity on failed GETs: https://jsonbin.io/b/2342342 as well as Content-Type: application/json instead of current text/html. "Entity" in
11.
▲
by
DorothySim
9y ago
> C# and Java allocate objects to the heap and primitive types to the stack by default (...) Note that it only applies to local variables. If you have a primitive inside an object then it's allocated on the heap as part of the outer
12.
▲
by
DorothySim
9y ago
Looks very good and I like that they have a screenshot right on the home page. I wish there was an anonymous instance to try it out without the tedious login process...
13.
▲
by
DorothySim
9y ago
I've used a simple iptables approach to redirect traffic to new Docker container: iptables --wait --table nat --append PREROUTING --protocol tcp --dport 80 ! --in-interface docker0 --jump DNAT --to $new_target Then removing tabl
14.
▲
by
DorothySim
9y ago
Also relevant: https://vimeo.com/110554082
15.
▲
by
DorothySim
9y ago
Note that it is about TLS client certificates so it's not as widespread as it seems (unless you use these certs of course :) ).
16.
▲
by
DorothySim
9y ago
Probably yes. Sending scores in HTTP requests is such a low-hanging fruit for exploitation. A friend of mine was responsible for scoring system on games. As they had some real awards (like bikes, tickets etc.) they captured the entire flow
17.
▲
CVE-2017-7477 kernel: net: Heap overflow in skb_to_sgvec in macsec.c
(git.kernel.org)
1 points
by
DorothySim
9y ago
|
0 comments
18.
▲
by
DorothySim
9y ago
Wow, very nice! I think this comment on issues is also relevant: https://github.com/Microsoft/vscode/issues/1031#issuecomment...
19.
▲
by
DorothySim
9y ago
...or Thunderbird (Enigmail) for people that like GUIs.
20.
▲
by
DorothySim
9y ago
> For hostkeys on DO you can probably get a script to run that'll request a signed certificate from a server you own. Or just embed the signed host certificate in cloud-init.
21.
▲
by
DorothySim
9y ago
You are not required to use SSL to do hello world. You are required to use SSL if you want to use HTTP2 (yes, I know about h2c).
22.
▲
by
DorothySim
9y ago
According to this [0] they are related ("SRP is related to Diffie-Hellman."). [0]: http://web.archive.org/web/20130407190430/http://chargen.mat...
23.
▲
by
DorothySim
9y ago
CVE disclosure list: oss-security@lists.openwall.com (unfortunately since Mitre stopped taking bug reports via e-mails it's not as active as it has been).
24.
▲
Secure Remote Password protocol
(en.wikipedia.org)
17 points
by
DorothySim
9y ago
|
19 comments
25.
▲
by
DorothySim
10y ago
Really interesting hack. It basically gives (almost) free timestamping (using Let's encrypt for cert issuance and CT logs for storing information). Previously one would use Bitcoin OP_RETURN outputs for timestamping [0]. [0]: https:&#
26.
▲
by
DorothySim
10y ago
The same thing exists in .NET IL where you can overload methods based only on return values (among other interesting things like modopt/modreq [0] etc.). [0]: http://stackoverflow.com/a/5294456
27.
▲
by
DorothySim
10y ago
a) is particularly interesting to me. I thought about giving people ability to create their own namespaces and used https://user.example.com or https://example.com/user as a namespace but tag URI looks cleaner.
28.
▲
by
DorothySim
10y ago
Is there a benefit of using tag URI instead of a regular old URL? E.g. tag:blogger.com,1999:blog-555 vs https://blogger.com/1999/blog-555 The only difference I see is that URL should point to something (can be referenc
29.
▲
by
DorothySim
10y ago
> The author seems to be ill-informed on the point which apparently is the only stated reason for not using the internet standard that directly applies to the use case. That's what I also suspected. Thanks!
30.
▲
by
DorothySim
10y ago
> As we iterated on our approach, we have decided to follow more recent recommendations and not limit our identifiers to the deprecated concept of URN. I was not aware URN was deprecated... Is there a reference somewhere to these recomme
More ›