Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dyaz17
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Dyaz17
6y ago
This is just awesome... Congrats on the launch. This product seems to protect really well websites that include many third party JavaScript. On the other hand ,if you are one of the third party offering the JS, I would advise you to imple
2.
▲
by
Dyaz17
6y ago
Regarding the security aspect, I created GuardScript to help catch malicious 3rd party (or 1st party) javascript changes: https://www.guardscript.com/ . You should use if you own a SaaS service that require your clients to
3.
▲
by
Dyaz17
6y ago
You can login to your instances from the admin console according to this : https://cloud.google.com/compute/docs/instances/connecting-t... So Google has a way to login to your instances...
4.
▲
by
Dyaz17
6y ago
What is the attack Vector that this solution prevent ? Am I missing something obvious ? Will it prevent Google from being able to have a Root access to the VM? From my understanding it does not seem to protect from Google. If they are still
5.
▲
by
Dyaz17
7y ago
Great job. Here is what I propose to make it more secure and prevent you from being able to read anyone diary... I propose that each day a link/token is sent to your email. The link then ask for a password that is handled only with cl
6.
▲
by
Dyaz17
7y ago
You can also use https://www.guardscript.com that does this for free and send you a diff in your email.
7.
▲
by
Dyaz17
7y ago
Nice product! And thank you for making it opensource. Any particular reason why you chose Ruby? A little plug : I have developed https://www.guardscript.com . It is a service that detect any modification made to static files host
8.
▲
How to avoid a $200M hack
(guardscript.com)
1 points
by
Dyaz17
7y ago
|
0 comments
9.
▲
by
Dyaz17
7y ago
You are right, for now all the analysis should be done by the owner of the script. I'll think about adding a runbook...
10.
▲
by
Dyaz17
7y ago
Thank you, I have corrected it
11.
▲
by
Dyaz17
7y ago
Thanks for the suggestion.
12.
▲
by
Dyaz17
7y ago
No it does not include the headers. Only the js file downloaded.
13.
▲
by
Dyaz17
7y ago
For now, Guardscript Goal is for the different SaaS services to use it, not for the individual website owners to use it to monitor the JS of SaaS services.
14.
▲
by
Dyaz17
7y ago
You are right. SRI is the best solution and I mention it in the FAQ. Unfortunately, it can't always be implemented. See my previous comment : Well many companies that offer you a service don't include the Subresource integrity Tag
15.
▲
by
Dyaz17
7y ago
Exactly.
16.
▲
by
Dyaz17
7y ago
Thanks for the suggestion
17.
▲
by
Dyaz17
7y ago
Thank you! I have changed it.
18.
▲
by
Dyaz17
7y ago
Well many companies that offer you a service don't include the Subresource integrity Tag. Check for instance Stripe : <script src=" https://js.stripe.com/v3"></script> or Facebook : <scrip
19.
▲
by
Dyaz17
7y ago
Hey HN! I created GuardScript because in my previous company we started to include more and more third-party Javascript from SaaS services on our homepage, and this created security risks for us [1] [2]. In order to reassure us, a few of th
20.
▲
Show HN: Guardscript – Detect any changes made to your JavaScript files
(guardscript.com)
28 points
by
Dyaz17
7y ago
|
37 comments