Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
IncludeSecurity
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
IncludeSecurity
7y ago
I gotta say, the Figma team's blog has been on fire with quality posts about their sandbox. They've posted all details about their sandbox implementation, then all the details about this dependency vulnerability that they were on
32.
▲
by
IncludeSecurity
7y ago
Yes I understand the problem, we've seen it before. I still have ideas that could help you if you'd like to communicate off HN, I'm happy to share.
33.
▲
by
IncludeSecurity
7y ago
Interesting! I have some ideas for options here if you'd like to chat offline to see if I can help you here hit us up. https://includesecurity.com/#contact Context: I work in this space and actively work on programs su
34.
▲
by
IncludeSecurity
7y ago
Agree 100% tptacek. Though I would suggest that opening up vetting to add new firms and the resulting competition would only improve the situation for partners in terms of pricing, scheduling, process, etc. Obviously we're a competing
35.
▲
by
IncludeSecurity
7y ago
Yep this is a common move a lot of companies are doing for their biz partners and customers are requiring these sorts of tests be done before getting final procurement sign-off.
36.
▲
by
IncludeSecurity
12y ago
>This sort of argument is becoming something of a fashion statement amongst some security people. Just the ones who don't understand how good API designs can work well to solve these problems, don't worry not all of us are like
37.
▲
by
IncludeSecurity
13y ago
Thanks, these are the kind that we find every week. We also get bored of the SQLi/XSS treadmill....it's much more fun to find a parsing error that leads to a crypto vuln that bypasses authentication (hint hint for a future blog po
38.
▲
by
IncludeSecurity
13y ago
thnx sigh words
39.
▲
by
IncludeSecurity
13y ago
sorry I added "which has since been fixed" to the first paragraph. We like to write C and Ruby langs, still getting used to this English lang.
40.
▲
by
IncludeSecurity
13y ago
Hey Harlan, we think we fixed the FontAwesome problem, it was false advertising...the font was not awesome at all, it broke our whole damn blog.
41.
▲
by
IncludeSecurity
13y ago
Hey HN, here's a link to the tech details of the vuln: http://blog.includesecurity.com/2014/02/how-i-was-able-to-tr... and a video demonstrating the app we made for exploiting this vuln: http://www
42.
▲
by
IncludeSecurity
13y ago
Hey HN here is a link to the tech details: http://blog.includesecurity.com/2014/02/how-i-was-able-to-tr...