Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
MajesticHobo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
MajesticHobo
9y ago
What is a cyber weapon? Knowledge of a vulnerability? Exploit code? How do you propose regulating it? Much of this has been tried before and ended up hurting rather than helping.
2.
▲
by
MajesticHobo
9y ago
I don't disagree with sanitizing data at output time when it's clear that A) the input won't affect anything else and B) output is going to happen . But realize not all input winds up in a SQL database, not all input will be
3.
▲
by
MajesticHobo
9y ago
If you allow binary uploads, you're going to be a malware distributor whether you scan or not. AV just introduces complexity and attack surface and doesn't really belong in a guide about Golang secure coding practices.
4.
▲
by
MajesticHobo
9y ago
You've said nothing that contradicts my post. As long as the data is sanitized before it can affect the storage/transport mechanism for its content type, you're good.
5.
▲
by
MajesticHobo
9y ago
Yes, really. Otherwise, you must take extra care not to reflect any input data back in any response to the user, whether it's in the HTML body or not. See: HTTP response splitting.
6.
▲
by
MajesticHobo
9y ago
This guide still has some issues. It's missing common classes of web app vulns I've seen in Go code (e.g. CSRF, SSRF) and has some weird advice here and there (scan uploaded files with AV? Really?)
7.
▲
by
MajesticHobo
9y ago
WhatsApp doesn't read your conversations for ads because it can't. Message content is end-to-end encrypted. You must have leaked your plans through some other medium inadvertently.
8.
▲
by
MajesticHobo
10y ago
>further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic Of course they do. You may disagree with the logic, but it's there.
9.
▲
by
MajesticHobo
10y ago
The notion that he "lacked the ability to leak carefully and strategically" because he was an outsider. I'm fairly sure he was more than capable of selecting only documents related to domestic surveillance if he wanted to --
10.
▲
by
MajesticHobo
10y ago
> It's not just that Snowden wasn't an insider, but that he lacked the ability to leak carefully and strategically --- and so the public outcome was inferior to the Pentagon Papers. This is hard to believe. I find it much more
11.
▲
by
MajesticHobo
10y ago
> Can we trust this information? The answer is: not fully, because the link timestamp can be altered by the developer in a way that’s not always possible to spot. However, certain indicators such as matching the year on the timestamp wit
12.
▲
by
MajesticHobo
10y ago
It is. The title is a little misleading; here's an explanatory excerpt from the actual paper: > In this work we analyze the iMessage protocol and identify several weaknesses that an attacker may use to decrypt iMessages and attachme
13.
▲
by
MajesticHobo
10y ago
Uh, no. Implementation bugs don't mean a protocol is broken.
14.
▲
by
MajesticHobo
10y ago
There's always Icedove, which gets updates from Debian.
15.
▲
Cyber researchers confirm Russian government hack of DNC
(washingtonpost.com)
1 points
by
MajesticHobo
10y ago
|
0 comments
16.
▲
by
MajesticHobo
10y ago
> offering complete untraceable anonymity Your argument falls apart the moment you claim this.
17.
▲
by
MajesticHobo
10y ago
Yes, that is what I meant. That's what I get for being a pedant.
18.
▲
by
MajesticHobo
10y ago
A valid point of view, but the US is technically a constitutional republic, not a true democracy. Certain values and principles are written into our DNA via the Constitution, and I contest your assertion that they can simply be voted away b
19.
▲
by
MajesticHobo
10y ago
> Whenever a story about Snowden is in the news, some people complain that some of the documents he released were "off topic". Which is odd, because I personally have not found any of the Snowden publications off topic or unnec
20.
▲
by
MajesticHobo
10y ago
I was under the impression that you are generally allowed to record content for your own personal use, as long as you don't distribute it to others.
21.
▲
by
MajesticHobo
10y ago
> something that DRM isn't preventing you from doing something you're otherwise not supposed to be doing anyways. And what would that be?
22.
▲
by
MajesticHobo
10y ago
WhatsApp is the most popular end-to-end encrypted chat app in the world. Shutting it down for 100 million people not suspected or charged with any crime is an incredibly disproportionate, privacy-thwarting response to not being able to acce
23.
▲
by
MajesticHobo
10y ago
Okay. So it's a protection against browser exploits, not overreaching web APIs.
24.
▲
by
MajesticHobo
10y ago
Aren't those already sandboxed browser-local filesystems?
25.
▲
by
MajesticHobo
10y ago
ZH's response: http://www.zerohedge.com/news/2016-04-29/full-story-behind-b...
26.
▲
by
MajesticHobo
10y ago
It's not that easy. Due to toolchain and platform differences, there is no guarantee that your compiler will produce the same binary as the official distribution. This is why deterministic, reproducible builds are a growing area of int
27.
▲
by
MajesticHobo
11y ago
A couple points: > the practice of allowing brutal murderers and rapists to live out their lives and die in peace Unless I'm misreading you, that's a huge misrepresentation of what death penalty abolitionists advocate. I don&#x
28.
▲
by
MajesticHobo
11y ago
Call it what you want. IMO, any society that recognizes the problems with capital punishment and accordingly outlaws it has at least some liberal tendencies.
29.
▲
by
MajesticHobo
11y ago
Why not? Some practices are totally abhorrent and have no place in any liberal society.
30.
▲
by
MajesticHobo
11y ago
Why would Google implement e2e crypto? Doesn't that violate their business model?
More ›