Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
MajesticHobo2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
MajesticHobo2
1mo ago
That is a linear growth problem whose answer is very easy to intuit.
2.
▲
by
MajesticHobo2
1mo ago
You also don't want adversaries to be able to disrupt long-lived streams with bad password guesses, since I think part of Wormhole's security model is it will terminate the session if the other side gets it wrong.
3.
▲
by
MajesticHobo2
1mo ago
They say it's rate-limited, so at least it probably won't scale to large botnets or similar...
4.
▲
by
MajesticHobo2
1mo ago
notabug wontfix; that's the end-to-end principle in action. Bring your own all of that.
5.
▲
by
MajesticHobo2
3mo ago
Browser sandboxing is now fully solved.
6.
▲
by
MajesticHobo2
3mo ago
It's the same style I see on Twitter and LinkedIn a lot.
7.
▲
by
MajesticHobo2
3mo ago
Why does it have to be deliberate? It's not surprising that people exposed to output from LLMs will unconsciously pick up their linguistic habits.
8.
▲
by
MajesticHobo2
5mo ago
I'd say also add a test that shows the HTML injection (which spurred the PR) isn't possible. Given an attacker-controlled URL of: foo onclick the following shouldn't render: <a class="item muted sidebar
9.
▲
by
MajesticHobo2
6mo ago
It was definitely partially about model quality. The frontier models are capable of producing valid findings with (reasonably) complex exploit chains on the first pass (or with limited nudging) and are much less prone to making up the kinds
10.
▲
by
MajesticHobo2
6mo ago
> With decompilation I think there's a higher risk of it missing the intention of the code. I'm not sure but suspect the lack of comments and documentation might be an advantage to LLMs for this use case. For security/reve
11.
▲
by
MajesticHobo2
6mo ago
That was then, this is now. The new models are scarily good. If you're skeptical, just take an hour to replicate the strategy the article references. Point Claude at any open-source codebase you find interesting and instruct it to find
12.
▲
by
MajesticHobo2
8mo ago
Third or fourth, maybe, not first.
13.
▲
by
MajesticHobo2
8mo ago
Yes, but it would likely have to be chained with other bugs - at minimum, something that gives you an info leak.
14.
▲
by
MajesticHobo2
9mo ago
Yeah, somebody came up with one here: https://news.ycombinator.com/item?id=46469897
15.
▲
by
MajesticHobo2
9mo ago
It’s a phase 1 clinical trial designed only to assess safety and determine the appropriate dosage. Future trials will focus on efficacy.
16.
▲
by
MajesticHobo2
10mo ago
Wouldn't platforms see the supposed XSS payloads in their logs and publish analyses of them, or at the very least, announce that they happened?
17.
▲
by
MajesticHobo2
10mo ago
I'm sure they can store far more than 20 TB now, but it is true that the content pool is much larger. I would guess it's not a favorable ratio.
18.
▲
by
MajesticHobo2
1y ago
Thanks for making this! I've been looking for something like this for a while.
19.
▲
by
MajesticHobo2
1y ago
xxd IMGP0847.DNG | grep 03e400: 0003e400: ffd8 ffc3 000e 0e10 800c 5002 0011 0001 ..........P..... Look at the byte at offset 11 (0xb), it's there.
20.
▲
by
MajesticHobo2
1y ago
Yes: dd status=none if=IMGP0847.DNG bs=1 skip=0x3e40b count=1 | xxd 00000000: 02
21.
▲
by
MajesticHobo2
1y ago
You need to click the link that says "RAW (33.0MB)". The filename should be "IMGP0847.DNG".
22.
▲
by
MajesticHobo2
1y ago
I AirDropped the PoC to my vulnerable iPhone. It didn't cause a crash until I tried to edit it in the Photos app.
23.
▲
by
MajesticHobo2
1y ago
That's exactly why I don't agree that GETs should be broadly exempted from CSRF protections. I'm not talking about CORS at all.
24.
▲
by
MajesticHobo2
1y ago
The problem boils down to the lack of equivalence between a site and an origin. The article explains how https://app.example.com and https://marketing.example.com may sit at very different trust levels, but are consi
25.
▲
by
MajesticHobo2
1y ago
Not sure I agree with this part: > Allow all GET, HEAD, or OPTIONS requests. > These are safe methods, and are assumed not to change state at various layers of the stack already. Plenty of apps violate this assumption and do allow GET
26.
▲
by
MajesticHobo2
1y ago
XFF handling is the bug that keeps on giving. I'd estimate I've seen incorrect parsing of it in at least half of the web applications I've audited professionally. The funniest is when the app renders user IP addresses somewhe
27.
▲
by
MajesticHobo2
1y ago
You can use FTP and SVN.
28.
▲
by
MajesticHobo2
1y ago
There doesn't need to be any kind of "polyglot payload". Local network services and devices that accept only simple HTTP requests are extremely common. The request will go through and alter state, etc.; you just won't
29.
▲
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages
(googleprojectzero.blogspot.com)
49 points
by
MajesticHobo2
1y ago
|
1 comments
30.
▲
by
MajesticHobo2
1y ago
Right, but now the vector for privilege escalation will have to be a logic bug in memory-safe sudo instead of either a memory corruption (see CVE-2021-3156) or a logic bug. It’s hard not to see this as a major improvement.
More ›