Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
RagingCactus
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
RagingCactus
2mo ago
While I dislike the feature getting removed, this argument does not hold up to scrutiny. They will remove using external SMTP servers to send emails from external, third-party addresses. Sending as another Gmail or Google Workspace address
2.
▲
Gmail support for sending from third-party email addresses ends January 2027
(support.google.com)
20 points
by
RagingCactus
2mo ago
|
8 comments
3.
▲
by
RagingCactus
3mo ago
You can do that, but my understanding is you can't get the browser to attach cookies to your request in this way, while you can with forms. Do you agree?
4.
▲
by
RagingCactus
3mo ago
This is fundamentally a CSRF issue and framing CSRF as an access control issue often yields to wrong conclusions. With CSRF you might face the situation that the request has a valid session cookie, but is actually created by an attacker coe
5.
▲
by
RagingCactus
3mo ago
You can massage a text/plain form into valid JSON. text/plain is also one of the allowed default types. It works if the server doesn't check the content-type. Source: I've done that successfully in multiple pentests. Edi
6.
▲
by
RagingCactus
4mo ago
> Some libraries being buggy never was an argument against using libraries. And do you expect your single-purpose code not to be? Of course you should use battle-tested and well-maintained libraries for the really hard stuff such as cryp
7.
▲
by
RagingCactus
4mo ago
> Also, WTF is wrong with people who accepted algorithm "none." They dared to use the default validation function of their JWT library. They did not choose to accept "none". And the library authors implemented it beca
8.
▲
by
RagingCactus
4mo ago
> First, we need to add a token_secret column to our users table: > ALTER TABLE users ADD COLUMN token_secret; So it's "stateless" but we have to query the users database on every request? How is that more stateless th
9.
▲
by
RagingCactus
4mo ago
> Necessary qualifier: for browser-based user sessions. > Plenty of good uses for JWTs for service-to-service communication. This is the sensible conclusion right there. I agree JWTs are the wrong tool for the use case of user session
10.
▲
by
RagingCactus
5mo ago
As a security person it is tiring to see so many people here either directly claim or at least allude to the claim that this is somehow much less scary because the _published_ exploit does not bypass ASLR. The writeup claims there is a way
11.
▲
by
RagingCactus
5mo ago
Seeing the confusion in the comments I want to provide some examples of situations where this might come up in a security or CTF context: * You have a restricted shell or other way to execute a restricted set of commands or binaries, often
12.
▲
by
RagingCactus
11mo ago
Lots of people here are (perhaps rightfully) pointing to the unwrap() call being an issue. That might be true, but to me the fact that a reasonably "clean" panic at a defined line of code was not quickly picked up in any error mon
13.
▲
by
RagingCactus
1y ago
Yes, you're definitely right that there are edge cases and I was simplifying a bit. Notably, it's called SameSite, NOT SameOrigin. Depending on your application that might matter a lot. In practice, SameSite=Lax is already very ef
14.
▲
by
RagingCactus
1y ago
I work as a pentester. CSRF is not a problem of the user proving their identity, but instead a problem of the browser as a confused deputy. CSRF makes it so the browser proves the identity of the user to the application server without the u
15.
▲
by
RagingCactus
1y ago
The SameSite cookie flag is effective against CSRF when you put it on your session cookie, it's one of its main use cases. See https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/... fo
16.
▲
by
RagingCactus
1y ago
I don't believe this is true, as https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web... exists. It does need an extension to be installed, but I think that's fair in your comparison wi
17.
▲
VS Code Material Theme Was Mistakenly Flagged as Malicious
(github.com)
6 points
by
RagingCactus
2y ago
|
2 comments
18.
▲
by
RagingCactus
2y ago
Direct link to the comment with the new information (apparently it is not possible to keep the URL fragment): https://github.com/microsoft/vsmarketplace/issues/1168#issue... The gist of it: > The publisher
19.
▲
by
RagingCactus
2y ago
The article doesn't mention possible security implications. However, we already get lots of vulnerabilities exactly _because_ implementations disagree on delimiters. Examples for this are HTTP request smuggling[1, 2, 3] and SMTP smuggl
20.
▲
by
RagingCactus
4y ago
`git push -u origin HEAD` pushes the current branch to `origin` with the same name you have locally. You could even add an alias for that.
21.
▲
by
RagingCactus
6y ago
And another party trick: Base64-encoded JSON objects always start with "ey".
22.
▲
by
RagingCactus
7y ago
Are there any resources you can recommend to understand D-wave's quantum computing a bit better? I took a very basic course about gate-model quantum computing at my university. The (mathematics) professor would have loved to be able to
23.
▲
by
RagingCactus
8y ago
For the Fibonacci example the author claims: > Notice how state was introduced? It made the code easier to read. Correct me if I'm wrong, but the only state in that snippet lives in Stream.iterate(), the Fibonacci object is still im
24.
▲
by
RagingCactus
8y ago
Thanks! Just defining it as a config variable is far too obvious in hindsight, I don't know why it didn't cross my mind. I'll definitely try it out!
25.
▲
by
RagingCactus
8y ago
Is there a way to manage different "categories" of systems with chezmoi? For example, a "linux-server" category would contain an essential set of dotfiles, but not all the window manager related stuff from my linux lapto
26.
▲
by
RagingCactus
8y ago
The Bundesnetzagentur does not have the capacity to ban random devices for children. They banned these devices because they are essentially bugs/covert listening devices and are even marketed as such. Devices that look innocious (such