Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aj-code
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Airtable Formula Injection - abusing formulas to steal data
(pulsesecurity.co.nz)
3 points
by
aj-code
2y ago
|
0 comments
2.
▲
Authentication Security Controls You Might Be Missing
(pulsesecurity.co.nz)
1 points
by
aj-code
6y ago
|
0 comments
3.
▲
by
aj-code
10y ago
In short, it's not. A robust scheme should be secure if the attacker knows the algorithm or not. The secret should not be the algorithm, the secret should be a sufficiently long secret value.
4.
▲
by
aj-code
10y ago
This is a good overview of how hackers actually crack hashes if anyone is interested. https://www.trustedsec.com/june-2016/introduction-gpu-passwo... The other things to take into account: Code complexity, quality, and
5.
▲
by
aj-code
10y ago
The password hashing algorithm outlined is really not best practise, only 7 rounds and the use of SHA-256 which is a general cryptographic hash, not a password specific one. The correct answer to password hashing is still mostly "just
6.
▲
by
aj-code
12y ago
I think the reality is that this style of attack is difficult enough that it would be something of a last resort, and probably only tried on high value targets. It'd take a long time (you'd probably need 100s of millions of reques
7.
▲
by
aj-code
12y ago
You'd think so! But that's not what I found, I found the minimum, max, and average were all crap. Even the median wasn't very good compared to the 10th percentile (which I got the idea from for here http://www.cs.r
8.
▲
by
aj-code
12y ago
I wrote a tool a while ago for testing network based timing attacks. Getting the measurement right is really hard, just taking the average doesn't generally work while the 10th percentile measurement is much better. I did find PHP fair
9.
▲
Christchurch transport card flaws expose identities, grant free bus rides
(scmagazine.com.au)
1 points
by
aj-code
13y ago
|
0 comments
10.
▲
Cracking Authy's Encrypted Cloud Backup
(shinynightmares.wordpress.com)
2 points
by
aj-code
13y ago
|
0 comments
11.
▲
Network auth timing attacks against hashed passwords
(github.com)
1 points
by
aj-code
13y ago
|
0 comments
12.
▲
by
aj-code
14y ago
Sure is! It would be possible to use a challenge response authentication scheme ( http://en.wikipedia.org/wiki/Challenge%E2%80%93response_auth... ) but just doing things over HTTPS is generally fine.
13.
▲
by
aj-code
14y ago
This has some fairly serious security issues, which is fine for a something not designed to be seriously used (or at all). However, the readme implies you could use this and your files will be safer than with some third party. Which is dang
14.
▲
by
aj-code
15y ago
One of the most useful features of that site used to be that you could tell at a glance which browsers the XSS payload would work on, and which it wouldn't. It hasn't been updated for modern browsers so now you have to test each browser you