Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aj3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
aj3
5y ago
It’s not forwarded to Apple/FBI though, under any circumstances.
62.
▲
by
aj3
5y ago
It's a security risk even if you don't use it. Someone just seeing your card briefly could copy it as the stripe has the same info that's printed on it. Incidentally, this discussion is filled with people who have no idea how
63.
▲
by
aj3
5y ago
No wonder people hate it then.
64.
▲
by
aj3
5y ago
That’s not what I meant. SPF checks Envelope Sender domain which does not have to be the same as the address seen in From header. Your configuration is trivially spoofable by setting Envelope Sender to something attacker controls (and thus
65.
▲
by
aj3
5y ago
Wow, that’s wonderful!
66.
▲
by
aj3
5y ago
Any recommendations for similar physics textbooks?
67.
▲
by
aj3
5y ago
Corporate politics and death by committee. These standards were created by many parties with conflicting interests. My understanding is that they couldn't agree on an exact way From header should be checked and thus deferred all policy
68.
▲
by
aj3
5y ago
Yeah, I didn't want to get stuck in details, but I'm setting up a couple of new mailservers (freshly registered domains, self-hosted VPS at cheap cloud providers (DO, Hetzner, OVH, AWS). And they do get delivered directly into Out
69.
▲
by
aj3
5y ago
Sure. Parsing DMARC requires understanding DKIM as well, so what you’re asking is a non issue. That said DKIM is not enough because that standard does not have a way to signal recipient that your domain has DKIM set up in the first place (a
70.
▲
by
aj3
5y ago
Eh, DMARC is meant to solve different problem. E.g. when your accountant receives spoofed mail with a fake invoice supposedly coming from a legit supply chain provider. They might be trained to check domain that was used to send email but w
71.
▲
by
aj3
5y ago
Your configuration provides no protection from email spoofing though.
72.
▲
by
aj3
5y ago
SPF (alone) is useless because it actually does not check the sender's domain in the From header (as one might naively think). Instead it only verifies Envelop Sender which can differ (intentionally) from the mail seen in From header.
73.
▲
by
aj3
5y ago
3rd party bulk senders likely know more about mail delivery than you do. Also DMARC aware recipients will treat ~ALL in SPF exactly like -ALl.
74.
▲
by
aj3
5y ago
No it doesn’t, unless said intermediaries are modifying contents and are not DMARC aware. Many European countries are forcing DMARC adoption for government infrastructure and it works just fine.
75.
▲
by
aj3
5y ago
It’s definitely not set and forget. In the past year alone there where multiple 0day attacks against Exim and MS Exchange servers.
76.
▲
by
aj3
5y ago
Outsourcing security is a very stupid thing to do. Of course copying a line you don’t understand into your DNS isn't that much better but at least you control it. In this case configuration is handled by an unknown entity that you no c
77.
▲
by
aj3
5y ago
Subnet level blocking is certainly a thing, but I’m setting up new domains routinely and Outlook works fine. Even with cheap / free domains. Lack of verbose feedback / delivery errors makes debugging issues in your own really hard
78.
▲
by
aj3
5y ago
No, domain reputation does not solve the problem of spam (and especially [spear]phishing).
79.
▲
by
aj3
5y ago
That’s a very controversial standard as it can be abused for tracking and does not really protect end users from spoofing.
80.
▲
by
aj3
5y ago
You can hack macOS using macOS, but kids won’t be able to get that level of understanding how OS works on iPadOS. This is bad for IT. Maybe not as dramatic as an existential crisis but it’s certainly a lost opportunity. My friend's dau
81.
▲
by
aj3
5y ago
You're wrong despite your confidence. Cage will have zero net gravitational effect on the black hole (assuming the cage is perfectly symmetrical), but that just means it won't by itself exert gravitational force on the black hole
82.
▲
by
aj3
5y ago
No, you’re not allowed to do crime even if you kill all witnesses and destroy all evidence.
83.
▲
by
aj3
5y ago
Explanation and comparison between platforms: https://mobile.twitter.com/mcclure111/status/142590242262759...
84.
▲
Microsoft Warns: Another Unpatched PrintNightmare Zero-Day
(threatpost.com)
21 points
by
aj3
5y ago
|
0 comments
85.
▲
by
aj3
5y ago
Github repo with data that was provided to researchers (looks like garbage to me): https://github.com/robertdavidgraham/cybersymposium
86.
▲
Robert Graham evaluates Mike Lindell's data
(twitter.com)
7 points
by
aj3
5y ago
|
1 comments
87.
▲
by
aj3
5y ago
Eh, I've studied in a "respected" post-Soviet school as well and can't related to this at all. Teachers were awesome and passionate, had really thorough understanding of math (and physics, and chemistry), without any hin
88.
▲
by
aj3
5y ago
Users need backups to protect from a device loss scenario. Apple needs to have keys for that to work. They also can’t rely on key derivation because users forget their Apple ID passwords all the time. It is relevant because this requirement
89.
▲
by
aj3
5y ago
1. Previous submission ( http://www.hackerfactor.com/blog/ ) claims that PhotoDNA is reversible to 26x26 grayscale 2. What’s more important is you can reverse engineer algorithm that’s used locally to compare these hashe
90.
▲
by
aj3
5y ago
The problem with rummaging through someone’s drawers is that this is done by people who in that process will inevitably find out much more about your life than binary “has CSAM / does not have CSAM in their possession”. There’s no viab
More ›