Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aj3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
aj3
5y ago
That's a pretty idealistic view. I guess the issue boils down to whether you believe there are things in digital realms that are illegal to possess. For comparison, it's pretty obvious that there are certain things in physical rea
92.
▲
by
aj3
5y ago
On the other hand, Google can run arbitrary queries over your data (published to their cloud) while Apple uses the same algorithm and hash database for everyone (which probably will get reverse engineered and audited by next BlackHat).
93.
▲
by
aj3
5y ago
Meh. Dropbox and Google Drive can run arbitrary queries over your files stored there. iCloud (assuming they finish e2ee transition) will have to push the same hashes to everyone. It's not transparent and we don't have a way to ins
94.
▲
Nirvana Fallacy
(en.wikipedia.org)
1 points
by
aj3
5y ago
|
0 comments
95.
▲
by
aj3
5y ago
Nirvana / perfect solution fallacy: https://en.wikipedia.org/wiki/Nirvana_fallacy
96.
▲
by
aj3
5y ago
Analogies between IT and physical world are often less than helpful but before digital photos most people would be developing photos in specialized studios. If these studios noticed what they thought was CSAM they would report it to police.
97.
▲
by
aj3
5y ago
This option is transparent to the user and easy to change. Also, anyone who has done IT support will appreciate that yeah regular users actually want / need backups enabled by default, it's often a life saver for them.
98.
▲
by
aj3
5y ago
Meh. Compared to 10 years ago we still live in a bright future where e2ee is available to everyone who needs it. Yeah, you might need to enable some options (like in Telegram) or disable some other options (like iCloud in iMessage), but it&
99.
▲
by
aj3
5y ago
Try stuffing pendrive there and going through airport securiyt. We're already checking for this (effectively).
100.
▲
by
aj3
5y ago
AFAIK, ML image classification is used for checking user-generated content on social networks, forums, etc. Cloud storage, email and IM providers will continue using hashes (either exact or perceptual) to lower false positives.
101.
▲
by
aj3
5y ago
Now we have cyber domain where this is definitely not true.
102.
▲
by
aj3
5y ago
Reviewing potential matches sounds like an awful job. Retention might be even lower than in those FB abuse centers.
103.
▲
by
aj3
5y ago
[citation needed]
104.
▲
by
aj3
5y ago
I'm pretty sure child abuse is a criminal offense everywhere. That's quite a disincentive.
105.
▲
by
aj3
5y ago
Well, it is de facto standard in Microsoft world. Honestly, I don’t actually share author's opinion, but it is well presented.
106.
▲
SAML Is Insecure by Design
(joonas.fi)
300 points
by
aj3
5y ago
|
180 comments
107.
▲
Mitigating NTLM Relay Attacks on Active Directory Certificate Services (Ad CS)
(support.microsoft.com)
2 points
by
aj3
5y ago
|
0 comments
108.
▲
by
aj3
5y ago
LEO and TLA need vendors with constant supply of exploits.
109.
▲
by
aj3
5y ago
Cutting down things that are unnecessarily complex would be a good start. I.e. most websites out there could be easily replaced by static code generators. Webauthn and client certificates can be used to protect admin interfaces. Technology
110.
▲
by
aj3
5y ago
Your second link mentions sellers avoiding liability by selling product (that can be inspected in stores) "as-is". It could be argued that open source falls in the same category. You have an opportunity to inspect it before using
111.
▲
by
aj3
5y ago
Initial vulnerability is OOB read, but it can be leveraged to gain arbitrary r/w. EDIT: source: https://saaramar.github.io/IOMobileFrameBuffer_LPE_POC/
112.
▲
by
aj3
5y ago
Apple is asking for "a reasonably reliable exploit" for full bounty payment: https://developer.apple.com/security-bounty/
113.
▲
by
aj3
5y ago
Well, some people want to have root access to study iOS internals, debug software, look for forensic artefacts and unknown vulnerabilities.
114.
▲
by
aj3
5y ago
Password hashes. /etc/shadow isn’t world readable in Linux dither
115.
▲
by
aj3
5y ago
That link just points to whole thread. You're entitled to your opinion and so do they. I don't really see how there's basis for bad faith accusations. Their stance and actions seems reasonable and consistent, even if other pe
116.
▲
by
aj3
5y ago
Meh, that's not a death threat, they're just looking for extra-judicial settlement. I get the activism aspect and I agree that copyright laws are outdated, but how entitled do you need to be to expect preferential treatment becaus
117.
▲
by
aj3
5y ago
Article summed up: there’s this thing called cargo cult programming and it’s bad.
118.
▲
by
aj3
5y ago
This seems like a very uncharitable reading of that quote. Btw, what is organisation meant to do in this situation? Sue the person they believe is infringing on their rights without regard to humanity? Ignore the issue altogether?
119.
▲
by
aj3
5y ago
Eh, the issue was found by a random (Chinese) guy on the internet. And it was reported to Microsoft in the beginning of January. It got leaked and once you have the exploit chain - yeah, pretty much any random guy on the internet could use
120.
▲
by
aj3
5y ago
Not the same thing. Solarwinds saga (the one Russians are blamed for) was 1) extremely targeted and 2) extremely sophisticated. Exchange attacks on the other hand were indiscriminate (not targeting any single country or infrastructure, just
More ›