Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aj3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
by
aj3
5y ago
You obviously haven't met Chinese infosec researchers, have no knowledge about Chinese underground and are simply speaking from your biases.
122.
▲
by
aj3
5y ago
What you're missing is that these attacks weren't targeted. They scanned internet and processed pretty much all accessible Exchange servers in the same manner. There were a few crews operating in parallel by the way which had acce
123.
▲
by
aj3
5y ago
To my knowledge this is the first attack of this sort (shadily) attributed to China, but they have been implicated in much more important attacks, such as OPM breach ( https://en.wikipedia.org/wiki/Office_of_Personnel_M
124.
▲
by
aj3
5y ago
All the good mechanical bluetooth keyboards I know are almost as heavy as this console. Is there anything actually portable in this form factor?
125.
▲
by
aj3
5y ago
I'd much prefer reading and reviewing code on an ipad, if only Apple wasn't so restrictive about their software.
126.
▲
by
aj3
5y ago
And it boosts Linux stats among Steam users.
127.
▲
by
aj3
5y ago
Can't imagine coding without a good keyboard though. And mobile mechanical keyboards are too heavy to carry around. It should be great for debugging random server problems while on vacation though.
128.
▲
Another Vulnerability in PrintSpooler Service
(zdnet.com)
2 points
by
aj3
5y ago
|
0 comments
129.
▲
by
aj3
5y ago
You just keep talking straight past my points without even trying to understand them. Why bother writing answers at all? I'm not advocating for installing a fresh OS on an exploited hardware and calling it a day, no matter how hard you
130.
▲
by
aj3
5y ago
You pose the questions but do not answer them. Assuming distros are selected purposefully you do get quite a lot of variability. Recompiling the kernel with different hardening options alone makes many exploits impractical. The threat model
131.
▲
by
aj3
5y ago
Standards don't provide such filtering functionality and telcos operate their equipment as a black box, so they don't have ability to implement additional features, especially when there is no business case for that and it could o
132.
▲
by
aj3
5y ago
Assuming that time travel is impossible, NSA can't break into something that does not exist anymore. Hence the idea when facing such adversary is to provide them a constantly moving target. Although NSA might be able to break any full
133.
▲
by
aj3
5y ago
That seems to be about stopping spamming over SMS. AFAIK censoring SMS between unknown individuals isn't even technically possible.
134.
▲
by
aj3
5y ago
Buddy, I'm not gonna follow this thread anymore because you seem to be baiting me to read you a lecture on OPSEC, security in depth and compartmentalization.
135.
▲
by
aj3
5y ago
That would be very unusual (unorthodox) definition of Pi though.
136.
▲
by
aj3
5y ago
You're definitely commenting on your own experience in high school and it's not universal. We were mostly doing analysis in high school with some analytical geometry thrown in.
137.
▲
by
aj3
5y ago
Euclidian geometry would be the same in any universe though, as it does not depend on objective physical reality.
138.
▲
by
aj3
5y ago
In case you're genuinely curious, 'NSA-proof' is a portmanteau from NSA and 'idiot-proof'. Distrohopping is when people change (usually GNU/Linux) distributions once a month or so (which is an allusion at tongu
139.
▲
by
aj3
5y ago
They must know who downloaded radare and IDA as well then.
140.
▲
by
aj3
5y ago
Yeah, that's bullshit. For NSA-proof personal tech stack you'd rely more on tamper-evident blocks that's all. Also, security in depth and security through obscurity are much more applicable if you're a person and not an
141.
▲
by
aj3
5y ago
Actually hacking systems is easier than (some) individuals. It's pretty obvious if you think about it. ICS are operated by group of people, they have well defined accessibility and availability requirements, some sort of documentation
142.
▲
by
aj3
5y ago
It's a huge code base, of course there are security issues. Same way IDA and radare have security issues. People who reverse malware take that into account.
143.
▲
by
aj3
5y ago
But it's hosted on Github. And some distros have ghidra in official repos.
144.
▲
by
aj3
5y ago
CSRF tokens have overhead and they have to be implemented for all inputs which isn't trivial (judging by amount of CSRF related vulnerabilities disclosed in hacker one reports). I think the intention here is to make cross site requests
145.
▲
by
aj3
5y ago
It's not FUD. There are protections, but csrf tokens are a workaround while these headers are more akin to proper solution. Also, it won't magically make CSRF obsolete same way Origin header and CORS didn't make CSRF obsolete
146.
▲
by
aj3
5y ago
That’s not much of a router with just two ports and no WiFi.
147.
▲
by
aj3
5y ago
There's no indication that company was doing anything illegal though.
148.
▲
by
aj3
5y ago
She’s not a native English speaker, fine. That doesn’t seem like a disqualifier to me.
149.
▲
by
aj3
5y ago
Even makefiles are Turing complete.
150.
▲
by
aj3
5y ago
Even if hypothetically there was such a strange bug in your piano and you decided to exploit it by recording copyrighted music and redistributing it, you would be accountable for it, not a piano. This analogy train went too far, don't
More ›