Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aj3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
42 ms
·
211.
▲
by
aj3
6y ago
But neither syspatch nor sysupgrade apply to stable branch, meaning you'll be running release and if that's how you're keeping your desktop system updated - you're definitely using vulnerable browser, as in this scenario
212.
▲
by
aj3
6y ago
The OpenBSD documentation does not really make that balance clear to the new user though. And of course there is no mechanism for regular updates either. > New users should be running either -stable or -release. https://www.op
213.
▲
by
aj3
6y ago
But that's just not true, check out how often they rebuild Chromium for their stable branch.
214.
▲
by
aj3
6y ago
I doubt anyone manages to get with just the OpenBSD system on their desktop. Browsers in particular are a gaping security hole if not updated regularly.
215.
▲
by
aj3
6y ago
Yeah, well that's kind of my point. Recommending new users to install stable OpenBSD as their work/home PC/laptop is irresponsible, especially if the lack of updates (presented as stability / ease of maintanence) is expl
216.
▲
by
aj3
6y ago
> Setup cwm, some XTerms, Otter Browser/Chromium, and done. Chrome patched three high-priority security vulnerabilities last week. And OpenBSD 6.8 hasn't rebuilt their package since October 1, unless I'm missing something:
217.
▲
by
aj3
6y ago
> sysupgrade every six months, syspatch otherwise But that won't keep your system up to date with security patches, because OpenBSD does not rebuild binary packages.
218.
▲
Ask HN: Security-Oriented HN Alternative
1 points
by
aj3
6y ago
|
1 comments
219.
▲
by
aj3
6y ago
That's not how reproduction works though. Losing a limb has zero impact on that person's germline cells.
220.
▲
by
aj3
6y ago
In this case no information was "stored" after meeting a spider or getting bitten by it. Rather people who (by accident) had predisposition to avoid spiders happened to survive better.
221.
▲
by
aj3
6y ago
WTF is "generational memory"?
222.
▲
by
aj3
6y ago
Font "representing one poorly in a professional environment" sounds to me pretty much the same as insisting on strict dress code, banning facial hair, black or traditional hairstyles, etc.
223.
▲
by
aj3
6y ago
In practice, no. Meaning, typical Windows environments (especially corporate AD) provide so many privesc vectors, that no pentester has ever been stopped by this security boundary. Same goes to AMSI bypasses, etc.
224.
▲
by
aj3
6y ago
Did they make money?
225.
▲
by
aj3
6y ago
Why would you burn that sort of access when you can at the very least resell it? - https://www.blackhat.com/presentations/bh-europe-07/Langlois/Presentation/bh-eu-07-langlois-ppt-apr19.pdf - https:&#
226.
▲
by
aj3
6y ago
It's not just that a few species go extinct. Whole ecosystems change. In 100 years the environment might not be suitable for the species anymore (e.g. reintroduction of wooly mammoths would be a disaster today) due to global issues (te
227.
▲
by
aj3
6y ago
S/MIME does not protect from phishing.
228.
▲
by
aj3
6y ago
We still have Magic Wormhole though and it's awesome! (at least for techies) https://magic-wormhole.readthedocs.io/en/latest/welcome.html
229.
▲
by
aj3
6y ago
TOR brosser != TOR
230.
▲
by
aj3
6y ago
Why wouldn't it? IP only provides best-effort delivery anyway, yet TCP which is built on it makes the connections reliable. Similarly you can use IP which isn't anonymous to build strongly anonymous systems.
231.
▲
by
aj3
6y ago
If you know about the bug, but manufacturer does not provide any patches, you can still mitigate it, put in place detection measures or just stop using that software. You can't (necessarily) do those if you don't even know about t
232.
▲
by
aj3
6y ago
But simple networks and roaming users are perfectly fine with regular static file. I have no idea what user base this overengineered crap is catering but it seems equally useless both on (my) servers and laptops.
233.
▲
by
aj3
6y ago
Linux != UNIX
234.
▲
by
aj3
6y ago
Why don’t Apple buy ARM?
235.
▲
by
aj3
6y ago
Source seems to be Net Marketshare: https://www.netmarketshare.com/operating-system-market-share...
236.
▲
Linux Is Becoming the Windows Alternative Microsoft Never Wanted
(news.softpedia.com)
2 points
by
aj3
6y ago
|
2 comments
237.
▲
by
aj3
6y ago
> Firewalls do absolutely nothing once someone got your weakest link to click something and go to town. Well, fw would be effective if organizations used network segmentation effectively, but of course close to no one does that in practi
238.
▲
by
aj3
6y ago
Apart from some special cases like Wannacry/NotPetya, ransomware crews do only as much lateral movement as is required for privilege escalation. Once they have DA, they can just disable protections and push malware centrally through AD
239.
▲
by
aj3
6y ago
They used multiple wallets. They also posted a bunch of useless/ridiculous comments and memes, not sure why would anyone do that if the attack was carefully planned and automated.
240.
▲
by
aj3
6y ago
This sounds reasonable.
More ›