Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alexbakker
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Bypassing app lock in Ente Auth
(alexbakker.me)
2 points
by
alexbakker
2y ago
|
0 comments
2.
▲
Bypassing app lock in Ente Auth
(alexbakker.me)
3 points
by
alexbakker
2y ago
|
0 comments
3.
▲
by
alexbakker
4y ago
Correct.
4.
▲
by
alexbakker
4y ago
You're right, it's been a while, but we actually issued a beta release for 2.1 today!
5.
▲
by
alexbakker
4y ago
There's a third option to switch from Google Authenticator to Aegis. You can simply scan those export QR codes of Google Authenticator with Aegis.
6.
▲
by
alexbakker
4y ago
Aegis is fully offline and doesn't have an official desktop application. You could of course create an export of your Aegis vault and import it in a third-party desktop application, like GNOME's Authenticator or OTPClient.
7.
▲
by
alexbakker
4y ago
It's just a group name for the two guys working on it. Source: I'm one of them (Hi!)
8.
▲
by
alexbakker
4y ago
This is amazing work! I was surprised to see that the reward was set at 10k initially. Granted, it was bumped to 75k later, but even that seems on the low side considering the degree of compromise that occurred here. I may have given up too
9.
▲
by
alexbakker
4y ago
I'm seeing this as well. While the amount of traffic has certainly decreased compared to the first couple of days after the CVE was announced, https://log4shell.tools is still being used by people every day.
10.
▲
by
alexbakker
5y ago
Glad to hear you like it!
11.
▲
by
alexbakker
5y ago
> android.permission.INTERNET is frankly hilarious since that permission no longer does anything (every app has access to the internet). This is incorrect. If an app doesn't specify this permission in its manifest, it cannot access
12.
▲
by
alexbakker
5y ago
It sucks to see your open source work being abused like this, and there's seemingly nothing we can do about it. Every now and then I scour the play store to see if I can find any Aegis clones. We've reported a couple that didn
13.
▲
Understanding the Impact of Apache Log4j Vulnerability
(security.googleblog.com)
1 points
by
alexbakker
5y ago
|
0 comments
14.
▲
by
alexbakker
5y ago
You're right, but this has always been the trade off with tools like this. You put some trust in the tool's authors and gain some insight in return. Remember the services that tested for Heartbleed (e.g. https://filippo
15.
▲
by
alexbakker
5y ago
I can't say I'm feeling the same. Still lots of people testing over at https://log4shell.tools almost a week after this vulnerability became widely known. Plenty of people still discovering they're vulnerable as w
16.
▲
by
alexbakker
5y ago
You're welcome! I'm glad you find it useful.
17.
▲
by
alexbakker
5y ago
I have a feeling this vulnerability is going to be with us for years. Shameless plug: I built a tool that assists in detecting whether you're vulnerable to this or the previous CVE: https://log4shell.tools . Just enter the J
18.
▲
Show HN: I built a tool that detects bad cases of the Log4j vulnerability
(log4shell.tools)
19 points
by
alexbakker
5y ago
|
0 comments
19.
▲
Show HN: Check if you're vulnerable to an egregious case of log4shell
(log4shell.tools)
4 points
by
alexbakker
5y ago
|
0 comments
20.
▲
by
alexbakker
6y ago
If you write down the secrets and the other parameters on paper, that would suffice as a backup as well. I'd recommend using Aegis' encrypted backup though.
21.
▲
by
alexbakker
6y ago
One of the authors here. We've gotten a lot of similar feedback lately. This is something we plan on addressing in a future release by introducing filter chips, either directly on the main view, or one tap away. Hopefully that'll
22.
▲
by
alexbakker
6y ago
One of the authors here. Yes! Aegis can scan the QR codes that Google Authenticator presents in the "Transfer accounts" screen. It's also possible to import directly from Google Authenticator's internal database if you
23.
▲
by
alexbakker
6y ago
One of the authors here. Recent versions of Aegis also come with an automatic backup feature, so that an export is created at a location of your choosing automatically every time a change is made to your entry list. Might be a little more c
24.
▲
by
alexbakker
6y ago
Thanks for your support! That's a fair point. We'll see what the feedback is like when we release initial support for icons packs and decide whether to include a pack out of the box after that.
25.
▲
by
alexbakker
6y ago
One of the authors here. Unfortunately, Google Drive and Dropbox only partially participate in Android's Storage Access Framework. In Aegis, exporting only requires the creation of a file, so that works with both. Configuring backups o
26.
▲
by
alexbakker
6y ago
One of the authors here. > Icon library for common websites using OTP Someone from the community is maintaining an icon pack for Aegis: https://github.com/aegis-icons/aegis-icons . We're currently working on mak
27.
▲
by
alexbakker
7y ago
Author here. I should have made this clear in the blog post, but I'd be interested in seeing boot logs from Pixel 3 (or newer) devices. If the firmware update failed on more devices than just mine, it would be good to know about that.
28.
▲
by
alexbakker
7y ago
The big question is indeed how many devices got themselves into this 'bad state'. Your guess is as good as mine.
29.
▲
by
alexbakker
7y ago
You're absolutely right about the excerpt. Fixed, thanks.
30.
▲
A mysterious bug in the firmware of Google's Titan M chip
(alexbakker.me)
238 points
by
alexbakker
7y ago
|
88 comments
More ›