Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bdelay
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
bdelay
2y ago
How much notification did you give the developers before you disclosed? Did you enforce a timeline?
2.
▲
by
bdelay
3y ago
If you're new, it's the same advice as any other field. Find a way to stand out. Build a portfolio, have great grades, come from a good university program, ping contacts from your alumni network, do bug bounties, find and fix issu
3.
▲
by
bdelay
3y ago
It looks like you made the best of a frustrating situation and, at the very least, have an excellent piece for your portfolio. With the rise in number of new security engineers all competing for few "security research" jobs (secur
4.
▲
by
bdelay
7y ago
I took Seacord's virtual class (CMU SEI? Can't remember) on Secure C coding a few years back and own, love, and regularly use the The CERT C Secure Coding Standard. I learned from K&R, but highly recommend Seacord's books
5.
▲
by
bdelay
7y ago
See the Note from Harman section. Hence, as the check wasn't working, I never ran into the check. Dat file signatures may very well be in the header or stored somewhere else.
6.
▲
by
bdelay
7y ago
Thanks! I wish there was a service I could pay for where I could ask lawyers vague security-research related questions like this. Right now I wouldn't even know where to begin looking for a lawyer that would be an authority on this typ
7.
▲
by
bdelay
7y ago
Not sure. Have an extra Tesla you can send me?
8.
▲
by
bdelay
7y ago
Okay, that's really cool. Tempted to see if I can get some AWS credits or spend a bit of cash and throw an 8xGPU instance at this for a few days...
9.
▲
by
bdelay
7y ago
Never assume anything. Well done. :)
10.
▲
by
bdelay
7y ago
I agree, but I don't have a consulting-firm/reputation/team of lawyers etc. to hide behind. Reporting flaws to companies related to embedded is often still scary today. The point of this is that hey, this isn't actually
11.
▲
by
bdelay
7y ago
You are correct. I don't believe those accounts worked over ssh due to a lack of password, just local serial.
12.
▲
by
bdelay
7y ago
Two reasons I didn't do that: 1. I believe Harman had a previous device hacked back around 2014 due to a weak shadow hash. My guess was that they learned their lesson and made the password more complex. An easy way to test would be to
13.
▲
Jailbreaking Subaru StarLink
(github.com)
4 points
by
bdelay
8y ago
|
0 comments
14.
▲
by
bdelay
8y ago
My guess is that yes, absolutely, but very few people know about it / a Doctor or nurse was blamed. Medical system security does not seem very good. When I was operating in the area a while back, one comment I kept seeing was similar t
15.
▲
by
bdelay
8y ago
Just read the r7800 had the best range for an all-in-one unit. Not sure if it's true, but it has been an amazing router. I picked one up for myself -- they are 130$ refurbished on Amazon every now and then. To answer your question: I h
16.
▲
by
bdelay
8y ago
Parents live in a smaller town with two awful ISP selections. They had a bunch of WiFi devices on an ISP router and the connection quality and latency was just terrible when more than one device was in use and any bandwidth intensive servic
17.
▲
by
bdelay
9y ago
Well done to the author. I always found working on more obscure systems to be a lot more entertaining as a hobby and I'd definitely recommend it -- you'll almost never run into the issue of another researcher coming out with somet
18.
▲
by
bdelay
10y ago
I don't think anyone with experience hacking kindles believed it was a permanent solution. Unfortunately, most of the technical expertise in that area is fleeting. I'd recommend an older Kindle if you want to get root easier. 5th
19.
▲
by
bdelay
10y ago
I don't believe Amazon officially pays for security flaws. They ended up sending me a free Kindle (pretty funny) and got an interview out of it. That didn't end up going anywhere, but I got a heck of a lot further than the black h
20.
▲
by
bdelay
10y ago
Started out cracking software on embedded systems a long time ago. That led to an understanding of ASM and reverse engineering. Going from there to exploitation isn't a giant leap. There's quite a few books on the subject. Hacking
21.
▲
by
bdelay
10y ago
Correct. At the time, this worked on the Paperwhite 2, 3, Voyage, and Touch. Forgot which version of the touch, they update that one a lot. I'll try to clarify that a bit better when I get some time. While this exploit is obviously clo
22.
▲
by
bdelay
10y ago
As mentioned, I think the most popular use is for custom covers. Recent firmware versions show that Amazon might be slowly working towards this as a feature. As the guy who wrote this, I don't use any of the addons. Just did it for fun
23.
▲
Jailbreaking the Kindle
(github.com)
306 points
by
bdelay
10y ago
|
86 comments