Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bensedat
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
Table of deprecated HTML tags
(cdn.rawgit.com)
3 points
by
bensedat
12y ago
|
0 comments
32.
▲
by
bensedat
13y ago
Also just wanted to mention: if you run a Rails app it's worth subscribing to the rubyonrails-security google group. Low traffic except for blasts like these to alert you to urgent patches.
33.
▲
Rails XSS vulnerability in number formatting (CVE-2014-0081)
(groups.google.com)
78 points
by
bensedat
13y ago
|
23 comments
34.
▲
by
bensedat
13y ago
Sorry about that! Things should be working again now :)
35.
▲
by
bensedat
13y ago
I've run into that before on VPNs using AWS. Likely the public IP my server is using was used for abuse before I got it, especially as they usually only stick very ephemerally unless you upgrade to an Elastic IP.
36.
▲
by
bensedat
13y ago
Thank you very much for the timings and pull request!
37.
▲
by
bensedat
13y ago
This VPN won't anonymize any traffic, just encrypt the traffic between you and the server. The Rackspace account would be tied to you, so any piracy-type violations will go to them first, which they will pass along to you.
38.
▲
by
bensedat
13y ago
Will do!
39.
▲
by
bensedat
13y ago
Definitely agree. We hopefully answer some of those questions on our FAQ ( https://www.tinfoilsecurity.com/vpn/faq ). We also link to the script we run if you want to set it up yourself.
40.
▲
by
bensedat
13y ago
Yeah, mobile support was a bit tricky to set up for us as well, but we managed it with just OpenVPN. The OpenVPN app for iPhone at least was able to be configured without too much headache, although it only supports a subset of the OpenVPN
41.
▲
by
bensedat
13y ago
Looks like Chromebooks may support it right out of the box: https://support.google.com/chromeos/answer/1282338
42.
▲
by
bensedat
13y ago
This answer possibly explains some of the differences between the two: http://superuser.com/a/423615
43.
▲
by
bensedat
13y ago
Oops, a lot of that looks to be coming from the article share links. Sorry!
44.
▲
by
bensedat
13y ago
Good point! I made the change when using the VPN at DefCon but haven't updated the post. I'll do that now.
45.
▲
by
bensedat
13y ago
Definitely true that cheaper is definitely possible, but a DigitalOcean droplet or an EC2 micro can be pretty cheap and you don't have to worry about the other VPN clients as much.
46.
▲
Don't Get Pwned on Public WiFi: Use Your Own VPN
(tinfoilsecurity.com)
168 points
by
bensedat
13y ago
|
123 comments
47.
▲
by
bensedat
13y ago
Good call! The more you can use the principle of least-privilege the easier things tend to be in the long run.
48.
▲
Stop Paying For SSL Certificates You Don't Need
(tinfoilsecurity.com)
21 points
by
bensedat
13y ago
|
10 comments
49.
▲
by
bensedat
13y ago
That's normally very true. What we didn't say in the article was that we have some customers whose corporate IT departments haven't upgraded yet and we didn't want to drop them on the wayside :)
50.
▲
16% of web vulnerabilities are still XSS
(tinfoilsecurity.com)
19 points
by
bensedat
13y ago
|
9 comments
51.
▲
by
bensedat
13y ago
https://www.tinfoilsecurity.com is a hosted automated security tool (Disclaimer: I work for Tinfoil)
52.
▲
by
bensedat
14y ago
Ah, that solves that :) I've seen recommendations of using Github Pages instead, but again I can't find any official Github stance on it. I'm guessing they reserve the right to cut you off if you start using large amounts of bandwidth.
53.
▲
by
bensedat
14y ago
This looks quite awesome! As a quick suggestion, the wiki ( https://github.com/polychart/polychart2/wiki ) recommends using github as the CDN which I thought was highly discouraged. However I can't find any official stance on this anymore..
54.
▲
by
bensedat
14y ago
Frameworks like Rails or Django offer options to encrypt or sign session cookies, but any other cookies are often left up to the developer to take care of. The HttpOnly and Secure flags are important to remember as well because otherwise a
55.
▲
by
bensedat
14y ago
(I work with/for Borski) Disagreement is one of the things that I think we tend to be pretty open with at Tinfoil. Not everyone has to agree with a decision, but they always get airtime to voice any concerns and for those to be addressed or
56.
▲
by
bensedat
14y ago
We also are seeing a small group of apps with vulnerable applications even after upgrading to Rails 3.2.11, possibly due to a rogue middleware or other library. Disabling XML parsing entirely is one approach (see http://news.ycombinator.co