Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bradleyjkemp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
bradleyjkemp
9mo ago
I'd like to see some examples of before/after code samples which have the same hash. I can see this will be tolerant of simple renames, but seems unlikely this hash will survive any real refactor of code
2.
▲
by
bradleyjkemp
1y ago
I believe this is another case of abusing GitHub for visibility, not actually doing anything meaningful open source The code in the repo just seems to be connection code ("provides a way for anybody to test our Redis synchronization se
3.
▲
by
bradleyjkemp
2y ago
Oh some of them definitely use a real reCAPTCHA, hCAPTCHA, or Turnstile widget. It actually useful sometimes to track the same API key being used across multiple different domains But yeah, I wouldn't even know where to report those AP
4.
▲
by
bradleyjkemp
2y ago
It's really common now for phishing kits to use interstitial pages that require solving a captcha before the actual phishing content is shown Victims just click through the captcha without thinking, but it makes automatic verdicting by
5.
▲
by
bradleyjkemp
2y ago
A typo I think, should be BM25F. From Wikipedia: > BM25F (or the BM25 model with Extension to Multiple Weighted Fields) is a modification of BM25 in which the document is considered to be composed from several fields (such as headlines,
6.
▲
by
bradleyjkemp
2y ago
Cool! Have you run this against a corpus of known ransomware samples to see how well it performs?
7.
▲
by
bradleyjkemp
3y ago
Appears the blogpost text is from a LinkedIn post (where the hashtags are clickable): https://www.linkedin.com/posts/zayarni_qdrant-summer-of-code... Nothing more interesting than copy-paste I'm afraid
8.
▲
Text Search at Scale with ClickHouse
(tinybird.co)
3 points
by
bradleyjkemp
3y ago
|
0 comments
9.
▲
YARA beyond files: extending rules to network IoCs
(blog.virustotal.com)
2 points
by
bradleyjkemp
3y ago
|
0 comments
10.
▲
by
bradleyjkemp
3y ago
If you've got a load balancer (like Caddy) in front of your pods you can configure it to hold requests while the new pod comes up: https://twitter.com/bradleyjkemp/status/1486756361845329927 It's not per
11.
▲
Detecting phishing sites with high-entropy strings
(phish.report)
3 points
by
bradleyjkemp
3y ago
|
0 comments
12.
▲
Detecting phishing sites with high-entropy strings
(phish.report)
1 points
by
bradleyjkemp
3y ago
|
0 comments
13.
▲
Flake IDs and insensitive ticketing systems
(phish.report)
1 points
by
bradleyjkemp
3y ago
|
0 comments
14.
▲
Show HN: IOK – an open ruleset and DSL for detecting phishing kits
(phish.report)
2 points
by
bradleyjkemp
4y ago
|
0 comments
15.
▲
Humans who can RPC: securing staff access to 2000 microservices
(monzo.com)
2 points
by
bradleyjkemp
4y ago
|
0 comments
16.
▲
Humans who can RPC: securing staff access to 2000 microservices
(monzo.com)
6 points
by
bradleyjkemp
4y ago
|
0 comments
17.
▲
by
bradleyjkemp
4y ago
May want to double check that: domain data shows it was only registered today about an hour ago: https://client.rdap.org/?type=domain&object=doctree.dev It was definitely available to purchase when I commented
18.
▲
by
bradleyjkemp
4y ago
And it's not just DNS issues. The domain doesn't even seem to be registered: it's available for purchase... edit: No longer! Hopefully someone benevolent picked it up
19.
▲
by
bradleyjkemp
4y ago
Ah neat, yeah that's exactly what I need, thanks!
20.
▲
by
bradleyjkemp
4y ago
Oh, 100% I need some more docs on the page: it's definitely not foolproof. From my testing, it works even if the window is in the background somewhere but generally it stops working if you switch to a different tab within the same wind
21.
▲
by
bradleyjkemp
4y ago
Yup, that's my bad CSS I'm afraid. https://bulma.io explicitly resets the color of <a> tags inside a hero, so I need to figure out how to stop/override that
22.
▲
Show HN: Prevent your computer sleeping with just a webpage
(nosleep.page)
252 points
by
bradleyjkemp
4y ago
|
130 comments
23.
▲
by
bradleyjkemp
4y ago
I think this is "zero day" in the sense of no patch is available, not in the sense of skipping responsible disclosure. This has a CVE number allocated (CVE-2022-29072) and the README mentions 7-zip disputing that this is their pro
24.
▲
by
bradleyjkemp
5y ago
Good sentiment but so so tricky to get the wording right. You've got to write a sentence so perfect the fraudster can't pervert it or persuade the victim to ignore it. For your example, the fraudster could say "yes, your acco
25.
▲
by
bradleyjkemp
5y ago
Defense in depth is a worthy goal though You'll never get 100% of people remembering that advice 100% of the time. So how do you mitigate the situation when they forget?
26.
▲
Are you building features for phishers?
(bradleyjkemp.dev)
63 points
by
bradleyjkemp
5y ago
|
23 comments
27.
▲
by
bradleyjkemp
5y ago
2FA included in the free tier and there's even a 10% discount on the paid tiers if 2FA is enabled! That's an incredibly cool and generous offer
28.
▲
by
bradleyjkemp
5y ago
My principle for https://phish.report (a tool for semi-automating the reporting of phishing sites) is: do as much statically or server side rendered as possible. Deployment: Docker Compose. It's great to just set a DOCKER_H
29.
▲
by
bradleyjkemp
5y ago
Similar: https://ja3er.com/ which is formed by taking a bunch of (stable) attributes from your TLS handshake, appending them into a string, and hashing it. They've also done the correlation with User Agent and it'
30.
▲
by
bradleyjkemp
5y ago
I report a lot of phishing sites but it gets very annoying very quickly. As well as reporting to SafeBrowsing, etc. for each site you also need to look up the domain registrar and hosting provider (via WHOIS) and email them. Rather than do
More ›