Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bwblabs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
bwblabs
3y ago
Researcher of the leak. I got a question from NOS to test the security of a 6-length short code link ( https://www.klm.nl/s/xxxxxx ) used in text messages. I've tested two ranges (FAbxxx and KLmxxx), which gave a co
32.
▲
Air France-KLM leaked estimated > 500M travel data via 6-char link codes (Dutch)
(nos.nl)
7 points
by
bwblabs
3y ago
|
2 comments
33.
▲
by
bwblabs
3y ago
Researcher of the leak. I got a question from NOS to test the security of a 6-length short code link ( https://www.klm.nl/s/xxxxxx ) used in text messages. I've tested two ranges (FAbxxx and KLmxxx), which gave a co
34.
▲
by
bwblabs
3y ago
It sounds 'late' to make it a docker container, but actually getting the IPv6 testing working with docker was challenging, only recently some IPv6 issues got solved, and the project needs the experimental and ip6tables docker flag
35.
▲
Internet.nl Score of news.ycombinator.com: No IPv6, DNSSEC, TLS1.3, RPKI ROA
(internet.nl)
3 points
by
bwblabs
3y ago
|
3 comments
36.
▲
by
bwblabs
3y ago
The news.ycombinator.com setup isn't really modern: - no IPv6 address for the webserver - no DNSSEC - no RPKI ROA for webserver BGP routes - use of TLS 1.0 and no TLS 1.3 - use of insecure* ciphers - CSP with 'unsafe-inline'
37.
▲
RPKI (BGP signing) requirement for new and existing systems of Dutch government
(forumstandaardisatie.nl)
5 points
by
bwblabs
4y ago
|
0 comments
38.
▲
by
bwblabs
4y ago
Shameless plug of my TOTP in '4' lines of PL/pgSQL: https://gist.github.com/bwbroersma/676d0de32263ed554584ab132...
39.
▲
by
bwblabs
4y ago
Note the Wizz Air anti-bot statement ( https://skift.com/2020/08/31/wizz-airs-odd-fee-for-buying-a-... ). The "System Surcharge Fee - Applicable to bookings made by automated systems" of € 10 is liste
40.
▲
by
bwblabs
5y ago
250k is off by one, actually 249999 entries: $ curl -s https://cdn.smoot.apple.com/static/autofill_tld_whitelist_url | jq '.tlds|length' 249999
41.
▲
by
bwblabs
5y ago
Dutch CERT has a advisory about it: https://www.ncsc.nl/actueel/advisory?id=NCSC-2022-0014 (in Dutch) with all relevant CVE codes, but the RCE in http.sys is rated the highest, that is CVE-2022-21907.
42.
▲
by
bwblabs
5y ago
Update NOW, patch is out. CVSS:3.1 9.8/8.5
43.
▲
Windows HTTP Protocol Stack RCE Vulnerability (CVE-2022-21907)
(msrc.microsoft.com)
4 points
by
bwblabs
5y ago
|
2 comments
44.
▲
by
bwblabs
6y ago
Summary of all European (EU+) apps initiatives: https://github.com/ct-report/summary
45.
▲
by
bwblabs
6y ago
After a quit scan of the protocol and API outlined by Apple and Google: it looks privacy & technically sound to me. I would remove the Android FAILED_REJECTED_OPT_IN status code ( https://www.blog.google/documents/55
46.
▲
by
bwblabs
7y ago
Some TUDelft students from The Netherlands are trying just that: https://youtu.be/DI4V32gNzYk?t=120 (in Dutch)
47.
▲
by
bwblabs
7y ago
Reminds me of the !sql in rust-postgres-macros: https://github.com/sfackler/rust-postgres-macros#sql With the difference: it uses the PostgreSQL parser, not a generic SQL parser
48.
▲
by
bwblabs
7y ago
Sapper is very useful and has quite some nice properties: - automatic SSR (Server Side Rendering) - possibility to export to server-less plain HTML/CSS/JS - option to resource preload/fetching on mouseover/touchstart (a
49.
▲
Dockerized Fullstack Mailserver
(github.com)
4 points
by
bwblabs
7y ago
|
1 comments
50.
▲
by
bwblabs
7y ago
Read tip: https://blog.smartdec.net/you-do-not-need-blockchain-eight-p... previous HN talk: https://news.ycombinator.com/item?id=19225857
51.
▲
by
bwblabs
7y ago
Ever looked at https://svelte.dev ? https://youtu.be/gJ2P6hGwcgo?t=1055 https://twitter.com/wolfr_2/status/1164621105476329472
52.
▲
by
bwblabs
7y ago
I use KeePassXC in multiple groups with different synchronization software (Dropbox, self hosted client side encrypted Seafile, etc.), for each group I use a different .kdbx and .key (of course that one not synchronized). There are multiple
53.
▲
by
bwblabs
7y ago
I use to (ab)use their Outlook Social Connector (OSC) from the now gone API ( https://outlook.linkedinlabs.com/osc/people/details ), they stopped it in 2015. I used it just to get names and profile images for easy o
54.
▲
by
bwblabs
8y ago
"Security Analysis of Estonia's Internet Voting System" @31C3 (December 2014) https://media.ccc.de/v/31c3_-_6344_-_en_-_saal_1_-_201412281... (starts at 20:26) They failed on quite some points, I cannot
55.
▲
by
bwblabs
8y ago
Better use an old printer indeed, since modern printers can have tracking dots with a timestamp and a serial number of the printer, which both can give away the backdating ( https://en.wikipedia.org/wiki/Machine_Identifi
56.
▲
by
bwblabs
8y ago
Or faking/randomizing your UA? Some sites (e.g. YT) serves other image formats based on the UA string.
57.
▲
by
bwblabs
8y ago
I've looking into this issue for the last 2 days: The APK we all looked into is IronChat-3.40-release.apk [1], after decompiling I think it is a copy/fork of Conversations version 1.14.6 with a few more commits until October 13th
58.
▲
by
bwblabs
8y ago
We (OpenStateFoundation) scanned 15070 Dutch (.nl) Symantec certificates that are in the Certificate Transparency via crt.sh, which are valid for 45822 different domain names (including wildcard certificates), which of 26971 are below the .
59.
▲
1/5 still use old Symantec certs (Certificate Transparency scan)
(openstate.eu)
4 points
by
bwblabs
8y ago
|
1 comments
60.
▲
by
bwblabs
8y ago
I had some years I thought the same way, however: From a DNS point of view: you can't have CNAME's on your root (can be useful, especially in some DNS load balancing situations, or load balancing on third party providers) From HTT
More ›