Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cablej
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
A Security Analysis of Voatz [pdf]
(internetpolicy.mit.edu)
3 points
by
cablej
7y ago
|
1 comments
2.
▲
by
cablej
7y ago
There are fundamental privacy risks to using the HIBP Pwned Passwords service which should be considered when implementing it. See my writeup here — https://cablej.io/blog/k-anonymity/ . In short, despite claims of
3.
▲
Attacks on applications of k-anonymity for password retrieval
(cablej.io)
2 points
by
cablej
7y ago
|
0 comments
4.
▲
by
cablej
8y ago
As a bug bounty hunter, this is nowhere near normal. The average payout for a single vulnerability is over $500, so even finding just one vulnerability a month would be more than mentioned in the article. Full-time bug bounty hunters often
5.
▲
Bypassing Payment Using Webhooks
(lightningsecurity.io)
1 points
by
cablej
9y ago
|
0 comments
6.
▲
by
cablej
9y ago
I've got my 96-year-old grandmother using Uber - https://www.gosmartride.com :)
7.
▲
by
cablej
9y ago
Being involved in bug bounties, don't be fooled by what happened here. This is exactly a case of extortion: the hacker had downloaded user data from Uber, and was paid off in order to delete the files. This differs from an actual bug b
8.
▲
Don't Trust the Host Header for Sending Password Reset Emails
(lightningsecurity.io)
3 points
by
cablej
9y ago
|
0 comments
9.
▲
by
cablej
9y ago
As someone involved in bug bounties, this was completely different from a traditional bug bounty reward. Uber disguised this payment as a "bug bounty" to hide what it actually was -- a ransom payment to get the hacker to destroy t
10.
▲
Exploiting and Protecting Against Race Conditions
(lightningsecurity.io)
1 points
by
cablej
9y ago
|
0 comments
11.
▲
This 17-year-old hacked the Air Force
(marketplace.org)
3 points
by
cablej
9y ago
|
0 comments