Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cscott
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Webbynode shutting down at the end of March
(webbynode.com)
1 points
by
cscott
11y ago
|
0 comments
2.
▲
by
cscott
12y ago
Decisions were made about certificate revocation based on assumptions about this code and Akamai customers ended up being exposed. Perhaps third-party security validation of such a critical piece of code should be a prerequisite before asse
3.
▲
by
cscott
12y ago
It comes down to intent. There are two distinct ways to evaluate Akamai's patch: 1. Did Akamai release the PoC patch to start a discussion about how to protect private keys and share their work as a starting point for changing the code
4.
▲
Are Bay Area technology companies situated like the OSI model?
(engineering.linkedin.com)
2 points
by
cscott
13y ago
|
0 comments
5.
▲
Do It Anyway: Why We Should Worry Less About Prior Security Research
(please.sabotage.me)
2 points
by
cscott
13y ago
|
0 comments
6.
▲
Want to ‘Change the World’? Come to San Francisco
(blogs.wsj.com)
2 points
by
cscott
14y ago
|
0 comments
7.
▲
by
cscott
16y ago
No doubt. Those who do not follow police officer instructions to produce identification, even in states without "stop and identify" statutes, will find themselves risking an obstruction charge. It may be dropped at the state/city attorney's
8.
▲
by
cscott
16y ago
Unless the state has a "stop and identify" statute on the books, you cannot be arrested for refusing to identify yourself. 24 states have such a statute. My new home state, California, has none.
9.
▲
Authentication Gap in TLS Renegotiation
(extendedsubset.com)
5 points
by
cscott
17y ago
|
0 comments
10.
▲
by
cscott
17y ago
Thanks for the feedback! The assumption is that you should consider your source code open and exposed to inspection by an attacker, not that it has been compromised. As a result, if any security control is dependent on "secret" functions or
11.
▲
by
cscott
17y ago
I'm concerned about the lack of revocation that comes with bundling a key in source. Shouldn't you warn people in your note that if the key is compromised, you're going to have a difficult time?
12.
▲
by
cscott
17y ago
Right you are, sir.
13.
▲
Typing The Letters A-E-S Into Your Code? You’re Doing It Wrong
(matasano.com)
258 points
by
cscott
17y ago
|
74 comments
14.
▲
by
cscott
17y ago
This is simply a re-application of device fingerprinting and voice verification that many banks are using to secure online banking. There are many things that can go wrong here, based on my previous experience dealing with these systems, bu
15.
▲
by
cscott
17y ago
As a hiring manager, my experience has been the opposite. When hiring staff members that need to be able to write documents as part of the job and explain things clearly, the cover letter can make a significant difference. Most good candida
16.
▲
Palm Pre impersonates an iPod to trick iTunes to sync
(nanocr.eu)
2 points
by
cscott
17y ago
|
0 comments
17.
▲
by
cscott
17y ago
Talk about contributing to the public health problem in our ERs. Emergency medicine in the US is in a horrible state. Overcrowding is one of the primary reasons. See: http://www.ama-assn.org/amednews/2009/01/19/prsb0119.htm One of the pri
18.
▲
by
cscott
17y ago
Employee performance reviews that enforce an arbitrary curve-based ranking or grading system often to do more harm than good. I have seen employees who have performed well all year get demolished by a performance review where they were rate
19.
▲
by
cscott
17y ago
Great story, and my favorite part was the link to the Slashdot iPod release story: "No wireless. Less space than a nomad. Lame."
20.
▲
by
cscott
18y ago
Agreed. I don't think there was any intentional deception either. However, don't forget the influence of the lobbyists hired by the security industry. Additionally, "non-profit" organizations involved with information security that see a po
21.
▲
by
cscott
18y ago
Executive orders to impacted entities would involve a much more formal chain of command and control than a direct kill switch from White House.
22.
▲
by
cscott
18y ago
There is a significant momentum building for stronger executive control over Internet connectivity to private-sector networks that are designated as "critical infrastructure." The proposed CyberSecurity Act of 2009 would allow the president
23.
▲
Final Report and Timeline of Fedora Server Compromise in 2008
(redhat.com)
3 points
by
cscott
18y ago
|
0 comments
24.
▲
by
cscott
18y ago
The key point of the article: "What's much more likely is that the Web, through its links, and Google, through its search algorithms, have inadvertently set into motion a very strong feedback loop that amplifies popularity and, in the end,
25.
▲
All hail the information triumvirate (Web, Google, Wikipedia)
(roughtype.com)
10 points
by
cscott
18y ago
|
3 comments
26.
▲
by
cscott
18y ago
Here's the info on the compromised support tools: http://blog.twitter.com/2009/01/monday-morning-madness.html
27.
▲
by
cscott
18y ago
Yes, they're taking a page out of Microsoft's playbook by using a blog post to respond in more detail to a security vulnerability. When executed well, it mollifies critics much better than the press release style of communication due to its
28.
▲
by
cscott
18y ago
If you accept credit card payment without SSL protecting the entry of the card and CVV2, you are in violation of PCI DSS standard 4.1. Depending on your relationship with your acquiring bank or payment processor, that will result in a passt
29.
▲
by
cscott
18y ago
What's slightly ironic is trust doesn't matter for the buyer. As long as you purchase your certificate from a CA well placed in the major browser vendors, you're good to go. Edit: Here's a list of Mozilla's included certificates: http://ww
30.
▲
by
cscott
18y ago
I'm surprised and a bit skeptical that every CA (except for one) randomizes serial numbers without it being published in a standard or guidance document somewhere. Best practice usually has something worse than a (n - 1) distribution.
More ›