Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cws
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
cws
8y ago
As of this writing, the fake Postman extension appears to have been removed from the Chrome extension store. Huzzah!
32.
▲
by
cws
8y ago
I just searched for the fake Postman extension again and it appears to have been removed. Hurray!
33.
▲
by
cws
8y ago
Yeah, that is incredibly frustrating. It seems to me that many of these types of scams target general consumers, piggybacking on legitimate app's names to get a few thousand people to pay a buck or give you some personal info, etc. The
34.
▲
by
cws
8y ago
Totally. This extension was trying to be stealthy about exfiltrating data...but it wasn’t trying that hard. As noted in the article, the same developer had at least one other extension using the same code to obfuscate and exfiltrate data. S
35.
▲
by
cws
8y ago
Yep that’s a great point. That deprecation probably contributed to the gap that the malware uploader exploited. People expect an extension called postman, and they find it. Their guard is down and they download the fake one. I don’t know th
36.
▲
by
cws
8y ago
It was sending off URLs visited by the host machine. Browsing history, essentially, which could be benign except that when your machine is inside a corp network you might be visiting all kinds of internal resources with URLs that shouldn’t
37.
▲
by
cws
8y ago
Here’s a ZDNet article about the same extension https://www.zdnet.com/article/industrial-espionage-fears-ari...
38.
▲
by
cws
8y ago
Yep. Pretty hard to police. Unlikely to be removed until it gets quite a lot of attention.
39.
▲
by
cws
8y ago
It is a network traffic analysis product. You send it traffic via port mirror and it analyzes for shady behavior. Here’s the main overview of what it is https://www.extrahop.com/products/security/
40.
▲
We busted a fake Chrome extension that was trying to steal data
(extrahop.com)
108 points
by
cws
8y ago
|
32 comments
41.
▲
The NSA Doesn't Need Zero-Days to Own You
(extrahop.com)
3 points
by
cws
10y ago
|
0 comments
42.
▲
by
cws
10y ago
This approach will likely be most useful for large enterprises that get attacked, since they're more likely to have a buffered packet capture of network traffic. This is still incredibly powerful given that most ransomware-prevention m
43.
▲
Recovering Ransomware-encrypted files from packet capture
(extrahop.com)
6 points
by
cws
10y ago
|
2 comments
44.
▲
For ransomware detection, behavior beats signatures
(extrahop.com)
5 points
by
cws
10y ago
|
0 comments
45.
▲
Network Performance Monitoring Is Dead
(networkworld.com)
18 points
by
cws
10y ago
|
0 comments
46.
▲
by
cws
11y ago
Fair enough. Preventing ransomware from getting all the way through is a worthy goal as well. The fewer files they can encrypt, the better. It's hard to stop individual users from download malware onto their own machines, but stopping
47.
▲
by
cws
11y ago
The headline refers to a different narrative that comes in about the middle section of the post, where a ransomware attack on a separate healthcare org was successfully thwarted (and thereby didn't make it into any headlines)
48.
▲
We stopped one healthcare ransomware what about the rest?
(extrahop.com)
9 points
by
cws
11y ago
|
4 comments
49.
▲
by
cws
11y ago
Fair enough. It is a blog on a company website, and the topic of the blog is relevant to the product. Pretty standard in my eyes. I would argue the "Message to Our Customers" from Apple that sat on top all day also had a fair bit
50.
▲
by
cws
11y ago
Valid point. An out-of-band network tap is definitely a pretty insider-y term to the networking community. What it means is that there's a device sitting in a company's datacenter that can receive a copy of all the traffic flowing
51.
▲
by
cws
11y ago
Good question. The statement was made by the Chief of Tailored Access Operations at the NSA, so that's some pretty high level brass. I don't know the answer, but I'd guess it is something the brass is aware of and maybe frust
52.
▲
The NSA's worst nightmare
(extrahop.com)
36 points
by
cws
11y ago
|
12 comments
53.
▲
How much data does the Super Bowl create?
(extrahop.com)
5 points
by
cws
11y ago
|
0 comments
54.
▲
Finding the ghosts in my machines via DHCP troubleshooting
(extrahop.com)
3 points
by
cws
11y ago
|
0 comments
55.
▲
Quiet time: the secret to finding resource leaks
(extrahop.com)
5 points
by
cws
11y ago
|
0 comments
56.
▲
by
cws
11y ago
Good discussion of tinygrams, nagle delays, and the role restricted MTUs play in them on StackOverflow too: http://stackoverflow.com/questions/2421107/how-does-sending-...
57.
▲
by
cws
11y ago
Loved this post. So prescient. I was exposed to Amdahl's law first through this blog post about how the concept can be leveraged for competitive advantage. Always love seeing how the technicals affect the biz side of things. https:&#x
58.
▲
Network Engineers: Become an ExtraHop Ambassador
(extrahop.com)
2 points
by
cws
11y ago
|
0 comments
59.
▲
by
cws
11y ago
I find digging into someone else's code incredibly intimidating and I like hearing about other people's approaches to this challenge. If anyone else has tools or processes they use to get oriented in a new codebase I'd love t
60.
▲
Learning a new codebase? Static Code Analysis is your friend
(extrahop.com)
9 points
by
cws
11y ago
|
1 comments
More ›