Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cypherg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
121.
▲
by
cypherg
9y ago
no different than if you accidentally leave an S3 bucket exposed to the internet. It's negligence either way.
122.
▲
by
cypherg
9y ago
always has been if the contents of the mail are sensitive
123.
▲
by
cypherg
9y ago
The best recent article on Shelley and Frankenstein: http://www.nybooks.com/articles/2017/12/21/frankenstein-out-... Includes reviews of: Frankenstein, Or, The Modern Prometheus: Annotated for Scientists
124.
▲
by
cypherg
9y ago
link to the in the wild exploitation or get the fuck out. Most over-hyped bug of 2018 /smh EternalBlue was 1000x worse than this but had a more boring name.
125.
▲
by
cypherg
9y ago
after long periods of sitting, you end up having to confront pain very closely. When you inspect it with your meditating mind, you can actually see that it isn't directly "hurting you". Instead the pain is just recognized for
126.
▲
by
cypherg
9y ago
The author doesn't working in infosec or the IC, and the article reads like it.
127.
▲
by
cypherg
9y ago
shorts + tshirt nearly everyday. Some people dress nicer, but no one honestly seems to care at all. I love that my company culture allows for this. Our founders wear tshirts and hoodies.
128.
▲
by
cypherg
9y ago
yeah, reCAPTCHA is not CAPTCHA mate. reCAPTCHA isn't even allowed in CN. If you're looking for an international captcha service, peep funcaptcha
129.
▲
by
cypherg
9y ago
tl;dr horrible php apps with zero security can be pwned with decades old vulnerabilities. <looks right> <looks left> uh huh. About as impressive as popping calc on an unattended computer at bestbuy. If you want to learn web secu
130.
▲
by
cypherg
9y ago
depends what kind of security researcher. AppSec is p hot rn. Mobile sec is p hot. Browser security research can still advance quite a ways. ExploitDev is always popular. Just depends what niche you want to go into. Once you know your niche
131.
▲
by
cypherg
9y ago
this is an obvious parody
132.
▲
by
cypherg
9y ago
I normally send to admin@, abuse@, phishing@, and hope that at least one don't get kicked back.
133.
▲
by
cypherg
9y ago
Don't use any social media. Don't use the same handle/screenname twice. Don't allow javascript. Do use unique 'throw away' email addresses. Do use unique/long passphrases for everything. Do use Tor browser
134.
▲
by
cypherg
9y ago
reinstall.
135.
▲
by
cypherg
9y ago
Same thing happened less than a year ago (blog heavily downplayed it) https://www.onelogin.com/blog/august-2016-incident
136.
▲
by
cypherg
9y ago
^^this. There are a few other tricks to reveal the old/true IP, but adding CF slows many/most DDoS attacks depending how it's configured.
137.
▲
by
cypherg
9y ago
:yawn: people just re-using creds already dumped online Basically a non-story/product placement if I've ever seen one
138.
▲
by
cypherg
9y ago
12+ yr exp in security default/dev/test/guest accounts+passwords with easy to guess credentials exposing servers and services to the internet when not needed (memcached, hadoop, mongo, etc) Insecure Direct Object Reference No
139.
▲
by
cypherg
9y ago
well written blog post imho
140.
▲
by
cypherg
9y ago
it's considered best security practice to do so
141.
▲
by
cypherg
9y ago
aka, being a Flexitarian
142.
▲
by
cypherg
10y ago
https://en.wikipedia.org/wiki/The_Bridge_(2006_documentary_f... "The Bridge is a 2006 British-American documentary film by Eric Steel spanning exactly one year (365 days) of filming at the famed Golden Gate Bridge
143.
▲
by
cypherg
10y ago
There isn't a single reputable one that I know of.
144.
▲
by
cypherg
10y ago
About 3 and half years late with this headline, geez. http://www.slideshare.net/nikhil_mittal/power-shell-forpenet... Next headline from Windowsitpro: AV isn't as effective as you think smh
145.
▲
by
cypherg
10y ago
Little bit late on the post I'd say. I started seeing LaCroix at every single startup around 2013. It's the only logical choice. No sugar, no calories, check. Cold, fizzy, and tasty, check.
146.
▲
by
cypherg
10y ago
So, 60% of small companies are out of businesses? I think not. What you need to ask yourself is: what is considered a 'cyber attack'? Is spam a cyber attack? What about phishing? What about your DNS provider being DDoSed? Ransomwa
147.
▲
by
cypherg
10y ago
Vegas smells like cigarettes and garbage. Skip the long lines and absurd Vegas expenses and watch the talks from YouTube.
148.
▲
by
cypherg
10y ago
I'm also going to be talking a bit about WPAD in my Blackhat talk this year. To over simplify: attacker stays at AirBnb/rental, attacker pwns local router and adds their dns server, attacker listens for wpad request and respond wi
149.
▲
by
cypherg
10y ago
This is what modern corporate hacking looks like.
150.
▲
by
cypherg
10y ago
Psycho-Pass, Serial Experiments Lain, Neo Tokyo, Akira, Ghost In The Shell (1995)
More ›