Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
davis_m
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
davis_m
13y ago
I was referring to calling it unauthorized access. If I do this to my own machines, which is how I wrote and tested this code, then it is entirely authorized. I would agree that collecting session ids on systems that you do not own or have
62.
▲
by
davis_m
13y ago
Do you have the same feelings about the Rapid7 team? What about the guys at Tenable? Heck, the Offensive Security guys are making an entire Linux distro that is nothing more than "evil hacker tools". Surely there are countless
63.
▲
by
davis_m
13y ago
Many people have commented on the legality of using this software. I didn't think it needed pointing out that using this on servers you do not own is strictly against the law. My only reasons for writing this is to show exactly what
64.
▲
by
davis_m
13y ago
Which only applies if you were to do it to systems that you aren't authorized to use it against. Simply creating and testing the code on your own servers is far from unauthorized access. If it were anyone who had posted any PoC code
65.
▲
by
davis_m
13y ago
I am literally just parsing the output of the original PoC.
66.
▲
by
davis_m
13y ago
If this were true, the Rapid7 guys would have been in jail long ago. This doesn't do anything more than the original PoC, but shows another reason for administrators to update their machines.
67.
▲
Using Heartbleed PoC for Hijacking User Sessions En Masse
(michael-p-davis.com)
43 points
by
davis_m
13y ago
|
23 comments
68.
▲
by
davis_m
13y ago
Seems more like "The customers we don't have want what we don't have"
69.
▲
Ask HN: Looking for examples of personal wallboards
2 points
by
davis_m
13y ago
|
0 comments
70.
▲
by
davis_m
13y ago
The former model still had SATA cards that the backplanes connected to. I think the biggest win for them is the fact that the backplanes were one of the more error prone pieces in the box. On a side note, each of the new SATA cards can sup
71.
▲
by
davis_m
13y ago
I'm sure that the move to direct wire was done purely because of the former backplanes being error prone, but the fact that they realize finding the parts is difficult for others and mentioning it in the blog post shows that the guys a
72.
▲
by
davis_m
13y ago
Is there any trick to getting a beta to try this out?
73.
▲
by
davis_m
13y ago
It is very easy to only allow others to pull your repository. It then functions much the same way as an open source project where pull requests are required to get code into the main repo.
74.
▲
by
davis_m
13y ago
The web client is a horrible experience on the Mac. The design decisions of the group that put it together are horrible. Why in the world did they think that sticking the app to the corner of my screen is okay? Why does it follow me acro
75.
▲
by
davis_m
13y ago
The email I received from Cloudant: "Hello-- Today is an exciting day for Cloudant as a business: We have agreed to be acquired by IBM [press release]. What does that mean for you as a customer? Not too much changes, actually. The key
76.
▲
IBM to Acquire Cloudant
(www-03.ibm.com)
137 points
by
davis_m
13y ago
|
23 comments
77.
▲
Biggest DDoS ever aimed at Cloudflare’s content delivery network
(arstechnica.com)
3 points
by
davis_m
13y ago
|
0 comments
78.
▲
by
davis_m
13y ago
I still don't understand why they allow people to edit other people's comments in the first place.
79.
▲
by
davis_m
13y ago
Backblaze's data shows that the number of errors is largely related to the age of the drive. Because the older drives are from before Hitachi was acquired by WD, it is going to take a few more years for the brands to equalize if they
80.
▲
by
davis_m
13y ago
I would find this very useful for downloading TV episodes of currently running shows. You could have a single torrent for a TV show, and all new episodes would download automatically. My current method involves some hacked together RSS fee
81.
▲
by
davis_m
13y ago
If a user is willing to press the button, a PIN isn't going to stop them. Your app is decreasing security in favor of usability, which is not something look for when they are looking to implement two factor auth. I think anyone who wo
82.
▲
by
davis_m
13y ago
A PIN would do nothing to keep a user from being tricked into authorizing an attacker's login.
83.
▲
by
davis_m
13y ago
In this model, all you have to do is time the authorization request appropriately. If an attacker can time their authorization at the same time that the user is logging in, a large number of users are simply going to authorize both request
84.
▲
by
davis_m
13y ago
From your home website, it looks like you are relying on users deciding if they should authorize a request based on OS, web browser, ip address, and location. Users are going to essentially ignore ip address. OS, web browser, and location
85.
▲
by
davis_m
13y ago
What methods are you using to make sure that an authorization comes from an authorized phone?
86.
▲
by
davis_m
13y ago
Are you concerned that it is a lot easier to trick users into clicking a button to authorize the login?
87.
▲
by
davis_m
13y ago
The same thing that prevents the merchant from charging the same card multiple times, or charging more than was agreed upon. Nothing.
88.
▲
by
davis_m
13y ago
Using pam_abl to disallow logging into an account that is being hit sounds like a easy way to DoS a box.
89.
▲
by
davis_m
13y ago
Only if the browser supports HSTS. Many do not, especially mobile browsers.
90.
▲
by
davis_m
13y ago
That statistic of 50% professors being adjunct is not cited, and from searching online appears to come from the SEIU, which is a group who's goal is to unionize adjunct faculty. The report it self is not available, and it has been quo
More ›