Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
deepbreath
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
deepbreath
2y ago
The knockee PoC should also be straightforward, can use socat + udp-listen + fork with a script that checks that input matches `sha1sum(secret||num)||num` and `num>previously_seen_num`, and if so, adds an iptables rule. This should preve
2.
▲
by
deepbreath
2y ago
Don't have to do anything too complicated. Here's the knocker code in a short Bash script, produced by GPT4: ~ % gpt4 'write a very short bash script that takes the number stored in ~/.ssh/knock_seq, increments it b
3.
▲
by
deepbreath
2y ago
> At the point an attacker has remote code execution The attacker doesn't have remote code execution in the xz case unless they can speak to your port 22. Port knocking prevents them from doing so, provided they don't know how
4.
▲
by
deepbreath
5y ago
You're right, I guess it depends on what you choose A and B to be. For: A = OP supports Mozilla making money from address bar ads B = Mozilla is honest about making money from address bar ads "B -> A" (OP supports Mozilla
5.
▲
by
deepbreath
5y ago
Except it's not used correctly here. "A iff B" means "A implies B and B implies A". "I'd be willing to entertain, or even support, this way of them making money iff they spelled out honestly what they'
6.
▲
by
deepbreath
6y ago
> I don't even know how people can say this stuff with a straight face. It's not too difficult to do so, when there are examples of courts banning satirical poems of a foreign leader from being uttered: https://www.b
7.
▲
by
deepbreath
6y ago
I thought I did? The condescending attitude is unnecessary. Happy to clarify my point if my initial comment was confusing: Websites such as http://panopticlick.eff.org/ showcase how fingerprinting works. They tell you how m
8.
▲
by
deepbreath
6y ago
Could you point what you believe to be the issues in the thread?
9.
▲
by
deepbreath
6y ago
If nothing else, it significantly reduces the entropy of your IP when websites are fingerprinting you, especially if your ISP assigns you a static IP. Even if you don't have a static IP, I suspect the entropy of your /24 (IPv4) is
10.
▲
by
deepbreath
7y ago
There are plenty of homeless people in London.
11.
▲
by
deepbreath
7y ago
Honestly, your comments are pretty much an r/wowthanksimcured meme.
12.
▲
by
deepbreath
7y ago
> (Hint: go ahead and start interviewing and have semi-serious job leads before this talk) I think this bit of advice is at odds with OP's statement: "I don’t think I’d come across very well (or as sharp as I usually) in interv
13.
▲
by
deepbreath
7y ago
Makes me think of the gradual increase of identity politics in mainstream media, politics and liberal circles, to the point it's driving me insane. Most people around me seem undisturbed by it though.
14.
▲
by
deepbreath
7y ago
Not thinkpad x1 carbon
15.
▲
by
deepbreath
7y ago
I committed the grave mistake of purchasing a laptop with only 8GB ram and I constantly run out of memory as a result. When it happens, I just repeatedly mash alt+sysrq+f until it kills off some chromium tabs and unfreezes my machine. It es
16.
▲
by
deepbreath
7y ago
https://www.telegraph.co.uk/news/2016/04/07/german-comedian-...
17.
▲
by
deepbreath
8y ago
The server would not be able to verify a changing hash without knowing the password
18.
▲
by
deepbreath
8y ago
It's unclear to me how your random salt would work. From my understanding, you're suggesting smth like: register: send (username, user_salt, HMAC(user_salt, pwd)) login: send (username). retrieve user_salt. retrieve a server_salt
19.
▲
by
deepbreath
8y ago
But the password is only known to the client?
20.
▲
by
deepbreath
8y ago
> meaning old hashes wouldn't be accepted and reducing hash "replay" possibilities How would the server even verify the hash, then?
21.
▲
by
deepbreath
8y ago
I think one of the things I'd really miss is Google Maps. The directions are really good, and the web app is unusably slow
22.
▲
by
deepbreath
8y ago
The last two employees would eat eachother's lunch. The issue is that the last employee has to have the moral integrity to fire himself.
23.
▲
by
deepbreath
8y ago
So then all he needed to do is write his name in addition to his IP address in the comment?
24.
▲
by
deepbreath
8y ago
It's happened before, with Microsoft, too. They've transitioned from an OS where you pay with cash (win7), to a spyware OS where you pay with cash and your data (win10).
25.
▲
by
deepbreath
8y ago
> People living in the EU absolutely want control of the gathering of their PII. I know everyone here wishes this to be true, but what data are you basing this claim on?
26.
▲
by
deepbreath
8y ago
> Anonymous comments Wordpress asks for your name and e-mail to post a comment, doesn't it? I guess the tuple (ip,name,email,comment_text) is PII?
27.
▲
by
deepbreath
8y ago
Is there reason to believe the strikes will result in thousands of innocent casualties? They claim that they're only striking "chemical weapon research facilities". Looks like it's 4am there, so I guess not a lot of peop
28.
▲
by
deepbreath
8y ago
Yeah, but you might feel differently if instead of $200 it had $10m cash. And instead of accidentally coming across it on the ground, you spend months of your own time just walking the streets looking for such a wallet to return. And also t
29.
▲
by
deepbreath
9y ago
Haven't heard of it before, but they look decent. I think the price difference with brand laptops becomes less impressive if you go for the higher specs and also want it shipped internationally (20% UK VAT). The base weight for their
30.
▲
by
deepbreath
9y ago
+1. Also using Debian on a X1 Carbon 5th gen (2017). Everything except the fingerprint reader (which I don't much care for) works perfectly.
More ›