Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ehhthing
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
ehhthing
4y ago
First and foremost, electron runs on often outdated versions of chromium which are vulnerable to known 0days. Electron RPC also makes it really easy to get RCE if you don't implement it properly, and most JavaScript developers don'
92.
▲
by
ehhthing
4y ago
I think the ruling is probably much more complicated than the simple statement that it was on pose alone. Whether or not the similarities between the original and derivative work meet the criteria for the Luxembourg equivalent of Fair Use i
93.
▲
by
ehhthing
4y ago
Generally, the way that you're paid if you sell to a exploit broker is in installments over time to prevent this kind of business. I'm not sure about whether it's your intellectual property or not. Can exploits be "int
94.
▲
by
ehhthing
4y ago
And clearly the Luxembourg copyright system doesn't work that way? Maybe in Luxembourg, copyright only exists in much more limited situations? Whether something should or should not be copyrightable in the moral sense is a very differe
95.
▲
by
ehhthing
4y ago
I'm active in the CTF crowd, and I think the general feeling is that you only want to burn your lower tier exploits at pwn2own. Usually these will be the exploits for things that are harder to sell to an exploit broker. You probably wo
96.
▲
by
ehhthing
4y ago
While FTX US did operate in the US, its finances were never nearly as fucked up as FTX (The Behamas company) was, especially with its relationship with Alameda.
97.
▲
by
ehhthing
4y ago
The article is rather misleading. It is almost certain that Samsung used HSMs to sign their APKs, so the key itself could never actually leak unless someone had physical access to the HSMs themselves and managed to somehow delid it and then
98.
▲
by
ehhthing
4y ago
They do peer locally, but of course they charge for it. It's all PNI, and quite expensive. For the longest time, Cloudflare routes from Toronto went down to Chicago.
99.
▲
by
ehhthing
4y ago
You can achieve the same thing with iframes using the "sandbox" attribute.
100.
▲
by
ehhthing
4y ago
The UAE's connectivity isn't actually bad. Latency to most of SEA is quite good (50ms to India, 80ms to Singapore). But for what I assume to be political reasons latency to Europe is about 20 or 30ms higher then what it could be .
101.
▲
by
ehhthing
4y ago
I was the one who reported this originally in 2020. Christian said it wasn't a vulnerability because it was intended that people who used standard library functions should validate user input. A day later I get another email saying tha
102.
▲
by
ehhthing
4y ago
This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-
103.
▲
by
ehhthing
4y ago
RCS is an open protocol, in fact it was developed with the GSM association https://en.wikipedia.org/wiki/Rich_Communication_Services You seem to want every single reason to dislike anything Google has ever helped to ma
104.
▲
by
ehhthing
4y ago
I just (barely) passed what is known as my university's hardest first year physics course: electricity and magnetism. We didn't use differential equations, but we had the same hand wave "just think about it" relationship
105.
▲
by
ehhthing
4y ago
Lesser known fact: this "feature" is actually built into Chrome on MacOS! If you try to print a website as PDF it will completely break it and copy and paste will result in random Unicode characters.
106.
▲
by
ehhthing
4y ago
You seem to have taken this quote out of context. My point is that "a less censored platform is always better", in other words "Google but censored is better than Baidu".
107.
▲
by
ehhthing
4y ago
As a former Chinese citizen, I've always been a bit confused why people get mad at companies operating in the country, censored. At least in my experience, a censored version of a foreign website is always much better than the stuff de
108.
▲
by
ehhthing
4y ago
I mean there are certainly alternatives to Visa and Mastercard. Credit cards aren't the only way to pay for goods and services. PayPal and Crypto being the most common. For personal transfers there's also Wise (which you can do pe
109.
▲
by
ehhthing
4y ago
But that's not the point is it? The point is that Mastercard and Visa are facilitating the transfer of money for illegal transactions. In the same way you can't start a bank to facilitate money laundering, Mastercard and Visa cann
110.
▲
by
ehhthing
4y ago
What, exactly is the alternative? The system might not be perfect or even good, but as far as I can see there is no alternative to this kind of issue. Even if there were a million different credit card companies (and god help us if that eve
111.
▲
by
ehhthing
4y ago
Thank you for introducing me to a wonderful privacy nightmare. P2P networks inherently are not private: everyone on the network knows who else is on the network and what they are doing. Thus one bad node could collect data on others' b
112.
▲
by
ehhthing
4y ago
30 days is not instant. The only issue here is HelloFresh not properly telling its customers how long it takes for them to actually delete the data.
113.
▲
by
ehhthing
4y ago
Can we add pacemakers to this list too? A bad lurch could kill someone...