Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gaia
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
gaia
9y ago
To me this quote is the best gauge of how incredible of a human feat this was. "One way to measure the greatness of any sporting achievement might be to consider the amount of time that passes before it’s achieved again. New world reco
32.
▲
by
gaia
9y ago
what if elon signs up as elon@spacex.com. he then fills out a personal details form, which includes a phone number. if a 2nd user comes around and enters the same unconfirmed email within 48hrs he'd get to see those personal details. t
33.
▲
by
gaia
9y ago
same here, on a daily basis. worse when my email is supplied by someone else to a party that does not confirm AND there is no way to unsubscribe (such as Best Buy's geek squad's email). my gmail delete filter list is 50+ items now
34.
▲
by
gaia
9y ago
More info, since the article is light on actual information on the vulnerability: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8314 (points to https://github.com/xbmc/xbmc/pull/
35.
▲
What comment did you leave on gofccyourself.com?
2 points
by
gaia
9y ago
|
0 comments
36.
▲
by
gaia
9y ago
That is a good question. Lenovo's advisory ( https://pcsupport.lenovo.com/us/en/product_security/ps500104 ) does not explicitly states which AMT status make it vulnerable, but given that Intel ME runs no m
37.
▲
by
gaia
9y ago
Deactivation merely resets the AMT settings. You can only turn it off by following these instructions.
38.
▲
by
gaia
9y ago
start here http://www.fsf.org/blogs/licensing/intel-me-and-why-we-shoul...
39.
▲
by
gaia
9y ago
ACUConfig is the Intel recommended way, per the mitigation guide (at least for now, until a patch is released).
40.
▲
by
gaia
9y ago
See https://news.ycombinator.com/item?id=14253704
41.
▲
by
gaia
9y ago
You are correct, I've updated the HN link title and post's title.
42.
▲
by
gaia
9y ago
These step by step instructions were built based on the mitigation guide, which is linked in the advisory. I've updated the HN link title and post's title (see https://news.ycombinator.com/item?id=14253732 )
43.
▲
by
gaia
9y ago
And how would you test for that?
44.
▲
by
gaia
9y ago
Yes, the exploit is only for Intel ME on Windows, AFAIK.
45.
▲
by
gaia
9y ago
You can run netstat and see it is no longer listening. Now, how you would verify this when the computer is off is beyond me (assuming it is the case - I have not yet been able to go thru the PDF below)
46.
▲
by
gaia
9y ago
Yes, windows only for now. The Linux guide is upcoming: https://twitter.com/IntelSupport/status/859437569368567811
47.
▲
Disabling Intel AMT on Windows
(mattermedia.com)
117 points
by
gaia
9y ago
|
70 comments
48.
▲
by
gaia
10y ago
Sometimes refreshing the console gives this error instead of showing ZERO buckets https://pbs.twimg.com/media/C5xZVGKUYAAXYGj.jpg:large
49.
▲
by
gaia
10y ago
2FA would make it harder to exploit, but phishing attacks are getting fancier. They capture the 2FA code you enter and immediately start a session elsewhere with your password and 2FA. Hardware 2FA, a security key, (such as a Yubikey) is th
50.
▲
by
gaia
10y ago
It is not the cache that causes the heavy IO. It is the SQLite DB at AppData\Local\Spotify\mercury.db AppData\Local\Spotify\mercury.db-wal See http://blog.scaleprocess.net/spotify-heavy-io-problem/ Besides that, a lot
51.
▲
by
gaia
10y ago
One more point for letsencrypt's certs short cert validity model.
52.
▲
by
gaia
10y ago
What about the absurd amount of water, an increasingly scarce resource, used by fracking?
53.
▲
by
gaia
11y ago
My Nexus 6 running Android 6.0.1 is encrypted and uses hardware backed credential storage. If the software (Android) had the same type of protection (if the wrong PIN is entered 10 times it destroys the key), would this device be at par wit
54.
▲
by
gaia
11y ago
Error. 53.
55.
▲
by
gaia
11y ago
Having only a half a dozen subdomains, with maybe another half a dozen being added per year (well below the limits), are there any advantages to using a wildcard cert VS individual certs for the subdomains? In other words, any way to justi
56.
▲
by
gaia
12y ago
Anyone up for decoding the cert used by GoGo Inflight WiFi Service? https://www.techdirt.com/articles/20150105/09344429597/gogo-...
57.
▲
by
gaia
14y ago
Best thing Zerigo could do for their customers at this point is export all zone information and email it to them or make available for DL. I have a feeling this is going to be a long outage. In the meanwhile, here is a great list of free DN