Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
graystevens
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
61.
▲
by
graystevens
8y ago
Not the owner - just wondered what the project was & figured I wouldn't be the only one to query it, seeing as we get linked to the release notes. Personally I would pick Scrapy too, but it's good to have competition, and Coll
62.
▲
by
graystevens
8y ago
For those that haven’t heard of go-colly before, it’s a scraping platform written in, yup you guessed it, go. See: http://go-colly.org/ Here’s an example we can all relate to: http://go-colly.org/docs/e
63.
▲
by
graystevens
8y ago
Looks like you committed a .env file previously with some semi-private details contained within it, plus you’ve hardcoded some Cloudinary API credentials. You may want to rotate them before they’re abused by someone. Edit: oh and some datab
64.
▲
by
graystevens
8y ago
I’m going to be cheeky and call out one of your edited points as something I focused on from the start. As a bootstrapped SaaS owner myself, automating almost everything has been key, giving me time to go and work on other things that simpl
65.
▲
Deploying a Hugo Static Site Using GitLab, CI/CD, and SSH
(grh.am)
2 points
by
graystevens
8y ago
|
1 comments
66.
▲
by
graystevens
8y ago
Surface Mounted Device/Technology ( https://en.m.wikipedia.org/wiki/Surface-mount_technology )
67.
▲
by
graystevens
9y ago
Were they unique and/or generated passwords each time, or was it a password you have used else where? It is unlikely to be a Spotify breach, but if the password was unique to Spotify then that certainly adds a little more weight to the
68.
▲
by
graystevens
9y ago
Zone transfers is one way, but you can also use brute force using a common word list. You can also these days use ‘OSINT’ (open source intelligence), and use things like TLS certificate transparency logs to go looking for obscure DNS names.
69.
▲
by
graystevens
9y ago
Would be interesting to know how they identified the breach. It is exactly these situations that I produced Breach Insider[0], in the hope to try and reduce the time to detection down from months to days. Those of you affected by this breac
70.
▲
by
graystevens
9y ago
Awesome, glad you like it!
71.
▲
by
graystevens
9y ago
I’ve always had a good experience with fastmail.com, and I know it gets a lot of love here on HN.
72.
▲
by
graystevens
9y ago
$0.50/million requests, but it’s a minimum of $5/month (giving you 10million requests essentially.) Not a criticism, this it looks like an excellent product for those who can benefit from it, just calling it out for others that re
73.
▲
by
graystevens
9y ago
Looks like exactly what I would suggest, although I’d argue EC2 might be slightly overkill. You’d get more for your money with Linode/DigitalOcean/OVH or even Hetzner’s new cloud offering. Will help save some pennies early on.
74.
▲
by
graystevens
9y ago
Breach Insider is a one person bootstrapped company: https://breachinsider.com Been live for a few months now and enjoyed finding the balance between sales and producing new features.
75.
▲
by
graystevens
9y ago
This has, similar to Meltdown and Spectre, been broken earlier than expected. As far as I am aware this wasn’t supposed to be released by Cisco until Wednesday, but anonymous reports started to circulate yesterday and today. This isn’t a gr
76.
▲
Show HN: Honey Buckets – Find out who is snooping through your Amazon S3 buckets
(breachinsider.com)
4 points
by
graystevens
9y ago
|
0 comments
77.
▲
Show HN: Honey Buckets – Find out who is snooping through your AWS S3 buckets
(breachinsider.com)
2 points
by
graystevens
9y ago
|
0 comments
78.
▲
by
graystevens
9y ago
Good point, the report calls out that the root password for 40+ servers was the same, and that a large number of employees knew or used it. Seems sensible to transfer that same mentality across to other sensitive accounts.
79.
▲
by
graystevens
9y ago
Section 13 onwards makes for a great read as to how this all went down. The attacker used a common security scanning tool Nikto, which would have told them that WordPress and its plugins were horrifically out of date. Any tool could have fo
80.
▲
by
graystevens
9y ago
Thanks for putting this together Scott - I remember running through the exercises a year or so ago and realising how awesome some of these mistakes are. I ended up turning the S3 bucket stuff into a conference presentation, after bruteforci
81.
▲
by
graystevens
9y ago
Depending on what is in your git repo, please don’t be the next Uber - if you had any secrets in your repository (even historical), definitely roll all your API keys and check secrets/credentials etc.
82.
▲
by
graystevens
9y ago
Nope, Windows Defender has already set the registry key, and you should be good to go. For the rest of you, there is a good public document[0] that is being regularly updated on the status of each of the AV products out there. [0] https:&#x
83.
▲
Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set
(doublepulsar.com)
188 points
by
graystevens
9y ago
|
101 comments
84.
▲
by
graystevens
9y ago
Agreed. Super disappointed by this (cleartext details and the breach). Will be looking to move all services from Mailgun shortly.
85.
▲
by
graystevens
9y ago
Another breach. Credit where credit is due, they haven’t done too badly with the announcement, but there are some key facts that people would like to know that they unfortunately haven’t mentioned. * They became aware of it Dec 11th – do th
86.
▲
by
graystevens
9y ago
SQLmap is a great tool for automated scanning and exploiting of SQLi vulnerabilities. Like everything though, it can miss the occasional exploit, where someone with the expertise might be better suited, but generally speaking it’s an awesom
87.
▲
by
graystevens
9y ago
My comments from the other thread: https://news.ycombinator.com/item?id=15963787 Very interesting. I wonder if any private organisations setup a pseudo/canary repositories, that when pulled triggered an alarm? Or simpl
88.
▲
by
graystevens
9y ago
Clickable link: https://gist.github.com/kailan/9f37ec2cd76314f945dda65e5beab... Very interesting. I wonder if any private organisations setup a pseudo/canary repositories, that when pulled triggered an alarm? Or s
89.
▲
by
graystevens
9y ago
Very interesting that Facebook ads are working for you - I have avoided them so far due to their cost but maybe I shall reconsider. So far I’ve been cold emailing my target market, but being new to all of this I am still tweaking my efforts
90.
▲
by
graystevens
9y ago
This. If it’s a side project that is intended for self-development and learning, try it in a new language and see how you get on. If it’s something even remotely important or think might turn into more than just a side-project, go with what
More ›