Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
graystevens
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
graystevens
9y ago
Just to clarify, he’s not with BT any longer, but with IBM Resilient: He has been working for IBM since they acquired Resilient Systems where Schneier was CTO.
92.
▲
by
graystevens
9y ago
Nope but there are certainly some articles discussing the use of USB NICs, and their performance. http://www.virten.net/2016/06/additional-usb-nic-for-intel-n...
93.
▲
by
graystevens
9y ago
This is the route I’ve just started down - a NUC with as much memory I can shove into it. Doesn’t cost a fortune to run, and as basically silent. Love it.
94.
▲
by
graystevens
9y ago
Would love to – We have quite a few cool features and interesting link ups that we would love to do, and this is certainly one of them.
95.
▲
by
graystevens
9y ago
It should alert as soon as it hits our mail servers - let check its route and see what happened for you.. apologies. Edit: Bug fixed, really sorry about that! I've sent an email to the insiders address, to give you an example alert.
96.
▲
by
graystevens
9y ago
That’s on the roadmap, as Troy sometimes get breaches personally handed to him. Ideally I’d like to be the one detecting the first of course :)
97.
▲
by
graystevens
9y ago
That’s a very valid point - whitelisting DKIM domains was the quickest option as it is easily parsed and verified. Will certainly look into this.
98.
▲
by
graystevens
9y ago
Completely agree, and that’s why our email addresses are formed in a way which shouldn’t be bruteforced/guessed to help reduce this. We’ve purchased a handful of our own domains that we monitor, rather than relying on any other supplie
99.
▲
by
graystevens
9y ago
I completely agree that preventative/proactive measures are always going to be better than something retrospective such as my service (although I’d argue that they complement each other nicely, of course). In terms of why a mid-sized S
100.
▲
by
graystevens
9y ago
Creator here – There are a few ways we can detect a breach/leak using our Insiders. 1. The unique email address assigned to the Insider is contacted. We gather forensic evidence of the email along with any attachments. Useful to identi
101.
▲
Show HN: Breach Insider – Detect a data breach using realistic pseudo-users
(breachinsider.com)
71 points
by
graystevens
9y ago
|
43 comments
102.
▲
by
graystevens
9y ago
Got a pull request in for our startup to say we do software 2fa. Will be looking into supporting hardware 2fa too when we get the chance. If you’ve got or know of a site using 2fa, definitely put in a pull request to show your support.
103.
▲
by
graystevens
9y ago
Valid point, and something I considered initially. However we've a security startup – the likelihood hood of us getting a huge wave of visitors, the hug of death, is highly unlikely. Our landing page is static & anything remotely i
104.
▲
by
graystevens
9y ago
Agreed with the automation — I’m a fellow bootstrapper[0] in the SaaS space, and wouldn’t be without it. If there is anything that can be automated, even if slightly prematurely before the need to scale arises, I do so. In terms of infrastr
105.
▲
by
graystevens
9y ago
We built our own using Chrome Headless and some python. This allows us to use a Tor proxy where required, capture full height screenshots, and dump the DOM.
106.
▲
by
graystevens
9y ago
From the email: Arq for Mac Vulnerabilities Fixed Mark Wadham (thank you Mark for all your help identifying and helping to resolve this!) identified a vulnerability in Arq 5 for Mac where an attacker could become "root" u
107.
▲
Arq 5 Mac security update
(arqbackup.com)
1 points
by
graystevens
9y ago
|
1 comments
108.
▲
Windows 8 and later have been failing to apply ASLR
(kb.cert.org)
3 points
by
graystevens
9y ago
|
0 comments
109.
▲
Credential Stuffing: How breached credentials are put to bad use
(breachinsider.com)
1 points
by
graystevens
9y ago
|
0 comments
110.
▲
by
graystevens
9y ago
https://breachinsider.com - Feedback welcomed :)
111.
▲
by
graystevens
9y ago
That was a temptation, but I held off as my Show HN didn't get much traction both times I posted it, so figured it is best not to come across as trying to force it. It is however in my profile, if anyone feels so inclined..
112.
▲
by
graystevens
9y ago
Up for me - UK.
113.
▲
by
graystevens
9y ago
How to run a bootstrapped startup as a single founder. I don’t have a problem with the tech etc. and those that see it and experience it, love it. However, that cliche stands true - marketing and sales are hard. ‘Cold emails’ feel extremely
114.
▲
by
graystevens
9y ago
Correct, the SIM800 line are 2G only which I believe is only provided in the US by T-Mobile as you mentioned. In the UK things are a little different, where the vast majority of the core mobile network providers still supply 2G networks, bu
115.
▲
by
graystevens
9y ago
Some of you may remember the previous discussion about BreachCanary (now Breach Insider) from the DocuSign breach: https://news.ycombinator.com/item?id=14347188
116.
▲
Show HN: Breach Insider – Find out about your data breach, before everyone else
(breachinsider.com)
3 points
by
graystevens
9y ago
|
1 comments
117.
▲
by
graystevens
9y ago
Mondo -> Monzo
118.
▲
by
graystevens
9y ago
It definitely is the most popular OS for security peeps, however those VMs mentioned in the article are purpose built to be vulnerable. They allow someone to spin them up and attempt to hack the boxes (likely using Kali) as a way of honing
119.
▲
by
graystevens
9y ago
A great example of folks either re-using passwords, or simply not being aware that their credentials have been included in a previous leak/breach. For an idea of a timeline, and a useful reminder to check your own personal accounts (an
120.
▲
by
graystevens
9y ago
Some of you may remember the previous discussion about BreachCanary (now Breach Insider) from the DocuSign breach: https://news.ycombinator.com/item?id=14347188
More ›