Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
harmon
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
harmon
1y ago
Fine, Kerberoasting abuses TGS-REPs which are colloquially referred to as TGS tickets or TGSs*. You know what I meant.
2.
▲
by
harmon
1y ago
> It's wild to me that this could happen just from solving the puzzle that allows the user's account to use the user's privileges (only) on the service... ? Yes, it is an unfortunate design decision in the Microsoft implem
3.
▲
by
harmon
1y ago
If you have the user's credentials then you can indeed connect to the service as you normally would. The advantages of performing this attack are: 1. You can obtain the service account's password, and the service account may be pr
4.
▲
by
harmon
1y ago
Managed and group managed service account passwords are typically 240 characters long and rotate every 30 days. It is highly unlikely that an attacker can crack these.
5.
▲
by
harmon
1y ago
This article is somewhat incorrect. Kerberoasting abuses Ticket Granting Service tickets (TGSs, which are used to request access to a registered service in Active Directory), not Ticket Granting Tickets (TGTs, which are used to prove identi
6.
▲
by
harmon
1y ago
As these tariffs are objectively likely to drive up costs, hurt user demand, and lower revenue for the company, I would argue that they have a duty to their shareholders and other stakeholders to push back against them and not be neutral. I
7.
▲
by
harmon
2y ago
As I understand it, you can only write off a business's expenses against that business's income, not income from other sources. For example, if you have a W2 income source and you have this business generating losses, you can'
8.
▲
by
harmon
3y ago
I agree, honestly I feel a much better solution to this problem would be to extend the same tax advantages that you allude to when talking about a personal company to W2 employees. Provision a home office? All of those expenses should be ta
9.
▲
Rapid7 lays off 18% of employees
(bizjournals.com)
6 points
by
harmon
3y ago
|
0 comments
10.
▲
by
harmon
4y ago
Mass surveillance is out of control as you say, and I am a strong proponent of reigning in warrantless wiretaps and governmental overreach. However, as many people have stated, a pen register (which requires a warrant) against a specific in
11.
▲
by
harmon
4y ago
So I used to be in a very similar boat as you: I was depressed while working towards a STEM degree in college and ended up almost failing out with a 2.X GPA. I didn't see a path forward, and there was only one entity that was willing t
12.
▲
by
harmon
4y ago
Ultimately if users are satisfied and happy, does it even matter if it is fake? The end goal is not to create a real relationship, it is to create a happy fantasy for the buyer.
13.
▲
by
harmon
4y ago
> The endless pursuit of growth is usually a byproduct of ego or at the behest of some intangible idea of "creating shareholder value." If you don't want to grow that's fine, but then don't go public and don'
14.
▲
by
harmon
4y ago
The existence of an "active" God as portrayed in most religions would complicate things tremendously though. If an entity can inject energy into the system or can alter system properties at will then the fundamental assumptions ab
15.
▲
by
harmon
4y ago
Even if you only take courses that aren't wastes of time, there just isn't that much to do on a typical day. I remember when I was in school I was taking something like 5 AP courses senior year but still had multiple study halls p
16.
▲
by
harmon
4y ago
> Hot take: It’s fine when it happens to extreme hubris with paper wealth. It is not fine when it was someone unsophisticated chasing the herd who lost a meager sum that was meaningful to them. Comedy vs tragedy. I think this is overlook
17.
▲
by
harmon
4y ago
Exactly this. Every project is going to impact the environment. The end goal of a risk assessment is not to bring the environmental risk to zero, it is to bring it down to an acceptable level given the benefits of the project.
18.
▲
by
harmon
4y ago
The story in the article was completely preventable if banks just tried harder. The default 2FA solution should be Google authenticator or an analogous tech. If SMS MUST be used, it should be opt in. Notification of anomalous transactions s
19.
▲
The Fugitive Next Door
(magazine.atavist.com)
1 points
by
harmon
4y ago
|
0 comments
20.
▲
by
harmon
4y ago
Honestly, I do think we should reopen psychiatric institutions (although properly funded and regulated this time) and forcibly treat certain people that need help. I don't think it is good or acceptable to allow people with obviously s
21.
▲
by
harmon
4y ago
I'm a crypto user, I'm a former Ethereum miner, I've read white papers, I've paid with things with crypto....and I'm disenchanted with it. Crypto seems to be great for three things: money laundering, tax evasion, an
22.
▲
by
harmon
4y ago
Agreed, if not a proxy then put your services behind a VPN or a bastion host when possible.
23.
▲
by
harmon
4y ago
I disagree. I went to a "tier 3" school for undergrad and then "elite" schools for post-graduate education. The difference in course and instruction quality, experience level of the professors, student ambition, and cali
24.
▲
by
harmon
4y ago
I agree and have had a similar idea for awhile. Have the best lecturers for given subjects create outstanding virtual courses, develop sets of curricula off of those courses, and have TAs (PhDs in your model) provide local instruction and t