Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
iancarroll
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
iancarroll
12d ago
I think most people are using some variation of Chinese models due to the safeguards. I have some self hosting but the economics are bad - OpenRouter etc are a very competitive marketplace and usually better.
2.
▲
by
iancarroll
13d ago
Pretty hard to implement in practice! % dig www.tesla.com +short www.tesla.com.edgekey.net. e1792.dscx.akamaiedge.net. <akamai IP>
3.
▲
by
iancarroll
13d ago
We can quantify the impact of the scripting tools pretty easily - 1.5k requests per day! I just went on Reddit and viewed a few posts, and it caused about 500 HTTP requests in DevTools. Luckily HN is not that bloated, but I just don't
4.
▲
by
iancarroll
13d ago
Even before AI, I can't imagine a single bug bounty researcher doing that. Pre-AI, everyone ran a tool like subfinder to enumerate subdomains, httpx to resolve them, nuclei to scan them, etc. There's no human review involved there
5.
▲
by
iancarroll
13d ago
Are you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless
6.
▲
by
iancarroll
13d ago
I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.
7.
▲
by
iancarroll
13d ago
The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?
8.
▲
by
iancarroll
13d ago
How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty pro
9.
▲
by
iancarroll
13d ago
As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla , and my agents will probe anything under
10.
▲
by
iancarroll
16d ago
Prepaid cards are great for the vendor because they have breakage (the unspent amount before expiry). I doubt the data is worth much relative to that. If anything, they have much less of a tie to the individual.
11.
▲
by
iancarroll
17d ago
Importantly, there is only an incentive for L2/L3 data on business/corporate cards, which have an inflated interchange rate above personal cards anyway. This is not a scheme to get enhanced targeting data for personal transactions
12.
▲
by
iancarroll
2mo ago
I agree, I have been in a lot of buildings where the elevators have extremely poor performance due to this. It can be 4AM but they are all configured to rest on one floor or something like that.
13.
▲
by
iancarroll
2mo ago
Looks great but the CLI output is not particularly interesting while the scan is running. I wish it could show token usage, some kind of progress, etc.
14.
▲
by
iancarroll
2mo ago
I've wasted so much money on vendor charging cables in the past 10 years while traveling or moving that I would probably buy this just for the USB-C port, assuming it is actually splash proof. I wonder what HR sensor they use. Samsung
15.
▲
by
iancarroll
2mo ago
We use github.com/go-webauthn/webauthn with no complaints!
16.
▲
by
iancarroll
3mo ago
In Shenzhen, they told me that I can take the full test on any visa if my permitted length of stay is 90 days or more. Supposedly the US embassies now issue 90 day visas for Americans, so I am hoping to try that route soon as I have already
17.
▲
by
iancarroll
3mo ago
Surprised to see this here but happy to answer any questions! Driving across China and getting to use the latest EVs has been quite fun and I hope to do it even more in the future.
18.
▲
Backstage access: an unauthenticated SQL injection in Front Gate Tickets
(ian.sh)
3 points
by
iancarroll
3mo ago
|
0 comments
19.
▲
by
iancarroll
3mo ago
Most apps (on desktop or mobile) open third party auth flows inside the user's default browser, which makes this a non-issue. For one, if you embed the Google login flow into your app then I can't reuse my existing session in my b
20.
▲
by
iancarroll
3mo ago
Apps installed via the MAS have sandboxing applied to them, so this isn't really true.
21.
▲
by
iancarroll
3mo ago
The latest FSD does not attempt to check if your hands are on the wheel at all.
22.
▲
by
iancarroll
3mo ago
My Cloudflare enterprise order form has costs for overages for Workers and the following language about everything else: > If Customer exceeds any of the Total Quantity for the Services below, Cloudflare will invoice Customer in arrears
23.
▲
by
iancarroll
3mo ago
Your whole account is undisclosed marketing for this service. Fingerprinting in this manner is highly unlikely to be viable - there are too many middleboxes at the TCP layer to try and fingerprint on it.
24.
▲
by
iancarroll
4mo ago
0.5% is a pretty incredibly low interchange rate in any case. But if you are saying that half of it is going to scheme fees, I doubt it is funding rewards programs for consumers.
25.
▲
by
iancarroll
4mo ago
Well, OpenAI already sold it (but kept the team), so it’s in someone else’s hands now.
26.
▲
by
iancarroll
5mo ago
I know plenty of security researchers who exclusively use Claude Code and other tools for blackbox testing against sites they don’t have the source code for. It seems like shutting down the entire product is the only safe decision here!
27.
▲
by
iancarroll
6mo ago
It’s pretty interesting to me that Cloudflare is collecting additional client-side data for individual customers. This is not widely done by most anti-bot solutions.
28.
▲
by
iancarroll
6mo ago
A bit skeptical of how this article is written as it seems to be mostly written by AI. Out of curiosity, I downloaded the app and it doesn't request location permissions anywhere, despite the claims in the article. I've noticed Cl
29.
▲
by
iancarroll
7mo ago
Verizon did manage to convince the FCC that this was enough a problem to change their settlement agreement[0] requiring more frequent unlocks. If you believe their numbers, they lost 700,000 phones to fraud in 2023, although a lot of those
30.
▲
by
iancarroll
8mo ago
That is a very old article that seems to be outdated now.
More ›