Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
infotogivenm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
infotogivenm
2y ago
source integrity is probably the more applicable feature for gp’s concerns
2.
▲
by
infotogivenm
2y ago
> Nah I don’t get it then… Do you never end up having to privesc in your pentests on linux systems? No doubt it depends on customer profile but I would guess personally on at least 25% of engagements in Linux environments I have had to f
3.
▲
by
infotogivenm
2y ago
Think “illegitimate” access to www-data. It’s very common on linux pentests to need to privesc from some lower-privileged foothold (like a command injection in an httpd cgi script). Most linux servers run openssh. So yes I would expect this
4.
▲
by
infotogivenm
2y ago
Fidelity, who remains a stakeholder in the private company and gets insight to internal financials, has cut the valuation of their holding by 75% so far [1]. While twitter might not have been profitable when purchased, it was structured as
5.
▲
by
infotogivenm
2y ago
Em, that seems an extremely generous comparison, where did you come up with that? Last I checked for example systemd relies on polkit for policies, which drags in a javascript interpreter engine. If the author thinks BNF is complex…
6.
▲
by
infotogivenm
2y ago
I’m surprised no one has written a tool (probably would involve disabling SIP) to import/export passkeys on macOS. They’re in memory, right?
7.
▲
by
infotogivenm
3y ago
https://newsletterhunt.com/emails/48880
8.
▲
by
infotogivenm
3y ago
Came here to mention this. I used this exact setup (used a laptop battery bank off of amazon as a UPS for my home modem), and came home months later to find the bank had caught fire at some point, melted, and was no longer functional. Would
9.
▲
by
infotogivenm
3y ago
It is fairly common to have noexec on /dev/shm; filesystem configurations are always up to the admin so they could feasibly set anything.
10.
▲
by
infotogivenm
3y ago
One good example is bringing up equipment that comes out-the-box with a default password. This is common on BMCs for example, and you have to initially provision things somehow.
11.
▲
by
infotogivenm
3y ago
It’s covered under footnote #1: > First, some vendors make it difficult to associate an SSH key with a user. Then, many vendors do not support certificate-based authentication, making it difficult to scale. Finally, interactions between
12.
▲
by
infotogivenm
3y ago
I’ve noticed the code reader is worthless on even slightly out of date browsers now, and even on newer browsers it tends to choke and stutter on large files. Sad :( it used to be the best
13.
▲
by
infotogivenm
3y ago
If you have metadata for a couple of messages it is no longer a needle. Not sure what your point about APNS tokens is - I agree, once they hone in on who received the messages Apple would know the device.
14.
▲
by
infotogivenm
3y ago
Ah good point, radar/ultrasonics were what I was thinking of, not lidar. Looks like they’re still gone.
15.
▲
by
infotogivenm
3y ago
I mean, the current requirement for human attentiveness and intervention probably has something to do with avoiding disaster scenarios.
16.
▲
by
infotogivenm
3y ago
I can imagine it could be useful, e.g. if you already have metadata on “dates when user A messaged user B”, and are trying to de-anonymize user B.
17.
▲
by
infotogivenm
3y ago
Are they still all-in on “pure vision” self-driving? I thought they had pivoted back to lidar but can’t seem to find any sources for that.
18.
▲
by
infotogivenm
3y ago
Correct. Worst rental car experience of my life.
19.
▲
by
infotogivenm
3y ago
The point of killing third party cookies is to prevent a tracking identifier cookie that uniquely identifies your browser from being reused across different sites. So you can of course host your own scripts and run them on your own origin,
20.
▲
by
infotogivenm
3y ago
I believe third-party cookies have been blocked on Safari and FF by default for many years
21.
▲
by
infotogivenm
3y ago
Can you elaborate? I have not kept up with the eSNI/ECH stuff... How will filtering still be possible?
22.
▲
by
infotogivenm
3y ago
What part of the world do you live in? Just curious, I travel very often but have yet to see any convenient way to spend bitcoin everyday.
23.
▲
by
infotogivenm
3y ago
the biden laptop story was temporarily banned for less than 24hrs as it violated various twitter rules for hacked content and nudity. The “Twitter Files” ( cue x-files theme ) show us this - it was certainly not banned because users reporte
24.
▲
by
infotogivenm
3y ago
Nice. A similar project, but more license-constrained, is fuse-t for macos: https://github.com/macos-fuse-t/fuse-t
25.
▲
by
infotogivenm
3y ago
Yes. And if your threat model really includes distrusting the manufacturer of your phone and its software after a specific point in time at which you have reversed all of its internals, you should have disabled software auto updates. But th
26.
▲
by
infotogivenm
3y ago
Kids these days will never know the struggle of having to search for libraries that were not just in your language, but also could interop with your inane monkey-patching-based concurrency model of choice. Python used to be an absolutely ho
27.
▲
by
infotogivenm
3y ago
I would guess this is a well-coordinated (with mgmt/HR) leave, and he has probably already announced it internally. Not sure why any employer would be upset in that case.
28.
▲
by
infotogivenm
3y ago
I think a lot of mastodon users left twitter as part of an existing community, and so the migration process was pretty straightforward; usually they had one community instance that is effectively Threads for them. I think being bullish on M
29.
▲
by
infotogivenm
3y ago
Vulnerabilities? I think if they are pervasive enough to enter mainstream consciousness, it can help with general awareness. Does every vuln with a logo, deserve a logo? Probably not. But such is life.
30.
▲
by
infotogivenm
3y ago
I would guess people who spend a lot of money on interior design. It’s a nice statement piece IMO.
More ›