Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
innoying
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
innoying
4mo ago
If you own a GitHub organization and are looking for what changes/controls you can apply to reduce the risk/impact of PAT token exfiltration (and subsequent abuse) like what occurred here, I listed a few at the end of https:
2.
▲
Building GitHub Canarytokens: A rant about Audit Log gaps
(blog.bored.engineer)
2 points
by
innoying
5mo ago
|
0 comments
3.
▲
by
innoying
9mo ago
The newer global node IDs (which can be forced via the 'X-Github-Next-Global-ID' header [1]) have a prefix indicating the "type" of object delimited by an underscore, then a base64 encoded msgpack payload. For most objec
4.
▲
Building a WebAuthn Click Farm: Bypassing Cloudflare's Attestation of Personhood
(betterappsec.com)
3 points
by
innoying
5y ago
|
0 comments
5.
▲
by
innoying
6y ago
CodeQL is based on an existing product from a company called Semmle which GitHub acquired in late 2019 [1] They have been part of GitHub for barely a year so it's not too surprising, especially given they are continuing to support the
6.
▲
by
innoying
8y ago
If anyone is interested in even more data than Artem released, I did a similar experiment based off Artem's work except with a couple hundred domains and with TLS certificates for every one a few years ago: https://bitfl1p.c
7.
▲
by
innoying
10y ago
Why does this comment appear on every bug bounty HN thread? Straight from the horse's mouth [0]: The black market is very unlikely to be a place you could sell a bug in a specific website or service. It is not “worth millions”.
8.
▲
by
innoying
10y ago
Technically they did employ some DNS validation. You had to setup a MX record to point to SendGrid before you could add the domain to your account. The problem was in order to send emails from a domain you had to add the same MX record. If
9.
▲
by
innoying
10y ago
I do not believe the author circulated this report to multiple companies, however once it was made public a number of other reporters in the community did and continued to iterate on it until SendGrid fixed the issues. Source: I am a member
10.
▲
by
innoying
10y ago
I believe they did retroactively search for accounts. Source: I had a number of accounts banned when testing different iterations of this bug.
11.
▲
by
innoying
10y ago
But that's not what happened here at all. Bitbucket has responded explaining why this (self-inflicted) bug exists (a security decision in an underlying framework) and deferred to the framework maintainers for further discussion because
12.
▲
by
innoying
10y ago
I think you're misunderstanding the attack scenario here: > Anyway, if the browser is connecting via port 80, the MITM can just use a transparent http->https proxy to rewrite the referrer, and forward the request to the https ser
13.
▲
by
innoying
10y ago
Hi "FBSecuritySux", I'm not a member of the Facebook security team, but I work in the industry and your comment frustrates me. I can understand criticizing companies for poor security decisions if they are legitimately bad de
14.
▲
Attacking Network Infrastructure to Generate a 4 Tb/s DDoS
(youtube.com)
2 points
by
innoying
10y ago
|
0 comments
15.
▲
by
innoying
10y ago
It's been private (invite-only) for about 2 years, they went public today.
16.
▲
by
innoying
10y ago
It's not an "easy fix", there could be (and probably are) thousands of different endpoints that can be redirected to after login, whitelisting all of those just doesn't make sense.
17.
▲
by
innoying
10y ago
I totally agree. I don't even see how the impact is even more than the open-redirects which already exist. You could do this exact same exploit against tons of providers (Facebook, Twitter, etc) via the standard OAuth flow and the 
18.
▲
by
innoying
12y ago
Or like any compiled language they can just grab a binary: https://github.com/github/hub/releases
19.
▲
LinkedIn Begins Ranking Universities Based on Career Outcomes
(blog.linkedin.com)
2 points
by
innoying
12y ago
|
0 comments
20.
▲
LinkedIn – Permanent launch of IPv6
(engineering.linkedin.com)
1 points
by
innoying
12y ago
|
0 comments
21.
▲
OpenSSL CVE-2014-3508 Information Disclosure Vulnerability
(securityfocus.com)
3 points
by
innoying
12y ago
|
2 comments
22.
▲
Open Source Craft Brewery
(twbrewing.com)
71 points
by
innoying
12y ago
|
22 comments
23.
▲
by
innoying
12y ago
Plausible deniability.
24.
▲
by
innoying
12y ago
Somewhat related, but I made a small site to help the average internet "user" understand what net neutrality is and why it's important: http://net-neutrality.io/ I'm not quite sure where to advertise it,
25.
▲
Save the Internet | Demand Real Net Neutrality
(net-neutrality.io)
2 points
by
innoying
12y ago
|
0 comments
26.
▲
by
innoying
12y ago
The problem is Skype recently moved to a centralized infrastructure instead of a P2P which has caused terrible issues for pretty much everybody. Allegedly this was done to allow the NSA to snoop on conversations easier.
27.
▲
by
innoying
12y ago
I've been working on a site dedicated to informing the public about net neutrality. It's using the new EFF data about legislators too! http://i.imgur.com/ML4rmKQ.png
28.
▲
by
innoying
12y ago
Apple bundles updates to core applications all at once as a single install. So it's all within the security update. Of course the iOS update is separate.
29.
▲
by
innoying
12y ago
Isn't that common sense? If you disclose the bug publicly before it's patched you won't get the reward...
30.
▲
by
innoying
13y ago
What's your issue with that statement?
More ›