Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
innoying
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
innoying
13y ago
Working just fine for me.
32.
▲
Google Chrome Universal Cross Site Scripting
(hydrantlabs.org)
1 points
by
innoying
13y ago
|
0 comments
33.
▲
by
innoying
13y ago
The problem here is you two are disagreeing because you're approaching the problem from different viewpoints: legal and ethical. Is it legal to hire an intern unpaid? Yes (assuming you comply with the law). Is it ethical to hire an int
34.
▲
by
innoying
13y ago
That report was incorrect, but it would be interesting to see that data.
35.
▲
by
innoying
13y ago
When you get to the end it lists keybinds for each contact option.
36.
▲
by
innoying
13y ago
Weird, I'm a registered ChromeCast developer and didn't get an email. Did any other developers get one?
37.
▲
by
innoying
13y ago
Opened a GitHub issue: https://github.com/clipperhouse/stack-correlation/issues/1
38.
▲
by
innoying
13y ago
It does, any changes?
39.
▲
by
innoying
13y ago
Has been for at least 10 minutes: https://news.ycombinator.com/item?id=7086711 EDIT: Actually almost 30 minutes ago by this reddit post: http://www.reddit.com/r/youtube/comments/1vmnfq/is
40.
▲
by
innoying
13y ago
And now everything is down except search and embedded videos.
41.
▲
by
innoying
13y ago
Individual user pages and searching still appears to be working, but My Subscriptions and the homepage are down.
42.
▲
YouTube is down
(youtube.com)
5 points
by
innoying
13y ago
|
3 comments
43.
▲
by
innoying
13y ago
It doesn't seem like a security issue by DO in any way. It seems that the fog api (the project this 'issue' is filled for) doesn't allow a user to access the required flag to scrub the drive. Not a DO problem in any way
44.
▲
by
innoying
13y ago
They would also have to make sure no iOS applications make use of symlinks at any point. Since a ipa is simply a zip archive it's possible (and probable) that some applications already make use of symlinks on install or during operatio
45.
▲
by
innoying
13y ago
As evidenced by hash Geohot posted on his twitter on December 8th of http://geohot.com/mt.jpg he has had access to some of the vulnerabilities for some time. I know for sure the use of the signed WWDC application has been k
46.
▲
by
innoying
13y ago
Many parts of the internal system depend on it. Here's a run of `find / -type l` on a jailbroken iPhone 5: https://gist.github.com/innoying/8cd04821e17b3f67aa4b A few of those are created by the jailbreak but
47.
▲
by
innoying
13y ago
Yeah, very cool. It only works because the rootfs is mounted as read-only or else they might end up messing it up if the system was writing to the same block. But then again if it wasn't read-only this wouldn't be a problem.
48.
▲
by
innoying
13y ago
Cool! That's better than what I had before.
49.
▲
by
innoying
13y ago
Additional/Duplicate Information: http://pastebin.com/mT2n7uyj
50.
▲
by
innoying
13y ago
Mods, please don't remove the title as the original page does not have a title.
51.
▲
Geohot presents an evasi0n7 writeup
(geohot.com)
146 points
by
innoying
13y ago
|
32 comments
52.
▲
iOS OTA Update Protocol Analysis
(hydrantlabs.org)
1 points
by
innoying
13y ago
|
0 comments
53.
▲
by
innoying
15y ago
You are correct. But the theoretical attack from " https://accounts.google.com/reallyuglyurl to " https://accounts.google.com/ServiceLogin remains on the same origin. So while what you say is true, it is not applicable for the example.
54.
▲
HTML5 PushState is dangerous. And you can't do anything about it.
(blog.innoying.com)
6 points
by
innoying
15y ago
|
4 comments