Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
invokestatic
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
91.
▲
by
invokestatic
6y ago
I've heard the exact opposite for security: defense-in-depth. For example, IdP with Okta and 2FA with Duo. This seems much better to me.
92.
▲
by
invokestatic
6y ago
I think the difference is that the scope of DynamoDB is limited. A breach in authentication could result in the complete compromise of a company.
93.
▲
by
invokestatic
6y ago
There's something about Okta that just scares me. If Okta is ever compromised, so are the thousands of companies that rely on it for IdP. How do companies mitigate this risk? Or do they?
94.
▲
by
invokestatic
6y ago
I think it only uses qemu if you attempt to execute on non-x86 architectures. So it’s not a build-time dependency.
95.
▲
by
invokestatic
6y ago
I'd love a device like this, but I don't think a raspi zero has enough processing power. My raspi 4 has a very hard time decoding P25 as it is, and that's with active cooling. Probably the best solution would be to offload th
96.
▲
by
invokestatic
6y ago
Interesting. I had a project that I wanted to use libFuzzer with custom instruction instrumentation. I never quite figured out how to pass back the custom instrumentation data back to libFuzzer. This project seems to do just that by calling
97.
▲
by
invokestatic
6y ago
In the LLVM project, x86_64 is handled inside the x86 namespace. To a compiler, there’s quite a lot of overlap between x86 and the 64-bit extensions that it makes sense to keep them together. In the source, where the difference matters, you
98.
▲
by
invokestatic
6y ago
I do believe x86 in this case encompasses x86_64 (I checked this on the llvm phabricator to be sure).
99.
▲
BitLocker touch-device lockscreen bypass
(secret.club)
4 points
by
invokestatic
6y ago
|
0 comments
100.
▲
by
invokestatic
6y ago
This page has critical misinformation which has already caused confusion on this thread. Version number alone cannot tell you if you are vulnerable or patched! Many, many Linux distributions, including (at least) Ubuntu and RHEL "backp
101.
▲
by
invokestatic
6y ago
If you segfault, you are vulnerable.
102.
▲
by
invokestatic
6y ago
I agree. I’ve employed the BeyondCorp philosophy behind a VPN as an extra measure of security, which is to say that all services are authenticated and encrypted inside the VPN perimeter. As shown in this article, service accounts are a majo
103.
▲
by
invokestatic
6y ago
I do not think wiphy runs on the xA4 because the FPGA is not powerful enough. So if you want to run this project, you'll need to shell out at least $720 for the xA9. I probably will.
104.
▲
by
invokestatic
6y ago
This is an issue with any domain-verified TLS certificate, which make up the overwhelming majority of certificates in use. Only CAs which offer organization-verified (OV) or extended-verified (EV) certificates, typically at exorbitant price
105.
▲
by
invokestatic
6y ago
I recently rolled out smartcard SSH authentication via PIV on Yubikey NEOs. Since the attack requires a few thousand observations, I’m still quite safe, right? An attacker would still need to know the PIV PIN.
106.
▲
by
invokestatic
6y ago
I used to write and sell cheat software for PC games (I work in anti-cheat now). I’ve never experienced this soft of behavior, nor have any of the many contacts I have in the space. I suspect this only occurs in litigious companies (Blizzar
107.
▲
by
invokestatic
6y ago
Yes, I think that use case falls in the 5% gap that had the rug pulled under them. But I really do believe 95% of CentOS users don’t really need that, hosting stuff like HTTP servers or containers. Stuff that really doesn’t need to match RH
108.
▲
by
invokestatic
6y ago
I think there was a very large knee-jerk reaction to the CentOS announcement, myself included. I immediately began looking into alternatives, completely discounting Stream as a viable production OS, a perception shared by many commentators
109.
▲
by
invokestatic
6y ago
This is exactly why I use Red Hat software. Its the insurance provided by the fact RH engineers are massive contributors to the Linux ecosystem as a whole.
110.
▲
by
invokestatic
6y ago
Even if 90% of the product’s value was the Linux kernel (which I disagree with but I won’t get into it), the massive value that Red Hat adds to the kernel is a stable ABI for 10 years. Fixes and new features have to be meticulously backport
111.
▲
by
invokestatic
6y ago
It wasn’t just 10 years of support, it’s 10 years of ABI stability as well. If that wasn’t a big selling point, I don’t think Red Hat or Microsoft would be as successful as they have been in enterprise.
112.
▲
by
invokestatic
6y ago
I sympathize with you and wish it was possible to support your situation and those similar situations like yours. It’s just disabling signature enforcement effectively removes a key security boundary between kernel and user space, something
113.
▲
by
invokestatic
6y ago
This is largely dependent on the passive collection capabilities of a particular anti-cheat. Sometimes getting a copy is useful to just to make 100% sure the detection you wrote works as intended. Sometimes it's because the techniques
114.
▲
by
invokestatic
6y ago
If they don’t want it on Linux it’s up to them. I’m just providing the tools to do it if they decide to be on that platform.
115.
▲
by
invokestatic
6y ago
Secure boot addresses other specific security concerns that are unrelated to exploitable drivers. For instance, it eliminates a whole class of PatchGuard bypasses.
116.
▲
by
invokestatic
6y ago
It’s usually down to the game developer to implement features like that.
117.
▲
by
invokestatic
6y ago
There’s nothing stopping you from using open source drivers, actually. Plenty of open-source projects like Dokan will typically run fine with an anti-cheat (ours will, certainly). What stops you from running a patched version is actually Wi
118.
▲
by
invokestatic
6y ago
When you can remotely prove that the entire boot chain has not been tampered with, it’s much harder to load cheat software in the kernel layer. Of course, still possible, just harder and easier to detect.
119.
▲
by
invokestatic
6y ago
I’m not going to comment on the specifics of what we do besides what I’ve already said. I will say that I’m really pushing to change the perception that all anti-cheats are bad and are user-hostile. I’m trying to build a product that shows
120.
▲
by
invokestatic
6y ago
Before I “switched sides” to anti-cheat, I used to write and sell cheat software for CS:GO. I had a registered company and purchased an EV code signing certificate just as your post suggests, even getting my cheat drivers signed by Microsof
More ›