Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jamesmotherway
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
(cloud.google.com)
4 points
by
jamesmotherway
1y ago
|
0 comments
2.
▲
by
jamesmotherway
2y ago
I've used favicons (along with analytics IDs) to identify related malicious sites. You can also apply this to detect brand abuse and phishing pages.
3.
▲
by
jamesmotherway
2y ago
See the "Data categories and encryption" section: "The table below provides more detail on how iCloud protects your data when using standard data protection or Advanced Data Protection." https://support.apple.
4.
▲
by
jamesmotherway
2y ago
Sorry, I overlooked part of your post earlier - I'm tired. As I previously alluded to, I don't use passkeys due to concerns about their implementation. Whether passkeys are better than TOTP really depends on the individual user&#x
5.
▲
by
jamesmotherway
2y ago
Hardware keys and passkeys are better because they can't be phished. In the case of hardware keys, one should register multiple to prevent lockout. Most implementations of passkeys seem to be portable, letting them exist on multiple de
6.
▲
by
jamesmotherway
2y ago
If the vault requires a hardware key and master password to access the encrypted password and token, would you still describe it as single-factor authentication?
7.
▲
by
jamesmotherway
2y ago
China-nexus threat actors tend to be focused on espionage, including intellectual property theft. "Prepositioning" is a more recent observation, but it doesn't mean a war is inevitable. While it would be useful in that scenar
8.
▲
by
jamesmotherway
2y ago
Is your system configured to share analytics and diagnostics? I disable both, and when a crash occurs, I receive a dialog with an "ignore" option.
9.
▲
by
jamesmotherway
2y ago
Bad actors frequently use BuyVM's services, also known as FranTech and Ponynet. Their popularity with Tor operators probably doesn't help how their network traffic is perceived either. As a result, organizations may handle traffic
10.
▲
by
jamesmotherway
2y ago
https://archive.is/NKPrR
11.
▲
by
jamesmotherway
2y ago
I'm assuming by "significant" you mean an attack on critical infrastructure. That's a strategic capability that very likely requires multiple attack chains, not a single exploit. For Western countries, cost is probably t
12.
▲
by
jamesmotherway
2y ago
The X230 is still relevant for those who want a ThinkPad that supports Libreboot (an alternative firmware without proprietary components). I personally found this demonstration interesting; users of these devices often believe they're
13.
▲
by
jamesmotherway
2y ago
I'm inclined to believe it. If someone managed to prove Apple's lying about it, there would be serious reputational (and other) risks to their business. I also can't imagine how they would benefit from such a fabrication. Tha
14.
▲
by
jamesmotherway
2y ago
"All Apple silicon-based Mac notebooks and Intel-based Mac notebooks with the Apple T2 Security Chip feature a hardware disconnect that disables the microphone whenever the lid is closed. On all 13-inch MacBook Pro and MacBook Air note
15.
▲
by
jamesmotherway
2y ago
Threat actors don't create malware to impress people; they do it to accomplish their goals. Apparently, this sample was sufficient for them. Security companies attribute activity based on their observations. ESET- a Slovakian company-
16.
▲
by
jamesmotherway
2y ago
The NSA publishes excellent cybersecurity resources: https://www.nsa.gov/press-room/cybersecurity-advisories-guid... I've highlighted advisories that may give you some perspective, listed in chronological order: I
17.
▲
by
jamesmotherway
2y ago
I understand where you're coming from, but Apple Intelligence is labelled as a beta feature.
18.
▲
by
jamesmotherway
2y ago
The alternative in many cases would be to install MDM software on one's personal device, which seems like the worse option to me.
19.
▲
by
jamesmotherway
2y ago
Banks use various other services such as Early Warning. Still, it's absurd the lengths we need to go to for any level of assurance against fraud.
20.
▲
by
jamesmotherway
2y ago
Thanks for your feedback. I posted this because I've seen many people stop their analysis when they find a site is on Cloudflare. Were you able to solve the challenge at the end?
21.
▲
Correlating Ownership of Sites Protected by Cloudflare
(jamesmotherway.com)
38 points
by
jamesmotherway
2y ago
|
6 comments
22.
▲
by
jamesmotherway
2y ago
Satiety is precisely it, and I would not be so quick to minimize its effect. Reasoning by analogy, most would accept that some people are better suited to extended release medication versus instant. A drug is defined as something that has a
23.
▲
by
jamesmotherway
2y ago
It's frightening to think about the implications of this when generalized toward mainstream topics.
24.
▲
by
jamesmotherway
2y ago
It's certainly interesting, but he's not a hero.
25.
▲
by
jamesmotherway
2y ago
Not everyone is doing coding interviews. Some might struggle with a particular language due to lack of muscle memory, but can dictate the logic in pseudocode and can avoid pitfalls inferred from past experience. This sort of workflow is com
26.
▲
by
jamesmotherway
2y ago
There's zero evidence showing the harm of processed foods? Consider that nutrition labels are largely focused on macronutrients. Carbs, fat, protein. Calories in and calories out. What processed food tends to lack are micronutrients fo
27.
▲
by
jamesmotherway
2y ago
Thanks. I would suggest you reconsider deferring updates. Apple does not consistently backport security updates to prior versions of macOS.
28.
▲
by
jamesmotherway
2y ago
Some people rise to the occasion during crises and find it rewarding. There's a lot of pop science around COMT (the "warrior gene" associated with stress resilience), which I take with a grain of salt. There does seem to be s
29.
▲
by
jamesmotherway
2y ago
I came across this post while searching for something else. This behavior is to mitigate the risk of abuse, plain and simple. Apple does not want ephemeral iCloud addresses sending out malicious content. Yes, you can still theoretically do
30.
▲
by
jamesmotherway
2y ago
I believe you're on the right track. To me, it only seems paradoxical when viewed in isolation. mTOR activation is conducive to growth, but unchecked growth is called cancer. A person (and the processes in their body) goes through cycl
More ›