Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jorge_leria
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
jorge_leria
1y ago
Same!
2.
▲
14-year-old Instagram account stolen and why it was an inside job
(twitter.com)
4 points
by
jorge_leria
2y ago
|
0 comments
3.
▲
by
jorge_leria
3y ago
Hey, I got into more details in my internal discussion with the researcher and previous post, but around the time we determined we couldn't replicate it, we got a similar report leading me to believe this was already closed. I didn
4.
▲
by
jorge_leria
3y ago
Hey 0xcrypto, I'm very sorry if I gave the impression that we weren't open to discussing anything further on the original issue. After my message, we only received a short comment from you. The issue actually will be still open fo
5.
▲
by
jorge_leria
3y ago
Thank you for your kind words. I can confirm that our support team is stellar. Despite being a small team, we approach every matter very seriously and I was personally involved in the investigation you referenced. The miscommunication with
6.
▲
by
jorge_leria
3y ago
Thank you for your feedback. While my main focus is on Data and Security, I'll ensure that your issues are heard by the team responsible for our mobile app. I'm aware that we're constantly working on improving the iOS app exp
7.
▲
by
jorge_leria
3y ago
Hey! I'm part of Harvest Security Team. We'll be changing the way we do this, but by the time this happened I triaged the report after reading it because it really looked legit. The reality is that we were never able to reproduce
8.
▲
by
jorge_leria
3y ago
Harvest Security Team here. I addressed this on another comment, but basically we were never able to reproduce and there was no explicit fix, but it stayed on Triage state when it should've been Closed, due to a human error on my side.
9.
▲
by
jorge_leria
3y ago
The fact that we kept it in triage means that we believed there was something. Also the reporter gave a really good explanation. By the time the report was originally sent the feature was just released, and while we never deployed a code ch
10.
▲
by
jorge_leria
3y ago
Hi! I'm the person in charge of managing the bug bounty program, and I'd like to shed light on what happened from our end. I already apologized and explained this to @0xcrypto internally, but I believe that I should say something
11.
▲
by
jorge_leria
6y ago
In general it is is not true that Argon2 should be recommended over bcrypt. Even even some of the people on the experts panel for the PHC (where Argon2 won) won’t recommend Argon2 over Bcrypt: https://twitter.com/TerahashCo
12.
▲
by
jorge_leria
6y ago
A new GPU is able to calculate ~50,000 million MD5 hashes per second, an MD5 hash is stored typically on a 32 bytes hex string. If you want to store that you'll need more than 1TB per second: https://gist.github.com/Chi
13.
▲
Supaplex reverse engineered, reimplemented, and ported to Switch and PS Vita
(twitter.com)
3 points
by
jorge_leria
6y ago
|
0 comments
14.
▲
by
jorge_leria
10y ago
Github takes security seriously, this disclosure post is a proof of that.
15.
▲
by
jorge_leria
10y ago
The article is not about serving, but about consuming. Not the same beast.
16.
▲
by
jorge_leria
10y ago
1M per minute it is something. Could you name those frameworks?
17.
▲
by
jorge_leria
11y ago
http://i.imgur.com/5sReybQ.gif Same image -> 333kb. There are a few tricks that you can apply to reduce the size while keeping the same visible quality: http://ezgif.com/optimize
18.
▲
by
jorge_leria
11y ago
The challenge on 360 stereo is on the creation side. While you are able to capture decent mono 360 video with two or three cameras 360 stereo is a different beast you need at least 6-8 cameras and a lot of processing.
19.
▲
by
jorge_leria
11y ago
The best tool around is MITMproxy/MITMdump: Scriptable, free software and multiplatform. http://mitmproxy.org/
20.
▲
by
jorge_leria
11y ago
If you have a jailbroken iOS device you can use SSL Kill Switch [0] to disable certificate pinning and get the traffic with MITMproxy [1] or Charles. [0] https://github.com/nabla-c0d3/ssl-kill-switch2 [1] http:/&
21.
▲
by
jorge_leria
12y ago
I call shenanigans. Spaniard here, the story is completely wrong. Most of the 6k registered users on Quitter Spain are inactive and it has nothing to do with Podemos and the indignados movement (they use Twitter actively along with Facebook
22.
▲
by
jorge_leria
12y ago
I'm currently in charge of answering reporters on a HackerOne program and I can tell that the way Slack is managing its own is completely unacceptable. Those reports were really high quality ones, whenever I receive a report like that
23.
▲
by
jorge_leria
12y ago
YC is famous for funding startups at a very early stage, even at a pre-traction stage, which seems to contradict the popular knowledge that an idea without a good execution is worth nothing. With just an application form and a 10 minute int