Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jwcrux
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
jwcrux
15d ago
How do you see passkeys as a walled garden but not 2FA? You presumably store your 2FA seed in a password manager.
2.
▲
by
jwcrux
2y ago
How is this a replacement for LangSmith? I browsed the source and I could only find what appear to be a few small helper functions for emitting structured logs. I’m less familiar with LangSmith, but browsing their site suggests they happen
3.
▲
by
jwcrux
2y ago
I feel like I’m missing something. Isn’t this blog post effectively “we patched our firewall, things broke, we made a support case, and the vendor investigated and filed a CVE”?
4.
▲
by
jwcrux
2y ago
Vanguard is also affected for me.
5.
▲
by
jwcrux
3y ago
Oh wow, gridstatus is super cool! I noticed that you have a page on records that have been set. It looks like Ercot released this data today that might be of interest: https://www.ercot.com/news/release/2023-09-14-
6.
▲
by
jwcrux
5y ago
Congrats on the launch! Could you expand a bit on how you differentiate your product from other products in the space like Tailscale and Nebula? Edit - I see you mention that Tailscale uses userland WireGuard. Is that the biggest difference
7.
▲
by
jwcrux
5y ago
> - Healthcare staff have great animosity towards the unvaccinated patients. In addition to this, I’ve also heard anecdotally that many of the unvaccinated (by choice) patients have animosity towards the healthcare workers themselves bec
8.
▲
by
jwcrux
6y ago
We also don't know what the effects of covid are in 10 years.
9.
▲
by
jwcrux
6y ago
> "So I need to check for-" That's the thing. If we're watching syscalls, we see these checks. These would be things like attempted file-reads. Would they be enough to set off alarms? Maybe, maybe not. This is general
10.
▲
by
jwcrux
6y ago
So there are two things to consider here: 1) The “observable window” is the entire installation time. If they make installs take forever, that’ll affect everyone which should raise alarms pretty quick. 2) The conditional execution is possib
11.
▲
by
jwcrux
6y ago
I've been in touch with folks from the Open Source Security Foundation [0] who is interested in making this a centralized service. I'm a big believer that functions like this should be centralized under a foundation like that, and
12.
▲
by
jwcrux
6y ago
Hey friends! Author here. If you're looking for a tl;dr you can find one on Twitter (with pictures!) [0] This research was a blast to do, and I learned a ton. Happy to answer questions! [0] https://twitter.com/jw_sec&#x
13.
▲
Hunting for Malicious Packages on PyPI
(jordan-wright.com)
4 points
by
jwcrux
6y ago
|
0 comments
14.
▲
by
jwcrux
6y ago
You almost certainly don't need a web framework. Over the long term, it's easy to find yourself boxed in with how opinionated many of them are. Instead, if you build on the standard library, you can compose your application from t
15.
▲
by
jwcrux
6y ago
> Hash is a Brazilian fintech building the next-generation of payments infrastructure. In general I agree with the point you're making, though.
16.
▲
by
jwcrux
6y ago
This is a scam that has been going on for years that has adapted its techniques over time. We used this botnet as a case study back in 2018 when doing analysis on finding Twitter bots at a large scale. You can find the paper here [0] - the
17.
▲
by
jwcrux
6y ago
You can find details on it here [0] > S2 Systems NVR technology intercepts the remote Chromium browser’s Skia draw commands, tokenizes and compresses them, then encrypts and transmits them across the wire to any HTML5 compliant web brows
18.
▲
by
jwcrux
6y ago
Nice! I did the same recently, where I requested my data from 14 different location data companies. [0] One company returned my data. Part of the difficulty was making the CCPA requests since I live in Texas, but the majority of responses w
19.
▲
by
jwcrux
6y ago
I love seeing comics like this that aim to show concepts in simple ways. Kudos! Worth noting that "The Handshake" episode [0] covers the key exchange using RSA. This has the downside that it doesn't support forward secrecy, m
20.
▲
Data Companies Are Watching Me
(duo.com)
1 points
by
jwcrux
6y ago
|
0 comments
21.
▲
by
jwcrux
6y ago
It is low. Estimates [0] put the number closer to 500M/day. [0] https://www.internetlivestats.com/twitter-statistics/#source...
22.
▲
Protecting Accounts from Credential Stuffing
(duo.com)
1 points
by
jwcrux
7y ago
|
0 comments
23.
▲
An Introduction to the Noise Protocol Framework
(duo.com)
2 points
by
jwcrux
7y ago
|
0 comments
24.
▲
by
jwcrux
7y ago
You’d love _The Unicorn Project_ if you haven’t read it. I highly recommend it, and it’s a story around roughly the same journey. https://www.amazon.com/Unicorn-Project-Developers-Disruption...
25.
▲
by
jwcrux
7y ago
I run both on my Pi4 and still have plenty of resources to spare.
26.
▲
How to Monitor GitHub for Secrets
(duo.com)
1 points
by
jwcrux
7y ago
|
0 comments
27.
▲
How Security Keys Store Credentials
(duo.com)
3 points
by
jwcrux
7y ago
|
1 comments
28.
▲
Detecting Phishing with SPF Macros
(duo.com)
1 points
by
jwcrux
7y ago
|
0 comments
29.
▲
Building Web Servers in Go
(getgophish.com)
5 points
by
jwcrux
8y ago
|
0 comments
30.
▲
by
jwcrux
8y ago
When I first launched Gophish a few years ago, I sent an email to a reporter I'm a fan of basically saying "Hey, I made this thing, I think your readers would benefit from it". Their response was lightheartedly asking me if I
More ›