Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
karma20
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
karma20
7y ago
Firefox for iOS and macOS. I have strict tracking protection [1] enabled on the former, and NoScript + uBlock Origin set up on the latter. I also use Little Snitch on the Mac. [1] https://support.mozilla.org/en-US/kb&#x
2.
▲
Awarding Google Cloud Vulnerability Research
(security.googleblog.com)
3 points
by
karma20
7y ago
|
0 comments
3.
▲
Apple expands its bug bounty, increases maximum payout to $1M
(techcrunch.com)
1 points
by
karma20
7y ago
|
0 comments
4.
▲
by
karma20
7y ago
I like the concept but share some of the blockchain concerns here. In particular, I'm interested in how the Gaia "driver model" [1] is actually architected, and how this compares to local storage: > Gaia enables applicatio
5.
▲
Amazon's Plan to Conquer the World of Publishing
(theatlantic.com)
1 points
by
karma20
7y ago
|
0 comments
6.
▲
by
karma20
7y ago
HN's policy on paywalls is outlined in the FAQ [1]. Private Browsing mode is generally a good workaround: > It's ok to post stories from sites with paywalls that have workarounds. > In comments, it's ok to ask how to re
7.
▲
Postmates lands first-ever permit to test sidewalk delivery robots in SF
(techcrunch.com)
3 points
by
karma20
7y ago
|
0 comments
8.
▲
by
karma20
7y ago
HackerOne is a platform on which Valve runs a public program [1] that awards monetary bounties. I'm confused as to why Valve is allowed to forbid disclosure of "out-of-scope" reports and will only "generally" disclo
9.
▲
HTTP Desync Attacks: Request Smuggling Reborn
(portswigger.net)
75 points
by
karma20
7y ago
|
11 comments
10.
▲
From the Depths of Counterfeit Smartphones
(blog.trailofbits.com)
14 points
by
karma20
7y ago
|
0 comments
11.
▲
by
karma20
7y ago
Also of interest is the follow-on discussion [1] taking place on the electron/asar repo. [1] https://github.com/electron/asar/issues/123
12.
▲
by
karma20
7y ago
Qihoo has also employed dark patterns to push deceptive security practices around its own browser [1]: > When you attempt to install other browsers, the 360 Safe Guards will allow the browser to be installed but will then popup saying no
13.
▲
Nintendo, Microsoft, and Sony commit to disclose drop rates for loot boxes
(theverge.com)
13 points
by
karma20
7y ago
|
2 comments
14.
▲
The People Who Love to Watch Other People Clean
(theatlantic.com)
2 points
by
karma20
7y ago
|
0 comments
15.
▲
Disney Announces $12.99 Bundle for Disney+, Hulu, and ESPN+
(theverge.com)
9 points
by
karma20
7y ago
|
5 comments
16.
▲
by
karma20
7y ago
TL;DR: Microsoft bumps Azure max bug bounty to $40k, introduces Azure segregated hosts for researchers to test against, and formalizes their Safe Harbor terms [1]. [1] https://www.microsoft.com/en-us/msrc/bounty-sa
17.
▲
Azure Security Lab: a new space for Azure research and collaboration
(msrc-blog.microsoft.com)
1 points
by
karma20
7y ago
|
1 comments
18.
▲
by
karma20
7y ago
Interesting concept. From the FAQ [1]: > Login into Hero Trainer when you go for a run (gym check-ins will come in the future) How would you calculate points earned for each run or gym visit? For the former, does the app rely on step cou
19.
▲
Apple Card Is Now Available in Early Access
(wired.com)
2 points
by
karma20
7y ago
|
0 comments
20.
▲
by
karma20
7y ago
TIL. I should check out Rectangle: > Spectacle used it's own keyboard shortcut recorder, while Rectangle uses MASShortcut [1], a well maintained open source library for shortcut recording in macOS apps. This cuts down dramatically o
21.
▲
by
karma20
7y ago
Interesting. From the source article [1]: > [...] they would essentially be "dev devices." Think of them as iPhones that allow the user to do a lot more than they could on a traditionally locked-down iPhone. It sounds like Appl
22.
▲
by
karma20
7y ago
At least in part, the author seems to conflate 'collecting images of pax' with 'their usage of the IFE': > Cathay confirmed it is collecting images of passengers while they're on board, monitoring their usage of
23.
▲
Lessons in auditing cryptocurrency wallets, systems, and infrastructures
(blog.doyensec.com)
2 points
by
karma20
7y ago
|
0 comments
24.
▲
by
karma20
7y ago
For sure. It definitely echoes the thrill of bug-hunting when you know you’ve found something interesting but need to dig a bit deeper.
25.
▲
Self-XSS to Site-Wide CSRF on Twitter
(speakerdeck.com)
2 points
by
karma20
7y ago
|
2 comments
26.
▲
Walmart Takes on Amazon with Streaming Video in India
(bloomberg.com)
1 points
by
karma20
7y ago
|
0 comments
27.
▲
by
karma20
7y ago
> It is fascinating how we are moving from traditional ads, as everyone has grown an automatic negative response, into these more subtle experiences. Absolutely, and overlay AR sounds like their next step: > Snap recently released zan
28.
▲
by
karma20
7y ago
Todos: I use Trello with a handful of boards, most containing Getting Things Done style lists (Today, Tomorrow, This Week, Sometime). Note-taking: I settled on Bear after trying Apple Notes, Evernote, and OneNote. While I can't searc
29.
▲
by
karma20
7y ago
Agree. This kind of DLP-like scanning is totally infeasible at GitHub scale. In particular, one excerpt from the complaint reads like output from a noisy scanner that has detected “exposed SSNs” in client-side code: > [...] Social Securi
30.
▲
by
karma20
7y ago
Das Pro, brown switches. Picked one up to replace my aging daily driver at work (Magic Keyboard). No complaints here.
More ›