Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kdbg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
Show HN: Day[0] – I started a weekly security podcast that gets technical
(dayzerosec.com)
2 points
by
kdbg
6y ago
|
2 comments
32.
▲
by
kdbg
7y ago
While I didn't have high hopes to get a summary of a technical paper, since I spend a good chunk of time every week reading some related to exploits and mitigations for a podcast I host, I hoped this might help reduce time spent trying
33.
▲
by
kdbg
7y ago
Not exactly the same but https://portswigger.net/web-security has several good lessons and labs about specific attacks.
34.
▲
by
kdbg
7y ago
Kind of relevant, a friend of mine posted his own writeup about exploiting this bug earlier this month. https://dayzerosec.com/posts/analyzing-androids-cve-2019-221...
35.
▲
Analyzing Android's CVE-2019-2215 (/dev/binder UAF)
(dayzerosec.com)
2 points
by
kdbg
7y ago
|
0 comments
36.
▲
by
kdbg
7y ago
Currently down, here is an archived version: https://web.archive.org/web/20191029172726/https://rietta.co...
37.
▲
by
kdbg
7y ago
Its really just two components - Kaspersky Safe Kids - Does the actual locking/restrictions - Custom Python Script - Communicates with Fitbit/leetcode/projecteuler/wechall and can update a the restrictions on the Kaspers
38.
▲
by
kdbg
7y ago
Kaspersky Safe Kids. I chose it after experimenting with a bunch of options, it was the only one that wasn't trivial to bypass on my phone. Basic setup is that I wrote a script (against Kaspersky ToS) that can login and change the lock
39.
▲
by
kdbg
7y ago
This might sound a little-bit stupid, but I automate locking/unlocking internet access on my phone and computer. That is to say, every night my computers and phone will lock me out[0] at a set time. Then in the morning I have to log 30
40.
▲
by
kdbg
7y ago
Some cross-site scripting in usernames there, otherwise its a fun concept. Edit: To the author the fix is pretty small: In socket.on('toplist', (data) => {...}) Replace the line: $('#toplist tr:last').after(
41.
▲
by
kdbg
7y ago
The original announcement email does a much better job of explaining the actual vulnerability, and the configuration under which its an issue (using ALL and !root in the runas part of the sudoers entry) https://www.openwall.com&#
42.
▲
by
kdbg
7y ago
Adding onto what nitrogen said (and I also am not a lawyer) but interoperability is a listed exemption to DMCA. It might be costly to fight but I really don't think they have a leg to stand on to claim copyright. Terms of service viola
43.
▲
by
kdbg
7y ago
Not sure how you're managing that, A is the answer to the first tutorial, but doesn't work for the second one. If you click Validate it'll shake and turn red, though you can skip ahead all you want, you want it to turn green
44.
▲
by
kdbg
7y ago
I think for that you might want to research Protein sparing modified fasting, https://en.m.wikipedia.org/wiki/Protein-sparing_modified_fas... Gist of it is you still cut significant calories only eating like 500-800 a
45.
▲
by
kdbg
7y ago
https://bugzilla.mozilla.org/show_bug.cgi?id=697436#c14
46.
▲
by
kdbg
7y ago
> Imagine one year where I dedicate two days a week learning, understanding and trying. Do I would have any chance at all to find something worth the $1M? Yes...but probably not the way you're thinking. Most issues are discovered th
47.
▲
by
kdbg
7y ago
Day[0] - https://www.youtube.com/channel/UCXFC76FDHZRVes6_lZqwLBA We are not putting out any new episodes right now though, I'm currently off on a long-distance hike.
48.
▲
by
kdbg
7y ago
> And that you were able to provide the US based documentation I don't recall needing to provide any documentation? I'm also not American so I couldn't provide "US Based documentation" whatever that means. There
49.
▲
by
kdbg
7y ago
I'm not entirely convinced it is. I started a exploit development/security podcast with a couple friends a few months ago, we were banned on Youtube shortly after the 4th episode for a community guidelines violation. We appealed i
50.
▲
by
kdbg
7y ago
I'll actually be a counter example to that, I recently started a security podcast with a couple friends, talking about the latest in exploit development and mitigations, and whatever news we find interesting. Shortly after we uploaded
51.
▲
by
kdbg
7y ago
I'm not a lawyer but this reminds me of how game mods are shared for old games. They are shared at patch files to avoid sharing the copyrighted original binary/rom file. My understanding is that use a patch file as long as your pa
52.
▲
by
kdbg
7y ago
> Why would I give WalMart $1 to forward to Children's Hospital when I could just give Children's Hospital $1 directly? Perhaps you don't want people knowing who you're donating to, and the third party offers that pri
53.
▲
by
kdbg
7y ago
I think the cryptocurrency was used so that they could make stronger privacy guarantees than they could using a proper currency. That seems like a fair trade-off to me, but it is indeed a trade-off between privacy and usefulness it is one I
54.
▲
by
kdbg
7y ago
> So, here's a thought, Mozilla should create a tip jar non-profit organization. Tipping would be something built into Firefox. If you tip someone, it's sent to the non-profit's bank, and connected to the url. Site owners
55.
▲
by
kdbg
7y ago
I had the same question. So a quick run down of what the architecture actually does: The core feature is Domain Tagging . The architecture adds 2 bits to data that define its 'domain' (code, code pointer, data, and data pointer).
56.
▲
by
kdbg
7y ago
I don't think they care about that type of attack, they specifically call out control flow attacks. From the abstract: > Morpheus defenses offer strong protection against control-flow attacks
57.
▲
by
kdbg
7y ago
That's how it reads. one important distinction is that it continually randomizes itself not just one time like ASLR. Without access to the paper it's hard to say how granular the randomization is, and what is static. It's app
58.
▲
by
kdbg
7y ago
Generally speaking, there isn't a difference between traveling for the purpose of work and working while traveling for other reasons. If you are physically in one country while performing work it is considered working in that country a
59.
▲
by
kdbg
8y ago
As a 9 year old in late 2000, Knoppix was my introduction to Linux. I wasn't asked to install Linux on the family computer (not that I knew how to). I don't remember how I first heard about Linux or Knoppix but I do remember those
60.
▲
by
kdbg
8y ago
I'm a bit mixed in this. I've actually had both experiences. I've turned two hobbies I loved intoy full time job. The first one (magician) went as you stated, I ended up hating it, or atleast hating it as a job. It paid prett
More ›