Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
kro
1y ago
The tools can be an editor/terminal/dev environment, automatically iterating to testing the changes and refining until a finished product, without a human developer, at least that is what some wish of it.
62.
▲
by
kro
1y ago
There is a jti claim that can be used for storing a token ID, so you could enforce tracking all issued tokens server side. Cracking 256bit by brute force is unrealistically unlikely as you said, and there are many systems that could be comp
63.
▲
by
kro
1y ago
That tool sounds a lot like rsnapshot, I'm still using it
64.
▲
by
kro
1y ago
Most IoT devices implement security and integrity using one time burnable registers (more importantly for keys). It's sad but yes, those devices are permanently bound to the vendor. There is no real alternative though, a TPM based ap
65.
▲
by
kro
2y ago
imo it should be considered to achieve the 404 design with minimal complexity. Keep the document small, to prevent i.e. old touch/favicon requests from wasting lots of bandwidth. (Not intended to criticize this post)
66.
▲
by
kro
2y ago
Yopmail does verify and show these results for free when receiving a mail, this not even being their core feature
67.
▲
by
kro
2y ago
The idea is good, as far as I understand TLS however, the cert / asymmetric key is only used prove the identity/authenticity of the cert and thus the host for this session. But the main content is not signed / checksummed wit
68.
▲
by
kro
3y ago
Last year I had a (of many) freshly provisioned Linux VMs clock change to the year 2257 2 nights in a row. Never figured that out sadly, reprovisioning "fixed" that.
69.
▲
by
kro
3y ago
Yes, The TPM & secure boot requirements are somewhat understandable, but the CPU whitelist on top of that is just weird.
70.
▲
by
kro
3y ago
Being one of the biggest publishing softwares naturally attracts all of that: more publicity/cases, uninformed users, incentive and a probing/persistence ecosystem for hackers,. I have to host a few dozen WordPress sites for custo
71.
▲
by
kro
3y ago
Discord has already started integrating their own payment for content/channels recently. https://discord.com/serversubscriptions
72.
▲
by
kro
3y ago
iirc often also with lots of fake comments claiming it's legit
73.
▲
by
kro
3y ago
I've also wondered that, seeing MrBeast giveaway ads to fakedomains every other day. Reporting all those gets exhausting soon.
74.
▲
by
kro
3y ago
Rotating (and removing old keys from DNS) without publishing the private keys would already make it really hard. For proving an old signature you'd lack an _authentic_ source for the signing public key that could only really be a dump
75.
▲
CVE-2023-42115 Exim RCE
(zerodayinitiative.com)
7 points
by
kro
3y ago
|
3 comments
76.
▲
by
kro
3y ago
The site makes it appear Exim never took action on their info to them more than a year ago. other: https://security-tracker.debian.org/tracker/CVE-2023-42115
77.
▲
by
kro
3y ago
That is for dedicated servers and additional IPs. The first on a VPS is 0,60€
78.
▲
by
kro
3y ago
dig +trace reveals that only some of the nameservers don't respond (on IPv4, but got a fine response after trying an IPv6). ;; communications error to 66.111.50.12#53: timed out ;; communications error to 66.111.50.12#53: tim
79.
▲
Nginx QUIC+HTTP/3 Preview Binary Packages available
(nginx.com)
2 points
by
kro
4y ago
|
0 comments
80.
▲
by
kro
4y ago
Flutter also comes to mind
81.
▲
by
kro
4y ago
The MX servers cert in my experience does not need to include your email domain name .
82.
▲
by
kro
4y ago
Installing without internet connection also has the major benefit that it allows you to use a local user account rather than forcing you to signup for an online Microsoft/hotmail/.. account
83.
▲
by
kro
4y ago
It reads like it indeed does not affect live data in running cloudservers, yes. Aside from backups, the snapshots can also be used as base images to provision new nodes though, losing those could indeed be inconvenient.
84.
▲
by
kro
5y ago
I think they talk about worms that spread by infecting other devices in the local network using RCEs in net-services like rdp/smb/.. That or maybe drive-by downloads / java/activeX code execution, which have become more
85.
▲
by
kro
5y ago
Where does it say that? As per rfc7489 4.2: A message satisfies the DMARC checks if at least one of the supported authentication mechanisms: 1. produces a "pass" result Personally I did not test yet what a DMARC result
86.
▲
by
kro
5y ago
It's a rather simple Postfix setup: transport.db: hotmail.com relay:[relay.server.tld]:587 # and other domains main.cf: transport_maps = hash:/etc/postfix/transport smtp_sasl_password_maps = hash:/etc/pos
87.
▲
by
kro
5y ago
To most, including Gmail, it's actually no problem with DMARC in my experience too. However, one of my servers IPs is on a Microsoft blacklist since many years now. It sends <10 messages / day. I've tried every unlist for
88.
▲
by
kro
5y ago
I remember a few months ago I got a bug-report from a customer that "their site didn't show in link-previews in MS-Teams". The URL includes a German "Umlaut": ü After tracing the HTTP requests received from the link
89.
▲
by
kro
5y ago
I already had Bind on the machine so it was logical to add the zone there and utilize nsupdate : https://gist.github.com/kronthto/893715f12cc0b1cda9fcfdbd8dc... But what you are suggesting should work just fine aswell
90.
▲
by
kro
5y ago
What I've done is delegate (NS record) only the subdomain _acme-challenge to a standalone DNS-zone the webserver has write access to. This way it cannot escalate to changing root A/MX.
More ›