Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kseifried
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
31.
▲
by
kseifried
3y ago
I’m going to suggest people try washing their clothes by hand for one week and see how they feel about the technology convenience versus speed argument.
32.
▲
by
kseifried
3y ago
AI won’t replace humans. But a human with AI will replace a human without AI. AI will be a supplemental tool. Just a much higher level tool. That can help improve itself and the users of it.
33.
▲
by
kseifried
3y ago
I’m trying to think of when I want my browser to make noise. Outside of Squadcast, YouTube and CBC, and… I’m drawing a blank. I feel like allow listing a handful of websites to make noise would be fine. Edit: Also, let’s see if anybody repl
34.
▲
by
kseifried
3y ago
Https://gsd.id/
35.
▲
by
kseifried
4y ago
This is the policy owner. Policy execution is different tthan making and owning the policy. Also this means that one person is both responsible for the policy creation and execution. Literally the whole process of "How does one become
36.
▲
by
kseifried
4y ago
There is a standard for this: CCADB.org, which is run by Mozilla (the salesforce login is to Mozilla's, ditto for the bug tracking used to track all this). There's also a LOT of root certificate stores in apps and languages (e.g.
37.
▲
by
kseifried
4y ago
I didn't pull it out of the ether, as per her email: ( https://groups.google.com/a/mozilla.org/g/dev-security-polic... ) > As per Mozilla's root inclusion process I need to make a decision about ap
38.
▲
Guess how many people at Mozilla decide that a CA can become a root? 1
(infosec.exchange)
8 points
by
kseifried
4y ago
|
8 comments
39.
▲
by
kseifried
4y ago
Guess how many people it takes to decide that a root certificate authority (#CA) is accepted into the #Mozilla program, from which all the browsers basically take their root CAs in turn? It's 1 person. And it's not actually docume
40.
▲
by
kseifried
4y ago
We covered this a while ago on the #osspodcast https://opensourcesecurity.io/2022/10/30/episode-347-airtags... TL;DR: Airlines hate being held accountable.
41.
▲
by
kseifried
4y ago
1) If that's the case they should be able to prove they are legitimate without to much effort. If a CA can't prove they are legitimate, well. Err.. they probably need to be booted then. 2) Correct but there are also many CA's
42.
▲
by
kseifried
4y ago
1) Nope, as evidenced by the fact that we just had one existing root CA booted out due to apparent links to spyware (Trustcor) and a second CA applying with links to spyware (BJCA.cn) that may or may not make it in. 2) As I've said, CA
43.
▲
by
kseifried
4y ago
Witness bjca.cn: https://groups.google.com/a/ccadb.org/g/public/c/o9lbCbr92Ug The summary of the public discussion is worrying: Summary of Discussion and Action Items Discussion Item #1: A concern w
44.
▲
by
kseifried
4y ago
It's wild that people think there is some sort of "CA Police" looking out for bad CAs. Sorry but random people like myself demanding answers during the public discussion phase is actually what the "CA Police" looks
45.
▲
by
kseifried
4y ago
So my response: CA's sell trust. Billions of people trust them. They should be above reproach. A CA in the root certificate store has supposedly passed through an arduous set of processes and should be rock solid. While you may not lik
46.
▲
by
kseifried
4y ago
I've been thinking about this a lot, how do we do Security at the SaaS level. Some thoughts: https://github.com/cloudsecurityalliance/CSA-IT-Operations/t... https://github.com/cloudsecurityall
47.
▲
by
kseifried
4y ago
Web3 - The sequel nobody wanted but the studio had to make https://docs.google.com/presentation/d/1V7UGmTw1pR6HsT8kF8dh... TL;DR: All the current stuff is flaming garbage, but that's ok, we're basically
48.
▲
by
kseifried
5y ago
I've assigned this the Global Security Database (GSD) ID GSD-2022-1000285 ( https://raw.globalsecuritydatabase.org/GSD-2022-1000285 ) and started a discussion about these informational entries at https://group
49.
▲
by
kseifried
5y ago
CVE probably won't do CVEs for these as they don't do backdoors/intentionally malicious code (but maybe they will, who knows). In any event the color.js issue is being tracked by the #GSD https://globalsecuritydat
50.
▲
by
kseifried
5y ago
Norton AntiVirus now includes an Ethereum crypto miner that has several problems including deceptive rewards program and difficulty in uninstalling it. Norton keeps 15% of all Ethereum mining proceeds and "pays" the remainder into
51.
▲
by
kseifried
5y ago
It's just a classic gift card balance exploit. From GSD-2022-1000002 ( https://github.com/cloudsecurityalliance/gsd-database/blob/m... ) Norton AntiVirus now includes an Ethereum crypto miner that has seve
52.
▲
by
kseifried
5y ago
You mean like the people paid to wait in line for other people at US gov hearings? https://www.vox.com/policy-and-politics/2019/2/13/18223836/p... Sounds awfully similar to "completing tasks co
53.
▲
by
kseifried
5y ago
On the flip side they sent me an email that wasn't lying, so they could have done this for everyone: priv...@princetonprivacystudy.org Tue, Dec 14, 12:25 AM (5 days ago) to me To Whom It May Concern, We are researchers at Princeton Uni
54.
▲
by
kseifried
5y ago
Trying to stop credential stuffing by blocking bots will not work, and can often severely impact people depending on assistive technologies. I think a better solution is to implement 2FA/MFA (even bad 2FA/MFA like SMS or email wil
55.
▲
by
kseifried
5y ago
This is a classic case of http://spellchecksquatting.com/
56.
▲
by
kseifried
5y ago
You want proof that people don't yet trust IPv6? Simply lookup SPF records, very few (like <5%) of domains list IPv6 records in their SPF record, for example Google and Outlook do, but aol.com/yahoo.com do not. Email is a criti
57.
▲
by
kseifried
5y ago
And conversely there are clocks with smooth movement of the second hand, something I prefer because then there's no annoying ticking noise.
58.
▲
by
kseifried
5y ago
And conversely there are clocks with smooth movement of the second hand, some
59.
▲
by
kseifried
5y ago
Just a heads up I assigned CVE-2021-1000189 https://json.distributedweaknessfiling.org/CVE-2021-1000189 , especially in light of the data harvesting concerns and DoS (offering people the ability to arbitrarily k-line people)
60.
▲
by
kseifried
5y ago
Because often times they didn't get to the asking stage, they got to the "can we talk to someone about X and ask questions?" stage and nobody replied by the article deadline.
More ›