Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kseifried
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
kseifried
5y ago
Assigned CVE-2021-1000040 for this issue because a minimum DroidScript can no longer get updates out to users. They may also be doing bad things, as claimed by Google, but either way the ecosystem will start to get stale and security issues
62.
▲
by
kseifried
6y ago
And that's great until you have a kid with special needs like autism. Some kids need parenting that involves a lot of direct hours being put in. Raising kids is not a "one size fits all" kind of deal.
63.
▲
by
kseifried
6y ago
MITRE is a non profit that "manages federally funded research and development centers (FFRDCs) supporting several U.S. government agencies" they have a technology and cyber security mandate which is still big (they run CVE, CWE, S
64.
▲
by
kseifried
6y ago
What I don't get is this: You build software, you ship it on an OS so it works, cool, this makes sense (I assume you need hardware and VM support, not just VM). Why would you accept additional risk on the OS if you can easily reduce th
65.
▲
by
kseifried
6y ago
Try getting an Alexa/Siri or whatever to play "Radio" by Rammstein. Come back when you're done listening to random top 40 radio or being told there is no Rammstein radio station and click the link below to hear the song.
66.
▲
by
kseifried
6y ago
Another option to: "One of the most effective techniques is one practiced unintentionally by most nerds: simply to be less aware what conventional beliefs are. " Is to be aware of them, and to be aware that they may not be correct
67.
▲
by
kseifried
6y ago
I dreaded leaving my desktop Mac as well due to OmniFocus but they have a web based version that's ok https://web.omnifocus.com/
68.
▲
by
kseifried
6y ago
What are the options (ideally Linux based) to synchronize files and data (e.g. contacts) between Google Drive, iCloud and Microsoft OneDrive? I guess we have to do RAICP (Redundant Array of Inexpensive Cloud Providers) now? I get that I can
69.
▲
by
kseifried
6y ago
Making security by obscurity actually work The reality is security by obscurity CAN work, but only if three critical elements are met: The first is to know when the obscurity has failed The second is to be able to quickly change the obscure
70.
▲
by
kseifried
6y ago
Dunning-Kreuger, the long and short of it is many problem appear "simple" and take an afternoon.. right? For something that converts a date from ISO format to American (M-D-Y) sure it might be simple, but anything that listens or
71.
▲
by
kseifried
6y ago
The entities that most benefit monetarily from OpenSource are companies that sell products and services based on them. Why would they contribute to this? It's an added expense they don't have to pay. In fact a major tenant of Open
72.
▲
by
kseifried
6y ago
File a ticket. I file so many tickets for work I do. Sometimes after the fact ("oh... they'll wonder why I ..."). A journal is good, but using whatever institutionalized knowledge system your company relies upon (usually some
73.
▲
by
kseifried
6y ago
To quote Tommy Boy: Ray Zalinsky: Goin' a little heavy on the pine tree perfume there kid? Tommy: No, it's an auto air freshener. Ray Zalinsky: Good, you've pinpointed it, now the next step is washin' it out.
74.
▲
by
kseifried
6y ago
But you pay for those in the form of rent. As a homeowner you can also pay someone to do those things. There are a ton of property management companies that will handle a single house if you want to completely hand it off to someone. In gen
75.
▲
by
kseifried
7y ago
For everyone freaking out about zoom security, some facts: 52 CVEs for Zoom https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=zoom 240 for webex https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=webe
76.
▲
by
kseifried
7y ago
We discussed this on the OpenSourceSecurity Podcast back in Feb 2020 https://www.opensourcesecuritypodcast.com/2020/02/episode-18... TL;DR: this is the least painful outcome of these DNS shenanigans.
77.
▲
by
kseifried
7y ago
Not everyone has access to a ton of bandwidth.
78.
▲
by
kseifried
7y ago
/msg Dave SCP-[REDACTED] is out again, can someone notify MTF-^$ to get on a disinformation campaign and cleanup?
79.
▲
by
kseifried
7y ago
Also to reiterate: "which would not be eligible for CVEs, since this is pre-release snapshot software" is not correct. It's usually correct, but not 100%.
80.
▲
by
kseifried
7y ago
Yeah and he's not the boss of CVE. If someone wanted a CVE for wireguard I'd be happy to help them get one.
81.
▲
by
kseifried
7y ago
CVE does cover "pre-release" software, part of the argument being you can't simply label something as "beta" and escape CVE coverage especially if millions of people are using it (Google's Chrome web browser wa
82.
▲
by
kseifried
7y ago
Sorry but... no. You are wrong. Completely wrong. CVE is just an identifier for a security vulnerability. "Common Vulnerabilities and Exposures" CVE generally covers released software, hardware and (in the process or being added o
83.
▲
by
kseifried
7y ago
I was planning to get a FitBit to replace my "veryfitpro" (it's cheap and waterproof) but cancelled that idea after Google announced the acquisition of FitBit. Now I'm seriously considering an Apple watch since they see
84.
▲
by
kseifried
7y ago
You mean Core Impact? =).
85.
▲
by
kseifried
8y ago
Still no CVE assigned, and no-one has requested, not even via https://iwantacve.org/
86.
▲
by
kseifried
9y ago
This now has the identifier: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259
87.
▲
by
kseifried
9y ago
This now has the identifier: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259
88.
▲
by
kseifried
9y ago
Ah it got a CVE yesterday: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259
89.
▲
by
kseifried
9y ago
I have requested a CVE for this, due to unsafe password storage (CWE-256).
90.
▲
by
kseifried
9y ago
With respect to https://lkml.org/lkml/2017/11/21/356 and this thread I just want to get #CVEs on all the things so we can figure out the scope of the problem, and then look at what we need to do to "
More ›