Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mastersplinter
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Man-in-the-Service: OpSec Safe Relay Techniques
(turtlesec.io)
1 points
by
mastersplinter
5mo ago
|
1 comments
2.
▲
by
mastersplinter
5mo ago
Hi there! Recently released the video of a talk about a new technique for stealthy NTLM relaying in a hardened Active Directory environment. Let me know what you think!
3.
▲
by
mastersplinter
2y ago
will think about this and try to find a good subtitle, thanks :)
4.
▲
by
mastersplinter
2y ago
I like “phishing passkey protected accounts”. I'm not sure I understand what you mean here with: > I’m not going to reach for my phone to scan the QR The whole point of the attack is that it can be delivered without you having to
5.
▲
by
mastersplinter
2y ago
Although this is an attack that can be carried out in practice, it is not quite as scalable as phishing passwords of potentially millions of users across the world. Passkeys are still in general more phish-proof than passwords.
6.
▲
by
mastersplinter
2y ago
So grad you enjoyed it! Chrome awarded 6000 USD, very grateful for it and will fuel some more security research for a while :)
7.
▲
by
mastersplinter
2y ago
I can't speak to the prioritization differences between the different browser teams, Chrome was definitely the best which isn't surprising considering their resources. Apple was also quite swift but I imagine it took them some tim
8.
▲
by
mastersplinter
2y ago
Author of the blog here, I actually agree with you the subheading is quite misleading, any tips on what would be more appropriate? "Phishing PassKeys sessions using browser intents" doesn't make much sense to me
9.
▲
TensorFlow Remote Code Execution with Malicious Model
(splint.gitbook.io)
3 points
by
mastersplinter
4y ago
|
0 comments
10.
▲
by
mastersplinter
4y ago
Ah thanks missed the typo from the title.
11.
▲
Tersorflow Remote Code Execution with Malicious Model
(splint.gitbook.io)
3 points
by
mastersplinter
4y ago
|
2 comments