Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mephux
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
mephux
2mo ago
Link to the disclosures then.. prove it. Anyone can say this.. i found an RCE in netBSD using gemma e2b
2.
▲
by
mephux
2mo ago
We all know this is propaganda to get a gov bailout or to slow down competition with regulations right? If this was an issue companies that did red team engagements would have been regulated long ago. There is no regulations on companies th
3.
▲
by
mephux
3mo ago
https://www.the-odin.com/whole-genome-sequencing-30x/ If you want it quick and cheap(er) - 599.00
4.
▲
by
mephux
11y ago
You just add it to the repo itself. Really not a lot of work. You're a dev... automate it.
5.
▲
Web Security Negligence
(dweb.io)
3 points
by
mephux
11y ago
|
0 comments
6.
▲
by
mephux
12y ago
Indeed! Whats also great about osquery is the security related tables available. I.e process_memeory_map, crontab, passwd_changes, shell_history etc. A lot of the stuff osquery gets is right from the kernel (system calls etc.)
7.
▲
by
mephux
12y ago
1. Security is a huge one. One of the saved queries is checking for processes running that don't have the original binary still on disk. etc. Being able to query stuff like that on demand is powerful. It also has a lot of ops related w
8.
▲
by
mephux
12y ago
Yea, I looked at them. EnvDB has plans to extend past just using osquery. Work could be done to connect deeper or use libosquery directly. I chose to wrap it and plan to build a plugin system for wrapping other processes. It would make wrap
9.
▲
Show HN: Envdb – Ask your environment questions
(github.com)
63 points
by
mephux
12y ago
|
7 comments
10.
▲
Komanda – IRC for people that write code.
(github.com)
9 points
by
mephux
12y ago
|
5 comments
11.
▲
by
mephux
13y ago
As an American that lived in Russia most of my life. It's not total BS but some of the points you mentioned contribute. 1. No one will help you - true. My group of friends would alway be targeted by skinheads and when we had to fight n
12.
▲
by
mephux
13y ago
True, we need a better way to control it. The wrong companies are becoming authorities for the wrong reasons. We at least need more transparency on the verification process. I would also like to see a public list of cert requests that faile
13.
▲
by
mephux
13y ago
DANE is an interesting concept for sure. Not 100% viable in the short-term but going forward we need to start thinking of a better solution. It would still be cert based and just add a layer of complexity. The cert model works it's jus
14.
▲
Let’s Take Back The Certificate Authority
(medium.com)
21 points
by
mephux
13y ago
|
14 comments
15.
▲
by
mephux
13y ago
Pretty good idea.
16.
▲
Detect hackers in action from your iPhone.
(blog.snorby.org)
2 points
by
mephux
14y ago
|
0 comments
17.
▲
by
mephux
14y ago
Reselling ATM (we put this together fairly quickly). We designed our backend architecture to be fairly agnostic though in case we want to switch providers or deploy it in house.
18.
▲
by
mephux
14y ago
Good call - We will get some documentation added asap. We are all security experts and user data has been a huge focus for us since day one. We currently spin up a private collection server per user and use SSL certs tied to each box for se
19.
▲
by
mephux
14y ago
More detailed information can be found on the snorby blog - http://blog.snorby.org/
20.
▲
Show HN: Snorby Cloud - Cloud Based Network Security Monitoring
(cloud.snorby.org)
1 points
by
mephux
14y ago
|
5 comments
21.
▲
by
mephux
14y ago
Yea, agree with the above comments. This can all be done with Nessus (for free). What do you mean by `deep dive`? Are you reselling Burp? What do you plan to offer on the network security side? Keep in mind you should be targeting people wh