Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mjschultz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
mjschultz
14y ago
The deluge wouldn't be worse than a targeted attack with a reset password style system, right?
32.
▲
by
mjschultz
14y ago
Your mobile device has email, right? Mine does. You'd just type your email into the site on mobile, then get the link for your device's browser. You'd have to type email, app switch, the click link. I don't think that is too bad actually.
33.
▲
by
mjschultz
14y ago
Unless Spotify has some backdoor API with Facebook, it seems like a major oversight in the Facebook API that an (any?) app can re-register a deactivated account and give itself whatever permissions it wants. Just because Spotify accidentall
34.
▲
by
mjschultz
14y ago
`bcp` assumes `make` and `gcc` along with a handful of devel headers are installed.
35.
▲
by
mjschultz
14y ago
You might still have the correct values in your DNS cache for the sites. It looks like the .pk registrar was hacked and the DNS for these site changed. Since you're in Pakistan, you've probably recently resolved some of these names so you'd
36.
▲
by
mjschultz
14y ago
I don't know about tumblr.com, but stackoverflow doesn't allow their site to be viewed within an iframe (security reasons). Nor does facebook.com or google.com. I also hope most banking sites wouldn't allow this. That said, it seems like a
37.
▲
by
mjschultz
14y ago
Wouldn't stripe's server logs also have the get params in cleartext?
38.
▲
by
mjschultz
14y ago
Here is the Google Moon view of his landing site: http://www.google.com/moon/#lat=2.460181&lon=23.708496&#...
39.
▲
by
mjschultz
14y ago
If there was a moment to use QR codes for something useful it would be that receipt. The last thing I want to do is type some 34 character case-sensitive id into my browser to get my money.
40.
▲
by
mjschultz
14y ago
Interesting. I may have accidentally stumbled on this hack a few years ago when I was sitting in an airport. I had downloaded the (I believe) Boingo iOS app, which works by performing an in-app purchase for the amount of time you want to u
41.
▲
by
mjschultz
14y ago
1. Press and hold a finger in the blue area (do not move this finger) 2. Tap a second finger somewhere else in the same blue area (again, do not move your finger only tap) 3. Observe the orange bar. It should become green when both finger a
42.
▲
by
mjschultz
14y ago
(Sorry, I misread the above post, but I believe LDLIBS is the Makefile built-in variable for libraries to link.) Actually, in this case, I believe LDLIBS would be more appropriate since the OP isn't passing any flags to `ld` but rather the
43.
▲
by
mjschultz
14y ago
Implementation specific. It looks like it is a bug in the Linux kernel with how it adjusts the time. It is possible that Windows, OS X, and other BSDs will be affected by a similar bug, but that would be coincidental as the bug is not due
44.
▲
by
mjschultz
14y ago
I ran into that problem a few weeks ago. After a fair amount of tinkering, I found that this: https://www.google.com/search?q=link:www.saygent.com Works the way you want it to. You just need to add search before the `?` and you sh
45.
▲
by
mjschultz
14y ago
I couldn't get it to reproduce on a VM (VirtualBox) either. I'm wondering if the SSE-optimized version of the glibc doesn't work the same way in a VM as it does on host hardware (i.e. SSE instructions are virtualized to some degree). Since
46.
▲
by
mjschultz
14y ago
Here is the reference from the Ubuntu CVE tracker: https://bugs.launchpad.net/bugs/cve/2012-2122 . So yes it looks like it is confirmed. Also, the associated bug report: https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/101... .
47.
▲
by
mjschultz
14y ago
Here is the fixed version of the MySQL code: https://bazaar.launchpad.net/~mysql/mysql-server/5.1/view/35... (line 534 didn't have the test()) previously)
48.
▲
by
mjschultz
14y ago
Well, the Ubuntu part came from HD Moore [1]. I haven't been able to confirm it on my Ubuntu 12.04 virtual machine instance though, nor does my virtual machine appear to trigger the bug using the CVE-2012-2122 checker [2]. But, that is just
49.
▲
Security vulnerability in MySQL ubuntu
(seclists.org)
125 points
by
mjschultz
14y ago
|
109 comments
50.
▲
by
mjschultz
14y ago
Ah, okay. So step 5 is the else condition from the "if" that begins step 4. At least, until the API is upgraded to the new improved edition and most/all API apps are using the new version.
51.
▲
by
mjschultz
14y ago
I'll admit, I must be the only one that doesn't quite get the jump from step 4 to step 5. In step 4, we make the assumption that their API is out in the wild, in use, and sends the md5(s, p) in the request. I get that we take that value, r
52.
▲
by
mjschultz
14y ago
Well, in the eHarmony case we're talking about MD5 hashes, so even if you self-salt the password but still choose a weak password a good password cracker will find the password fairly quickly. As an example, yesterday user rorrr posted this
53.
▲
by
mjschultz
14y ago
It might help, but I think the cracking tools would simply get an update that tries `password` and `<salt>password` (and even `password<salt>`). As the salt is guessable (as it is in your examples) it just turns into a cat-a
54.
▲
by
mjschultz
14y ago
$ echo -n "Spiderpig1MD5 rules" | md5sum b520542710812f347432232b2a1fba83 - Thus the password here is "Spiderpig1" MD5 is broken.
55.
▲
by
mjschultz
14y ago
Right, that's what my assumption is too but I didn't see anything in the post that says "recently logged in users" or "once you log in you'll be protected by the new scheme." Just "members whose passwords have not been compromised benefit [
56.
▲
by
mjschultz
14y ago
> members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our current password databases. If we presume that the 6.5m password dump was th
57.
▲
by
mjschultz
14y ago
Doesn't this imply that LinkedIn doesn't salt the password prior to storing it. So then a good chunk of those passwords will be in a rainbow table.
58.
▲
by
mjschultz
14y ago
That graphic isn't even internally consistent. I measure the 2000 "computer usage" circle at 56 pixels in diameter and the outer 2008 circle at 195 pixels. The text states usage in that time frame has increase 342%. Visually the change is
59.
▲
by
mjschultz
14y ago
That just means you have a local formula that knows how to build and install c, but you have not shared it with the community so no one else will have access to the formula. You'd need to fork, push to your fork, and create a pull request t
60.
▲
by
mjschultz
14y ago
Are you sure you committed it to the homebrew repository on github? Your github page doesn't show any activity that indicates you've forked the homebrew repo or created a pull request in the past 14 days (since you made the "c" repo). Even
More ›