Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mmsc
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
91.
▲
by
mmsc
10mo ago
That was a typo, yeah. It should be console.log(config.isAdmin); // true!
92.
▲
by
mmsc
10mo ago
https://archive.md/2025.12.03-165833/https://www.wiz.io/blog... Mismatched smart quotes are visible in this archive.
93.
▲
by
mmsc
10mo ago
Note however, that proposal does not cover some other types of prototype pollution, such as: > let config = {}; > Object.assign(config, JSON.parse('{"__proto__": {"isAdmin": true}}')); console.log
94.
▲
by
mmsc
10mo ago
It seems like this vulnerability is yet another prototype pollution vulnerability. There was a TC39 proposal a few years ago [0] that proposed to block the getting/setting of object prototypes using the bracket notation, which would ha
95.
▲
by
mmsc
10mo ago
>> According to Wiz data, 39% of cloud environments have instances vulnerable to CVE-2025-55182 and/or CVE-2025-66478. > Numbers! I do not see how such numbers are valuable to people reading this post, as the first indication
96.
▲
by
mmsc
10mo ago
Hackernews' submission guidelines clearly state: "Please submit the original source. If a post reports on something found on another site, submit the latter." [0] The Wiz post has significantly changed since it was first publ
97.
▲
by
mmsc
10mo ago
These wiz.io blog posts should be banned from HN; AFAICT, they're AI generated. Here's the original post with the details: https://react.dev/blog/2025/12/03/critical-security-vulnerab... - the
98.
▲
by
mmsc
10mo ago
>I assume that putting a 'rua=' into your DMARC record makes it look more legitimate to (some) receiving systems. Yes, Gmail for example will drop emails from mass-senders that don't implement both SPF and DKIM.
99.
▲
by
mmsc
11mo ago
Keycloak has various vulnerabilities they haven't even responded to after a month of reporting them.
100.
▲
by
mmsc
11mo ago
Same author, even!;)
101.
▲
by
mmsc
11mo ago
Why would the company need to figure it out from commit hashes? It's all public, in public GitHub repositories, with the person's personal GitHub account: https://github.com/auth0/nextjs-auth0/pull/2
102.
▲
by
mmsc
11mo ago
(op here) On the one hand, you're right, it is distasteful, I completely agree. On the other hand, GitHub and Google and the public domain internet isn't everybody's CV that they can pick and choose which of their actions are
103.
▲
by
mmsc
11mo ago
>First, the typical AI-powered reporter, especially one just pasting GPT output into a submission form, neither knows enough about the actual codebase being examined nor understands the security implications well enough to provide insigh
104.
▲
by
mmsc
11mo ago
There's a restaurant in Sarajevo which specializes in this stuff, called The Singing Nettle. Recommended.
105.
▲
by
mmsc
1y ago
It's also possible to pack a whole codebase into "before main()" - or with no main() at all. I was recently experimenting doing this, as well as a whole codebase that only uses main() and calls itself over and over. Good fun:
106.
▲
by
mmsc
1y ago
If you'd like to print the middle of a file, try out `body`: https://github.com/megamansec/body
107.
▲
by
mmsc
1y ago
>after having received a lukewarm and laconic response from the HackerOne triage team. A slight digression but lol, this is my experience with all of the bug bounty platforms. Reporting issues which are actually complicated or require an
108.
▲
by
mmsc
1y ago
TFA calls it unhinged, I call it creative and exciting. Now all we get is rounded edges, solid colours, and "copies of reality" - boring; if I wanted reality I'd go outside and touch grass.
109.
▲
by
mmsc
1y ago
FYI, it's quite easy to support both Firefox and chrome (both mv2 and mv3, even) in a single extension codebase.
110.
▲
by
mmsc
1y ago
Thank you, it means a lot.
111.
▲
by
mmsc
1y ago
Always fun to wake up (ok; I didn't wake up, I got off a 10 hour flight) to see my work on the front page of hn. I'll be doing a retrospective in a few weeks when the dust has settled, as well as new tools I've been made awar
112.
▲
by
mmsc
1y ago
> rent a server > infect it with unremovable backdoor > stop paying server so company rents server to somebody else > ???? > profit!
113.
▲
by
mmsc
1y ago
Use fbpurity
114.
▲
by
mmsc
1y ago
It'd be nice to have a feature in uBlock origin where you can block certain websites' ip addresses, with a requirement to re-resolve the ip address every few days to ensure the ip hasn't been rotated (blocking unnecessary web
115.
▲
by
mmsc
1y ago
Currently living through a great litmus test of competency versus luck by company leaders
116.
▲
by
mmsc
1y ago
I think what will happen in the future is that the people that drink, will be drinking way more; while the people that rarely drink, will more rarely drink.
117.
▲
by
mmsc
1y ago
Is there a bug bounty? I found an open redirect.
118.
▲
by
mmsc
1y ago
Is this a bot? Three day creation date and the sentence of TFA is >Last night at a Hacker News meetup, I shared something
119.
▲
by
mmsc
1y ago
That's more or less how Project Honey Pot [0] worked for forums, blogs, and elsewhere. Cloudflare spawned from this project, as I remember, and Matthew Prince was the founder. [0]: https://en.wikipedia.org/wiki/Pro
120.
▲
by
mmsc
1y ago
this requires being signed in (obviously), which doesn't help with the limit tracking part of hating these things
More ›