Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mmsc
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
211.
▲
by
mmsc
2y ago
The irony of it is that these types love to then support software and hardware that is full of vulnerabilities. "Oh, our management software/SSL-VPN has just been pwned for the sixth time in two years? Well at least the vendor has
212.
▲
by
mmsc
2y ago
It would have stated "the Marine's" (singular third-person) in that case, not the plural third-person "the Marines'".
213.
▲
by
mmsc
2y ago
"Why do we have to do X? Because we have to do X and have always had to do X" is a human problem coming from lack of expertise and lack of confidence to question authority. It's a shame, your story isn't unique at all.
214.
▲
Toynbee Tiles
(en.wikipedia.org)
5 points
by
mmsc
2y ago
|
0 comments
215.
▲
Upcoming Hardening in PHP
(dustri.org)
312 points
by
mmsc
2y ago
|
126 comments
216.
▲
by
mmsc
2y ago
> modern compiler string literal obfuscation the what now?
217.
▲
by
mmsc
2y ago
a member of the 'video' group
218.
▲
by
mmsc
2y ago
Are there any studies about the harm of a craze in non-sweet diets? While I would generally agree with this "confirmation" based on my understanding of diabetes, I wonder if it's actually sugar that is the problem here. For
219.
▲
by
mmsc
2y ago
Ubuntu does not claim they have a stable ABI between major version releases.
220.
▲
by
mmsc
2y ago
Forcing modernisation of some - (probably) especially gui - applications is overall a positive for the platform as it also identifies projects which are under-maintained and allow for overall modernisation / forking / maintenance
221.
▲
by
mmsc
2y ago
> Surprisingly, libFuzzer struggled to figure out that input should be of size 1024 and couldn’t start fuzzing. Is this surprising? Does libFuzzer support Redqueen or laf-intel like AFL++ [0][1] which will pick up on any comparisons (lik
222.
▲
by
mmsc
2y ago
Because in the USA, they're seen as target practise. Good luck leaving an (expensive) pinball machine in a Manhattan subway for 72-hours.
223.
▲
by
mmsc
2y ago
https://archive.ph/8lxPO
224.
▲
by
mmsc
2y ago
>EnterpriseFirewall/VPN-Gateway Lan-> LocalNetwork(DNS,NTP,SMB/NFS etc) Lan-> EnterpriseFirewall HTTPS This does not seem to agree what you previously said: "VPN's where made so you can securely work inside your
225.
▲
by
mmsc
2y ago
>Your exceptions are wrong, a correct configured VPN-tunnel is tunneling all data from one point to another (zero exceptions) if vpn is de-connected no data should be transferred (aka interface down). >VPN's where made so you can
226.
▲
by
mmsc
2y ago
No: >Okay, at that point I was clueless. I tried changing the DNS settings of OpenVPN (i.e. dhcp-option DNS 1.1.1.1) but it didn't work. After a couple of iterations with ChatGPT, it finally led me to the correct path.
227.
▲
by
mmsc
2y ago
It would be intercepted at the ISP level and the false results would still be received. There are lots of DNS intercepting tools ISPs buy these days. DNS isn't authenticated.
228.
▲
by
mmsc
2y ago
Clicking the link, it bought this was going to be about the issue identified in Mullvad discussed here; https://news.ycombinator.com/item?id=41856883 but this isn't even a bug or about trust. A VPN (in this context) is
229.
▲
by
mmsc
2y ago
Adding to the list of "now try it with".... The SEC's EDGAR database (which is for SEC filings) is another nightmare ready to end. Extracting individual sections from a filing is, afaik, impossible pragmatically. I tried maki
230.
▲
by
mmsc
2y ago
Fwiw, I wouldn't be surprised if the author of this article is a bit upset that Daniel hackermondev gained a significant % of the income that the author makes a year. If this was "fixed" by Zendesk, they would have paid less
231.
▲
by
mmsc
2y ago
>Sometimes for real bugs you have to explain the impact with a good "look what I can do with this." I'm not sure. Anybody that keeps up to date with security (e.g. those working in a security team) should know that ticketi
232.
▲
Zendesk: Email user verification bug bounty report retrospective
(support.zendesk.com)
11 points
by
mmsc
2y ago
|
3 comments
233.
▲
by
mmsc
2y ago
Yes, I expect a security engineer to hold knowledge. That's why they have a job, instead of replacing the security them with an LLM. If nobody in the team has that experience, it speaks exactly to the issue that has been outlined in th
234.
▲
by
mmsc
2y ago
They all are. Bugcrowd once told me that, "yes, it's not a security issue or even a bug, but we recommend providing small (100€) rewards for non-bugs to keep researchers engaged!"
235.
▲
by
mmsc
2y ago
>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here The implications of being able to read arbitrary email contents from arbitrary domains' support (or otherwise)
236.
▲
by
mmsc
2y ago
>It doesn’t make sense, companies with less revenue aren’t the ones doing this. It’s usually the richer tech companies. Because for some reason, it's larger tech companies that love to bean-count their way through security.
237.
▲
by
mmsc
2y ago
Which falls into the problem of "nobody is looking at it or trying to improve it." FreeBSD foundation recently got a million dollar cash injection. Maybe they can look into using it there.
238.
▲
by
mmsc
2y ago
The problem is that this only works if your hardware supports emulation and you can actually use PCI pass through - for USB devices, you'd need to pass the whole USB hub, for example.
239.
▲
by
mmsc
2y ago
>HackerOne declared the issue out of scope so I don't see why disclosure would make a difference here. Indeed, but just you wait for Zendesk to say "well, _we_ didn't mark it out of scope!" as if delegating it to h1 r
240.
▲
by
mmsc
2y ago
It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - &quo
More ›