Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pfg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
pfg
8y ago
How was the disclosure irresponsible? AIUI, multiple attempts were made to report the bug. It went viral a couple of days later on social media. I'm not aware of a link between those two events.
62.
▲
by
pfg
8y ago
Public disclosure once patches are available is a fairly common policy. Google's Project Zero operates like that as well.
63.
▲
by
pfg
8y ago
Chrome's implementation solves this by racing a TCP connection with the QUIC connection.
64.
▲
Password Strength Meter Comparison
(password-meter-comparison.org)
1 points
by
pfg
8y ago
|
0 comments
65.
▲
by
pfg
8y ago
The GCP move was decided upon months before Microsoft acquired GitHub[1]. [1]: https://venturebeat.com/2018/04/06/why-and-how-gitlab-abando...
66.
▲
by
pfg
8y ago
It's certainly not an interpretation I'd punish a CA for, the language in section 3.2.2.8 is rather ambiguous. Let's Encrypt is running a fail-close setup for DNSSEC, so I wouldn't quite say it's too unreliable in
67.
▲
by
pfg
8y ago
The magic sauce would be CAA. This is under the assumption that all publicly trusted CAs respect CAA and have no bypass bugs (CAs probably aren't ... too far off target) and that they properly validate DNSSEC (good luck with that, I
68.
▲
by
pfg
8y ago
In the modern Web PKI, it seems to me that the only thing DNSSEC is good for is mitigating BGP hijacking and similar attacks (in combination with CAA and either some contractual agreement with your CA or the ACME CAA extension). That's
69.
▲
by
pfg
8y ago
Note that I was referring to client/stub resolvers specifically. Last time I checked, it was rather uncommon for them to perform their own DNSSEC validation rather than trusting the AD bit sent by their upstream resolver. In practice t
70.
▲
by
pfg
8y ago
> Right now there are no benefits though. In terms of privacy, I would mostly agree. Using an authenticated channel to your resolver still protects against many common MitM vectors, so there's definitely a benefit there. Unlike DNSS
71.
▲
by
pfg
8y ago
It's important to note that DNSSEC does not provide encryption. Additionally, very few client resolvers validate DNSSEC. In typical MitM scenarios, DNS over TLS or HTTPS provides much better protection. If the resolver happens to val
72.
▲
by
pfg
8y ago
In this attack, the maintainer's primary device was not owned. The maintainer's npm account was breached due to a reused password. Code signing would mitigate this because the attacker would be unable to release/sign a malici
73.
▲
by
pfg
8y ago
What you'd want is for the owner/maintainer to sign the code, rather than the repository. This wouldn't protect you against a malicious maintainer, but it would help in a case like this as long as the signing key or the maint
74.
▲
by
pfg
8y ago
Does your approach respect TTL, i.e. by updating your source of truth after a record expires? Because you'd still be affected by DNS rebinding attacks in that case - and if not, I imagine there'd be quite a bit of breakage when IP
75.
▲
by
pfg
8y ago
One could argue that things like the Infineon prime number generator weakness affecting RSA keys are much more severe than this, but honestly, just flip a coin until modern curves become viable for typical smartcard use-cases.
76.
▲
by
pfg
8y ago
You're thinking of HPKP and other certificate and key-pinning implementations. HSTS only enforces HTTPS, it does not prevent the usage of things like mitmproxy with custom roots added to your trust store.
77.
▲
by
pfg
8y ago
> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, prett
78.
▲
by
pfg
8y ago
Presumably the legal basis would've been the Bundesdatenschutzgesetz, which is Germany's implementation of the DPD. The DPD itself is not very specific, only saying "such a data protection official, whether or not an employee
79.
▲
by
pfg
8y ago
This is not about advertising or any kind of misuse of the data. Rather, IT's role is very much one where they they setup and maintain systems and procedures that process data. It's certainly true that GDPR compliance is something
80.
▲
by
pfg
8y ago
> It seems to me a bit of a stretch that working in IT is a conflict of interest with adhering to data processing regulations; ensuring that your infrastructure is compliant is generally one of the remits of the IT function. That's
81.
▲
by
pfg
8y ago
Depending on the organization, it can be quite hard to find someone who does not have a conflict of interest while still having the necessary skills to act as a Data Protection Officer. As an example, someone working in IT might have the ne
82.
▲
by
pfg
8y ago
I'm not sure what you're trying to say here, but Enigmail 2 was released a few months after the researchers disclosed the vulnerability to the project[1], so it would've been a rather sad state of affairs if the release hadn&
83.
▲
by
pfg
8y ago
Signal merged support for devices without Play Services about a year ago. Is that what you're looking for?
84.
▲
by
pfg
8y ago
There's a bit of an explanation of this in the article describing the other XSS that's recently been found in Signal[1]. Basically, since the Electron app itself runs under the file:// origin, 'self' can be byp
85.
▲
by
pfg
8y ago
So to be clear, a lot of the blame definitely belongs in the "all that comes with it" bucket here, which is one of the reasons why you should think twice about developing desktop apps using a platform that forces you to deal with
86.
▲
by
pfg
8y ago
> Thunderbird does not download remote content by default. The researchers behind EFAIL found a number of ways to bypass the remote content setting. Not only that, but Hanno Böck found another one today[1] that hasn't been fixed yet
87.
▲
by
pfg
8y ago
As much as I'm not a fan of JavaScript, the problem is not so much the language but rather the choice of Electron and all that comes with it. Heck, even a web version or Chrome app would've successfully mitigated these attacks. El
88.
▲
by
pfg
8y ago
YubiKeys are non-upgradable by design. This is occasionally annoying when new standards come out and you need to go buy new keys (which is not something that's gonna happen a lot), but it significantly reduces the attack surface of the
89.
▲
by
pfg
8y ago
I don't know about 7-Zip specifically, but AV vendors use plenty of FOSS code. Here's some findings just from Google's P0 showing that Symantec[1], Bitdefender[2], Microsoft[3] and Avast[4] all use unrar in their products. It
90.
▲
by
pfg
8y ago
> To be fair to virus scanner vendors, the only way to mitigate this kind of bug is NIH: don't use 3rd party libs, implement everything yourself. But then, of course, without bugs yourself, as well :) That is not the only way to mit
More ›