Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
photon12
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
Okta’s Investigation of the January 2022 Compromise
(okta.com)
282 points
by
photon12
5y ago
|
117 comments
62.
▲
by
photon12
5y ago
Doing user IP address change detections as part of a heuristic vector for account compromise is sometimes a best practice and sometimes a great way to generate a bunch of useless noise, but I know which is less likely to break UX by integra
63.
▲
by
photon12
5y ago
Because in both auth and email one can make a small screw-up that allows for a company threatening breach. As someone who has performed penetration tests for all of: companies that roll their own SSO, companies that use a third party SSO se
64.
▲
by
photon12
5y ago
It's worth noting we don't know what the true motive of any group that claims to be solely about ransomware and extortion actually is.
65.
▲
by
photon12
5y ago
There have been some headlines about what you reference but I'm skeptical that work has amounted to anything lasting.
66.
▲
by
photon12
5y ago
If you are operating from a jurisdiction that's already under heavy sanctions or severed diplomatic relations and extradition is unlikely, the laws of another country don't really matter.
67.
▲
by
photon12
5y ago
Seems a bit premature to assume this was the vector used for those other breaches.
68.
▲
Two Attacks on Proof-of-Stake Ghost/Ethereum
(eprint.iacr.org)
2 points
by
photon12
5y ago
|
0 comments
69.
▲
by
photon12
5y ago
There's a reason I'll only ever run NPM in a VM on any machine that has any data I care about
70.
▲
by
photon12
5y ago
I do enough hardware security work to where I wouldn't want anything like this anywhere near the motor or sensory or emotional functions of me or my loved ones anyway. One abusive partner or associate could do so much damage. Don'
71.
▲
by
photon12
5y ago
Here's a video of what an exploit of this kind looks like. You are correct it requires accepting prompts: https://youtu.be/E7y_UCshcCM
72.
▲
by
photon12
5y ago
The Qubes clipboard model is one of the reasons I use that OS: https://www.qubes-os.org/doc/how-to-copy-and-paste-text/
73.
▲
by
photon12
5y ago
I worked in a role at Amazon that required me to interact with a different team every 1-3 weeks. I would often sit directly with the teams as I was doing work with them for the duration. There are teams at Amazon full of some of the best te
74.
▲
by
photon12
5y ago
Amazing what started with Heroku* has turned into. *Started for me at least. Heroku was how I got started as a Rails developer, and it made it so easy to get a deployment available to interact with from anywhere.
75.
▲
by
photon12
5y ago
Here's a series of tweets by @SwiftOnSecurity to give a feeling of how those really impacted are doing that I think capture the mood: https://twitter.com/SwiftOnSecurity/status/14694518560910090... https:&#x
76.
▲
The Universal Loader for Go
(symbolcrash.com)
1 points
by
photon12
6y ago
|
0 comments
77.
▲
Qubes: Passwordless Root Access in VMs
(qubes-os.org)
1 points
by
photon12
6y ago
|
0 comments
78.
▲
Zerologon: Instantly become domain admin by subverting Netlogon cryptography
(secura.com)
6 points
by
photon12
6y ago
|
0 comments
79.
▲
by
photon12
6y ago
History and Class Consciousness, György Lukács I got it at a bookstore one day because the shelf note on it from one of the staff members made it seem interesting, didn't really know what I was getting into. Apparently I had bought a b
80.
▲
Asemica: An asemic Markov-chained cipher
(github.com)
38 points
by
photon12
6y ago
|
8 comments
81.
▲
Offensive Go Tradecraft Interviews
(lockboxx.blogspot.com)
1 points
by
photon12
6y ago
|
0 comments
82.
▲
by
photon12
6y ago
Credit card data is relatively small cardinality and easy to predict the form of. Medical data is... not that
83.
▲
NP-complete Problems and Physical Reality (2005) [pdf]
(scottaaronson.com)
2 points
by
photon12
6y ago
|
0 comments
84.
▲
by
photon12
6y ago
FYI, here's the link https://www.symbolcrash.com/podcast/interview-with-josh-pitt...
85.
▲
by
photon12
6y ago
They don't There's a lot of bad advice on secret storage that is Not Based On A Threat Model™
86.
▲
by
photon12
6y ago
Yep, planning on editing it tomorrow It's with Josh Pitts, author of this tool [1] and another payload that caused lots of go projects to be eaten by Kaspersky [2] [1] https://github.com/secretsquirrel/the-backdoor
87.
▲
by
photon12
6y ago
I mean the same company built a service with better architecture that they sell as part of their managed computing environment options. Some people complain about not wanting to use it due to "lock-in."
88.
▲
by
photon12
6y ago
Interviewed someone last night for my podcast who has written some python malware tools, and there's enough stuff out there to where you can't exactly call it a new concept.
89.
▲
by
photon12
6y ago
Like HAM radio, there is an incredible amount of metadata that is necessarily public. (Seriously, any use case for which Bitcoin is a privacy solution puts Bitcoin up against strictly superior implementations of decentralized BFT value exch
90.
▲
by
photon12
6y ago
It's a large company that built their own bespoke internal credentials service running over a TCP port to the application with another proprietary protocol to push key material to hosts. Can't say much more due to NDAs. Edit: this
More ›