Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raesene2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
31.
▲
by
raesene2
14y ago
This is, as far as I know, already in the Dropbox T&C's (article here http://articles.businessinsider.com/2011-04-18/tech/30033770... ) and their T&C's here https://www.dropbox.com/privacy do mention handing over data in relation
32.
▲
by
raesene2
14y ago
They have the exploits ready to go, the challenge is whether they can exploit the target system (which is fully patched) within their time slot. It's a useful excercise, I think, in that it demonstrates that even the most hardened of codeba
33.
▲
by
raesene2
14y ago
This kind of black-listing of specific domains is, unfortunately, just a game of whack-a-mole that's very hard for defenders to win. If they're seeing targeted phishing (which the article implies that they are), then the attackers will just
34.
▲
by
raesene2
14y ago
While you're obviously correct to imply that languages/frameworks have different levels of security the problem with that proposition is how does a prospective user of the framework assess the level of security it provides? You could argue
35.
▲
by
raesene2
14y ago
Whilst I think it is a bit hyperbolic to describe it as a paperweight, I think that one significant problem is the lack of security updates for the iPad 1. iOS6 patched a large number of CVEs http://support.apple.com/kb/HT5503 so any dev
36.
▲
by
raesene2
14y ago
A couple that I know of which are based on the security side of things are Brakeman ( https://github.com/presidentbeef/brakeman ) and Scanny ( https://github.com/openSUSE/scanny ) on the open source side. On the commercial side I know Chec
37.
▲
by
raesene2
14y ago
Personally I think that there's a big risk of Kickstarter acquiring a bad reputation here. Whilst a lot of the comments on this thread show that some people look at Kickstarter contributions as donations or investments, I don't think that
38.
▲
by
raesene2
14y ago
I wonder if it's possible to get it to higher than 0.5. I just tried it with some patent gibberish and it only made that score. -- "This project is a blue sky implementation of a cloud based virtual paradigm which really shifts the boundri
39.
▲
by
raesene2
14y ago
Most corporates that I've seen make heavy use of Java applet based software for internal software (and have multiple versions installed as a result). Also I've seen a fair number of administrative interfaces for IT kit that work via Java A
40.
▲
by
raesene2
14y ago
Yeah I'd reckon with the depth and breadth of talent across the testing business now, it should be really cool. I hope they make the internal information sharing/collaboration piece a priority. Almost makes me regret being a freelancer.
41.
▲
by
raesene2
14y ago
It's a reference to the WS family of standards, which are a huge group of enterprisey web services standards. A good illustration of the family is http://www.innoq.com/soa/ws-standards/poster/innoQ%20WS-Stan...
42.
▲
by
raesene2
15y ago
Another anecdotal point, we got iPad 2's at Christmas for my mother (in her 60's) and father in law (in his 80's) both have picked up using them really easily and it makes my life as family IT support person quite a bit easier!
43.
▲
by
raesene2
15y ago
I'm not sure that the iPad is unbeatable (and in the long run what is, really), but in my opinion it is and will continue to be extremely successful for one main reason. (Most) people don't want a computer. They want something to give them
44.
▲
by
raesene2
15y ago
FWIW, I hardly ever see WEP any more on wireless tests. WPA-PSK is still reasonably common even in corporates (mainly for guest networks), but realistically most companies I see are running 802.1X and PEAP against either Active Directory o
45.
▲
by
raesene2
15y ago
Most "enterprise" level switches (eg, Cisco) actually have a reasonable number of features which can be enabled to protect against things like ARP Poisoning. It doesn't need to be as inflexible as a one-to-one static mapping, they can be c
46.
▲
by
raesene2
15y ago
Yep that sentence, and ones like it always worry me when I see them in companies' documentation about security. If the best thing you can say about your system and application security programme is that you use a firewall, that wouldn't fi
47.
▲
by
raesene2
15y ago
There's some interesting answers to this question on security.stackexchange http://security.stackexchange.com/questions/6758/can-webcams... . Short answer is that it looks to be possible with some webcams but not others, depending on the
48.
▲
by
raesene2
15y ago
Interesting idea, could be very useful. One thing with this kind of service is always how they handle validation of data from the 3rd party service (eg, in headers). So as an example http://hurl.it/hurls/db870b49c7203ec9acb47ba7769c12614
49.
▲
by
raesene2
15y ago
there's some scenarios where it may not be too bad. From what I've read I'd agree that truecrypt on an SSD doesn't sound like a good option. Bitlocker seems possible if you're running Win7 (ultimate or enterprise). One other thing to watc
50.
▲
by
raesene2
15y ago
Short answer from my experience is cost. The individual tokens have a cost, then there's the management overheads of running the system. Initially it doesn't seem like too much but if you've got a customer base numbering in the millions,
51.
▲
by
raesene2
15y ago
Very likely to be zeus or another related banking trojan, that's a trick that i know it can pull. You may want to watch as changing browser may not get rid of the underlying problem, and anti-virus is apparently somewhat spotty st detecting