Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raesene6
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
raesene6
9y ago
Well they sold services which made use of a vulnerable version of struts.... You can argue services != products, but It could be argued a similar approach could apply. The fact that they didn't sell those services to consumers but tha
32.
▲
by
raesene6
9y ago
on it's own it doesn't mean anything either in favour or against her. Lots of more experienced IT Security people don't have appropriate degrees, generally as they didn't exist when those people got into the profession.
33.
▲
by
raesene6
9y ago
As to the first point, Equifax could be liable as they are the one operating the system (for profit), and they're the one processing personal information using it. If they had been using commercial software they might have been able to
34.
▲
by
raesene6
9y ago
In Europe Windows is down to 83% of desktop class machines http://gs.statcounter.com/os-market-share/desktop/europe and in overall "computing devices" including mobile it's down to 47% http:/&
35.
▲
by
raesene6
9y ago
What markets is it that you feel Microsoft have a monopoly in? Desktop/Laptops is now a 3-way split between MS, Apple and Google with chromebooks. Mobile is a split between Apple and Google with MS out of it. Cloud is Amazon out in fro
36.
▲
by
raesene6
9y ago
I agree, the good thing about Apple and Microsoft is I know what they want to sell me. Apple want me to buy relatively expensive devices on a regular basis and ideally a cloud subscription. Microsoft want me to buy subscriptions to their cl
37.
▲
by
raesene6
9y ago
The public sector in a number of countries seems addicted to these large-scale high risk forms of procurement. Instead of running a larger number of smaller projects, which would be harder for them to adminster, there's a temptation to
38.
▲
by
raesene6
9y ago
Supply chain attacks are an obvious avenue for high-end attackers, where their direct targets are hardened, so I guess we'll see more of these going forward. Whilst companies like Microsoft can likely afford to harden their software up
39.
▲
by
raesene6
9y ago
You can do it in Windows with something like glasswire, or on OSX with Little snitch or equivalent. I run glasswire, and regularly see legitimate traffic from odd sounding processes. A non-technical user would have zero chance of determini
40.
▲
Founder Field Trips
(medium.com)
1 points
by
raesene6
9y ago
|
0 comments
41.
▲
by
raesene6
9y ago
I don't doubt that if you tried to convert all BCH to Fiat it wouldn't fly, but surely a lot of people have made money by transferring BCH at one nominal value to other crypto currencies. Now it probably is all a shell game ultima
42.
▲
by
raesene6
9y ago
Maybe although from a passing look at the markets their price swings (after a couple of days after the initial split) don't seem to correlate...
43.
▲
by
raesene6
9y ago
In the last split people who held bitcoins got an equal quantity of "Bitcoin cash", so if you had 1 BTC, after the split you had 1 BTC and 1 BCH. Looking at https://coinmarketcap.com/ you can see that each BCH is
44.
▲
by
raesene6
9y ago
Yep. I like alpine and use it for my images for preference, but some things like getting Ruby on Rails working with therubyracer can bascially hit a wall in alpine, so this could be pretty handy.
45.
▲
by
raesene6
9y ago
I like the patreon model, as it's let me support various creators whose content I like (Webcomics/Websites/Musicians) without having to endure web ads. I get what this post is saying about wanting to add new features, but I c
46.
▲
by
raesene6
9y ago
The major difference, to me, between Slack and Office is that Slack lacks user lock-in. Companies that make heavy use of office would find it very difficult to move over to another office suite (if they could find one that meets their needs
47.
▲
by
raesene6
9y ago
Indeed they do, and you can get some libs for Node/ruby etc there, however most companies, from what I've seen choose the option of using direct access to npm/rubygems etc.
48.
▲
by
raesene6
9y ago
Indeed it's not impossible to do (although full code review would be expensive/tricky/slow). The fact it hasn't been done despite the obvious risks indicates how much demand there is for this feature...
49.
▲
by
raesene6
9y ago
npm is a commercial organisation, they offer paid subscriptions but don't offer a curated package signed option...
50.
▲
by
raesene6
9y ago
So, apologies for being a bit cynical here, but I don't see this one being addressed any time soon. it's been at least 5 years since npm started getting scrutiny relating to security weaknesses https://blog.andyet.com&#
51.
▲
by
raesene6
9y ago
Interesting if you think that npm/Rubygems/PyPI are leaving a load of money on the table, why do you think they haven't introduced those services so far...
52.
▲
by
raesene6
9y ago
Those service already exit, e.g. https://www.sourceclear.com/ whilst I hope they're doing well, I don't think they've made significant in-roads into the volume of people using open source software library r
53.
▲
by
raesene6
9y ago
Credibility is an easier check but still tricky. Many of the package are uploaded by anonymous or pseudonymous authors, so there's no easy way to even tie that to an IRL identity, let alone check for credibility. I'd agree that a
54.
▲
by
raesene6
9y ago
Not a typo, http://www.modulecounts.com/ has the details. npm is adding 497/day at the moment.
55.
▲
by
raesene6
9y ago
This isn't, in any way, a new problem. I did a presentation on this topic for OWASP AppSecEU 2015 ( https://www.youtube.com/watch?v=Wn190b4EJWk&list=PLpr-xdpM8w... ) and when doing the research for that I encountere
56.
▲
by
raesene6
9y ago
Another fun fact to consider is that with many package formats, you can execute arbitrary code at install time so if a malicious package can get into a repository, it's very likely to start compromising systems quickly. Whilst a pack
57.
▲
by
raesene6
9y ago
Package managers are providing (in the most case) a free service, so it's hard to see a strong case for them providing more services here. The problem is one of scale. npm has over 500,000 packages, so no manual review will address th
58.
▲
by
raesene6
9y ago
A review system unfortunately isn't likely to be practicable with current development models. npm alone has over 500,000 packages ( http://www.modulecounts.com/ ) so even a one time review isn't going to happen. If
59.
▲
by
raesene6
9y ago
It would seem that if China shuts down domestic Bitcoin exchanges that could have quite a big impact on the network as it could make the position of miners in china difficult. Looking at articles like ( https://www.buybitcoinwor
60.
▲
by
raesene6
9y ago
If it's implemented in the same way as TouchID, you can always fall back to PIN.
More ›