Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rainonmoon
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
rainonmoon
10mo ago
It's a good question and one mature orgs ask themselves all the time. As you can see from most of the replies here, XSS captures the fancy of the bug bounty crowd because there are tonnes of hypothetical impacts so everyone is free t
32.
▲
by
rainonmoon
10mo ago
As someone in a related line of work: we find vulnerabilities so close to 100% of the time that it might as well be 100% of the time. Whether they're practically exploitable or surpass your risk appetite is the real question.
33.
▲
by
rainonmoon
10mo ago
XSS is categorically not an RCE and my point is that mitigations exist which make "It allows you to run any action as if you were the owner of the account" an unwarranted assumption. The writeup shows that it's possible to
34.
▲
by
rainonmoon
10mo ago
And to my earlier point, none of that is in the writeup here to support the enormous claims made in framing the finding. This is good work, and congratulations on the bounty. I hope you have a long career in security ahead. Obviously you co
35.
▲
by
rainonmoon
10mo ago
Nice! So the Cookie is accessible by JavaScript on all of those sites? That would be pretty surprising given the prevalence of HttpOnly, so that doesn't seem clear to me at all. And they're all using Cookie-based auth, you think?
36.
▲
by
rainonmoon
10mo ago
You're pretty much on the money. Reflected XSS requires social engineering to really target anyone without other primitives. Unfortunately this report is not very clear about the tangible impacts or limitations of what they could do wi
37.
▲
by
rainonmoon
10mo ago
This is very, very, very bad advice. A non-standard port is not a defence. It’s not even slightly a defence.
38.
▲
by
rainonmoon
10mo ago
I don’t think we should pass laws just because there was allegedly a nice thought behind him. More reasonable protections have been in discussion for long before this entered the picture. That aside, you probably missed this, but the exact
39.
▲
by
rainonmoon
10mo ago
> which is the usual fare for Crikey Just for anyone else reading this, Crikey is an extremely reputable source of original reporting and not some conspiracy rag.
40.
▲
by
rainonmoon
10mo ago
David Pocock is still beating the drum on this issue.
41.
▲
by
rainonmoon
10mo ago
This comment is a neat encapsulation of the hypocrisy in the “think of the children” mentality. We’ve gotta protect the kids, let’s push them around like obstacles and exclude them from society! Meanwhile, social media is melting the brains
42.
▲
by
rainonmoon
10mo ago
Obviously software development in general has become more ingenious (by some metrics) over the past few decades but very little of its growth has involved secure development principles. Often the primary goal is efficiency and scalability w
43.
▲
by
rainonmoon
10mo ago
Stock price is an extremely narrow view of the total consequences of lax cybersecurity but that aside, the notion that security doesn’t matter because those companies got hacked is ridiculous. The reason there isn’t an Equifax every minute
44.
▲
by
rainonmoon
10mo ago
Try working at a company of any remote public significance and see if your view changes.
45.
▲
by
rainonmoon
10mo ago
> It has been implemented so that age verification is a token only, a yes/no authorisation. This is misinformation. The legislation does not specify a single particular implementation for age-based verification and there's abso
46.
▲
by
rainonmoon
10mo ago
The government have previously stated they won’t pursue breaches unless they’re particularly egregious anyway so this is basically shameless political theatre.
47.
▲
by
rainonmoon
10mo ago
Given that “social media” is in fact not banned and all this does is impact a select (and frankly logically inconsistent) list of services, this seems very unlikely. Children are still free to be groomed and gamble on Roblox and join server
48.
▲
by
rainonmoon
10mo ago
eSafety’s line against this sort of bypass is they’re mandating that bans are arbitrated based on user activity and behaviour. So the reality is that the government is attempting to force companies to increase their surveillance of children
49.
▲
by
rainonmoon
11mo ago
And?
50.
▲
by
rainonmoon
11mo ago
You're right, but with an asterisk. I don't care if my DO droplet gets popped with an RCE. I do care if someone establishes persistence in my home.
51.
▲
by
rainonmoon
11mo ago
Most people shouldn't use a Pi because most people can't configure a web server securely. A VPS would be a better option for just about everybody trying to "self-host" whether they put Cloudflare in front of it or not.
52.
▲
by
rainonmoon
11mo ago
Enshittification refers to a specific thing that this isn't.
53.
▲
by
rainonmoon
11mo ago
Why? Lots of examples of things like indirect prompt injection via image content.
54.
▲
by
rainonmoon
11mo ago
If you're working with the people Amazon works with, the risk assessment isn't "Will we get in trouble for this?" it's "When we get in trouble for this, can we defend it on legal grounds?" Given that even
55.
▲
by
rainonmoon
1y ago
It already is a life/death epidemic. An extremely similar automated decision making scandal to the one OP is referring to led to people's deaths: https://www.abc.net.au/triplej/programs/hack/2030-peo
56.
▲
by
rainonmoon
1y ago
You are dreadfully insistent on proof yet provide none of your own that there is no genocide, despite multiple credible organisations and experts, and the consensus of the international community, contradicting you.
57.
▲
by
rainonmoon
1y ago
White nationalism is the neutral state of the United States, hence the misperception of a return to “the center”.
58.
▲
by
rainonmoon
1y ago
The problem (exhibited all over this thread) is the conflation of protocols and apps. You misled yourself by overthinking it. This happened a lot a couple of years ago when people fled Twitter for Mastodon, putting themselves off by assumin
59.
▲
by
rainonmoon
1y ago
This is really excellent work team. It's great to see more straight-forward but polished tools that solve a concrete problem simply.
60.
▲
by
rainonmoon
1y ago
This attitude towards exposing customer data as a palatable oopsie on someone’s path to learning (by… outsourcing the effort of learning to an LLM?) is truly disgraceful.
More ›