Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
relaxnow
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Top Security Anti-Patterns in Asp.net Core Applications
(veracode.com)
2 points
by
relaxnow
6y ago
|
0 comments
2.
▲
Anatomy of a Cross-Site Scripting Flaw in the Telerik Reporting Module
(veracode.com)
1 points
by
relaxnow
9y ago
|
0 comments
3.
▲
The ECB Penguin (2013)
(blog.filippo.io)
2 points
by
relaxnow
9y ago
|
0 comments
4.
▲
Guide to Automatic Security Updates for PHP Developers
(paragonie.com)
2 points
by
relaxnow
10y ago
|
0 comments
5.
▲
Nokia CEO: “we didn’t do anything wrong, but somehow, we lost”
(linkedin.com)
1 points
by
relaxnow
10y ago
|
0 comments
6.
▲
Back to the Future: JavaScript Best Practices
(ibuildings.nl)
2 points
by
relaxnow
10y ago
|
0 comments
7.
▲
Secure Development Anti-Pattern: Failure to separate resource from user
(ibuildings.nl)
1 points
by
relaxnow
10y ago
|
0 comments
8.
▲
JavaScript, the Universe and Everything – Part 3: Comparing Node to PHP
(ibuildings.nl)
1 points
by
relaxnow
11y ago
|
0 comments
9.
▲
JavaScript in a PHP World
(ibuildings.nl)
1 points
by
relaxnow
11y ago
|
0 comments
10.
▲
JavaScript, the Universe and Everything – Part 1: What Is JavaScript?
(ibuildings.nl)
1 points
by
relaxnow
11y ago
|
0 comments
11.
▲
Programming guidelines – Part 4: Messages
(ibuildings.nl)
2 points
by
relaxnow
11y ago
|
0 comments
12.
▲
Programming guidelines – Part 3: The life and death of object
(reddit.com)
3 points
by
relaxnow
11y ago
|
0 comments
13.
▲
Getting rid of NULL
(ibuildings.nl)
27 points
by
relaxnow
11y ago
|
7 comments
14.
▲
Programming guidelines (for PHP developers) – Part 1: Reducing complexity
(ibuildings.nl)
3 points
by
relaxnow
11y ago
|
0 comments
15.
▲
by
relaxnow
11y ago
Heh, well it is an old picture, I'll see if I can't get a better one made. I didn't join IT for my looks though so hopefully it doesn't stand in the way of your enjoyment of the content.
16.
▲
by
relaxnow
11y ago
To be fair, most of the bad correspondence was from 2014. Their new representative 'Leigh' appears to be doing excellent work. Also we're still happy users of Slack, I would just never trust them with secrets :-).
17.
▲
by
relaxnow
11y ago
It probably means that they're not prioritising vulnerability reports. Which is their prerogative honestly, but it doesn't make researchers happy to work with you. The biggest 'fault' here I think lies squarely with Hack
18.
▲
by
relaxnow
11y ago
Don't forget that it should ideally be cryptographically random. If the sequence is predictable (like based on an auto incrementing number or on time) then you might still be able to guess a 256-bit number.
19.
▲
Hidden in plain sight: Brute-forcing Slack private files
(ibuildings.nl)
146 points
by
relaxnow
11y ago
|
51 comments
20.
▲
Ten things everyone should know about lock picking [pdf]
(blackhat.com)
2 points
by
relaxnow
11y ago
|
0 comments
21.
▲
JSON Schema abandoned while still in draft
(groups.google.com)
2 points
by
relaxnow
12y ago
|
0 comments
22.
▲
Are your (GitHub) SSH keys outdated?
(checkmysshkey.ibuildings.com)
1 points
by
relaxnow
12y ago
|
0 comments
23.
▲
RTFM is a four-letter word (2012)
(software.ac.uk)
3 points
by
relaxnow
12y ago
|
0 comments
24.
▲
A PHP Developers look back at OWASP AppSec.eu 2013
(ibuildings.nl)
1 points
by
relaxnow
12y ago
|
0 comments
25.
▲
Documenting author in source code: graffiti or attribution?
(blog.relaxnow.nl)
1 points
by
relaxnow
13y ago
|
0 comments
26.
▲
by
relaxnow
13y ago
* CSP is actually the header that most security professionals are the most excited by (in my experience) as it gives you more control over what resources are and are not allowed. Especially when you're thinking of a future where you wa
27.
▲
by
relaxnow
13y ago
The irony is not lost on me, we have a saying in the Netherlands "the carpenters doors are the creakiest". Also we don't use them all the time yet even for customers, this blog post (and an accompanying internal training next
28.
▲
by
relaxnow
13y ago
Unfortunately, as the web stands today, for our developers I do advocate including it by default, unless a specific use-case comes up to not include it. While for a simple content page allowing for framing should be okay, the truth is very
29.
▲
by
relaxnow
13y ago
As an author that doesn't write publicly all that often, thank you for your kind words. Lots of feedback is amazing in that it helps me grow, but the occasional compliment from a stranger does feel really really good.
30.
▲
HTTP Security headers you should be using
(ibuildings.nl)
278 points
by
relaxnow
13y ago
|
61 comments
More ›