Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
resfirestar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
resfirestar
6y ago
For a direct answer to your questions about how this is determined, it may help to look at the legalese, which includes a detailed definition and some examples of types of "misrepresentations" made by schools that would cause a bo
32.
▲
by
resfirestar
6y ago
A competitor would have to get most/all of the phone manufacturers to all at once drop Google Play and use their ecosystem instead, otherwise no one would bother publishing apps for it. There's no way to ramp up a competitor becau
33.
▲
by
resfirestar
6y ago
Except they moved performance backwards in WSL2 for accessing files shared with Windows: https://github.com/microsoft/WSL/issues/4197
34.
▲
by
resfirestar
6y ago
The fact that users don't usually control the servers with web apps is just a reflection of the fact that users don't usually control anything these days, and most user facing applications these days are implemented as web apps. T
35.
▲
by
resfirestar
6y ago
High profile security vendors and national security officials have a real history of describing script kiddie jobs using months or years-old public exploits as "sophisticated" or "nation-state level", one instance that t
36.
▲
by
resfirestar
6y ago
This looks like the real nightmare scenario for a supply chain attack. How long has SolarWinds has been breached? Were the attackers after a small number of US government targets + Fireeye or will we (more likely) discover extensive breache
37.
▲
by
resfirestar
6y ago
That could refer to anything from an OAuth consent attack (not much more sophisticated and arguably easier than phishing a password but much less likely to be detected because most companies don't know they should be looking for it) to
38.
▲
by
resfirestar
6y ago
Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984 >SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credent
39.
▲
by
resfirestar
6y ago
I sympathize, it's difficult to get a satisfying answer in a situation where you trust the user to accurately remember and own up to a mistake. You need both good logs (Microsoft's default logging and retention usually don't
40.
▲
by
resfirestar
6y ago
If your IT department cared, they could disable the app notification MFA method in AAD and force you to either use passwordless or a TOTP code, both of which prevent you from blindly approving a sign-in you aren't involved in.
41.
▲
by
resfirestar
6y ago
How did you determine that the attacker hijacked the existing O365 session rather than logging in with the phished username and password? For an app like O365, usually that kind of cookie-stealing doesn't happen without malware on a us
42.
▲
by
resfirestar
6y ago
While this is a pretty cool abuse of the Windows APIs, it seems to me from a first reading that it's not very "dangerous" compared to existing techniques for malware and ransomware to hide their activity. While the user imita
43.
▲
by
resfirestar
6y ago
"We pay our taxes" sounds a bit disingenuous from a company that is famous for aggressively offshoring its profits to avoid paying US and California taxes, the latter of which would directly contribute to local housing programs.
44.
▲
by
resfirestar
6y ago
Working in consulting with a lot of these products, I don’t really see ML claims as indicative of anything one way or another. I know some pretty good products claim to have advanced ML and some better ones that don’t talk about ML at all,
45.
▲
by
resfirestar
6y ago
Older people love touchscreens on laptops and use the feature very heavily (I think my mother touches her Surface Book's screen in laptop mode more than the trackpad). I see it as a nice to have when I'm recommending laptops for o
46.
▲
by
resfirestar
6y ago
Youtube has to listen to the RIAA's demands because music and music videos are a huge portion of their traffic. The music industry could decide to move all that to Spotify if they chose.
47.
▲
by
resfirestar
6y ago
Hard to tell if this is Charles Koch actually deciding to become more of a philanthropist than a partisan in his old age, or just a veiled threat to the GOP that he's ready to jump ship in the event that the GOP remains the "party
48.
▲
by
resfirestar
6y ago
The whole Twitch music DMCA fiasco and the obvious outrage of punishing people for playing their favourite tunes in public made a funny thought occur to me. With the trend toward "smart cities" and "smart vehicles" and t
49.
▲
by
resfirestar
6y ago
I think the lesser popularity of piracy with the younger generations is somewhat less about intentional takedown-based anti-piracy efforts and more their preference for mobile devices and the "pirate" options failing to keep up wh
50.
▲
by
resfirestar
6y ago
I see moves like this as seriously harmful. By removing popular pirate sites (already shady enough), search engines steer traffic to even worse places: referral spam blogs, mirrors with malware-laden ads, abandoned and spam-filled forums, e
51.
▲
by
resfirestar
6y ago
I think it's just because Downdetector is getting tons of traffic which makes it think people are having more issues than usual with virtually everything. I haven't heard any actual people say Spotify, Twitter, or Twitch are down.
52.
▲
by
resfirestar
6y ago
Most enterprise ransomware payments involve actual negotiation/haggling on the price, timing, release of stolen data, etc.
53.
▲
by
resfirestar
6y ago
Doesn’t matter if their Epic servers are up to date if the attacker got a domain admin account somewhere else and can just log in normally to run the ransomware.
54.
▲
by
resfirestar
6y ago
DMCA doesn’t give the service provider much room to adjudicate these claims. The intended way to correct bogus DMCA notices is a counter notice. GitHub’s particular policy says they reinstate content 10-14 days after getting a counter notic
55.
▲
by
resfirestar
6y ago
What’s the difference? The main one I can see is that the RIAA is accusing ytdl of being a DRM circumvention tool while Popcorn Time is just a straightforward P2P infringement tool. That doesn’t make the DMCA notice any more valid. I guess
56.
▲
by
resfirestar
6y ago
Worth noting the MPA already tried doing this to Popcorn Time, a BitTorrent client designed to provide a Netflix-like UX.[1] The Popcorn Time devs put in a counter-notice and the repository was back up a few weeks later when the period for
57.
▲
by
resfirestar
6y ago
Personally I find the 1Password X browser extension is perfectly fine for my 1Password needs on my Linux desktop. That said the extension probably isn’t as good if you have a lot of server passwords or accounts you have to enter a lot in de
58.
▲
by
resfirestar
6y ago
DGAs aren't a solution to the "my phishing page is blocked by safebrowsing/some other blacklist" problem. You can't send someone an email with a "link" that generates URLs until one of them isn't bloc
59.
▲
by
resfirestar
6y ago
> an ashtonishing 70% of the exploits are through various forms of Phishing and other attacks in the browser Credential phishing doesn’t care where your browser is running, as I frequently have to remind IT teams who think their web prox
60.
▲
by
resfirestar
6y ago
>Web browsers are the culprit behind 70% of endpoint compromises This seemed like a pretty remarkable statistic to open with (where are the Office macros? If I download a shady exe or vbs with the browser and then run it, is the browser
More ›