Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rtev
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
31.
▲
by
rtev
4y ago
Totally. It’s a very hard line to walk, because leaning into either side can be very damaging.
32.
▲
by
rtev
4y ago
While I generally agree with the sentiment of the article, and I do like the neutral presentation of most of the information, one thing stood out to me. The “it’s not your fault, it’s the food” attitude seems dangerous. I think that mindset
33.
▲
by
rtev
4y ago
That WAF needs to be tuned. If they’re worried about the possibility of a local file read that can disclose /etc/shadow, there are much bigger issues.
34.
▲
by
rtev
4y ago
It’s worse than that, unfortunately. Windows happily authenticates with an NTLMv2 hash using this method as well - requires zero interaction.
35.
▲
by
rtev
4y ago
LastPass has always been atrocious. Crazy that anyone has been on their platform post ~2016.
36.
▲
by
rtev
4y ago
I do know the answer to this - Firefox is not an acceptable alternative to a strong password manager. Local admin can dump any passwords from Firefox, and I think a user can even dump their own passwords from Firefox on windows and Linux.
37.
▲
by
rtev
4y ago
Good question. Can local admin dump apple keychain passwords? If so, hashed or plaintext?
38.
▲
by
rtev
4y ago
I really hope that’s true, it’s hilarious either way!
39.
▲
by
rtev
4y ago
Great take. Do you have any thoughts on how to improve on CVSS 3.1? I’m wondering if perhaps the optional “additional details” section, where you can contextually upgrade or downgrade scores, should be a mandatory part of the score.
40.
▲
by
rtev
4y ago
While I disagree with the author’s overarching opinion on ReDoS vulnerabilities, I agree that some CVEs make it through with incorrect severity scores. If you find a CVE like this, MITRE can be contacted to mark it as disputed for investiga
41.
▲
by
rtev
4y ago
“Choose to not be poor” is the thesis of your statement, whether you meant for it to be or not. It’s hard for that to be a good faith start to any discussion regarding poverty.
42.
▲
by
rtev
4y ago
No one making $9/hr with a kid or two is going to be dishing out for a Costco membership and getting a volunteer to drive them around everywhere they need to go. There is no long-term savings and “financial sense”, it’s hand-to-mouth,
43.
▲
by
rtev
4y ago
Your first paragraph seems to be “others are already doing it”. That’s a problem, not a justification for doing more of it. It’s a shame to see embedded analog grain stripped out because it was inconvenient for a dev team. It strikes me as
44.
▲
by
rtev
4y ago
To many film artists, what you’re suggesting seems like the equivalent of hardcoding a custom massive bass boost into commercial headphones because “it makes music better”. It might seem better to you, but you’re modifying someone’s art, w
45.
▲
by
rtev
4y ago
This is really out of touch. First off, poor people can’t afford Costco memberships. Second, 5 miles is a very long distance in Chicago. How can someone justify spending an hour in traffic each way, and with what car?
46.
▲
by
rtev
4y ago
This is 100% OP’s fault, it’s not like Azure itself was breached. Their account got hacked due to weak security practices on their part.
47.
▲
by
rtev
4y ago
questionable pentesting firms use it on their reports for critical info
48.
▲
by
rtev
4y ago
The scale of factory farming suffering is much greater than the shark fin industry, even if most of it is a milder form of torture. This just reads as “that’s worse!” fallacy caused by cognitive dissonance. Both can be bad and it strikes me
49.
▲
by
rtev
4y ago
With all this App Store monopoly talk and pressure to open up, I think Apple will take a hit too. With that said, I think they deserve to be valued higher than most of these companies; Apple seems to have stronger product offerings and cust
50.
▲
by
rtev
4y ago
They’re advertising here on their platform, so the tie-in is strong.
51.
▲
by
rtev
4y ago
Funny you mention this, because we’re already seeing it. In fact, I recall reading that unfiltered marijuana smoke is slightly more harmful to the lungs than unfiltered cigarette smoke.
52.
▲
by
rtev
4y ago
This is an entertainment site maintained by a comedian
53.
▲
by
rtev
4y ago
You did the right thing. If more people spoke up and stood up, the world would be a much happier place.
54.
▲
by
rtev
4y ago
Markdown has been a popular vector for XSS in the past due to the more esoteric media embedding features it has.
55.
▲
by
rtev
4y ago
Thanks! It totally went over my head, I thought you must have had some justification due to the quotes.
56.
▲
by
rtev
4y ago
Why continue to use the incorrect and offensive term “indians”? You even quoted it, so I’m confused why you used it at all.
57.
▲
by
rtev
4y ago
People get defensive when they feel like they’re being attacked. Many people really enjoy alcohol and don’t like to think about it as a dangerous drug (which, of course, it is).
58.
▲
by
rtev
4y ago
Is it just me or does this kind of thing reek of a nation state? This feels like the Twilio breach where the suspected goal was access to Signal MFA codes for 15 minutes or whatever that was. Feels like it’s hyper-targeted as some kind of
59.
▲
by
rtev
4y ago
That doesn’t matter, best practice is storing them as variables that are injected upon deployment from a secret manager.
60.
▲
by
rtev
4y ago
Yeah, I was expecting heartbleed and this is “denial of service if you manage to sneak a malformed certificate by a CA and it makes into an attack chain”. Other than the sheer number of devices vulnerable, I don’t see this as being that big
More ›