Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rtev
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
rtev
4y ago
In my opinion, if a disclosure by a person takes place within their lifetime then it’s too soon.
122.
▲
by
rtev
4y ago
It’s considered irresponsible disclosure to publish the hit track proof-of-concept prematurely. You should have waited another 5-10 years.
123.
▲
by
rtev
4y ago
Slack Huddles directly address this issue pretty effectively.
124.
▲
by
rtev
4y ago
Look at hackerone. They absolutely do. Many top-tier companies take 4-10 months to patch things that could be explicitly used for significant compromise. A company you’ve worked for has probably done it.
125.
▲
by
rtev
4y ago
You might think so, but these kinds of logical errors are in everything. Someone didn’t sit down and write “file name == certificate”, but unexpected behavior during tainted data processing resulted in that. Even the best programmers consta
126.
▲
by
rtev
4y ago
It’s fascinating how effortlessly the best researchers are able to bypass authentication mechanisms and security boundaries. This is the kind of code base that has had nation state-level eyes on it, yet he breezes through like it’s nothing.
127.
▲
IAM Whoever I Say IAM – VMware Workspace One 0-Click Exploit (Steven Seeley)
(srcincite.io)
1 points
by
rtev
4y ago
|
1 comments
128.
▲
by
rtev
4y ago
1Password has fairly extensive permissions and can do this
129.
▲
by
rtev
4y ago
I have, actually - they don’t make any sense. What about TOTP are you opposed to? That’s modern 2FA, not something related to phones.
130.
▲
by
rtev
4y ago
At the risk of sounding rude, I don’t think you understand how modern 2FA works. No phone number is involved. Your parent comment is based on misinformation and is the top comment; please consider editing or deleting it.
131.
▲
by
rtev
4y ago
That’s a security flaw. Backup codes are the fix if you get locked out. Sure, the attacker could find the backup codes, but that can be a challenging task.
132.
▲
by
rtev
4y ago
I think the parent comment is really onto something here. Isn’t this just weaponizing Cunningham’s Law? Few people can resist the pull of being a smart-ass and telling others they are doing things wrong. It’s kind of brilliant.
133.
▲
by
rtev
4y ago
The US also has a very poor handle on heart disease; almost 10% of men in the US have coronary heart disease. The recommended strategies aren’t working.
134.
▲
by
rtev
4y ago
Alternatively, the people who score big bounties become extremely skilled very quickly. That often translates to 300-400k salaries a few years down the line.
135.
▲
by
rtev
4y ago
I’m a pentester. US salaries are about 20-30% less than very competitive dev salaries. Security engineers make a bit more than pentesters, but both are typically less than well-paid dev work.
136.
▲
by
rtev
4y ago
Great article, I learned more about these daily-use tools. An easy trick I use a lot is host OS identification via ICMP. A TTL of around 64 is Linux, ~128 is windows.
137.
▲
by
rtev
4y ago
Definitely the first. Beacons have better cross-platform support than most Microsoft products.
138.
▲
by
rtev
4y ago
When I clicked the link, I expected to see media security DRM functionality or something along those lines. However, from what I can tell, this is all critical security stuff; the security community has been begging for features like these
139.
▲
by
rtev
4y ago
My father had a heart attack at 43. In response, he dropped red meat and dairy and had to have stents put in 2 years later as his condition deteriorated. He stopped eating any foods with added oils, as well as anything fatty like nuts and a
140.
▲
by
rtev
4y ago
All of your advice is good. It should be noted that taking Tyrosine can help replenish depleted dopamine stores.
141.
▲
by
rtev
4y ago
Why no mustard? Everything else you mentioned is stuff I know, but I eat quite a bit of Dijon.
142.
▲
by
rtev
4y ago
All oils and added fats are bad for people with heart problems or those at risk of them.
143.
▲
by
rtev
4y ago
Can’t shell the computer if I break the OS ;)
144.
▲
by
rtev
4y ago
Doing Airbnb over hotels also contributes greatly to city housing shortages and gentrification. Major US cities have large swaths of apartment units sitting empty, held by some management company to rent out as a pseudo-hotel room.
145.
▲
by
rtev
4y ago
Right? There are a lot of very complex suggestions for this simple problem. To simplify even more, based on the use case, it would probably be fine to just share an inline user:pass@site.com link. That would avoid even needing the user to f
146.
▲
by
rtev
4y ago
It’s true that there are many better ways to do it. If a nation state only had this option, I think they could pull it off though.
147.
▲
by
rtev
4y ago
What you’ve described is an issue with the bank’s procedures, not pentesting.
148.
▲
by
rtev
4y ago
That’s a strong possibility. While I’m not religious, I frequently envy the close community that religious life brings.
149.
▲
by
rtev
4y ago
While I do see the value in something like that, I can’t help but feel like that would just bake in more complexity. The python ecosystem is fragmented with micro fixes and half-solutions without anything truly addressing the major confusin
150.
▲
by
rtev
4y ago
Someone attacking a nuclear facility can get a receiver within range
More ›