Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ryuuchin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
ryuuchin
10y ago
But the point of failure is not likely to be your database of unencrypted passwords. Also if an attacker can get their hands on a password database which is stored locally you probably have more problems than just that. Simply using the br
92.
▲
by
ryuuchin
10y ago
Randomly generate a password for every site. Store said passwords in a password manager protected with one master password which you remember (taking the number of passwords you would have to remember from hundreds (impossible) to one (ver
93.
▲
by
ryuuchin
10y ago
>>Enforced W^X userland as of 6.0 >Linux Well grsecurity's mmap protections are a strict superset of OpenBSD's W^X which we've had for what 10 years now? >Literally every other OS out there has stack protector, an
94.
▲
by
ryuuchin
10y ago
Arch Linux enables -fstack-protector-strong last I checked by default. I admit Debian often drags it feet on some things like this but I think Ubuntu has enabled it for a number of packages as well.
95.
▲
by
ryuuchin
10y ago
I was just trying to make a point that OpenBSD is not always the best choice for all possible use cases to expand upon tptacek's post a little. In may be for someone uninformed or lazy but my argument is if you're willing to put
96.
▲
by
ryuuchin
10y ago
Linux with grsecurity is a pretty obvious alternative. There are distros which include grsecurity patched kernels in their repo (or use it by default) although going this route over a self-compiled one does loose out on a few security feat
97.
▲
by
ryuuchin
10y ago
Enterprise users get a 4th option called "security" for telemetry I think (which in gpedit is option 0 I believe). I think it sends even less than basic and as the name implies it only sends security relevant telemetry (Defender,
98.
▲
by
ryuuchin
10y ago
> I figured out it was the one box on the network that upgraded itself to Windows 10. Very disconcerting. Sounds like an oversight by IT. On corporate/enterprise network the Windows 10 upgrade should be disabled through group polic
99.
▲
by
ryuuchin
10y ago
With msvc the /sdl flag can zero initialize class members to zero[1] (among other things). This runs before the constructor. Aside from the warnings that get turned into errors (you can disable the warning to bypass this behavior) it
100.
▲
by
ryuuchin
10y ago
Why isn't the ssa optimizer mentioned in the Update 3 release notes? Is it enabled by default in Update 3?
101.
▲
by
ryuuchin
10y ago
I'm not saying that the publicity isn't a good thing here but this isn't new. I feel like the writer of this article just discovered this or something or is just trying to bring attention to the issue which is a good thing.
102.
▲
by
ryuuchin
10y ago
> real benefits to Firefox by enhancing security of isolated components like this mp4 parser Now if only there was a way to isolate stuff at runtime (i.e. a sandbox) to better take advantage of operating system mitigations. I hope tha
103.
▲
by
ryuuchin
10y ago
There also BoringSSL[1] but that might be even more of a departure than LibreSSL in terms of API compatibility. I still think it's surprising that we don't see more BoringSSL being used especially with nginx. [1] https:/&#x
104.
▲
by
ryuuchin
10y ago
Reminds me of of the Power Metal Lyric Generator[1]. Although obviously that was done more as a joke instead of actual analysis on metal lyrics. [1] https://youtu.be/wpe8eNdpAiM?t=307
105.
▲
by
ryuuchin
10y ago
Do you mean uBlock (Origin)[1]? That's the one with the element picker[2] if that's what you're referring to. uMatrix[3] does not have cosmetic filtering which may be required to hide an element like the one in question. Y
106.
▲
by
ryuuchin
10y ago
Obligatory uBlock Origin[1] plug with a recommendation to run it in "medium mode"[2] which offers the best bang for your buck (i.e. the most that can be blocked with the least amount of effort from the user). Dynamic filtering is
107.
▲
by
ryuuchin
10y ago
Reading commit messages from Chrome's support[1][2][3] for win32k system call disable mitigation (aka win32k lockdown) on Windows (specifically for PPAPI plugins) I think Flash, at least in Chrome, loads fonts from the browser. Which
108.
▲
by
ryuuchin
10y ago
It's marked fixed because Microsoft released a patch for it. However at the very least Chrome and Firefox have been doing font sanitization for quite some time now (several years+ I believe). I'm not sure for other browsers. Op
109.
▲
by
ryuuchin
10y ago
Both Firefox and Chrome use font sanitizers[1]. I'm not sure about others, Opera probably does since it's just a Chromium fork and OTS is part of the WTF (webkit tools framework). AFAIK its been used for quite some time now, sev
110.
▲
by
ryuuchin
10y ago
You don't even have to update Flash anymore. It's built-in to Chrome (and updates on its own) and (the other one) updates with Windows Update. I suppose you might have to if you're using Firefox but Firefox would be the las
111.
▲
by
ryuuchin
10y ago
grsecurity[1] for linux. You don't even have to use RBAC if you don't want to (you can still use AppArmor/SELinux/etc) but RBAC comes with a built-in learning mode which is good and will likely do a better job than you c
112.
▲
by
ryuuchin
10y ago
I realize that it's better than nothing but be careful with the default AppArmor profiles, they're very coarse grained and allow a lot of stuff that they don't really have to for compatibility reasons (so they just work). I&
113.
▲
by
ryuuchin
10y ago
grsecurity just disables it outright IIRC (the new one that was added sort of recently, probably year+ at this point).
114.
▲
by
ryuuchin
10y ago
Try dynamic filtering (in medium mode)[1] and raise that number even higher. [1] https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
115.
▲
by
ryuuchin
10y ago
Clicking the power button only disables it for that specific site. Every other site would still have blocking enabled so that sounds like a pretty good reason to have it installed.
116.
▲
by
ryuuchin
10y ago
What filter lists were you using? uBlock Origin's behavior is identical to Adblock Plus given the same filter lists are used for both. uBlock uses a few more filter lists by default although I still think it's on the conservativ
117.
▲
by
ryuuchin
10y ago
Your guess is as good as mine. Blame Netflix, Microsoft or the people pushing DRM. Maybe it's some combination of all of the above or none of them. I'm not sure anyone really knows why we have this behavior. It's not neces
118.
▲
by
ryuuchin
10y ago
Well I also use uMatrix which covers the cases where the built-in option does not. It can also be controlled on a per-site basis. I assume the functionality is pretty much the same.
119.
▲
by
ryuuchin
10y ago
You can also do this in Chrome although I'm not sure if the behavior is identical. On chomre://flags search for reduced-referrer-granularity and enable it to get a similar effect. I believe it may only affect web sites that
120.
▲
by
ryuuchin
10y ago
Chrome uses widevine (DRM) for Netflix which uses HTML5. Really the more significant difference is that Chrome gets capped to 720p. Edge actually gets the 1080p streams (as does IE11 on Windows 8+ and the Netflix Windows Store app).
More ›