Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sarciszewski
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
91.
▲
by
sarciszewski
11y ago
I was curious about their "encryption" since they seem to emphasize it a lot. https://www.stackfield.com/security This page indicates they're using RSA-2048 and AES-256. Wow, that's so vague. So I signed
92.
▲
by
sarciszewski
11y ago
That's how things used to be. However, the meaning of words is decided by their usage. My attempt to summarize the new meaning of the word hacker is "any person who employs (especially technological) ingenuity to solve a problem&q
93.
▲
by
sarciszewski
11y ago
TL;DR - VTech is terrible. Slightly less TL;DR - VTech got hacked, hard, and instead of investing in securing their products and services, they opted to update their Terms and Conditions to make them not liable for any data loss you experie
94.
▲
by
sarciszewski
11y ago
Fortunately there aren't many with Tavis's skills, but you don't need to be that legendary to find these sort of vulnerabilities. Assuming you can identify (skill) and safely sell (anonymity expertise and market savvy) a zero
95.
▲
by
sarciszewski
11y ago
I wasn't one of the downvoters, but I will say: > I think sysadmins need monitoring and automation tools so that expired certificates can be an exceedingly rare event. Letsencrypt has taken a big step towards this by making a fully
96.
▲
by
sarciszewski
11y ago
Sure, but instead of throwing our arms up and accepting defeat, initiatives like Decent Security are trying to move the needle away from "insecure by default". I'm trying to do the same thing with developers. :)
97.
▲
by
sarciszewski
11y ago
Sandboxing is good for stopping memory corruption and privilege escalation bugs. It's not very useful for problems affecting cryptography implementation flaws, logic errors, out-of-date software, etc. Those problems are better solved b
98.
▲
by
sarciszewski
11y ago
Your comment reminds me of this: http://swiftonsecurity.tumblr.com/post/98675308034/a-story-a... It's a good read, and it was one of the pieces that motivated me to pursue making security easier for people.
99.
▲
by
sarciszewski
11y ago
This is very close to the advice I give laypeople, but I hit a few other points (e.g. password security): https://paragonie.com/blog/2015/06/guide-securing-your-busin...
100.
▲
by
sarciszewski
11y ago
I (and many others far more impressive than myself) am trying to solve this problem at a fundamental level: Give the developers tools that are secure-by-default (i.e. libsodium not mcrypt) and teach better development habits. Make it easier
101.
▲
by
sarciszewski
11y ago
http://www.sevagas.com/IMG/pdf/BypassAVDynamics.pdf Anti-Virus is little more than snake oil. If you need to secure a Windows box, get EMET and read http://decentsecurity.com and you'll eliminate
102.
▲
The Comprehensive Guide to URL Parameter Encryption
(paragonie.com)
3 points
by
sarciszewski
11y ago
|
0 comments
103.
▲
Deploying UBlock Origin for Firefox with CCK2 and Group Policy
(decentsecurity.com)
2 points
by
sarciszewski
11y ago
|
0 comments
104.
▲
by
sarciszewski
11y ago
I feel like sharing something. It's somewhat a tangent to this article (and isn't special enough to really share as a separate submission or anything) but still related. For a while, I was working 40+ hours per week at my dayjob a
105.
▲
by
sarciszewski
11y ago
> OK so basically appeal to authority etc. No, I'm not making an appeal to authority. Sorry if it sounded like that. The team behind Zcash has serious technical chops, and it's worth pointing out that some of the most competent
106.
▲
by
sarciszewski
11y ago
I can't do an apples-apples comparison to the ones you listed because I'm only familiar with Bitcoin and the original Zerocash paper. I can say that the zkSNARK approach to crypto-currency is certainly novel and they have a grea
107.
▲
by
sarciszewski
11y ago
> Nothing new here. Add it to the pile of hundreds of other altcoins. It sounds to me like you don't understand the technology involved. To be fair, it's probably Greek to most people outside of crypto. How many of the other al
108.
▲
How to Secure Your Business's Online Presence (for Non-Experts)
(paragonie.com)
1 points
by
sarciszewski
11y ago
|
0 comments
109.
▲
by
sarciszewski
11y ago
It's raw binary. The best way would be to base64 encode it and break it into four tweets.
110.
▲
by
sarciszewski
11y ago
That was my intention. Dion Hulse really pulled through on WP's end, and he's quick to pull in upstream changes into their trunk branch for testing. :)
111.
▲
by
sarciszewski
11y ago
Good answer. :)
112.
▲
How to Secure Your Business's Online Presence (for Non-Experts)
(paragonie.com)
3 points
by
sarciszewski
11y ago
|
0 comments
113.
▲
by
sarciszewski
11y ago
I use Github for a lot of things. When it goes down, I just delay pushing a commit for a little while.
114.
▲
by
sarciszewski
11y ago
I can't comment on either project's security scrutiny, as I'm not intimately familiar with either of their security teams. I will say that, as a rule, I don't believe I can ever trust Github, regardless of how good the
115.
▲
by
sarciszewski
11y ago
> Apologies if my comment came off as accusatory, I really did find it funny This thread has been a land mine of accusatory reactions, so I apologize for painting yours in a similar brush. > I have seen people have a bias towards the
116.
▲
by
sarciszewski
11y ago
> It was just informal advice to rein yourself in. Take it or leave it. Okay, I'll take it. It's just really frustrating that this keeps happening even though I take care to choose my words very precisely. Especially qualifiers
117.
▲
by
sarciszewski
11y ago
Have I overlooked bugs? Sure. Have I overlooked really obvious bugs? None so far that I've been informed of. I'm not careless when I get paid to audit a project. Of course, I know I'm not perfect either. One time, I was wri
118.
▲
by
sarciszewski
11y ago
> That's a funny double standard you have right there with how you don't feel the need to audit GitHub before using it. Where did I ever say I use Github with confidence ? I've answered this several times below: I use sof
119.
▲
by
sarciszewski
11y ago
Close enough, right?
120.
▲
by
sarciszewski
11y ago
Sorry, I don't know how to be clear to people whom treat the very important phrase "with confidence" as nonexistent in that sentence. Maybe this app will help? https://play.google.com/store/apps/deta
More ›