Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sdevlin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
181.
▲
by
sdevlin
13y ago
He's citing this as a potential cross-authorization vulnerability, not SQL injection. The form he's demonstrating is a common misstep in Rails. Instead of writing something like: current_user.apartments.destroy(params[:id])
182.
▲
by
sdevlin
13y ago
Other people have answered this for me, but I mean the overhead of another moving part in the tool chain. Sometimes this is worth it (i.e. your example of C v. assembly down thread), but I don't think it's the case here. I don
183.
▲
by
sdevlin
13y ago
> The explanation for most people’s dislike of CoffeeScript is probably our natural resistance to new things and our comfort in what we know. This is a mildly insulting, as is the invocation of Blub. CoffeeScript doesn't have a ton
184.
▲
by
sdevlin
13y ago
Typically CSRF tokens are only required for state-changing requests - POSTs, PUTs, DELETEs. They're broadening that recommendation also to include pages that reflect input. Think GET requests that take query string parameters. So e.g.
185.
▲
by
sdevlin
13y ago
> The alternative is auditing every single endpoint to ensure that it won't leak attacker data into the response, I think you're underestimating how common this is. For example, view source on https://www.google.com&
186.
▲
by
sdevlin
13y ago
In many web application frameworks, CSRF tokens are session scoped. So an attack might look like this: 1. User logs in to target web app (e.g. hapless.com). 2. User visits your malicious content (e.g. evil.com). 3. Your page does a
187.
▲
by
sdevlin
13y ago
I think the idea is to find e.g. a query string parameter that gets reflected back in the response's HTML along with a target secret. The attacker can then spawn requests and monitor the size of the response.
188.
▲
by
sdevlin
13y ago
> Ah, so in fact the naive concatenating solution I gave, in addition to being just as easy because the attacker only has to break half of it, is actually even easier because the attacker has two targets to collide with. I wouldn't
189.
▲
by
sdevlin
13y ago
This is actually a pretty interesting question. The answer, at least for Merkle-Damgard hash functions (MD5, SHA-1, SHA-2, etc) is that concatenating (or "cascading") hash functions doesn't really improve the strength of the
190.
▲
by
sdevlin
13y ago
Apologies on this, and thanks for your patience. This is something we work on in our spare time, and we've got a bit of a backlog at the moment. I'm going to try to find time to power through most of this over the weekend. As you
191.
▲
Applied Cryptography Engineering
(sockpuppet.org)
118 points
by
sdevlin
13y ago
|
30 comments
192.
▲
by
sdevlin
13y ago
The format of a document is relevant to the recipient. Not every text editor will open a Word document. Also, you probably wouldn't look at someone funny for requesting a kleenex. All the things you mentioned have pretty strong brand-n
193.
▲
by
sdevlin
13y ago
> once you learn how to exploit the flaw in RC4 he's talking about Quick version: RC4 has biases in the key stream it generates. This means that for a given offset, certain bytes are more likely to appear than others. How do you exp
194.
▲
by
sdevlin
13y ago
RC4 is a stream cipher. This means you have a stream of key bytes and a stream of plaintext bytes. You pair these up and XOR each pair together to get a stream of ciphertext bytes. The key stream is generated independently of the plaintext,
195.
▲
by
sdevlin
13y ago
Typically the secret data you're interested in is specific to a particular user. Session cookies, for example. (Not saying this is universally true, this is just the scenario I think is on most people's minds.) If the traffic is c
196.
▲
by
sdevlin
13y ago
Unfortunately, I don't think so. It's pretty easy to eyeball your ciphertext and think it's sufficiently garbage-looking, but it's difficult to predict what an attacker can do with access to your running system. Seemingl
197.
▲
by
sdevlin
13y ago
I don't think this is good advice for the developer population at large. > Sure, it's complex and you have to get all the details right What's really dangerous about cryptography (someone on HN pointed this out a few week
198.
▲
by
sdevlin
13y ago
16% of web vulnerabilities found by a scanner are still XSS.
199.
▲
by
sdevlin
13y ago
I wouldn't say we use lisp. We do test lisp apps every so often.
200.
▲
by
sdevlin
13y ago
Matasano - New York City, Chicago, San Francisco Bay Area We break into banks. And hospitals. And financial firms. And social media startups. And any other business that puts an open port between itself and the big bad world. Matasano is lo
201.
▲
by
sdevlin
13y ago
Einstein did his best stuff while he was working as a patent clerk.
202.
▲
by
sdevlin
14y ago
Surely questions of readability should be decided with an eye towards experienced users of the language and not those who "don't know the first thing about F#". I agree with the GP that x::xs is more appropriate.
203.
▲
by
sdevlin
14y ago
> Also, I don't know any F#, but is he correct when he says that the order of declarations in a file matters, and that the order of files in a project matters? He is correct. (At least, this was true a couple years ago. I haven't used F
204.
▲
by
sdevlin
14y ago
Since you're only going to store the hashed value, there's no practical reason to limit the maximum length of the password.
205.
▲
by
sdevlin
14y ago
If this were true, there would be no reason to hash passwords. There are hashing algorithms (bcrypt, scrypt, PBKDF2) that are specifically designed to be slow to prevent these attacks.
206.
▲
by
sdevlin
14y ago
This is not accurate. If it were, what would be the point of hashing at all? Password hashes like scrypt, bcrypt, and PBKDF2 are specifically designed to be slow, such that breaking them takes not weeks but many years.
207.
▲
by
sdevlin
14y ago
Depending on how they're hashed, that may or may not be an effective countermeasure.
208.
▲
by
sdevlin
14y ago
Symbols in Ruby are basically interned strings. So if you reference the symbol :foo, it will transparently get pinned in memory somewhere. Referencing :foo again will not allocate an additional object - the interpreter will just give you th
209.
▲
by
sdevlin
14y ago
It's probably worth noting that Contre Jour was originally an iOS game. The HTML5 version is a port of the original. (Not to take anything away from it!)
210.
▲
by
sdevlin
14y ago
Nice article. This makes me wonder if Visual Studio's F# mode could help detect common errors, e.g. highlight recursive calls not made in tail position. On the other hand, this could get annoying as such calls are often not a real problem i
More ›