Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
secalex
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
Information Operations and Facebook [pdf]
(newsroom.fb.com)
2 points
by
secalex
9y ago
|
0 comments
32.
▲
by
secalex
10y ago
You can configure U2F+Code Generator+Backup Codes and end up with no reliance on the security of SMS for either authentication or account recovery.
33.
▲
by
secalex
10y ago
Firefox will be supported after they land support in release builds.
34.
▲
by
secalex
10y ago
AFP is also a security disaster. Check out the spec for "DHX2" https://developer.apple.com/library/mac/documentation/Networ...
35.
▲
by
secalex
10y ago
This is a great example of security nihilism. "This tool can't protect against every possible attack from every possible adversary, therefore it is useless." Building safe, secure products at scale for real populations is a p
36.
▲
Understanding and Hardening Linux Containers [pdf]
(nccgroup.trust)
196 points
by
secalex
10y ago
|
106 comments
37.
▲
by
secalex
11y ago
Different key, dude. We rotated what was exposed.
38.
▲
by
secalex
11y ago
Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
39.
▲
by
secalex
11y ago
Probably because this post was getting lots of links for a domain that is otherwise rarely seen on FB? You can read about the challenges of spam-fighting at scale (and people actually getting paid to write Haskell) here: http://w
40.
▲
by
secalex
11y ago
This was a mistake due to this specific blog post sharing some design elements as some spammy blogspot posts and it was fixed. If we really wanted to censor this story wouldn't we block all criticism of Facebook and not a pretty straig
41.
▲
by
secalex
11y ago
I filed a bug. I don't know why the spam filters picked this up but it was not intentional. EDIT: Fixed
42.
▲
Rule by a Foreign Power Considered Harmful (1776)
(archives.gov)
18 points
by
secalex
11y ago
|
5 comments
43.
▲
by
secalex
11y ago
Me too.
44.
▲
Collateral Damage
(textslashplain.com)
84 points
by
secalex
11y ago
|
39 comments
45.
▲
by
secalex
11y ago
To be clear I'm not claiming that firewalls are irrelevant in the enterprise campus scenario, especially if they have DPI functions that are effective in discovering outbound control channels. Even huge corporate environments rarely ha
46.
▲
by
secalex
12y ago
So you clean your clothes in the stream out back using a washboard and lye you made from white ash? "The dream of the 1890's is alive in Portland..."
47.
▲
by
secalex
12y ago
> I haven't heard many alternatives (in general). These problems don't call for a general solution. We should respect the fundamental truth behind the end-to-end principle and solve these problems as close to the application a
48.
▲
by
secalex
12y ago
A bunch of us who were "open" applicants for new TLDs (my company applied for .secure) tried our best to fight this in ICANN. The "closed generic" was not something properly anticipated by ICANN when they created the nTL
49.
▲
by
secalex
12y ago
Free filing is going to increase fraud since $10 means the attackers need enough credit card numbers to not set off Intuit's or the payment networks' fraud systems. That probably means almost a 1:1 ratio between returns and workin
50.
▲
by
secalex
12y ago
I once had an interesting discussion with a tech-savvy criminal attorney about whether security researchers could trade public equities using early indicators of compromise or private knowledge of 0-day (gained from outside the company, not
51.
▲
by
secalex
12y ago
The well-meaning but naive people behind this and other ad-disrupting extensions are doing more than anybody to end the era of general purpose computing. These products (several of which are created by for-profit companies that then extort
52.
▲
by
secalex
12y ago
Yes, the systems with the log parsing bug are part of an internal subnet. As with most web scale companies HTTPS requests are terminated on a unified edge and load-balanced to web service hosts in internal clusters. In this case the malicio
53.
▲
by
secalex
12y ago
I appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.
54.
▲
by
secalex
12y ago
We have several participants in our program who are making a pretty decent living, especially the ones for whom a US$5000 reward is comparable to their nation's per-capita GDP. We are hoping to highlight some of these people in a futur
55.
▲
by
secalex
12y ago
Twice means once for the initial bug on Wednesday, the second time with one of the "nuke the attack surface from orbit, it's the only way to be sure" patches that became available that Thursday. This is no guarantee, of cours
56.
▲
by
secalex
12y ago
Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the si
57.
▲
by
secalex
12y ago
Although I'm an AGL fanboy (I have his rookie card) I have to agree with Matthew here. Pushing the transition this fast, just when the world is on the verge of accepting HTTPS as the default, is reckless and will overall reduce the saf
58.
▲
by
secalex
12y ago
I gotta back Matt here. While none of the three of us would endorse the iMessage key exchange model, the truth is that the team that implemented iMessage crypto have kept more communications safe from dragnet surveillance than everybody com
59.
▲
by
secalex
12y ago
I did not miss that, nor did I make any comparisons to car dealers. In fact, I've been to seven ICANN meetings and have participated in the debate on the proper role of law enforcement and civil seizure in policing the namespace. Micro
60.
▲
by
secalex
12y ago
The Microsoft hate here is unfounded and ill informed. Those of us working defense at large organizations have known for a while that No-IP domains are wretched hives of scum and villainy. Any company with a threat model that includes at le
More ›