Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
splintersio
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Ransomecare.io a tabletop journey where everything sucks
(ransomecare.io)
2 points
by
splintersio
4mo ago
|
0 comments
2.
▲
Classic Trollyology but you've been Ransomwared
(actlikeabreach.online)
1 points
by
splintersio
5mo ago
|
1 comments
3.
▲
by
splintersio
5mo ago
It's always irritated me how quite it is after people say 'Don't pay' (I don't think you should pay, and at the same time, the loud voices turn to whispers regarding consequences, this is awful game where everything
4.
▲
by
splintersio
8mo ago
I submitted a vulnerability to Bugcrowd. Out of Scope. I published on my blog. I pointed out it was actually in scope. They acknowledged they'd made a mistake. I took the post down voluntarily. They followed up with a threat anyway. I
5.
▲
Conditional Privilege Escalation Synology DSM 7.3.2
(thecontractor.io)
2 points
by
splintersio
8mo ago
|
0 comments
6.
▲
Aruba via VPN LPE+
(thecontractor.io)
2 points
by
splintersio
9mo ago
|
0 comments
7.
▲
My Problem with Hacklore (WiFi)
(thecontractor.io)
2 points
by
splintersio
10mo ago
|
1 comments
8.
▲
by
splintersio
10mo ago
Hacklore, WiFi thoughts ... If I had to boil it down, I'd say they're thinking like cyber security engineers instead of information security officers and even then all they've done is mask nuanced conversations with foundatio
9.
▲
by
splintersio
10mo ago
What Bob and the signatories fail to recognise is that they're attempting to swap out nuanced advice for foundational advice and they're patting themselves on the back for it, actually. that foundational advice has always been the
10.
▲
Content-Security-Policy Trust Erosion Scanner
(github.com)
1 points
by
splintersio
10mo ago
|
1 comments
11.
▲
by
splintersio
10mo ago
CSP Header Analysis: Scans websites for Content Security Policy headers Domain Extraction: Identifies all external domains trusted by CSP policies Availability Checking: Uses AWS Route53 to check if trusted domains are available for registr
12.
▲
by
splintersio
10mo ago
well, the good news is, that the attacker (should there be one) has to be either on the same flight, or have pesistence (bi-directional entry) into that infrastructure that's a good edge case for not using a hotspot, but at the same ti
13.
▲
by
splintersio
10mo ago
I don't think you understand Joseph, the attacks I'm mostley speaking too are happening on the Local network the WiFi, not outbound TLS connections, do you get this ?
14.
▲
by
splintersio
10mo ago
Based on your quiz results( https://lolwifi.network/quiz/58efbbca-9b4d-4825-adb7-0e98133... ) , I notice you acknowledged: - TLS only protects application-layer data (Q1) - doesn't cover layers 2-6 - Client is
15.
▲
by
splintersio
10mo ago
are you suggesting that an insecure laptop connected to the owners mobile hotspot is somehow carrying the same level of risk as an insecure laptop connected to an untrusted wireless network Josheph ? ... come on lad.
16.
▲
by
splintersio
10mo ago
Hey josephcsible, thanks for the reply, i think you can share your answer UUID and we can see all this (I think this is you, https://lolwifi.network/quiz/58efbbca-9b4d-4825-adb7-0e98133... ) you've mentioned a well
17.
▲
"But HTTPS encrypts everything" – A WiFi security conversation
(lolwifi.network)
9 points
by
splintersio
10mo ago
|
13 comments
18.
▲
by
splintersio
10mo ago
Author here. After seeing "TLS makes WiFi safe" repeated endlessly, I built this to walk through a broader thinking distance. The /quiz version tracks contradictions in responses (surprisingly common, even among technical