Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
startling
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
startling
10y ago
I think you mean ://
32.
▲
Dirty COW (CVE-2016-5195)
(dirtycow.ninja)
7 points
by
startling
10y ago
|
0 comments
33.
▲
by
startling
10y ago
366 unique views in three days is not that high.
34.
▲
CVE-2016-6187: Exploiting Linux kernel heap off-by-one
(cyseclabs.com)
3 points
by
startling
10y ago
|
0 comments
35.
▲
Linux containers in 500 lines of code
(blog.lizzie.io)
6 points
by
startling
10y ago
|
0 comments
36.
▲
by
startling
10y ago
So, he's developing on the same server the c2 wiki runs on? One solution is to not do that.
37.
▲
by
startling
10y ago
It's a matter of degree. Do the positives of publishing outweigh the negatives? I think so.
38.
▲
by
startling
10y ago
Why does Ward need to do that before putting a tarball up somewhere? I've seen so many sites cease to exist after undertaking ambitious overhauls like this.
39.
▲
by
startling
10y ago
So, where's the content? How many backups are there? How many backups are offsite? Are any publicly-available?
40.
▲
by
startling
10y ago
The people you're afraid of ("if anything, this list provides a potential target list for other hackers to try and compromise those stores even further") already have access to the data gwillem used as a source.
41.
▲
Exploiting CVE-2016-8606: a cross-protocol attack on Guile Scheme repls
(blog.lizzie.io)
1 points
by
startling
10y ago
|
0 comments
42.
▲
by
startling
10y ago
Yep. Someday.
43.
▲
by
startling
10y ago
I'd love to go to Antarctica.
44.
▲
by
startling
10y ago
Maybe! But for example Piwik's main competitor is Google Analytics. It's reasonable to not trust Google for privacy reasons, but Google employs one the largest security teams in the world and produces very well-regarded research.
45.
▲
by
startling
10y ago
I was interested in Piwik until I noticed the many, many open security issues: https://github.com/piwik/piwik/issues?q=is%3Aopen+is%3Aissue... Includes an issue from January about insecure random-number-generation
46.
▲
by
startling
10y ago
Sometimes you can do this with things like smtp servers as well.
47.
▲
by
startling
10y ago
It was fixed, but not (publicly) recognized as a security issue, so likely not backported + updated by distros in "stable" channels.
48.
▲
by
startling
10y ago
I wrote a bit about it: https://blog.lizzie.io/notes-about-cve-2016-7117.html tl;dr looks like it'd function well a local privilege exploit. not an expert, but as a remote exploit think it would need 1) a service runni
49.
▲
by
startling
10y ago
Password managers don't have a single point of failure: an attacker needs both your password and the state of the password manager.
50.
▲
Notes about CVE-2016-7117
(blog.lizzie.io)
2 points
by
startling
10y ago
|
0 comments
51.
▲
by
startling
10y ago
I couldn't find anything, so I wrote some https://blog.lizzie.io/notes-about-cve-2016-7117.html
52.
▲
by
startling
10y ago
> It is believed that the hack compromised personal data from the accounts including names, email addresses, telephone numbers, dates of birth, hashed passwords (the majority with bcrypt) and, in some cases, encrypted or unencrypted secu
53.
▲
by
startling
10y ago
The primes are hardcoded into the source the same way that the primes are hardcoded into the sequence of natural numbers. They're there, but the important bit is finding them.
54.
▲
by
startling
10y ago
That's not similar, at all. This is actually removing multiples, as in the sieve of erastosthenes.
55.
▲
by
startling
10y ago
And the BIOS?
56.
▲
by
startling
10y ago
AIUI, no: https://www.youtube.com/watch?v=JABJlvrZWbY This is a talk from 2012, so things may have changed.
57.
▲
by
startling
10y ago
Once you reprogram the monitor, you can store or exfiltrate all of the data the user sees, and do clever things like erase and redraw the mouse pointer, or draw new prompts, to induce the user to click on the things they wouldn't have
58.
▲
by
startling
10y ago
I do mean display monitor, not temperature monitor.
59.
▲
by
startling
10y ago
Since the monitor is external, I wonder if they've considered monitors as attack surface: https://github.com/RedBalloonShenanigans/MonitorDarkly
60.
▲
by
startling
10y ago
Does that work? Can't the evil maid install a malicious hypervisor to dump interesting pieces of memory every few minutes?
More ›