Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
technion
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
241.
▲
by
technion
3y ago
I've seen people file cve requests 20 years ago with the output of "grep strcpy" as the entire report. All an llm bought to this modern version is the apologising, arguing and hallucinated code sample.
242.
▲
by
technion
3y ago
It's only been the last few weeks that LinkedIn started laying out so many "suggested " posts that every person you unfollow only creates more room for more "trending" crap.
243.
▲
by
technion
3y ago
Ironic given half my LinkedIn feed has been overtaken by this ridiculous meta of screen capping your own tweets, photoshopping a blue tick into it and posting on LinkedIn. Edit: A relevant example. https://infosec.exchange/@
244.
▲
by
technion
3y ago
What hasn't gotten enough attention here in my view is how astoundingly basic this exploit is. https://github.com/GossiTheDog/scanning/blob/main/CitrixBlee... You've got a single curl request t
245.
▲
by
technion
3y ago
You can use #![deny(unsafe_code)] in your own code. If you're hoping to enforce across all called functions, it's likely to be unworkable since a lot of stdlib ends up calling unsafe code.
246.
▲
by
technion
3y ago
As usual.. The target market for Windows are not you and I. The target market for Windows absolutely love this stuff. For every complaint about candy crush there are three decision makers playing it. He'll I've dealt with a cto th
247.
▲
by
technion
3y ago
I've seen this argument from Ms a lot but let's be real, of the ways typical home windows users are compromised spectre isn't a thing, and isn't hasn't done a thing about, for example, how readily windows let's
248.
▲
by
technion
3y ago
This reminds me of the fact the dos teenage mutant ninja turtles game had a jump you literally couldn't make and yet was loved by my whole friend group despite being unable to complete without exploiting a level skip bug.
249.
▲
by
technion
3y ago
That conditional commenting is still amazingly prevalent. It's strange how many websites "don't support ie" but have three sets of conditions for different ie versions.
250.
▲
by
technion
3y ago
Projects would do well to adopt your views, I believe that always leads to a better product. Age for example always has someone complaining about a feature they want - the refusal to oblige is exactly why it's a better product than gpg
251.
▲
by
technion
3y ago
The automation trap I keep seeming to hit is where I can only output garbage because the input is garbage. And people around me say "well it's obvious this user wrote their name incorrectly and you should have fixed it when you co
252.
▲
by
technion
3y ago
The "difference" is only an advantage to attackers, in that executables are typically blocked as email attachments and Office macros are not. Here's a ransomware incident report from someone opening an Excel document with mac
253.
▲
by
technion
3y ago
It feels contradictory to talk about these super locked down environments when "lock down Excel macros" in my view comes first if you're trying to secure an environment. I deal with before dealing with local administrator acc
254.
▲
by
technion
3y ago
https://knowyourmeme.com/memes/i-accidentally
255.
▲
by
technion
3y ago
The usual answer is your WAF blocks them and then you write a report counting it in the cyber attacks blocked by the WAF, proving it saved the company.
256.
▲
by
technion
3y ago
Meanwhile I've got a penetration test costing tens of thousands of dollars in front of me and your third finding is in there pretty much word for word.
257.
▲
by
technion
3y ago
It doesn't come much easier than the Citrixbleed exploit. https://github.com/GossiTheDog/scanning/blob/main/CitrixBlee... But I do think society needs to get over the "14 year old script kiddie
258.
▲
by
technion
3y ago
I would generally suggest if you haven't patched a Netscaler by this point, which Shodan suggests they had not, you're a timebomb for a ransomware outbreak. There's a lot of political suggestions that have reasonable argument
259.
▲
by
technion
3y ago
It's been weird here in Australia- where this is not a thing. - that pos software from America is more and more making us press zero every time I buy something when it prompts for a tip.
260.
▲
by
technion
3y ago
At one point I tested that theory by literally creating a paid Facebook ad for getcryptolocker.com, advertising that getting your data held to ransom was just one click away. I had no problems getting the ad published and Facebook alleges I
261.
▲
by
technion
3y ago
Wait.. just to be clear are you saying you could get in without owning one? I heard for years the "benefit you don't understand" is the exclusive club access. Exclusive nightclubs were a specific use case I kept seeing argued
262.
▲
by
technion
3y ago
I think the one moderate vulnerability is an example of this. I have serious doubts about anyone having wanted to use that remove timestamps parameter in 2023. I'd be surprised if many people know it exists. I more surprised an os woul
263.
▲
by
technion
3y ago
This depends what you mean by "security bulletins". In general, Microsoft did stop publishing from their traditional, hand written format a while back. The closest you get this is sort of thing now, which is completely automated a
264.
▲
by
technion
3y ago
Today's version of this would simply be an advertisement for Windows defender and a page of advise about how you sleep easy with an e5 license. I do agree some types of people would find that "professional " but I won't
265.
▲
by
technion
3y ago
I'm happy to be told to look harder but I couldn't find an R2 Object Lock equivalent. I do have to wonder if that leaves R2 customers one minor compromise away from losing their whole data store.
266.
▲
by
technion
3y ago
I highly recommend signing dev builds with your proper key because building a reputation of signing legitimate binaries is a strong signal for Microsoft smartscreen.
267.
▲
by
technion
3y ago
Just throwing in that the dollar value isn't the only cost. I've been using an automated release workflow tomanage signing, eg https://github.com/technion/rustypwneddownloader/blob/main/.... Th
268.
▲
by
technion
3y ago
Well technically this exists but after seeing my wife with an arterial pressure monitor for weeks... you don't want it.
269.
▲
by
technion
3y ago
I did a lot of the Pentesterlab Pro exercises: https://www.pentesterlab.com/exercises And was astounded by how many of them came in the class of "OAuth Exploits". And far from a list of specific CVEs in some rando
270.
▲
by
technion
3y ago
Yep, for every person who says they haven't touched osi in a decade, there's someone studying the topic either at a school or for a vendor certification. And for every "the bottom layers are worthwhile", there's a n
More ›