Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
troyhunt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
troyhunt
14y ago
Yes - education! Your average desk jockey will know when the sites they use break, they won't know why and they won't know about the alternatives.
32.
▲
by
troyhunt
14y ago
I'm not so sure that this is to their commercial advantage, in fact I think it could be quite the opposite. Where there is the motivation (i.e . by those managing the desktop environments), the IE8 dependency is an easy one to solve via alt
33.
▲
by
troyhunt
14y ago
In most managed corporate environments, you do have to run IE. The freedom of installing your own software at will doesn't exist.
34.
▲
The impending crisis that is Windows XP and IE 8
(troyhunt.com)
63 points
by
troyhunt
14y ago
|
78 comments
35.
▲
Is Java the root of all evil and can you really live without it in the browser?
(troyhunt.com)
4 points
by
troyhunt
14y ago
|
1 comments
36.
▲
Inviting hackers into our homes via the Internet of things
(troyhunt.com)
7 points
by
troyhunt
14y ago
|
0 comments
37.
▲
Please login to your Facebook account: the execution of a data mining scam
(troyhunt.com)
2 points
by
troyhunt
14y ago
|
0 comments
38.
▲
EE-K DM'ing your password is Never a good idea
(troyhunt.com)
5 points
by
troyhunt
14y ago
|
2 comments
39.
▲
Stored procedures and ORMs won't save you from SQL injection
(troyhunt.com)
9 points
by
troyhunt
14y ago
|
3 comments
40.
▲
Hacktivism is dead. Long live opportunism
(troyhunt.com)
1 points
by
troyhunt
14y ago
|
0 comments
41.
▲
She did WHAT in school? The mechanics of a Facebook worm
(troyhunt.com)
2 points
by
troyhunt
14y ago
|
0 comments
42.
▲
Hacking is child’s play – SQL injection with Havij by 3 year old
(troyhunt.com)
3 points
by
troyhunt
14y ago
|
0 comments
43.
▲
by
troyhunt
14y ago
Given the web is credited as being created by a Brit in Switzerland, I think we can all agree that both its origins and its intent are international in nature. Given that uncultured in this context is about lack of awareness of cultures bey
44.
▲
Lessons for uncultured web developers
(troyhunt.com)
244 points
by
troyhunt
14y ago
|
112 comments
45.
▲
Why XSS is serious business (and why Tesco needs to pay attention)
(troyhunt.com)
52 points
by
troyhunt
14y ago
|
31 comments
46.
▲
by
troyhunt
14y ago
That's a bit of an "it depends" situation though. There's a good answer on Super User about this: http://superuser.com/a/156969/4682
47.
▲
Is Stack Overflow “secure”? Kind of...
(troyhunt.com)
71 points
by
troyhunt
14y ago
|
19 comments
48.
▲
by
troyhunt
14y ago
Well actually, we are talking about JavaScript, 5 separate .js files actually. The challenge comes back to the fact that "Secure" in an HTTPS context is an absolute; either everything is loaded over HTTPS and you get a shiny padlock or
49.
▲
by
troyhunt
14y ago
The relevance is that none of the additional protections added to the technologies are available. We're in a very different threat landscape today than what we were in 9 years ago and the technologies provide advances to better protect ou
50.
▲
by
troyhunt
14y ago
Why rewrite? When there's a new major feature release, take the opportunity to change the target framework. Most servers also have a refresh cycle so update that at the time and roll it into the testing procedure. I'm not saying do this imm
51.
▲
by
troyhunt
14y ago
GMail is a good example of HTTPS everywhere. When you embed HTTP elements you can no longer trust their authenticity. If, for example, you load JS into your banking app over HTTP it would be possible for a man in the middle attack to substi
52.
▲
by
troyhunt
14y ago
Actually, you do a lot with them; I could take a significant portion of them and log on to the account holders' Twitter / Facebook / GMail. Reuse is rampant and anyone who holds credentials has a duty of care to protect them.
53.
▲
by
troyhunt
14y ago
I totally agree, which of course is why they shouldn't be commenting on it! But regardless of the Customer Care's Twitter account, their messaging is consistent with the misunderstandings demonstrated throughout the website.
54.
▲
Lessons in website security anti-patterns by Tesco
(troyhunt.com)
352 points
by
troyhunt
14y ago
|
118 comments
55.
▲
Stronger password hashing in .NET with Microsoft's universal providers
(troyhunt.com)
1 points
by
troyhunt
14y ago
|
0 comments
56.
▲
by
troyhunt
14y ago
Yeah, but statistically even the loyal sausage dog would have a better than average chance of having moved on since the ASP launch! (10 years ago avg age would have been < 10 years)
57.
▲
by
troyhunt
14y ago
Actually, I think it's very clear there were just a lot of bad dev practices happening across the different technologies. Classic ASP on Impact Data, PHP on the main Billabong site and current day .NET on the store. Clearly bad things were
58.
▲
by
troyhunt
14y ago
Quite right, and I did refer to that, the point was that if you can't get simple things like these right (among others referred to), is it any surprise that a major breach occurs?
59.
▲
Here’s why we keep getting hacked – clear and present Billabong failures
(troyhunt.com)
155 points
by
troyhunt
14y ago
|
47 comments
60.
▲
by
troyhunt
14y ago
Yahoo! have confirmed the breach: http://news.cnet.com/8301-1009_3-57471178-83/yahoos-password...
More ›