Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tsujamin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
181.
▲
by
tsujamin
4y ago
Cool write up, reminds me of a .net app I had to RE a few years ago which used a custom bytecode/VM for sensitive functions, such as some string crypt/obfuscate operations which I was trying to grok. Giant pain in the ass. …until
182.
▲
by
tsujamin
4y ago
I absolutely _loved_ mailcow. Worked out of the box way better than my hand rolled solution, and ended up using it for some small orgs too. Thanks for all your work on it!
183.
▲
by
tsujamin
4y ago
+1 for DXO, I’m not a big photographer but it’s good for sorting through and developing the RAWs of shots that initially come out poorly
184.
▲
by
tsujamin
4y ago
“When one begins to live by habit and by quotation, one has begun to stop living.”
185.
▲
by
tsujamin
4y ago
So many times on engagement I’ve opened files that looked like canaries but we’re just dumb jokes between sysadmins (is_rsa containing “hah got you” for instance) A dozen canary tokens will probably get your security detection program alot
186.
▲
by
tsujamin
4y ago
The conversations between Maughm and his characters in The Razors Edge are chefs kiss
187.
▲
by
tsujamin
4y ago
His recent posts about over the horizon radar are a super good read: https://computer.rip/2022-12-04-over-the-horizon-radar-pt-II...
188.
▲
by
tsujamin
4y ago
Whenever I see this pop up I also think of Steve, how randomly the stuff I did on JikesRVM with him has weirdly come back up in my career and also how I royally stuffed up my honours thesis :)
189.
▲
by
tsujamin
4y ago
Most MDM persists a wipe unless they’re de-enrolled by serial or other unique identifier (e.g. computrace, Windows Autopilot although it’s a bit weird, apple too I think) Computrace/absolute is a literal rootkit
190.
▲
by
tsujamin
4y ago
Echoing a response to a nearly invisible comment above, why did make this comment? These sorts of articles are a weird attractor on this site…
191.
▲
by
tsujamin
4y ago
It’s probably a lot less time consuming and risky than “going to market”. Reminds me of a panel at DEFCON this year that dealt with the fact this stuff is increasingly covered under export restrictions and a lot of the ecosystem is trust ba
192.
▲
by
tsujamin
4y ago
iCloud Mail with Custom Domains if you’re on iOS et al. Alternatively I had a one seat Exchange Online license for a few years that went pretty well reputation and anti spam wise
193.
▲
by
tsujamin
4y ago
Developer adoption operators? As horrible as it is sometimes it’s simpler to build and ship android apps to app The models and sub distrust than using existing Linux frameworks
194.
▲
by
tsujamin
4y ago
Its very cool, some thoughts: * They have support in there to get an API client that auths using your nodekey - not sure what endpoints it can hit but makes for some interesting cases like updating ACLs maybe * You can use it as an ex
195.
▲
by
tsujamin
4y ago
Something else interesting they're doing is their tsnet package, which lets you join your process to the tailnet and bind tcp listeners/connect to TCP services via their tailnet IP or subnet. I'm writing some stuff using th
196.
▲
by
tsujamin
4y ago
looool so I’m literally working on something like funnel (built on their tsnet package) as I type except for generic TCP/UDP listeners. This explains so much of what I’ve seen added to their codebase recently
197.
▲
by
tsujamin
4y ago
> a falcon heavy costs $97 million, and would enable detection of threats we'd be otherwise blind to if we stuck to terrestrial observations. What's the cost of a space-based detection platform compared to a ground based one, a
198.
▲
by
tsujamin
4y ago
Don't let the [victim memory-spaces] win!
199.
▲
by
tsujamin
4y ago
I've spent my last few weeks writing a platform in Go. Buffer management/strong typing is definitely an improvement on C. Shame about tall the null-pointer-exceptions though :') In all seriousness though it does seem to mitig
200.
▲
by
tsujamin
4y ago
The Australian counterpart to NCSC does similar with its CHIPs program ( https://www.cyber.gov.au/acsc/view-all-content/news/acscncsc... )
201.
▲
by
tsujamin
4y ago
Imagine what it would be worth if it did everything it does but with just Musk employed
202.
▲
by
tsujamin
4y ago
not sure if incident responders will be cheering or crying for less Friday dumpster fire causing tweets :’) but yeah it’s going to sting r badly…
203.
▲
Australian Cyber Security Centre Annual Cyber Threat Report (2022)
(cyber.gov.au)
2 points
by
tsujamin
4y ago
|
0 comments
204.
▲
by
tsujamin
4y ago
+1 for systemd-networkd too: it let me declaratively describe some netns/ipvlan interfacing the other day that netplan et al simply couldn't. It could use with some more netns awareness but its pretty great at the current stage
205.
▲
So long and thanks for all the bits (Ian Levy, NCSC)
(ncsc.gov.uk)
5 points
by
tsujamin
4y ago
|
0 comments
206.
▲
by
tsujamin
4y ago
“Suffering occurs when your ideas about how things ought to be don’t match how they really are.” I started reading Hardcore Zen out of interest after seeing it recommended in a twitter thread. Still deciding about the book but this one stuc
207.
▲
by
tsujamin
4y ago
> From power user perspective iPhone is like Windows and Android like Linux. A widely adopted platform/operating system with every improving security fundamentals versus a kernel with numerous spins each awaiting their day on the de
208.
▲
by
tsujamin
4y ago
I’m sure there’s no risk or liability letting a gpt3 bot loose to provide medical advice /s
209.
▲
by
tsujamin
4y ago
*deep existential crisis intensifies*
210.
▲
by
tsujamin
4y ago
Hopper is my go-to for light reveng or macOS binaries, Ghidra for Windows mainly because you can refine your typing until the decompiler window becomes very readable. as an aside - When I was taught Ghidra the trainer said "in IDA you
More ›