Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
werrett
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
Target says 40 million credit cards compromised in data breach
(washingtonpost.com)
1 points
by
werrett
13y ago
|
0 comments
62.
▲
by
werrett
13y ago
In case anyone is interested the primary source for the article is the following blog post (it is slightly buried): http://blog.spiderlabs.com/2013/12/look-what-i-found-moar-po...
63.
▲
by
werrett
13y ago
The source is this SpiderLabs blog post: http://blog.spiderlabs.com/2013/12/look-what-i-found-moar-po...
64.
▲
by
werrett
13y ago
Hong Kong is only part of China in the same sense Puerto Rico is part of the United States. If you are a citizen then you can hold a Hong Kong passport. The majority of the population is either Cantonese or Han Chinese in ethnicity (Han Chi
65.
▲
by
werrett
14y ago
Invariably all the researchers / organisations competing have developed their exploits well ahead of the event. The exploits are now pretty involved. I've linked to a blog post from the Chrome developers that details the exploit that won la
66.
▲
by
werrett
14y ago
Nope. If you read two paragraphs further: >Prime numbers, which are divisible only by themselves and one, have little mathematical importance. Yet the oddities have long fascinated amateur and professional mathematicians. Admittedly, ge
67.
▲
by
werrett
14y ago
Mind you if they keep up with the kick-arse-- volunteer --coding then they are ok with me.
68.
▲
by
werrett
14y ago
Not false I'm afraid. I use this issue to grab FileVault passwords from OSX boxes on a monthly basis. In combination with DMA access from the Firewire port it can be quite fun[1]. Although with Lion, you can't use DMA when the machine is lo
69.
▲
by
werrett
16y ago
Woah woah woah. Don't forget take into account the overheads in consulting. Just off the top of my head you'd need to think about winning each contract, paying taxes, holidays, health cover, professional indemnity, sick leave, misc business
70.
▲
by
werrett
16y ago
The money quote is: While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness o
71.
▲
by
werrett
16y ago
I've spilt out my admin and day-to-day accounts. I couldn't articulate why I thought it was a good idea but you've given me at least one!
72.
▲
by
werrett
16y ago
_On the other hand, note that some big shops, particularly in the big 4, offer huge discounts on consulting rates that they make up on audit works._ I'd be very surprised to see this in 2011. Giving discounts to ensure audit work was one of
73.
▲
by
werrett
16y ago
Think of it as just a big disk enclosure. You can either plug it into the back of an HP server or plonk it on the network by itself. Google has some good pictures: http://www.google.com/images?q=HP%20MSA%203000 HP's high-end 'ProLiant' ki
74.
▲
by
werrett
16y ago
... have never suffered a fatality since becoming a jet airline . It had quite a few fatalities during the pre-jet era. [1] One Qantas flight was even shot down by the Japanese in 1942! (Apologies for the pedantry) [1] http://en.wikipedia
75.
▲
by
werrett
16y ago
> I think the main problem with wave was that it wasn't > solving any problems it was just mashing up a lot > of features in to one application. Kinda sounds like Facebook to me. They seem to be handling growth / performance w
76.
▲
by
werrett
16y ago
Obviously the company and nature of a site will dictate whether leaking that information is considered a "flaw" and how bad a one. Depending on how user sessions are tracked, being able to predict other valid "user ids" based on your own is
77.
▲
by
werrett
16y ago
Was the genie ever in the bottle? That's not a rhetoric question. I generally wonder whether Finance has been consider to be anything other than self-serving.
78.
▲
by
werrett
16y ago
Security has been a focus of NaCl from the outset. It uses a sandbox security model built around a restricted set of "native code". The aim was to make NaCl apps verifiable from a security stand point. Chris Rohlf from Matasano did a great
79.
▲
by
werrett
16y ago
You amight be lucky enough to be near one of the public screenings of Objectified . A lot of them are free. http://www.objectifiedfilm.com/screenings/ I'm planning on heading to the one @ the Pratt Institute in Brooklyn on October 1.
80.
▲
by
werrett
16y ago
You're confounding peoples preference for usability (including portability ) with a preference for applications with low computational demands. If you could pack the "extreme gamer" capabilities of a Playstation or an Xbox into a format
81.
▲
by
werrett
16y ago
Ha, OK while it is slightly naff to do it I couldn't help but smile and pull this quote out of pg's essay: 11. Its daddy is in a pinch. Sun's business model is being undermined on two fronts. Cheap Intel processors, of the same type
82.
▲
by
werrett
16y ago
Yahoo went bad because a business person was put in charge? From my point of view I would say that is generally the rule rather the exception. Particularly for those firms wanting to go public. I'm going to defer to mixmax's quip about putt
83.
▲
by
werrett
16y ago
infarct - an area of dead tissue caused by a loss of blood supply; a localized necrosis. infarction - the process which causes an infarct. [1] I think you meant infraction but infarction works too. :) [1] htt
84.
▲
by
werrett
16y ago
That keynote idea rocks! I'm not designer, I wouldn't even class myself as a developer, but like everyone else I have a few web projects on the go. I've been searching for a low overhead way of getting a design mock-up down and your keynote
85.
▲
by
werrett
16y ago
To quote the announcement email which zacs posted earlier: This work was pursued independently of my duties as a HP Labs researcher, and without the knowledge of others. I made several unsuccessful attempts these past two years
86.
▲
by
werrett
16y ago
There you go, I stand corrected. Are you able to make requests between instances on non-public ports? As someone else pointed out Memcached infrastructure typically won't sit on your local webserver.
87.
▲
by
werrett
16y ago
I've come across unprotected Memcached deployments in a couple of pen-tests. On one engagement in particular someone poking Memcached would be able to (temporarily) increase their account balance and even access CC numbers from recent trans
88.
▲
by
werrett
16y ago
Having a bunch of awesome people increases the likelihood of it happening... I'd hazard a guess and say the non-repeatability comes down to the awesome bit. It is easy to label someone as awesome after coming out on the good sid
89.
▲
by
werrett
16y ago
Stephen Conroy seems to repeatedly fail at understanding the basic concepts involved in information security and the Internet. A recent quote from him at the launch of the "Cyber Security Awareness" week [1]: "There’s a staggering numbe
90.
▲
by
werrett
16y ago
And yet strangely enough, this doesn't refute the thrust plusbryan's comment if you take it as a reflection on Job's suite owning status or his general character.
More ›