Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zer01
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
61.
▲
by
zer01
9y ago
Oh very cool! I hadn't seen this. Good stuff! http://cdn.ebaumsworld.com/mediaFiles/picture/718392/8489089...
62.
▲
by
zer01
9y ago
> I would have to check regularly on CT logs You would indeed, which is part of the reason I released this service + libraries, so some enterprising developer can build a nice alerting service with it for folks just like you! > Do I t
63.
▲
by
zer01
9y ago
This is (imo) the most correct response to this query. The idea behind the CT lists is that browsers will flip into a "if it's no publicly identifiable, it's not valid" mode. The Coinbase Engineering blog actually just p
64.
▲
by
zer01
9y ago
Thanks! It's a few iterations in, and my designer ( http://www.jweiller.com/ ) was definitely responsible for the best looking parts!
65.
▲
by
zer01
9y ago
Yeah, it's interesting to see how certs are issued from the larger lists, since they tend to come in a deluge. This goes doubly for the cloudflare SNI certificates for their edge nodes!
66.
▲
by
zer01
9y ago
Hey folks, developer of CertStream here. You can read more about the motivations and implementation behind this project by visiting the announcement page ( https://medium.com/cali-dog-security/introducing-certstream-...
67.
▲
Show HN: CertStream – See SSL certs as they're issued in real time
(certstream.calidog.io)
142 points
by
zer01
9y ago
|
60 comments
68.
▲
Frida Codeshare: Building a Community of Giants
(medium.com)
1 points
by
zer01
9y ago
|
0 comments
69.
▲
by
zer01
9y ago
My favorite part about this documentation is actually the "Safety and correctness" section: https://html5-parser.readthedocs.io/en/latest/#safety-and-co... It shows that a good engineer took the time to
70.
▲
by
zer01
9y ago
I've long heralded this as some of the most attractive things about interpreted languages like Python and friends, and what really draws me to them in the first place. Take parsing a config file - it doesn't need to be fast unless
71.
▲
Retrieving, Storing and Querying 250M+ Certificates Like a Boss
(medium.com)
3 points
by
zer01
9y ago
|
0 comments
72.
▲
by
zer01
10y ago
This is absolutely it. I worked for 2 different start-ups and as an engineer it is damn near impossible to get tangible value out of equity options, yet they're being used as a mechanism not to pay market rate salaries with the notio
73.
▲
Introducing Cali Dog Security
(medium.com)
1 points
by
zer01
10y ago
|
0 comments
74.
▲
My infosec mantra
(medium.com)
1 points
by
zer01
10y ago
|
0 comments
75.
▲
WSStat – Websocket testing made beautiful
(github.com)
2 points
by
zer01
10y ago
|
0 comments
76.
▲
by
zer01
10y ago
...and that's 100% my experience with it too :-/ Awesome fuzzing engine but modifying it is not for the faint of heart.
77.
▲
by
zer01
10y ago
aoh also wrote the very awesome Radamsa fuzzing engine in it - https://github.com/aoh/radamsa
78.
▲
by
zer01
10y ago
Reminds me of one of my favorite commit logs from the LibreSSL project: "Do not feed RSA private key information to the random subsystem as entropy. It might be fed to a pluggable random subsystem…. What were they thinking?!" htt
79.
▲
by
zer01
11y ago
Or things like JSONP, CORS, and directory traversal :-/.
80.
▲
by
zer01
11y ago
My vote is for pure CSS. It's definitely possible, reasonably supported, and has 0% chance of doing something nefarious/malicious or introducing security issues.
81.
▲
by
zer01
11y ago
It should be possible to do all the collapsing and whatnot in pure CSS, which would leave your setup un-affected :)
82.
▲
by
zer01
11y ago
Came here to say the same thing. For people selling audio, having dubstep in the foreground seems completely pants-on-head.
83.
▲
by
zer01
11y ago
I have a feeling that we're going to wake up one day and there will be a legitimate breakthrough in quantum computing, leading to RSA no longer being a legitimate standard for security. My question to HN: Have any of you guys attempted
84.
▲
by
zer01
11y ago
I agree that depending on the context session fixation and login CSRFs can have actual security impact, but those cases are far and few between, so calling them a "serious flaw" feels a bit hyperbolic to me.
85.
▲
by
zer01
11y ago
As far as I can tell that particular vulnerability isn't a CSRF at all, it's an insecure JSONP endpoint[1]. The original author is mistaken. [1] http://homakov.blogspot.com/2013/02/are-you-sure-you-use-js
86.
▲
by
zer01
11y ago
Both Michal Zalewski[1] and Chris Evans[2] have commented on this, and I tend to agree with them. The actual implications for a CSRF like this are very minimal. [1] https://lcamtuf.blogspot.com/2010/10/http-cookies
87.
▲
by
zer01
11y ago
Agreed, I'm extremely glad this is being done in such a public fashion. It's important to have transparency about these issues.
88.
▲
by
zer01
11y ago
Signing code can only do so much. What Apple possesses is the somewhat unique ability to design a system that is actually secure by burning the key into the secure enclave and not allowing it to be updated. The only way someone would be a
89.
▲
by
zer01
11y ago
I agree that it would be upsetting if precedent was made, but I believe it is technically feasible to build a device whose keys are only known by an end user. The FBI is basically asking to go down legitimate update channels to brute forc
90.
▲
by
zer01
11y ago
Don't pigeon-hole yourself, most people just want a phone that can load facebook and is cheap. The number of people who care about security is definitely rising, but they're still in a fairly small minority. Also I'd venture
More ›