Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
4mnt
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Keycloak unauthenticated account takeover via reset-credentials flow bypass
(github.com)
4 points
by
4mnt
28d ago
|
1 comments
2.
▲
by
4mnt
6y ago
The thread is in the body of the tweet. Here is the start: https://twitter.com/axi0mX/status/1313620262768635904
3.
▲
New NextCry Ransomware Encrypts Data on NextCloud Linux Servers
(bleepingcomputer.com)
6 points
by
4mnt
7y ago
|
1 comments
4.
▲
by
4mnt
9y ago
They decided to skip a year for some rooms to allow other interesting topics to have a room. https://twitter.com/fosdem/status/915543798763139074
5.
▲
by
4mnt
9y ago
Sure, LetsEncrypt can issue certificates for that domain. If you have a webserver you control that runs on port 80, you can use Certbot[1] to get a certificate for that domain. [1]: https://certbot.eff.org/
6.
▲
by
4mnt
11y ago
> If the cookie is set through HTTPS, the browser won't send it when loading HTTP resources. If the cookie is set through HTTPS and does not have the Secure flag set, the browser will happily send it along when loading HTTP resource
7.
▲
by
4mnt
11y ago
It seems it is fixed now,. $2,506 last 24 hrs ($104.41 / hr) Seems somewhat more reasonable
8.
▲
by
4mnt
11y ago
If you read the article, you would know that it is a terminal emulator written in javascript that gives you access to the computer the webserver runs on. There is no change to the browser itself at all, just plain javascript that shows a te
9.
▲
by
4mnt
11y ago
> In the case of md5, creating a pair of inputs with the same hash is easier than creating another input with the same hash as something else which you didn't yourself generate. This is the case with all instances of seeking a coll
10.
▲
Poisonous MD5 – Wolves Among the Sheep
(blog.silentsignal.eu)
110 points
by
4mnt
11y ago
|
52 comments
11.
▲
by
4mnt
11y ago
You do not ask for an extension of an SSL certificate, but you get a new one signed with another expiry date. I think it is theoretically possible to change the expiration date, and ask a certification authority to sign that new certificate
12.
▲
by
4mnt
12y ago
It might be a good idea to delete this thread since this bug is in the openssl client, which is not as widely used as the library.
13.
▲
by
4mnt
12y ago
The site cannot detect that you have an extra root certificate lying around on your computer. If you visit the website without the Superfish program installed, you just evaluate the SSL settings of your browser.
14.
▲
by
4mnt
12y ago
That is: MITM SSH connections to these devices without getting any warning. Of course you first have to get in a position to MITM the person who connects to these devices.
15.
▲
by
4mnt
12y ago
Yep, she published too soon. http://www.frsag.org/pipermail/frsag/2015-January/005727.htm...
16.
▲
by
4mnt
12y ago
That would be very interesting to watch (albeit a bit annoying for the people trying to chat)
17.
▲
by
4mnt
12y ago
Function Oriented (~ OO: Object Oriented)
18.
▲
by
4mnt
12y ago
Snowden was not introduced until after OP posted this link
19.
▲
by
4mnt
12y ago
> The second is because there isn't any way I know of to have Chrome start in clean mode (with no bookmarks, etc. from personal use). Chrome has user profiles [1], which are even easier to use than what Firefox uses. [1]: chrome:&#x
20.
▲
by
4mnt
12y ago
Of course not. It is a wireless keyboard :)
21.
▲
by
4mnt
12y ago
Yes they are. But only after they get dropped from the reflog, after 30 days by default.
22.
▲
by
4mnt
12y ago
I'm pretty sure $login can be set to true/false somewhere on top of the file as 'configuration'. Only it gets overwritten by the call to extract(). It was not meant to be user input
23.
▲
by
4mnt
12y ago
Nope, the cert is valid till 2016, but the root certificate is not trusted.
24.
▲
by
4mnt
12y ago
No sound, as it does not travel far enough and is easily disrupted by any other sounds in the area of the detector. I think it is just waiting for input of an electro-magnetical wave, then timestamps it and sends it to the server. The serve
25.
▲
by
4mnt
12y ago
With small receivers that are run by volunteers http://www.blitzortung.org/Webpages/index.php?lang=en&page=3
26.
▲
by
4mnt
12y ago
That is basically the default of git push
27.
▲
“Free” as in “we own your IP”
(brendangregg.com)
61 points
by
4mnt
12y ago
|
21 comments
28.
▲
by
4mnt
12y ago
Do you mean a directory name cannot contain a hyphen (-)? Or perhaps you did mean a slash (/)? I have never heard nor encountered about a package manager or filesystem that does not allow the use of hyphens.
29.
▲
by
4mnt
13y ago
Google has that too on the app page, right below the download button.
30.
▲
by
4mnt
13y ago
Why not just disclose it responsibly to github without using it on other people's accounts?
More ›