Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Bnshsysjab
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
Bnshsysjab
4y ago
How does this work on a technical level? What stops an app bypassing the firewall?
2.
▲
by
Bnshsysjab
6y ago
Because TVs rapidly get outdated and die. If nothing else the 2inch thick bezels are an eye sore. Just because I don’t care about 4K doesn’t mean I don’t care about image quality. I’d prefer 1080p@60 over 4k@30.
3.
▲
by
Bnshsysjab
6y ago
720 to 4K is not the same as 480p to 720. The latter is far more noticeable. Most of the world hasn’t moved to 4K, I don’t see a huge amount of value in it personally.
4.
▲
by
Bnshsysjab
6y ago
You’re missing the point. Most people don’t want to download a video instead of streaming directly, which is a far lower barrier than procuring equipment, dealing with compatibility issues, doing system updates etc. I doubt competitive game
5.
▲
by
Bnshsysjab
6y ago
That’s a fair point.
6.
▲
by
Bnshsysjab
6y ago
As a side note, and I’ll create a separate thread: say my host is comprised by super sophisticated malware, aside from a reformat what other sanitisation practices can I do? Can I ever trust the hardware again? I don’t think we’re at a poin
7.
▲
by
Bnshsysjab
6y ago
If you wanna go a little bit more paranoid, use a dedicated host to virtualise those machines and connect to the host via RDP/whatever, that should create another layer of safety.
8.
▲
by
Bnshsysjab
6y ago
No the risk is that somebody has decided to disregard security and general security process and create shadow IT, which if left unchecked will create massive problems within the organisation long term. If the culture is to disregard securit
9.
▲
by
Bnshsysjab
6y ago
Nah you pull it offline and tell them to follow correct procurement and development practices. If your development teams aren’t talking to your security teams you have bigger problems than Wordpress.
10.
▲
by
Bnshsysjab
6y ago
You need to tweet your view of security requirements if you want to provide IT functions to users. Yes they are a nice to have, yes the cost of a data breach either to you or the user are highly damaging. There’s nothing stopping most indus
11.
▲
by
Bnshsysjab
6y ago
See comment on parent.
12.
▲
by
Bnshsysjab
6y ago
I think ‘stop wasting time on dumb stuff and focus on actual security’ is a good take home for the HN crowd. Time and money is finite, so spend it wisely.
13.
▲
by
Bnshsysjab
6y ago
No it’s not recommending snake oil and telling them to do things properly instead I don’t. Care if that makes the security industry dry up, my only hope is that if it does the snake oil salespeople die with it.
14.
▲
by
Bnshsysjab
6y ago
I’ll ignore your condescending dribble but: > Let’s also not forget that there is good money to be made off consulting for those companies that are “fucked” Where the hell are your ethics?
15.
▲
by
Bnshsysjab
6y ago
Or maybe I’m just not scraping bottom of the barrel when it comes to security assessments. If the software is at that point the organisation is well and truly fucked, waf or not.
16.
▲
by
Bnshsysjab
6y ago
What if the payload is ‘a,b’ which renders as Select a, b from foo;
17.
▲
by
Bnshsysjab
6y ago
Right but I’m the context of antivirus you’re executing unconstrained data in an unconstrained environment, in appsec you can handle data correctly rather than rely on a third party product that can’t contextualise or assess the impact of a
18.
▲
by
Bnshsysjab
6y ago
I hate these kind of defenses. If your application is vulnerable to sqli, select is one of many tools an attacker can use and you’re pretty much screwed anyway. Instead, use sane tooling, like modern ORMs and parameter izers, with some data
19.
▲
by
Bnshsysjab
6y ago
Also be sure to check out the super Mario world flappy bird code injection: https://youtu.be/hB6eY73sLV0
20.
▲
by
Bnshsysjab
6y ago
2037 is a potential overflow, I believe. I imagine only pre 2000 systems would likely be affected.
21.
▲
by
Bnshsysjab
6y ago
I’d love $myhandle.sucks but alas the domain registrar decided to charge extortion rates in the hopes that large companies register their own domain to prevent hate sites >_>
22.
▲
by
Bnshsysjab
6y ago
Esoteric hardware won’t work first, then maybe browsers. I’d estimate 15 years. I was not using pulse or systemd until early this year, having used Linux since 2008 thats a pretty decent lifespan. It was finally required for Bluetooth headp
23.
▲
by
Bnshsysjab
6y ago
I’m not an X hater but just know you’ve given that server access to your display socket which is effectively remote command execution. In most cases this could be solved with a good web user interface, but you can rest assured X won’t be de
24.
▲
by
Bnshsysjab
6y ago
The beauty of public key cryptography is they don’t need to hold your private key, ever :)
25.
▲
by
Bnshsysjab
6y ago
I regularly wonder why we don’t have some form of physical verification token which signs things with our identity, the whole system is broken in that regard.
26.
▲
by
Bnshsysjab
6y ago
Yeah but your hardware requirements are driven by software bloat.
27.
▲
by
Bnshsysjab
6y ago
I’ve recently tried to pickup Go having coded python since 2007. I find the ideologies behind the language awkward, particularly explicit error object returns, but ultimately I feel upset with what boils down to ‘it’s not python’ Am I desti
28.
▲
by
Bnshsysjab
6y ago
I generally don’t try and engage in such conversations. In the case of matrix, terrorism existed long before its existence and other encrypted services were available. Unless you block them all, terrorists will just follow the path of least
29.
▲
by
Bnshsysjab
6y ago
Based on that logic we should ban all forms of crypto and just live in clear text. It won’t stop the boogeymen, but it’ll make us feel safer.
30.
▲
by
Bnshsysjab
6y ago
100% of terrorists actively consume water on a regular basis, too.
More ›