Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dublum
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
Dublum
11y ago
thank you!
2.
▲
by
Dublum
11y ago
The link appears dead with an access denied error, does anyone have a mirror?
3.
▲
by
Dublum
11y ago
it seems like maybe a more reasonable conclusion to draw is that the search feature is still being tested and tweaked quietly, and as such facebook's press office isn't hitting the gas as hard on getting it media attention as it i
4.
▲
by
Dublum
11y ago
the common theme for half of the top 10 seems to be physical proximity to the pentagon, fort meade, or both. UMD, GW, George Mason, Georgetown and Hopkins are all in driving distance.
5.
▲
by
Dublum
11y ago
I agree, it also does a lot of little things right that other platforms mess up. For example, it's the only platform that doesn't penalize a team's defense for scores that occur when they're not on the field (e.g. an in
6.
▲
by
Dublum
11y ago
right, that's the aspect they address, it's the same for sellers agents. The issue is that if the agent (recruiter) has the option to increase the salary by say, 2000$, they see a small percentage of that, maybe 100$ worth? If i
7.
▲
by
Dublum
11y ago
With regards to your last point, it's true that the recruiter and candidate's objectives are loosely aligned, but it plays out a lot like the relationship between a real estate agent and client in practice, in which the best deals
8.
▲
by
Dublum
11y ago
reading between the lines, it seems like they may have cause to believe fitbit induced the employees to grab that information before leaving. If that's the case then the case against fitbit makes more sense
9.
▲
by
Dublum
11y ago
I enjoyed this part in particular: Conley made the most colorful remarks of the day, including saying that he didn’t believe technical experts who said building backdoors is impossible. “Did John Kennedy say we couldn’t go to the moon?” Con
10.
▲
by
Dublum
11y ago
Aspect Security - Application Penetration Testers https://www.aspectsecurity.com We're looking for people with application security skills to join our team. If you've been doing security for a while, or you're a
11.
▲
by
Dublum
12y ago
yes, though it's probably worth noting that a video of their CEO talking about it is probably pretty hard to fake
12.
▲
by
Dublum
12y ago
FYI, to reply directly to a comment, hit the "reply" link right below it, rather than typing into the "add comment" box at the top. It makes the thread more readable that way
13.
▲
by
Dublum
12y ago
An aspect of this no one is touching on is the mechanism for it. If it's done digitally, securing the process sufficiently would be nigh impossible. I had an instructor in an application security course who said "the moment we h
14.
▲
by
Dublum
12y ago
Title is slightly misleading in that that's only the REPORTED losses. I'd venture to guess that the actual numbers are significantly higher. A lot of these go unreported due to embarassment, etc.
15.
▲
by
Dublum
12y ago
Except TPB doesn't actually host the leak, all they do is index the .torrent files, so if it's going to leak, it'll leak, and another tracker will have a link to it. The takedown and the DDoS came pretty close to each other,
16.
▲
by
Dublum
12y ago
If they're going to insist on binding ID to account, it seems like the simplest way to do it would be just to submit the ID as an additional parameter in the login POST request and associate it as a single transaction, but again, using
17.
▲
by
Dublum
12y ago
Right? I'm also curious about the fix. The vulnerability he describes is most obviously that they fail to associate the token you get after login with an actual account, so you can re-use that token to bind an arbitrary account, but
18.
▲
by
Dublum
12y ago
Lots of ways. They're actually relatively cheap to buy if you're sufficiently motivated. This might be of interest to you: http://krebsonsecurity.com/2014/10/id-theft-service-customer...
19.
▲
by
Dublum
12y ago
It makes it more secure, but not fully. If the password hashes ever got dumped via other means, the effort required to brute force those hashes (even salted) would still be far less than you want it to be.
20.
▲
by
Dublum
12y ago
you can check a hash without uploading the file in question. VT only stores a set of results if it has seen the actual file, not if a hash is checked against it. This is why, when doing incident response, a lot of people suggest not uploa
21.
▲
by
Dublum
12y ago
This is all true. There exist essentially blackhat versions of virustotal that don't submit the samples, and don't have a feed delay that are pretty popular among the virus writing community. One of the ways that virustotal IS us