Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
EnFinlay
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
1.
▲
by
EnFinlay
5y ago
I know Gitlab takes security seriously and I think part of why we hear so much about it is because they're so transparent.
2.
▲
by
EnFinlay
5y ago
hacker101.com and join the community Discord. There's a ton of Bug Bounty hunting content on the internet. Plenty of room to explore and find your niche.
3.
▲
by
EnFinlay
7y ago
I can't find the article right now, but I remember reading an article many years ago on Wired about the Obama campaign and their use of targeting and "big data". Really interesting stuff about how they were buying TV spots an
4.
▲
by
EnFinlay
7y ago
Saying you want "authentic" vs "just like home" are very different to me. One implies value judgement, the other does not.
5.
▲
by
EnFinlay
7y ago
I'm having trouble articulating this, so bear with me. In general, having a Bug Bounty program is good. We can agree on that, right? Most Bug Bounty programs have a scope, and staying inside the scope is important to the business for
6.
▲
by
EnFinlay
7y ago
I'm not trying to defend Valve, I'm just surprised that everyone seems to be so upset about the ban.
7.
▲
by
EnFinlay
7y ago
I was responding to a comment that (I interpreted) to be talking in more general terms than the scope of the article.
8.
▲
by
EnFinlay
7y ago
Retailiated as in he was banned from their bug bounty program. The program with a scope that they went outside of. I think it's reasonable to be banned. Obviously it would be better if Valve fixed the issue and gave a (possibly reduced
9.
▲
by
EnFinlay
7y ago
And Valve has ever right to ban him from their program, right?
10.
▲
by
EnFinlay
7y ago
The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.
11.
▲
by
EnFinlay
7y ago
a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose
12.
▲
by
EnFinlay
7y ago
Might be easier to lay off everyone on that half-full 3rd floor and save money on your lease next cycle.
13.
▲
by
EnFinlay
7y ago
It's crazy to hear someone pull a scam like that and deny it's scam because they were working hard too.
14.
▲
by
EnFinlay
7y ago
I have no insight into the matter. My guess is that their traction and market dominance are far more fragile than you think. Because their drivers are contractors and not employees, they can't be forced to only work for Uber, so even t
15.
▲
by
EnFinlay
7y ago
I want to make sure that I understand your analogy. - The right to secure encryption is like the right to bear arms - Government mandated weakened encryption are like gun control - The victims of weak encryption (stolen data for example) ar
16.
▲
by
EnFinlay
7y ago
I don't think you need a conspiracy to get to a place where in aggregate the decisions of people in control create or perpetuate a poor underclass. Just like some companies make decisions for the benefit of the next quarter, rather tha
17.
▲
by
EnFinlay
7y ago
Sounds like the same destructive behaviour that is commonly referenced as the bad 10x developer.
18.
▲
by
EnFinlay
7y ago
This is a some next level bullshit > 3. 10x engineers laptop screen background color is typically black (they always change defaults). Their keyboard keys such as i, f, x are usually worn out than of a, s, and e (email senders).
19.
▲
by
EnFinlay
7y ago
I doubt you would get a positive reaction because listening to music isn't considered a problem. There might be a lot of reasons for that, one of them might be that most people don't sit and exclusively listen to music.
20.
▲
by
EnFinlay
7y ago
I think they're referring to actually cancelling the service, rather than unsubscribing.
21.
▲
by
EnFinlay
7y ago
The pithy way of saying it is "Engineering is making something with $1 that any fool could make with $2"
22.
▲
by
EnFinlay
7y ago
- Many convention talks are really good and are too many to list - OWASP - zseano - hackerone - Bugcrowd (Jason Haddix's stuff is a pretty important pillar) - OWASP - DarkOperator - Absolute AppSec - KacperSzureEN - PwnFunction - LiveO
23.
▲
by
EnFinlay
7y ago
Too many to count.
24.
▲
by
EnFinlay
7y ago
I would say yes, since "secure" is a spectrum and there's nothing about a YouTube video that means the information is lower quality or less valuable than any other source.
25.
▲
by
EnFinlay
7y ago
There are thousands of hours of excellent cybersecurity content hosted on YouTube. The possibility of losing this wealth of information and history is shocking to me. Time to start the archive effort. And to finally appreciate what so many
26.
▲
by
EnFinlay
7y ago
I'm positive they are more "developer" than "engineer".
27.
▲
by
EnFinlay
7y ago
How the technology is viewed isn't the question, the question is how to most ethically administer this technology at the moment, with the medical interventions that are possible/reasonable.
28.
▲
by
EnFinlay
7y ago
As far as I can tell, jokes are an important method of communication. There are times where they are light-hearted, or just part of the culture, but there are other times (where there is, say, one person in a position of authority, making t
29.
▲
by
EnFinlay
7y ago
That's my perception of all phones, iPhones included.
30.
▲
by
EnFinlay
7y ago
> A dev posting their own content for once should be some of the most welcomed content. It's usually accompanied by Q&A and insights into the design process, the rare opportunity to actually talk to the creator of a game on that
More ›