Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
LukasReschke
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
Sovereignty 2030: Nextcloud invests over €250M in digital sovereignty
(nextcloud.com)
1 points
by
LukasReschke
10mo ago
|
0 comments
2.
▲
Exploitable heap overflow in libgcrypt 1.9.0
(twitter.com)
4 points
by
LukasReschke
6y ago
|
0 comments
3.
▲
by
LukasReschke
6y ago
Earlier discussion from yesterday: https://news.ycombinator.com/item?id=25869798
4.
▲
by
LukasReschke
6y ago
> Most rewrites fails because the team rewriting is not the team that did the initial development. Looking at https://github.com/owncloud/core/graphs/contributors , most of the initial core contributors con
5.
▲
by
LukasReschke
6y ago
> Plus as far as I know neither ownCloud nor nextCloud went through a security audit This is inaccurate. Nextcloud does receive security audits and is in fact also used by quite some security-conscious organizations (to name a few: Germa
6.
▲
by
LukasReschke
6y ago
I've been working on an open-source Identity Access Management solution in the past few months: https://gatekeeper.page/en/ Gatekeeper aims to enable small and medium-sized enterprises to have their own on-premise
7.
▲
SOCKS5 and HTTP over Turn/Stun Proxy
(github.com)
1 points
by
LukasReschke
6y ago
|
0 comments
8.
▲
by
LukasReschke
6y ago
> So what do you think is going on in this piece (5 years old), where Alex Stamos characterizes the issue as "trivial and of little value"? I sadly wasn't there at the time, and Stamos post doesn't refer to it at all.
9.
▲
by
LukasReschke
6y ago
I'd advise anyone against trying that for a system not owned by them. (e.g., someone's else website) As soon as you do that, you venture into dangerous territory. Companies are required to investigate claims of breaches seriously
10.
▲
by
LukasReschke
6y ago
I was part of "big corp" for the past three years and was involved in many bug bounty reports. A reasonable claim like "I think this should be higher because XYZ" gets investigated and, if justified, higher bounties issu
11.
▲
by
LukasReschke
6y ago
How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first sounds quite clearly like extortion
12.
▲
by
LukasReschke
6y ago
Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in
13.
▲
by
LukasReschke
6y ago
> Companies always say they will investigate the full impact of a vulnerability when you follow the protocol they urge of "as soon as you find something, report it and don't try to escalate". But this is nearly impossible
14.
▲
by
LukasReschke
9y ago
Just as a remark, we run a bug bounty program at https://hackerone.com/nextcloud offering up to $5,000 for Remote Code Executions. If someone here feels challenged: We look forward to your reports. :)
15.
▲
German Parties and Ministries Vulnerable to Hacking Attacks
(spiegel.de)
4 points
by
LukasReschke
10y ago
|
0 comments
16.
▲
by
LukasReschke
10y ago
Fair enough, there is some kind of marketing-ishy statement in that. I give you that :-) But considering the security features that we include such as Same-Site Cookies, CSP using Nonces, etc. I don't think the statement is totally wro
17.
▲
by
LukasReschke
10y ago
We don't offer any PPA for the server repository ourselves. Mainly because we didn't had many good experience in the past with repositories. So what we're focusing on is providing an easy and reliable updater (just like Wordp
18.
▲
Nextcloud 11 sets new standard for security and scalability
(nextcloud.com)
18 points
by
LukasReschke
10y ago
|
7 comments
19.
▲
Nextcloud Box – a private cloud and IoT solution for home users
(insights.ubuntu.com)
14 points
by
LukasReschke
10y ago
|
1 comments
20.
▲
by
LukasReschke
10y ago
> Is it the locations services workaround thing? That's correct.
21.
▲
Introducing the Nextcloud bug bounty program
(nextcloud.com)
3 points
by
LukasReschke
10y ago
|
0 comments
22.
▲
by
LukasReschke
10y ago
I highly doubt that the planned features are related. Seems just to be a try to make the press release look less worse... Disclaimer: I quit ownCloud to work now at Nextcloud.
23.
▲
by
LukasReschke
10y ago
Happy to answer this. First of all: Makes using a specific programming language a software much less secure? Probably not. You can do mistakes in every programming language. But since a lot of software is written in PHP and there are also m
24.
▲
by
LukasReschke
10y ago
Good questions! Note, that I'm affilated with Nextcloud so obviously a bit biased. Only because a project is very transparent about security vulnerabilities does not necessarily mean it's inherently insecure. In fact, at ownCloud
25.
▲
by
LukasReschke
10y ago
Not in the way that you require it. But you can always file an issue or enhancement request :-) That said, we'll likely have Webcal support ( https://github.com/owncloud/calendar/pull/443 ), that way you c
26.
▲
by
LukasReschke
10y ago
Actually, I should add that to my CV "poached developer" ;-) - Lukas (Nextcloud'er - see also http://www.zdnet.com/article/owncloud-founder-forks-popular-... )
27.
▲
by
LukasReschke
10y ago
The impact is a different one though. In that scenario pointed by Hanno somebody needs to have access to the storage which already requires some kind of previous gained access. What could be done by an attacker then is to infect EXE files o
28.
▲
by
LukasReschke
10y ago
I'd like to point you to https://statuscode.ch/2015/09/ownCloud-security-development-... and make you aware of https://seacloud.cc/group/3/wiki/security-records.md and you shou
29.
▲
by
LukasReschke
10y ago
Fantastic idea! We have started a public discussion about this at https://help.nextcloud.com/t/should-we-adopt-c4/113/1 . You're more than welcome to join it as well :-)
30.
▲
by
LukasReschke
10y ago
We can't talk about this in detail yet but http://blog.jospoortvliet.com/2016/06/nextcloud-is-replacing... has some more information on what's upcoming. If you can understand German a very good in-depth
More ›