Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Shamiq
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Shamiq
9y ago
That's neat -- similar to a short squeeze.
2.
▲
by
Shamiq
9y ago
Yea, I'm thinking about cases similar to HTTP parameter pollution, and what the program expectations are. You'd be right to argue environment variables should not be user controlled. :)
3.
▲
by
Shamiq
9y ago
Will need to double check some machines to make sure these two don't bite me: On Unix systems the environment variables SSL_CERT_FILE and SSL_CERT_DIR can now be used to override the system default locations for the SSL certificate fil
4.
▲
by
Shamiq
9y ago
https://www.udacity.com/start-mentoring
5.
▲
by
Shamiq
9y ago
Not that far off: https://en.wikipedia.org/wiki/Life_expectancy#/media/File:Li...
6.
▲
by
Shamiq
9y ago
triplebyte mentions taking a particular problem from CtCI and solving it within 30min on a whiteboard (pen/paper, plaintext editor).
7.
▲
by
Shamiq
9y ago
The email address field in your user form isn't public. you need to add it to text in your description.
8.
▲
by
Shamiq
10y ago
dang, this is excellent. thank you so much :)
9.
▲
by
Shamiq
10y ago
oh, I scrolled down and only saw the purchase option.
10.
▲
by
Shamiq
10y ago
I don't have access to the full article, but the premise is interesting. at what transaction volume would I be better of running my own fgpa hardware?
11.
▲
by
Shamiq
10y ago
Awesome project! This is a step in the right direction for better access management.
12.
▲
by
Shamiq
10y ago
hah -- i found the same result with gofmt, golint, and go vet
13.
▲
by
Shamiq
10y ago
That could be a decent hack to get started. Ideally, I'd like for it to be a feature of hackerone et al, assuming security@ as a service providers become the point of interaction with the external security community.
14.
▲
by
Shamiq
10y ago
oh, i know -- i got spoiled working at matasano where we'd usually get the first crack.
15.
▲
by
Shamiq
10y ago
I would love a Marauder's Map for bug bounty programs: Show me who is working on what, where they're finding bugs, and help me identify where I can most efficiently spend my time. Lots of 'feel bads' if I report a bug th
16.
▲
by
Shamiq
11y ago
I'm color blind, and the charts you use are unintelligible to me.
17.
▲
by
Shamiq
11y ago
Congrats on the launch! Why the choice to build on Kubernetes?
18.
▲
by
Shamiq
11y ago
Just stick it up on medium for the time being. you can always figure out a 'real' blog later :). Alternative is using github pages with something like jekyll.
19.
▲
by
Shamiq
11y ago
You've got a point there, but I'd ask why not remove the packages that aren't being used? Here's some of the raw data about which system libraries are lagging in security patches: liblwres90 1:9.9.5.dfsg-3ubuntu0.6
20.
▲
Pain in the PaaS: The Problem of Lagging Security Updates at Heroku
(patchworksecurity.com)
4 points
by
Shamiq
11y ago
|
2 comments
21.
▲
by
Shamiq
11y ago
Cool idea -- I'll go get the golf clubs! We'd love to be at the point where Patchwork notifications are ahead of public releases, and get you patched before the vulnerability is widely exploited. In fact, one of the crazy ideas we
22.
▲
by
Shamiq
11y ago
Sure thing! The service pivots around machines as it's core pilar. On a more fundamental level, we consider a machine to be the set of unique packages tracked together. So for your case, you'd spin up a pilot, run the script, then
23.
▲
by
Shamiq
11y ago
Great idea! We're looking to build out and extend a callback API so you can have it post data to whichever end point you want. Some integrations I've been toying with are: alerts in a slack channel, SMS notifications, push issues
24.
▲
by
Shamiq
11y ago
Halite, feel free to ping me about the volume pricing! shamiq@patchworksecurity.com
25.
▲
by
Shamiq
11y ago
Hi all! I’m Shamiq, ex-Matasano and co-founder of Patchwork Security. David and I built Patchwork as a devops tool to help manage Open Source Vulnerabilities. We want to drive the time between an available fix and patched infrastructure to
26.
▲
Show HN: Patchwork – Real-time notifications for OSS vulnerabilities
(patchworksecurity.com)
122 points
by
Shamiq
11y ago
|
49 comments
27.
▲
by
Shamiq
11y ago
Matt Krisiloff mentioned it'll be sent by EOD today: https://twitter.com/MattKrisiloff/status/633690502039121920
28.
▲
by
Shamiq
11y ago
submit a pull request? find the dev who wrote it and ask if you can help get it patched? file an bug? same thing as finding any other type of bug, really. Just avoid sounding like an ass and you might make traction. As a corollary: consider
29.
▲
by
Shamiq
11y ago
6500 videos -- 4.5 DAYS worth of video if every application stuck to exactly 1 minute each.
30.
▲
by
Shamiq
11y ago
that's so fucked. this sucks :<.
More ›