Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_slih
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
_slih
5mo ago
signal did everything right on their end. encrypted push, content only shown if the user opts in. the weak link is iOS caching decrypted notification content in an unencrypted sqlite database that survives app deletion. the 'e2e'
2.
▲
by
_slih
5mo ago
same threat group hit filezilla last month with a fake domain. this time they didn't even need a fake domain, they compromised the real one's api layer. the attack is evolving from 'trick users into visiting the wrong site&#x
3.
▲
by
_slih
5mo ago
flock says customers own their data and control access. but their national lookup tool means 5,000+ agencies can search your city's cameras without your city's permission. 'customer-owned data' that anyone in the network
4.
▲
by
_slih
5mo ago
5,000 flock networks searched per query. cities that approved cameras for local burglary investigations are now having their data searched for immigration enforcement by fish and wildlife cops in florida. nobody voted for that.
5.
▲
by
_slih
6mo ago
yo, livekit acts as independent controller for call detail records under their own dpa. that means proton's privacy constraints don't even apply to that data. livekit can hand call records to us law enforcement without notifying p
6.
▲
by
_slih
6mo ago
palantir is a US company subject to the cloud act. patient data from 123 hospital trusts is now one mlat request away from us law enforcement regardless of where the servers sit.
7.
▲
by
_slih
6mo ago
the attestation is a real step forward for silicon provenance. the problem is your board, firmware, bmc, and nic still come through the same opaque supply chain as before. the processor is rarely where a hardware implant goes.
8.
▲
by
_slih
6mo ago
rpki adoption is the new ipv6 adoption. it looks great until you realize it only validates who owns the prefix, not the path to get there lol
9.
▲
by
_slih
6mo ago
the privacy manifest declares no data collected while the app sends your device model, ip address, session count, and a persistent tracking id to onesignal on every launch. false attestation anyone?
10.
▲
by
_slih
6mo ago
I think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire key management chain into a legal liability.
11.
▲
by
_slih
6mo ago
Forget the Iran attribution for a second. The FBI director's personal email was already in leaked credential databases from prior breaches.
12.
▲
by
_slih
6mo ago
FBI director was asked point blank if he'd commit to not buying Americans' location data. he said no.
13.
▲
by
_slih
6mo ago
two verdicts in two days, $375m in new mexico and $6m in LA. meta's insurance company already got cleared of covering these claims. if even ten more states follow, meta is paying out of pocket at a scale that actually shows up on the b
14.
▲
by
_slih
6mo ago
the fine is 0.6% of last year's profit. the lobbying budget probably costs more.
15.
▲
by
_slih
6mo ago
cloud providers design for software failures and network partitions. they do not design for drone strikes. the redundancy model assumes your availability zones won't get hit by the same military operation.
16.
▲
by
_slih
6mo ago
the ban covers all foreign-made consumer routers but practically every router is manufactured abroad, even the ones sold by American companies. the only domestic exception is Starlink, iirc
17.
▲
by
_slih
6mo ago
hack back assumes you know who hit you. attribution in cyber is hard enough for the NSA
18.
▲
by
_slih
6mo ago
second breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.
19.
▲
by
_slih
6mo ago
telling users on a cybersecurity website to click past certificate warnings is training them to do the exact thing every security awareness program says never to do. DISA runs the security standards that every defense contractor has to comp
20.
▲
by
_slih
6mo ago
the supply chain for offensive tooling is now indistinguishable from the supply chain for malware. take care of your security team!
21.
▲
by
_slih
6mo ago
the product got deployed across the government while the security review was still in progress. then fedramp approved it because it was already everywhere. seem like i saw a lobbyist or two with a broom sweeping something under a rug...
22.
▲
by
_slih
6mo ago
Thanks for the heads up. The links are in the text body. Demo dashboards here: https://awsight.com/demo.html and main site: https://awsight.com . I posted as a text submission so I could include context.
23.
▲
by
_slih
6mo ago
A few technical details: checks run via scheduled API queries across your services. No agents or collectors run in your account. The cross-account role is scoped to read/list calls only. Findings are stored historically so you can see
24.
▲
Show HN: AWSight: flat-rate AWS security checks mapped to CIS/NIST
1 points
by
_slih
6mo ago
|
3 comments
25.
▲
by
_slih
6mo ago
three states passing the same template bill in three months isn't organic legislation
26.
▲
by
_slih
6mo ago
the infrastructure outlasts whoever is in office. that's the part that doesn't get repealed.
27.
▲
by
_slih
6mo ago
the post getting mass-reported off reddit twice is the best evidence that the research is accurate lol
28.
▲
by
_slih
6mo ago
the timeline for all of this is not a coincidence. meta spent millions lobbying for age verification laws that require content scanning. hard to scan content that's encrypted.
29.
▲
by
_slih
6mo ago
"no actual age verification" is doing a lot of work in these defenses
30.
▲
by
_slih
6mo ago
every age verification mandate creates another one of these databases. billion records, no password, plain text.
More ›