Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ainsleyb
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
DevSec: Empowering DevOps with Security
(tinfoilsecurity.com)
2 points
by
ainsleyb
12y ago
|
0 comments
2.
▲
by
ainsleyb
13y ago
That's awesome. We used OpenVPN because that's what we were familiar with, but your L2TP script looks great. Would you mind if we tried to integrated that at some point?
3.
▲
North Korean ship seized in Panama - carrying weapons from Cuba
(nytimes.com)
3 points
by
ainsleyb
13y ago
|
0 comments
4.
▲
First ever web security add-on for Heroku
(tinfoilsecurity.com)
4 points
by
ainsleyb
13y ago
|
0 comments
5.
▲
by
ainsleyb
13y ago
There are a number of ways: malware, browser extensions, man in the middling, etc. SQLi would have been a better example than XSS, but there are definitely ways in which XSS can still be harmful if thrown in a cookie. If you wanted a persis
6.
▲
Hackers Think Cookies Are Tasty, Too
(blog.tinfoilsecurity.com)
13 points
by
ainsleyb
13y ago
|
12 comments
7.
▲
by
ainsleyb
13y ago
Flying cars DO exist! :) http://www.terrafugia.com/
8.
▲
by
ainsleyb
14y ago
No problem at all! We may very well start crawling your advisory DB for our own mailing list, which isn't limited to just Ruby, to be fair. ;) It's always good to have more eyes on security issues - Ruby or not - and keeping the community i
9.
▲
Rails Vulnerability Compilation
(blog.tinfoilsecurity.com)
46 points
by
ainsleyb
14y ago
|
5 comments
10.
▲
by
ainsleyb
14y ago
This is an interesting take. For us, it's not about age, but about personality. We have a financial controller who is 20 years older than everyone else on the team and we'd bring her on full-time in a heartbeat if we needed a full-time cont
11.
▲
by
ainsleyb
14y ago
As a founder your job is to take the high road as much as possible while still pushing through the strengths of your company. It seems pretty obvious that NYT won't be changing their opinion, and maybe even reached out to Musk to confirm th
12.
▲
Facebook phishing scam: free Southwest flights
(blog.tinfoilsecurity.com)
8 points
by
ainsleyb
14y ago
|
0 comments
13.
▲
by
ainsleyb
14y ago
Sorry about the confusion. If you run a scan from our homepage, you're actually looking for a lot more than just the YAML vulnerability (XSS, Mixed Resource, etc.) as our product isn't limited to just the YAML vulnerability. If you run the
14.
▲
by
ainsleyb
14y ago
There are other workarounds, too. You could disable XML parameter parsing, for example (as seen here: https://groups.google.com/forum/?fromgroups=#!topic/rubyonra... ). Thus, you might be running an old version, but still actually be safe
15.
▲
by
ainsleyb
14y ago
I've posted a little bit more on our blog at: http://blog.tinfoilsecurity.com/use-rails-check-yourself-for...
16.
▲
by
ainsleyb
14y ago
Mind if we copy that verbatim? :)
17.
▲
Zero Day MySQL Buffer Overflow
(isc.sans.edu)
1 points
by
ainsleyb
14y ago
|
0 comments
18.
▲
by
ainsleyb
14y ago
We're actually offering free web security, too: http://news.ycombinator.com/item?id=4792073 :)
19.
▲
by
ainsleyb
14y ago
Love what Mixpanel is doing, so we'd like to jump on the bandwagon. Offering our $59 Basic plan for free for life, and 50% off all other plans. Happy to keep startups secure :) Email your YC rejection letter to founders@tinfoilsecurity.com
20.
▲
by
ainsleyb
14y ago
Try http://www.youtube.com/playlist?list=ELdlNqFzO2slw&featu...
21.
▲
by
ainsleyb
14y ago
The first episode is available for free on iTunes: https://itunes.apple.com/us/tv-season/start-ups-silicon-vall... It's a travesty, and puts female entrepreneurs in a poor light, pitting them against each other and making them look petty.
22.
▲
Top Army General Demoted For Spending Taxpayer Money On A Lavish Lifestyle
(businessinsider.com)
4 points
by
ainsleyb
14y ago
|
0 comments
23.
▲
by
ainsleyb
14y ago
This looks a lot like BugHerd ( http://www.bugherd.com ). Might be worth looking at what they do?
24.
▲
by
ainsleyb
14y ago
Seems awesome - like a GUI for git-flow. What is the pricing for this? Seems there's a free download at the top, but the bottom says "Buy for $29.99". Might want to make the pricing structure clearer. :)
25.
▲
by
ainsleyb
14y ago
And this is the precise reason we exist. :)
26.
▲
by
ainsleyb
14y ago
I'm super surprised that the plans for 2013 don't include a charging station in the Bay Area, seeing as they're headquartered here.
27.
▲
by
ainsleyb
14y ago
This looks great! It seems to make Stripe simpler (since Stripe is essentially simple payments for developers, but non-developers have a hard time grasping all of their docs). If you don't plan on expanding it too much, you might try to tal
28.
▲
by
ainsleyb
14y ago
What we've found is that there are 2 mindsets: building and breaking. When you're building a product it's super hard to switch to the breaking mindset of security, simply because mental context switching is expensive and mentally exhausting
29.
▲
by
ainsleyb
14y ago
Legally you must disclose any sort of security breach to your users: http://en.wikipedia.org/wiki/Security_breach_notification_la...
30.
▲
by
ainsleyb
14y ago
This is a severe lack of customer service. The least that can be done is a quick shutdown of the site until there's a good fix, an email to all customers (since legally they have to disclose the breach: http://en.wikipedia.org/wiki/Securit
More ›