Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chrismsnz
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
chrismsnz
3y ago
> What have you blocked the attacker from doing? Not blocked necessarily, but if they want to leverage a stolen token, they’re now forced down a more difficult and highly visible pathway. You can imagine anomaly detection along the lines
2.
▲
by
chrismsnz
7y ago
> That being said, you could probably create a pair of colliding images, give one to a news outlet or something, then later post the second (presumably banned) one. The app would on short notice need to decide between banning neither or
3.
▲
by
chrismsnz
7y ago
Ignoring MD5/image format-specific collision realities, theoretically an attacker could submit a contraband image that collides with a valid, allowed image they may want to remove. When action is taken on the first image, the collided
4.
▲
by
chrismsnz
7y ago
Not for me - seems it depends on libssl1.0 and buster ships 1.1
5.
▲
by
chrismsnz
8y ago
Clips were autoplaying in the live updates tab of twitter.
6.
▲
by
chrismsnz
10y ago
It has good in-kernel support for virtio drivers (e.g. kvm, bhyve, vmware) and can also run domU in the latest release. It doesn't support "vmware tools" as such, but does support the virtual interfaces for network, disk, bal
7.
▲
by
chrismsnz
11y ago
Well, it's not obsolete - more incomplete. OpenBSD has supported ipv6 natively for a long, long time. Additionally, with a "home/office" router, there's many ways that IPv6 may be implemented by their ISP (e.g. stat
8.
▲
by
chrismsnz
11y ago
Not 100% sure, but I think this is to mitigate exploitation of UAF (Use After Free) flaws. Adding an unpredictable delay in between when an application frees some memory, and it becomes available for reuse elsewhere will likely reduce the w
9.
▲
by
chrismsnz
11y ago
> anyone wanting to know OpenBSD's position on virtualization should spend 20m-1hr digging through threads like that Okay, okay. Personally, I think the fact that OpenBSD did not support any of the current virtualisation solutions,
10.
▲
by
chrismsnz
11y ago
If you actually read the thread he was reacting to the premise that: as a secure operating system, OpenBSD should implement virtualisation (in this case, Xen) due to its security benefits. A premise which he rightly shat directly on, and is
11.
▲
by
chrismsnz
11y ago
Is this really a compromise? OpenBSD has happily run as a guest for a long time now, with various virtio drivers being added some time ago. Solutions like virtualbox and xen reach far into the system and are still a no-go on OpenBSD. vmm on
12.
▲
by
chrismsnz
11y ago
On the flip side, if they were offering TLS services to these sites, they're literally man-in-the-middling encrypted comms to those sites. And in scope of US law-enforcement/intel collection. Might be that they were asked to conti
13.
▲
by
chrismsnz
11y ago
OpenBSD has had VirtIO (supported by KVM, VMWare and now virtualbox too) guest support for a while now. AWS uses Xen and domU support is a lot more invasive - OpenBSD had supported it in the past but I believe it was dropped?
14.
▲
by
chrismsnz
11y ago
> How do you justify the 1.3% share on servers[1]? OpenBSD is a research operating system. A lot of their development and deployment methods do not align with the needs/wants of large infrastructure deployments (e.g. biannual releas
15.
▲
by
chrismsnz
11y ago
Theo has been softening on x86 virt for a long time. Additionally, he's still right. Don't rely on it to enforce security boundries (e.g. host untrusted systems and trusted systems on different tin) and his rant is totally congrue
16.
▲
by
chrismsnz
11y ago
I guess the goal of Security is to not become the next OPM or Hacking Team. I agree with what you say regarding perimeter security, a concept quickly decreasing in relevance in today's environments. Unfortunately, when you have thousan
17.
▲
by
chrismsnz
11y ago
I'm a security guy so I obviously have a differing viewpoint, but when it comes to ensuring what data comes in and leaves your environment there's little choice. The ability to analyse outgoing traffic is really a requirement for
18.
▲
by
chrismsnz
11y ago
Running an internal DNS resolver is actually very cheap, almost every broadband CPE device runs or can run its own DNS proxy resolver. It's also a great source of information when monitoring egress communication, so I would just make s
19.
▲
by
chrismsnz
11y ago
Circumventing your companies firewall is not a great idea in the first place. Additionally, if they have aggressive egress filtering, its likely that the only DNS communication will be via an internal resolver which is going to be monitored
20.
▲
by
chrismsnz
11y ago
5.8 is still currently in development/snapshot - not for amateur users. 5.7 is the latest official release. 5.8 is due on Nov 1.
21.
▲
by
chrismsnz
11y ago
> And yet the OP was turned down for not being able to invert a binary tree Your source is a series of salty tweets.
22.
▲
by
chrismsnz
11y ago
That's not what the interview process is like at all. They're more interested in how you approach real world issues (the questions I got asked were conceivably real-life issues a company like Google would face with its products).
23.
▲
by
chrismsnz
12y ago
> Hardware like that makes me yearn for one with no wireless and a pair of Gigabit Ethernet ports to use as a firewall and server. Unfortunately, general purpose hardware and operating system needs a fair amount of juice to route and ins
24.
▲
by
chrismsnz
12y ago
Just use a procmail rule to call gpg on every incoming email before it's stored using your public key, then your client (configured with your private key) can decrypt every email as normal.
25.
▲
by
chrismsnz
12y ago
If I had to take a guess... It'd be easier to carefully add specific features to a well-designed and secure codebase such as OpenBSD, rather than try and pare down and audit the huge codebase and large amount of features provided by so
26.
▲
Bitrig 1.0 Released – OpenBSD fork
(article.gmane.org)
60 points
by
chrismsnz
12y ago
|
35 comments
27.
▲
by
chrismsnz
12y ago
Yes, root's shell should be one provided by the distribution's base install. I think the biggest worry is that if you need to do something like boot into single user mode for an emergency recovery, and /usr or /usr/
28.
▲
by
chrismsnz
12y ago
I would assume that's the job of the disk's firmware, manage the physical disk and present a compliant interface to the OS (e.g. IDE, SCSI etc...)
29.
▲
by
chrismsnz
12y ago
What do you mean by "Network effect"? I don't really see how it applies in this situation. (e.g. you can use uber today and a taxi tomorrow and suffer no loss of value).
30.
▲
by
chrismsnz
12y ago
Does this involve collusion with the telco? IIRC There's a fair amount of baseband-layer stuff that can be done with SMS from a trusted party.
More ›