Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
christophetd
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
K-Shaped AI Adoption
(jeremyg.dev)
3 points
by
christophetd
6mo ago
|
1 comments
2.
▲
Building an NPM Worm (2016)
(contolini.com)
8 points
by
christophetd
10mo ago
|
0 comments
3.
▲
Stop worrying about 'allowPrivilegeEscalation'
(blog.christophetd.fr)
5 points
by
christophetd
2y ago
|
0 comments
4.
▲
Amazon ECS is the new EC2 for crypto mining
(securitylabs.datadoghq.com)
1 points
by
christophetd
3y ago
|
0 comments
5.
▲
Partial bypass of the login rate limiting in the AWS Console
(securitylabs.datadoghq.com)
2 points
by
christophetd
4y ago
|
0 comments
6.
▲
Cloud Breaches of 2022
(securitylabs.datadoghq.com)
3 points
by
christophetd
4y ago
|
0 comments
7.
▲
by
christophetd
4y ago
The malicious commit (2cd2223dcd90fa9d9c72851427602aa0e179e061) was not signed. Sorry you feel like the writing isn't frank.
8.
▲
by
christophetd
4y ago
If the maintainer themselves added the backdoor, can't they be considered a malicious actor?
9.
▲
by
christophetd
4y ago
Yes, that would be caching. We kept the first sentence, as it's still possible his account was compromised (we have no strong evidence to prove it, but no strong evidence to refute it either).
10.
▲
by
christophetd
4y ago
Thanks for the heads-up, the goal was mostly avoiding that typing the author's name in Google brings up this post. I'll have it blurred for the sake of consistency, though.
11.
▲
by
christophetd
4y ago
We just updated the wording. Thanks for the feedback.
12.
▲
by
christophetd
4y ago
One of the authors of the post here. We prefer sticking to the facts rather than speculating the account was compromised without having a solid proof. Someone on /r/netsec also had an interesting theory that this might be an inten
13.
▲
by
christophetd
4y ago
Hello! One of the authors of the post here. Just added a sentence in the introduction to make it crystal clear: > While FastAPI itself is not impacted, this is an interesting occurrence of an attacker attempting to deploy a FastAPI-spec
14.
▲
by
christophetd
4y ago
Hello there! I'm one of the authors of the post. Sorry you feel we "hyped it up", that was definitely not the intent. The malicious package is targeting FastAPI applications. The point is that there are a lot of application
15.
▲
Investigating a backdoored PyPI package targeting FastAPI applications
(securitylabs.datadoghq.com)
12 points
by
christophetd
4y ago
|
0 comments
16.
▲
Identify malicious PyPI packages using static analysis and metadata heuristics
(github.com)
2 points
by
christophetd
4y ago
|
0 comments
17.
▲
Demystifying the OpenSSL punycode vulnerability and exploitation walk-through
(securitylabs.datadoghq.com)
3 points
by
christophetd
4y ago
|
0 comments
18.
▲
by
christophetd
4y ago
Author here - have a look at the methodology section at the bottom of the page. Feel free to ask if anything is unclear.
19.
▲
by
christophetd
4y ago
Author here - sorry you feel like this is content marketing. I identify myself as a cloud security engineer, so that's a clear antigoal. The intent is to show what's the systematic adoption of cloud security controls _that matter_
20.
▲
by
christophetd
4y ago
Sure. My point is that Trusted Advisor is also a commercial product, as opposed to IAM Access Analyzer which is free.
21.
▲
by
christophetd
4y ago
One of the authors here - confirming that "40 percent of organizations have at least one IAM user that has AWS Console access and does not have multi-factor authentication" is about IAM users and does not include the root user.
22.
▲
by
christophetd
4y ago
Hello! One of the authors here. We did release some (hopefully) actionable guidance alongside the study[1]. Trusted Advisor is a fair point, but note that most of its security checks only come with the Business or above AWS support plan. IA
23.
▲
Using the Dirty Pipe Vulnerability to Break Out from Containers
(datadoghq.com)
2 points
by
christophetd
4y ago
|
0 comments
24.
▲
"Stratus Red Team", an open-source adversary emulation tool for the cloud
(github.com)
2 points
by
christophetd
5y ago
|
0 comments
25.
▲
Using Twitter to notify careless developers – the unorthodox way
(incognitatech.medium.com)
5 points
by
christophetd
5y ago
|
2 comments
26.
▲
by
christophetd
5y ago
It's been taken down, but still available through https://web.archive.org/web/20211230160444/https://vpnovervi...
27.
▲
Cloud Security Breaches and Vulnerabilities: 2021 in Review
(blog.christophetd.fr)
8 points
by
christophetd
5y ago
|
0 comments
28.
▲
by
christophetd
5y ago
The tweet has been removed. Now that this has been clarified, I don't want to be a vector for spreading inaccurate information.
29.
▲
by
christophetd
5y ago
I made wrong assumptions when writing this tweet. I clarified this on Twitter. Apologies for the confusion. Not sure if it makes sense to delete the tweet / thread.
30.
▲
by
christophetd
5y ago
UPDATE: GitHub CISO pointed out that GitHub did NOT take down the JNDI Exploit repository. https://twitter.com/_mph4/status/1470343429599211528 https://twitter.com/christophetd/status/147
More ›