Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dagrz
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Clippers cap circumvention report explained
(clippersreport.com)
1 points
by
dagrz
15d ago
|
0 comments
2.
▲
by
dagrz
2y ago
Author here. There's no complaint. It's an observation rather than an absolute good or bad. It's something you have the consider in designing your application.
3.
▲
Hacking Terraform State for Privilege Escalation
(blog.plerion.com)
3 points
by
dagrz
3y ago
|
0 comments
4.
▲
Conditional Love for AWS Metadata Enumeration
(blog.plerion.com)
3 points
by
dagrz
3y ago
|
1 comments
5.
▲
by
dagrz
3y ago
How would you feel if an attacker could read your AWS resource tags? Turns out they can! We’ve found a way to enumerate various metadata from public resources and created a tool to help you test your environment.
6.
▲
Give direction to an engineering-led startup without a chief product officer
(blog.plerion.com)
1 points
by
dagrz
3y ago
|
0 comments
7.
▲
by
dagrz
3y ago
Author here. There's been a lot of great work recently on hacking Github-AWS OIDC integrations but I've think we've undersold how bad it is. Here's my guide to finding all the vulnerable roles in all public repos, includ
8.
▲
Hacking GitHub AWS integrations again
(dagrz.com)
2 points
by
dagrz
3y ago
|
1 comments
9.
▲
Disrupting AWS logging
(danielgrzelak.com)
3 points
by
dagrz
10y ago
|
0 comments
10.
▲
by
dagrz
11y ago
I feel like Secure Code Warrior has solved this problem much better with gamification. https://www.securecodewarrior.com/
11.
▲
by
dagrz
13y ago
This applies to everything you do which depends on review. Want a particular job? Put in more effort than everyone else. Create a ‘I want to work for you’ website. Be prepared at the interview. Understand everything about the organisation.
12.
▲
by
dagrz
13y ago
Author here - As an information security manager at a large organisation, this scares me. As much as we train our users and put governance structures in place to help them do the right thing, they don't always make the right decisions and w
13.
▲
LinkedIn is the ultimate phishing site
(blog.danielgrzelak.com)
2 points
by
dagrz
13y ago
|
1 comments
14.
▲
by
dagrz
14y ago
This is awesome. I don't know much about typography but every time I try to learn something, I give up pretty quickly because of the overwhelming amount of (boring) information. I love how this guide is set out in easy to read and consume c
15.
▲
Media interviews and making them work for you
(blog.danielgrzelak.com)
1 points
by
dagrz
14y ago
|
0 comments
16.
▲
by
dagrz
14y ago
Is it me or does the author of this article, and the abusers of the exploits he writes about, land on the wrong side of both the law and common morality? Surely EA being a "terrible company" has nothing to do with whether it is okay to stea
17.
▲
Media interviews for the little guy
(blog.danielgrzelak.com)
2 points
by
dagrz
14y ago
|
0 comments
18.
▲
by
dagrz
14y ago
Whenever I see a new post about this saga I feel compelled to post this mini documentary about it before everyone gets into the same old arguments. Sex, Lies and Julian Assange http://www.abc.net.au/4corners/stories/2012/07/19/3549280.ht..
19.
▲
Moving reference checks to the start of the recruitment cycle
(zdnet.com)
1 points
by
dagrz
14y ago
|
0 comments
20.
▲
by
dagrz
14y ago
You are pointing your anger in the wrong direction. The reality is that security is a hard problem, much too hard for Blizzard, much too hard for RSA, much too hard for banks, and much too hard for governments. Major companies being hacked
21.
▲
Video gaming an Olympic sport?
(torchforgaming.org)
2 points
by
dagrz
14y ago
|
0 comments
22.
▲
by
dagrz
14y ago
For the scenerio you mentioned, just having the login/comment submissions work over SSL results in zero added security. In short, this is because of tools such as SSL strip. A better suggestion would be to have the entire site available of
23.
▲
by
dagrz
14y ago
There are a few people who blog about some great ideas they have. Check out the one by Bosco Tan at http://boscotan.tumblr.com/
24.
▲
Moneyball for recruiters
(getlisted.tumblr.com)
2 points
by
dagrz
14y ago
|
0 comments
25.
▲
Kids not doing their chores? Use broadband as currency
(boscotan.tumblr.com)
3 points
by
dagrz
14y ago
|
1 comments
26.
▲
Don't be afraid of security testing or "bad" reports
(community.securusglobal.com)
1 points
by
dagrz
14y ago
|
0 comments
27.
▲
Leaked "RSA dump" appears authentic
(risky.biz)
22 points
by
dagrz
15y ago
|
4 comments
28.
▲
by
dagrz
15y ago
I think this article summaries the whole big fish, small fish, decentralized discussion: http://risky.biz/anonymous
29.
▲
The sad truth about Anonymous/LulzSec arrests
(risky.biz)
13 points
by
dagrz
15y ago
|
0 comments
30.
▲
by
dagrz
15y ago
All the data has been removed and only exists in sha1 hash form but you can see if you were affected at https://shouldichangemypassword.com/
More ›