Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
execveat
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
26 ms
·
61.
▲
by
execveat
4y ago
HN crowd is completely missing the intent. Nobody wants to chase open source developers. The problem is that right now a person can go buy a smartphone or WiFi router which uses obsolete software components already and will never receive an
62.
▲
by
execveat
4y ago
There's a cool tool to detect regexes like these in your code: https://github.com/doyensec/regexploit (disclosure: I work for Doyensec)
63.
▲
by
execveat
4y ago
To be fair, HN commenters probably all have opted out of the Personalized Ads. Have you done it, by the way?
64.
▲
Comparing Semgrep and CodeQL
(blog.doyensec.com)
2 points
by
execveat
4y ago
|
0 comments
65.
▲
by
execveat
4y ago
Location: Malta (EU) Remote: Yes, will consider only remote positions Willing to relocate: No Technologies: Penetration Testing, Red Teaming, Malware Analysis, Exploit Development, Security Engineering, Cybersecurity Advocacy, Pu
66.
▲
by
execveat
4y ago
XKeyscore is/was used to fight terrorism and it's only available to federal agencies, not local law enforcement. Abortion isn't prohibited on a federal level and it's not a national security concern. It doesn't expl
67.
▲
by
execveat
4y ago
Returning to the topic of the article, how does DICT - a network protocol - makes a difference here? Are there any states where traffic gets recorded or queried for keywords? That seems like a huge privacy violation and would be a more inte
68.
▲
by
execveat
4y ago
There are multiple public bypasses for SafetyNet. Many 3rd party roms provide them out-of-the-box. Granted, Apple's attestation is bypassable as well. Furthermore, others mentioned that a large portion of SMS-spam originates from the F
69.
▲
by
execveat
4y ago
You can make positive assertions though. E.g. attack might have been simple in which case it's possible to produce indicators that cover 100% of variants. Or it could have been complex and indicators either don't cover every possi
70.
▲
by
execveat
4y ago
It doesn't tell you whether they have actively investigated the incident though. And if they did, how thorough they were.
71.
▲
by
execveat
4y ago
It's still the case, but nowadays they're branded as an "Office 365 license".
72.
▲
by
execveat
4y ago
It's just a CTF focusing on forensics and reverse engineering. Here are the writeups from the 2021 challenge: https://github.com/luker983/nsa-codebreaker-2021
73.
▲
by
execveat
4y ago
Without HSTS browser might fall back to HTTP which would disclose passwords and sessions leading to account compromise. I'm a penetration tester / red teamer and we do this all the time. DEFCON has been hosting a Wall of Sheep sin
74.
▲
The funniest way to throw away your life
(twitter.com)
4 points
by
execveat
4y ago
|
0 comments
75.
▲
by
execveat
4y ago
API used in the PoC is not used during parsing of the traffic. In order to trigger the bug remotely you'd either need to chain it with another exploit or have a way of running arbitrary commands as a local user (e.g. by exploiting weba
76.
▲
by
execveat
4y ago
This isn't what you're asking, but you could just implement Single Sign-On through a social network (Google, Facebook, Twitter).
77.
▲
by
execveat
4y ago
Aren't configuration profiles necessary for configuring VPN though? For the best security you'd want all your traffic to go through your own server for retrospective analysis.
78.
▲
by
execveat
4y ago
RHEL 9 (and likely many other distros with same kernel version) is vulnerable as well: https://access.redhat.com/security/cve/cve-2022-34918#cve-fa...
79.
▲
Google Authenticator removes Tap to Reveal feature
(play.google.com)
2 points
by
execveat
4y ago
|
0 comments
80.
▲
Algae biopanel windows make power, oxygen and biomass, and suck up CO2
(newatlas.com)
1 points
by
execveat
4y ago
|
0 comments
81.
▲
by
execveat
4y ago
Assuming that really anyone can become a provider in 20 minutes as the website states and there is no KYC whatsoever, this is ridiculously insecure.
82.
▲
by
execveat
4y ago
These "arbitrary commitments with strangers" are only good as long as they do what you intended. Roughly every week there is a major incident with millions of funds lost due to a bug and people who lost money usually are very quic
83.
▲
by
execveat
4y ago
In physical world a collateral can be a car or house. In that case you continue using them while paying out the loan. In crypto world "loan" is a pretty pointless construct useful only for attracting clueless investors.
84.
▲
Researcher defends Formidable in fight against ‘critical’ CVE assignment
(portswigger.net)
2 points
by
execveat
4y ago
|
0 comments