Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gepeto42
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
S&P Global has lowered Oracle’s creditworthiness from BBB to BBB-
(heise.de)
339 points
by
gepeto42
2mo ago
|
366 comments
2.
▲
by
gepeto42
4mo ago
Absolutely does. But it would definitely keep you away from switching between 13 Slack groups!
3.
▲
by
gepeto42
4mo ago
I feel like my phone is so sluggish when in low power mode (even a 17 Pro), that it could work for this.
4.
▲
Detecting and removing dangerous secrets on workstations before Shai-Hulud does
(recyclebin.zip)
3 points
by
gepeto42
4mo ago
|
0 comments
5.
▲
by
gepeto42
4mo ago
After using the cyber defense matrix quite a bit, it felt obvious AI required it to evolve. Will definitely try this one out for security architecture projects etc.
6.
▲
by
gepeto42
5mo ago
The last year has shown that this vector is getting weaponized for real so it's great to see more tools to help defenders! Is this something only companies with public repos should be worried about?
7.
▲
Unveiling Bagel: Why Your Developer's Laptop Is the Softest Target
(labs.boostsecurity.io)
1 points
by
gepeto42
7mo ago
|
0 comments
8.
▲
by
gepeto42
8mo ago
Been running it for about two months. A few thoughts: 1 - I replaced 2x4k 27inch monitors, and so far so good, only annoyance is sometimes I want to share an entire screen as a reflex, I have to remember to have a more window focused workfl
9.
▲
by
gepeto42
1y ago
They’d likely block you if they detected something like RDP open, cause that would likely indicate you’re hiding your real IP address.
10.
▲
Exposed MCP servers across the internet
(knostic.ai)
80 points
by
gepeto42
1y ago
|
30 comments
11.
▲
Weaponizing Dependabot: Pwn Request at its finest
(boostsecurity.io)
4 points
by
gepeto42
1y ago
|
1 comments
12.
▲
OpenAI reportedly plans to charge up to $20k/month for specialized AI agents
(techcrunch.com)
4 points
by
gepeto42
2y ago
|
0 comments
13.
▲
MacBook Yubikey Induced Insomnia
(recyclebin.zip)
3 points
by
gepeto42
2y ago
|
0 comments
14.
▲
DeepSeek's cutoff date is July 2024: We extracted DeepSeek's system prompt
(knostic.ai)
8 points
by
gepeto42
2y ago
|
0 comments
15.
▲
by
gepeto42
2y ago
Thanks for recognizing it, it was absolutely by design!
16.
▲
by
gepeto42
2y ago
I don't have my home email on work devices. I also don't have my email on my gaming PC (I agree this must be rarer). I don't have all of my work emails on my personal devices either. So now when I log in I need to DM myself l
17.
▲
by
gepeto42
2y ago
I have to admit I bought it mostly to annoy a few very specific friends, but then I kept using it. I would not recommend trying to host anything serious on such a TLD. If you check the early comments on the thread I posted the full content
18.
▲
by
gepeto42
2y ago
You're right, I forgot to even cover that part because I was focused on how annoying they are to me as a user, not necessarily as a service provider. I also forgot to mention how they train people to click on links, how my inbox now co
19.
▲
by
gepeto42
2y ago
Yeah that would not surprise me, in general. I don't think that would be 404's goal, since they provide full-text RSS feeds I could share with a friend easily, but I could see that happening with other services.
20.
▲
by
gepeto42
2y ago
As someone in the security industry, I find it amazing how much we've told people (in awareness training) to "not click things on the thing-clicking machine™" while simultaneously having processes like password resets that re
21.
▲
by
gepeto42
2y ago
Even with passkeys or TOTP 2FA, we've decided email is the root, for better or for worse (for people with gmail, it's likely better than SMS would be on a crappy carrier, but it depends on so many factors, including how many hundr
22.
▲
by
gepeto42
2y ago
To be fair to 404, they're trying to limit the amount of data they hold which IS good, but in the end they need to have the email address of subscribers.
23.
▲
by
gepeto42
2y ago
What I'd recommend is if you're worried about this (or worried about it in certain instances), disable biometrics to unlock the device itself. Then, passkeys on it don't really matter anymore.
24.
▲
by
gepeto42
2y ago
I meant Ricky’s post is great and if I had known about it first I might not have written mine! Added a link to it at the bottom of mine.
25.
▲
by
gepeto42
2y ago
Thanks for that link, I had not seen it and if I had known Ricky Mondello had written that, I probably wouldn't have bothered. I'm still used to Apple people being almost completely invisible publicly.
26.
▲
by
gepeto42
2y ago
Some of them make it way easier for threat actors to obtain large amounts of domains for cheap or free, without fear they'll disappear right away. Paul Vixie had a great talk and research about this ~2018: https://www.youtub
27.
▲
by
gepeto42
2y ago
Yeah the Stratechery implementation for podcasts is great. The more annoying thing is each of them has its own domain and requires logging in, if you don't know you can dig into Stratechery.com. I would prefer if I could login to it wi
28.
▲
by
gepeto42
2y ago
You're welcome. Been thinking about it for a few days, and I had to do it. I don't disagree there's some benefits but being told "IT'S BETTER!" annoyed me quite a bit.
29.
▲
by
gepeto42
2y ago
Because I'm an idiot who likes hosting stuff on bad gTLDs, here's the markdown content of the actual post for you and everyone behind some corporate firewall that blocks dot zip: The term "Magic Links" once meant a [futu
30.
▲
by
gepeto42
2y ago
Yeah exactly. Plus, sometimes SOMETHING will click the link before it even gets to the person's inbox (some enterprise spam filter with a sandboxed browser for example). edit: saw that nicce basically said that a second before I hit po
More ›