Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gmazzola
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
gmazzola
17y ago
Ironically, I was very careful with my choice of "virus vs. virii" when I wrote that message. I looked up the Wikipedia article for Plural of Virus ( http://en.wikipedia.org/wiki/Plural_of_virus ), and noted the sentence "In reference to
2.
▲
by
gmazzola
17y ago
Indeed. I figured this particular piece of news would interest both types of hackers, as it contains technical details you wouldn't expect from a standard defacement. It's rather similar to the urge to rubberneck at a car crash: it's both h
3.
▲
by
gmazzola
17y ago
Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For tho
4.
▲
Astalavista.com hacked, including details
(astalavista.com)
171 points
by
gmazzola
17y ago
|
64 comments
5.
▲
by
gmazzola
17y ago
Internships are generally for University students, but it's not a completely strict rule. I worked with a going-on-thirty intern, a graduate student with a wife and a kid! You'll definitely get some odd looks as a non-student, but there's n
6.
▲
by
gmazzola
17y ago
If the password hashing scheme is secure (bcrypt, as tptacek repeatedly recommends) dictionary attacks become non-trivial and slow. It's still possible to brute force the database, of course, but the time required makes the attack less prof
7.
▲
by
gmazzola
17y ago
From a theoretical security perspective, it's a terrible idea to store passwords in plaintext, but again there's a difference between theory and practice as you've stated. If your auditing can reduce/eliminate unauthorized out-of-band datab
8.
▲
by
gmazzola
17y ago
It could have been worse, fortunately. The attacker broke into a Twitter admin's Yahoo account, and used that information to gain access to the Twitter admin CP. Very little was compromised. You can see screenshots of the Control Panel here
9.
▲
by
gmazzola
17y ago
I've worked at a very large (60,000+ employee) company, so perhaps my background clouds my judgment somewhat, but I think requirements documents are quite helpful. The Software Functional Specification that was handed to me provided a good
10.
▲
by
gmazzola
17y ago
Sadly, this is outside my area of expertise. I will nonetheless attempt to answer your question, but please take my words with a grain of salt. Before we even begin delving into true RNGs, it is worthwhile to consider if we're over-engineer
11.
▲
by
gmazzola
17y ago
I'm sorry if this response is off-topic, but your last question piqued my curiosity so I would like to answer it. There is an authoritative source of random numbers. In 1955, The RAND Corporation (a Cold War-era think tank) published a wond