Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
iancarroll
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
iancarroll
3d ago
How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty pro
2.
▲
by
iancarroll
3d ago
As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla , and my agents will probe anything under
3.
▲
by
iancarroll
7d ago
Prepaid cards are great for the vendor because they have breakage (the unspent amount before expiry). I doubt the data is worth much relative to that. If anything, they have much less of a tie to the individual.
4.
▲
by
iancarroll
7d ago
Importantly, there is only an incentive for L2/L3 data on business/corporate cards, which have an inflated interchange rate above personal cards anyway. This is not a scheme to get enhanced targeting data for personal transactions
5.
▲
by
iancarroll
2mo ago
I agree, I have been in a lot of buildings where the elevators have extremely poor performance due to this. It can be 4AM but they are all configured to rest on one floor or something like that.
6.
▲
by
iancarroll
2mo ago
Looks great but the CLI output is not particularly interesting while the scan is running. I wish it could show token usage, some kind of progress, etc.
7.
▲
by
iancarroll
2mo ago
I've wasted so much money on vendor charging cables in the past 10 years while traveling or moving that I would probably buy this just for the USB-C port, assuming it is actually splash proof. I wonder what HR sensor they use. Samsung
8.
▲
by
iancarroll
2mo ago
We use github.com/go-webauthn/webauthn with no complaints!
9.
▲
by
iancarroll
2mo ago
In Shenzhen, they told me that I can take the full test on any visa if my permitted length of stay is 90 days or more. Supposedly the US embassies now issue 90 day visas for Americans, so I am hoping to try that route soon as I have already
10.
▲
by
iancarroll
2mo ago
Surprised to see this here but happy to answer any questions! Driving across China and getting to use the latest EVs has been quite fun and I hope to do it even more in the future.
11.
▲
Backstage access: an unauthenticated SQL injection in Front Gate Tickets
(ian.sh)
3 points
by
iancarroll
3mo ago
|
0 comments
12.
▲
by
iancarroll
3mo ago
Most apps (on desktop or mobile) open third party auth flows inside the user's default browser, which makes this a non-issue. For one, if you embed the Google login flow into your app then I can't reuse my existing session in my b
13.
▲
by
iancarroll
3mo ago
Apps installed via the MAS have sandboxing applied to them, so this isn't really true.
14.
▲
by
iancarroll
3mo ago
The latest FSD does not attempt to check if your hands are on the wheel at all.
15.
▲
by
iancarroll
3mo ago
My Cloudflare enterprise order form has costs for overages for Workers and the following language about everything else: > If Customer exceeds any of the Total Quantity for the Services below, Cloudflare will invoice Customer in arrears
16.
▲
by
iancarroll
3mo ago
Your whole account is undisclosed marketing for this service. Fingerprinting in this manner is highly unlikely to be viable - there are too many middleboxes at the TCP layer to try and fingerprint on it.
17.
▲
by
iancarroll
3mo ago
0.5% is a pretty incredibly low interchange rate in any case. But if you are saying that half of it is going to scheme fees, I doubt it is funding rewards programs for consumers.
18.
▲
by
iancarroll
4mo ago
Well, OpenAI already sold it (but kept the team), so it’s in someone else’s hands now.
19.
▲
by
iancarroll
5mo ago
I know plenty of security researchers who exclusively use Claude Code and other tools for blackbox testing against sites they don’t have the source code for. It seems like shutting down the entire product is the only safe decision here!
20.
▲
by
iancarroll
6mo ago
It’s pretty interesting to me that Cloudflare is collecting additional client-side data for individual customers. This is not widely done by most anti-bot solutions.
21.
▲
by
iancarroll
6mo ago
A bit skeptical of how this article is written as it seems to be mostly written by AI. Out of curiosity, I downloaded the app and it doesn't request location permissions anywhere, despite the claims in the article. I've noticed Cl
22.
▲
by
iancarroll
7mo ago
Verizon did manage to convince the FCC that this was enough a problem to change their settlement agreement[0] requiring more frequent unlocks. If you believe their numbers, they lost 700,000 phones to fraud in 2023, although a lot of those
23.
▲
by
iancarroll
8mo ago
That is a very old article that seems to be outdated now.
24.
▲
by
iancarroll
8mo ago
Although I don’t like Flock, I’m a bit skeptical of the claims in the article. Most screenshots appear to be client-side JavaScript snippets, not API responses from this key. In the bug bounty community, Google Maps API key leaks are a comm
25.
▲
by
iancarroll
8mo ago
Chase issues cards on both the Visa and Mastercard network (i.e. certain cobrands and the Freedom Flex), so I doubt this was a serious consideration.
26.
▲
by
iancarroll
10mo ago
The GFW is certainly looking for traffic to block, but it is not really going to invade much privacy, as it cannot decrypt anything using HTTPS/TLS.
27.
▲
by
iancarroll
10mo ago
I don't think there is any reason to assume they would allow forced code execution just because they allow data residency for mainland accounts. And unfortunately, China is likely a much larger and more profitable consumer market than
28.
▲
by
iancarroll
10mo ago
Even in mainland China, where iOS does have a large amount of changes to comply with local regulations, Apple does not pre-install any apps from anyone.
29.
▲
by
iancarroll
10mo ago
It’s great that you have coverage across multiple countries. I’ve noticed most budget apps cannot handle multiple currencies at all, much less automated sync across multiple countries.
30.
▲
by
iancarroll
11mo ago
Aren’t they both hardware backed, just changing the X in “trust X”?
More ›