Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jmau111
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
A Framework for Knowing What You Don't Know
(luciacerchie.dev)
2 points
by
jmau111
4y ago
|
0 comments
2.
▲
by
jmau111
4y ago
cheat sheet attack/defense https://github.com/jmau111-org/powershell_commands
3.
▲
XSS Under the Radar
(github.com)
2 points
by
jmau111
4y ago
|
1 comments
4.
▲
by
jmau111
4y ago
XSS without alert
5.
▲
by
jmau111
4y ago
Practical security guide that contains useful links to learn Linux internals and security (attack/defense). I tried to summarize what I've learned so far, but, of course, it's neither exhaustive nor suited for targeted attack
6.
▲
Linux OS Security
(github.com)
1 points
by
jmau111
4y ago
|
1 comments
7.
▲
by
jmau111
4y ago
You clearly made your point but comparing this tool with my introduction seems a bit unfair ^^. Indeed, I was not thinking about that level of attacks. However, if individuals and organizations do not understand the minimum required to secu
8.
▲
by
jmau111
4y ago
To me, the comparison does not make sense and was definitely not my intention when I mentioned Linux in the guide. It's just that privesc and kernel exploits is possible under some conditions on Linux.
9.
▲
by
jmau111
4y ago
indeed, but the point was this malicious scripts usually try to install programs, like droppers.
10.
▲
by
jmau111
4y ago
This tool looks sharp, but why do you say "HardeningKitty is a good start." It seems to be an all-in-one solution to harden your system, and not an introduction, like my guide.
11.
▲
by
jmau111
4y ago
> The biggest help with that has been uBlock origin It seems that browsers and extensions handle a huge part of the global security for users, maybe even more than the OSes.
12.
▲
by
jmau111
4y ago
Nope. It's not a statement, it's just not in the guide.
13.
▲
by
jmau111
4y ago
Not to mention kernel exploits, local privesc, unmaintained or abandoned distros, and many other issues. I've seen so many people relying on the OS and thinking themselves as power users just by using it with default settings. I think
14.
▲
by
jmau111
4y ago
?
15.
▲
by
jmau111
4y ago
I've tried to analyze the situation with objective arguments, but it seems to make me appear as a Windows/Microsoft advocate or fan boy, which is a bit ironic. Many security news worried about actively exploited 0-days, but many o
16.
▲
by
jmau111
4y ago
erf, that's what I mean by "download and install all patches," but I'll try to write that better if it's confusing.
17.
▲
by
jmau111
4y ago
Performance is important, as you don't want to have a dysfunctional system, but, typically, you have to disable important security mechanisms to force the install. You lose on both sides.
18.
▲
by
jmau111
4y ago
Users have reported various performance issues. It does not make 11 worse than 10. It's more secure to keep windows 10 if your hardware is too old.
19.
▲
by
jmau111
4y ago
> Everything I listed above can be solved by a single sysadmin with group policy and 30 minutes to kill, and they wont reoccur. Good point. I tried to highlight that (not relying on default policies).
20.
▲
by
jmau111
4y ago
This is not what I mean actually. Windows simplifies some procedures, which can be beneficial for most users. I'm a big Linux fan boy, but it's easy to mess up your config and get a false impression of security, especially with so
21.
▲
by
jmau111
4y ago
I understand that problematic, but it's worth it.
22.
▲
by
jmau111
4y ago
While it's true, such scripts usually install crap using the victim's privileges behind the scene.
23.
▲
by
jmau111
4y ago
> the guide recommends application updates only for enterprise users No. Maybe read this part https://github.com/jmau111-org/windows_security#7-recommenta... > strong passwords [...] counter to NIST and other acc
24.
▲
by
jmau111
4y ago
Thoughts on Windows Security, misknown mitigations, and solutions to keep the system safe.
25.
▲
macOS Security Guides
(github.com)
4 points
by
jmau111
4y ago
|
1 comments
26.
▲
by
jmau111
4y ago
Personal thoughts of OS security from a casual user and a DEV's perspectives.
27.
▲
by
jmau111
4y ago
Hi, what you're saying is technically accurate, but Firefox and Duckduckgo are still far better than chrome + google session + google search + gmail. Although, I've edited the post, as it could be misleading.