Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
markarichards
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
markarichards
2y ago
I like to think of a breach as hole through into the hull... they don't mean the boat will sink or even ever will sink; just that the layers of security protections has been compromised. In the case you mention it seems that happened t
2.
▲
by
markarichards
2y ago
It's relatively common for publications to lazily only reference an action that resulted in a legal outcome, rather than the justification provided for the outcome. For instance, Bob imprisoned for car bomb rather than Bob imprisoned a
3.
▲
by
markarichards
2y ago
> i read it twice and i still don’t understand the article. Any recommendations to improve are welcome > is this site complaining about 3rd party analytics? If a bank page includes a script tag that loads third party JavaScript from a
4.
▲
by
markarichards
2y ago
Even if you do switch accounts, which bank do you choose, as most have this nature of vulnerability; hopefully with delivery providers that may be more trusted, but ultimately the bank has no control of the security and cannot distinguish t
5.
▲
by
markarichards
2y ago
The technical fix to this exact issue is remove or SRI and review third party code. None of these features are a must have requirement for online banking. However, the breadth of this problem indicates the fix is bigger, else this will just
6.
▲
by
markarichards
2y ago
The security breaches reported here have been detected by SRI checking bank websites using https://gitlab.com/markalanrichards/access-test/ If anyone wishes to help improve this test suite or fork it for other pur
7.
▲
They Can Be You
(theycanbeyou.com)
37 points
by
markarichards
2y ago
|
6 comments
8.
▲
by
markarichards
2y ago
From the customer's perspective everything has been supplied to them. However, from the bank's perspective, of their supply chain, the component shown to a customer has not been handled by them: they never received it, to supply i
9.
▲
by
markarichards
2y ago
For our systems we run, we have supply chain breaches. But, when our code runs client side and depends on software artefacts being pulled from elsewhere by the client device, I feel like a supply chain paints a picture of a flow of control
10.
▲
A Delivery Chain Breach: A UK bank opened the back door to China
(markalanrichards.com)
59 points
by
markarichards
2y ago
|
8 comments
11.
▲
Who doesn't have remote access to your bank account?
(markalanrichards.com)
1 points
by
markarichards
3y ago
|
0 comments
12.
▲
by
markarichards
3y ago
Sorry, I shortened the original title to fit. Is it just me or is this like a finance regulator urging companies to adopt cryptocurrencies to harness the power of transactional integrity?
13.
▲
ICO urges organisations to [use] privacy enhancing technologies
(ico.org.uk)
3 points
by
markarichards
3y ago
|
1 comments
14.
▲
by
markarichards
4y ago
This is also an interesting read https://www.jewishvirtuallibrary.org/ibm-and-quot-death-s-ca...
15.
▲
KidsHarms – Nspcc Wants Troubled Kids on an Online Harms Site
(kidsharms.com)
3 points
by
markarichards
4y ago
|
0 comments
16.
▲
by
markarichards
4y ago
I love this idea, but I didn't choose it when I kicked off because of my experiences of feature backlogs. Too often seeing something along the lines of "we'd love to use your site, if only it worked in IE|Firefox|insert here&
17.
▲
by
markarichards
4y ago
I'd like to think that cost isn't the issue, that they aren't sacrificing their cause because of that. I believe the charity has an income near £100m a year, so it could justify some cost (how much I don't know) I would
18.
▲
Ask HN: What to do about Childline sending kids to YouTube?
2 points
by
markarichards
4y ago
|
4 comments
19.
▲
by
markarichards
7y ago
Google presented pitches to customers and employees alike that it cares about things like sustainability https://sustainability.google/ , along with a breadth of other commitments https://about.google/commitm
20.
▲
by
markarichards
7y ago
From what we’ve seen it appears many real-time bidding practices are unlawful. What we’re less sure about is whether industry players are aware that what they are doing is unlawful, or whether they do and are continuing to flout the law re
21.
▲
Speech: The future of online advertising regulation
(ico.org.uk)
2 points
by
markarichards
7y ago
|
1 comments
22.
▲
by
markarichards
8y ago
Mozilla is warning about Privacy again this Christmas. However, when it comes to Firefox, it has been invading user privacy for years and sharing referers without consent, visibility (to non-devs) or often even the websites asking them to.
23.
▲
Mozilla's “Privacy Not Included” Missed Out Firefox [2014]
(bugzilla.mozilla.org)
2 points
by
markarichards
8y ago
|
1 comments
24.
▲
Please Add Regulatory, Security and Privacy Concerns to Web Docs
(developer.mozilla.org)
2 points
by
markarichards
8y ago
|
0 comments
25.
▲
by
markarichards
8y ago
This is from a new private browsing session, no page loaded (tabs only prefilled with urls to load). Notice, no consent given on Facebook or the political party sites. Facebook has been sent a wealth of data on who is a member of UK politi
26.
▲
Facebook tracking UK political party websites
(youtube.com)
1 points
by
markarichards
8y ago
|
1 comments
27.
▲
Petition to ban Facebook and advertisers from spying on NHS users
(petition.parliament.uk)
9 points
by
markarichards
8y ago
|
0 comments
28.
▲
Reset Password Links Are a Security Failure
(markssoftware.com)
1 points
by
markarichards
8y ago
|
0 comments
29.
▲
by
markarichards
8y ago
The performance risks may not be so bad, if you're using a common CDN/library as it may be cached and save on download speeds: just hope most of your users don't have secure browsers, wiping caches regularly. But there is sti
30.
▲
by
markarichards
8y ago
I'm not sure I can answer this, but it might help anyone who could if you know an example of an application that does the nature of tracking you are concerned with? I should mention, that demanding tracking may well be okay in GDPR, in
More ›