Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
michiel3
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
michiel3
10y ago
It actually looks like the company was OK with it. The disclosure timeline shows they were responsive and addressed the problem quickly when they were made aware of its existence.
2.
▲
Brad Smith: In the Cloud We Trust
(news.microsoft.com)
2 points
by
michiel3
11y ago
|
0 comments
3.
▲
by
michiel3
12y ago
That is correct. The reporter requested public disclosure after the report was closed. The bug automatically gets disclosed publicly 30 days after the report is closed, unless the team requests more time by re-opening the bug. You can read
4.
▲
Permanent Denial of Service Vulnerability in MS-DOS
(hackerone.com)
3 points
by
michiel3
12y ago
|
0 comments
5.
▲
by
michiel3
12y ago
"Introducing a bounty program for the most secure open source project on the planet, 0 CVEs in its 30+ year history! http://hackerone.com/msdos" - https://twitter.com/Hacker0x01/status/45
6.
▲
Internet Bug Bounty pays $10K for Flash vulnerability
(threatpost.com)
1 points
by
michiel3
13y ago
|
0 comments
7.
▲
Memoize all the things?
(markijbema.github.io)
1 points
by
michiel3
13y ago
|
0 comments
8.
▲
by
michiel3
13y ago
Relevant blog post by Yahoo! from earlier this month: http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the...
9.
▲
Yahoo Bug Bounty Program is Now Live
(yahoodevelopers.tumblr.com)
50 points
by
michiel3
13y ago
|
9 comments
10.
▲
by
michiel3
13y ago
In the post he also describes that he now uses a new process which involves a computer that has never been connected to the internet and its sole purpose is encrypting and decrypting files. Why not use it to encrypt and decrypt emails as we
11.
▲
HoneyDocs: Create documents that buzz back home
(honeydocs.com)
3 points
by
michiel3
13y ago
|
0 comments
12.
▲
Why Los Angeles could become the next technology epicenter
(thenextweb.com)
3 points
by
michiel3
13y ago
|
0 comments
13.
▲
by
michiel3
14y ago
Why do you think 2GB free is no-where near enough? I know a lot of users that use Dropbox's free plan and are happily syncing and sharing. I use 7% of my 12 GB.
14.
▲
by
michiel3
14y ago
Remove all friends sounds malicious to me. Must say that I haven't tried the app myself.
15.
▲
Common CSRF vulnerability in OAuth2 implementations
(online24.nl)
36 points
by
michiel3
14y ago
|
3 comments
16.
▲
by
michiel3
14y ago
For users with a Retina MBP: this version of Sublime Text supports Retina graphics on OS X Lion.
17.
▲
by
michiel3
14y ago
Yep, if you're blocking remote hosts to authenticate on 3306 (or any other port you're running mysqld on) you're safe. The attacking host can't authenticate itself, so it's unable to exploit this bug.
18.
▲
by
michiel3
14y ago
There's not much on this topic yet. @securityerrata started tweeting about it and trying to find out more: https://twitter.com/securityerrata/status/210550374627676160 . Could be a hoax, or VUPEN keeps it quiet. We'll probably never know.
19.
▲
by
michiel3
14y ago
If you're going to use a password manager, I would recommend 1Password or LastPass. Other tricks you can apply: - Use a different password on every website. To help you remember it, you can choose one main password and make variations on it
20.
▲
Reports say VUPEN has been hacked - 130 0days reportedly in the wild
(kevtownsend.wordpress.com)
13 points
by
michiel3
14y ago
|
6 comments
21.
▲
Obama's Secret Wars and Surprising Use of American Power
(amazon.com)
1 points
by
michiel3
14y ago
|
0 comments
22.
▲
by
michiel3
14y ago
This is probably a best practice you could learn yourself to implement every time you know for sure you don't want a GET/POST variable to be a hash/array. This can also prevent other application errors when someone passes a hash/array which
23.
▲
by
michiel3
14y ago
This won't help that much, because this means you can only visit the website with some authentication string, otherwise the browser will prompt for your credentials.
24.
▲
by
michiel3
14y ago
This technique is widely abused by phishers. Most browsers detect such phishing attacks and warn the user for it (see example in Safari 5). Firefox might do a better job on this subject: it performs a HEAD request first, to see if the websi
25.
▲
Wicd 0day potentially making your Linux setup vulnerable for local r00t
(osdir.com)
1 points
by
michiel3
14y ago
|
0 comments
26.
▲
Security risks associated with Unicode
(online24.nl)
3 points
by
michiel3
14y ago
|
1 comments
27.
▲
A plan to bring credibility to the web
(blog.factlink.com)
23 points
by
michiel3
14y ago
|
0 comments
28.
▲
iOS push notifications (APNS): some security considerations
(online24.nl)
32 points
by
michiel3
14y ago
|
10 comments
29.
▲
Github hack: How to protect your Rails apps against a similar hack
(online24.nl)
4 points
by
michiel3
15y ago
|
0 comments
30.
▲
Quick online tool to check SSL configurations
(ssllabs.com)
39 points
by
michiel3
15y ago
|
15 comments
More ›