Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ninegunpi
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
ninegunpi
4y ago
tl;dr: Balancing tradeoffs and benefits during disclosure is a hard job sometimes and if authors chosen to do it this way - they could have done it for a reason? You don't have to trust me on this, but it has no commercial agenda behin
2.
▲
by
ninegunpi
5y ago
Infosec emotional climate always had a certain pessimistic, paranoid and panicky perception from the outside, but it is greatly exaggerated, I think. FUD, bullshit, lack of skilled people, lack of budgets, lack of understanding from adjacen
3.
▲
by
ninegunpi
5y ago
Love cryptopals beyond my ability to articulate it well enough. This is monumental work many engineers owe their “cryptography 101-404” education to. For a long while company I work for used Cryptopals as means to train/qualify interns
4.
▲
by
ninegunpi
7y ago
To scale shipping static content, I'd rather look into CDN with proper caching, instead of maintaining ten layers of abstraction just to feel good about how modern my stack is.
5.
▲
by
ninegunpi
8y ago
Isn't RASP just slapping the WAF-like signature detection into your application data streams directly? How would RASP prevent: 1. Insiders having access to database front? 2. Same SQL bypass techniques as employed to bypass WAFs? 3. Mi
6.
▲
by
ninegunpi
8y ago
If your security strategy relies on one or two security controls, you're doomed most of the time. We've added SQL filtering as a defense-in-depth measure, having a convenient seat in the architecture, complementing every other mit
7.
▲
Preventing SQL Injections When WAF’s Not Enough
(cossacklabs.com)
18 points
by
ninegunpi
8y ago
|
13 comments
8.
▲
by
ninegunpi
8y ago
I actually came to comment on this matter. Anecdotal evidence of several people I know is that playing FPS games with trackpad (pretty much of a torture) improves touchpad intuitive usage to an extent where they don't notice any discom
9.
▲
Web app data leaks and how to prevent them 101
(hackernoon.com)
3 points
by
ninegunpi
8y ago
|
0 comments
10.
▲
On avoiding band-aid security after penetration tests
(medium.com)
2 points
by
ninegunpi
8y ago
|
0 comments
11.
▲
Quiche: QUIC implementation in Rust
(github.com)
2 points
by
ninegunpi
8y ago
|
0 comments
12.
▲
by
ninegunpi
8y ago
What you are describing is effectively two aspects of the first step of traditional buddhist meditation Shamatha - awareness on chosen object and awareness on present signals of the body, so yes, meditation is is.
13.
▲
by
ninegunpi
8y ago
>We may never be able to build a machine that can recognize the full diversity of human emotional experience Even humans have a lot of problems recognizing full diversity of their own emotional experience, unless trained appropriately.
14.
▲
by
ninegunpi
8y ago
You've made far better one than me below. Hats off.
15.
▲
by
ninegunpi
8y ago
1. A "quite a while" is less than a hundred years after Godel and in math? Compared to 2000+ years of Aristotlean logic dominance in hard sciences just because Romans inherited most of their scientific views from Greeks, not from
16.
▲
by
ninegunpi
8y ago
Indeed. Yet, it is still based on True/False pair, which does not reflect neither reality or human experience in most cases. Where it is applicable - it perfectly works. But the scope is limited.
17.
▲
Hiring external security team: what you need to know
(cossacklabs.com)
2 points
by
ninegunpi
8y ago
|
0 comments
18.
▲
by
ninegunpi
8y ago
Descendants of Aristotle still find limitations of the system amusing, that’s amusing itself. I hope to live to the day when philosophical advancements of 20th century (or re-discovery of 2500-old Indian logic, if you like), formalized in a
19.
▲
by
ninegunpi
8y ago
1. The problem is that most population is terribly poor at defining and managing risk, by biological design and social selection - those who are good at it are usually not the best neighbors you want to have. 2. In many businesses, the actu
20.
▲
by
ninegunpi
8y ago
You are correct. I get a bit irritated when somebody claims to teach developers "all they need to know about cryptography" and goes on with explaining things they'd be happy to obsess on, instead of explaining things they _ne
21.
▲
by
ninegunpi
8y ago
Opened the book, read first random page ( https://cryptobook.nakov.com/key-exchange/diffie-hellman-key... ), closed the book. If this is what "developers need to know", then explaining why anonymous key exchang
22.
▲
Implementing tracing in modern distributed app
(cossacklabs.com)
4 points
by
ninegunpi
8y ago
|
0 comments
23.
▲
by
ninegunpi
8y ago
It would be terribly interesting to hear what some of the brighter minds here think about CS security model.
24.
▲
CipherSweet: searchable field-pevel encryption for PHP
(github.com)
2 points
by
ninegunpi
8y ago
|
1 comments
25.
▲
by
ninegunpi
8y ago
In fact, due to browser execution model, it’s not impractical - it’s impossible - it can mutate any moment.
26.
▲
by
ninegunpi
8y ago
I do get your arguments very well: having to advocate ZKPP primitive in our own solution I end in discussions about ‘ZKPP does not prevent brute force’ a lot. But it’s unfair to rule out the analysis because this is a choice - these are we
27.
▲
by
ninegunpi
8y ago
There are good general observations on e2e claims for any web app (5.1 and part of conclusions section), which apply to almost any web app, aside from design flaws in the protonmail itself.
28.
▲
by
ninegunpi
8y ago
with good general observations on web app trust as a whole as a bonus (section 5.1).
29.
▲
Analysis of ProtonMail Cryptographic Architecture
(eprint.iacr.org)
2 points
by
ninegunpi
8y ago
|
1 comments
30.
▲
by
ninegunpi
8y ago
Background in infrastructure is the best you can have - you will be far ahead compared to many newly educated ‘security engineers’, knowing the application domain. What I would think about if I were you (was so 15 years ago - started as sys
More ›