Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
parable
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Hacking xAI for unreleased models and confidential documents
(schizo.org)
2 points
by
parable
1mo ago
|
1 comments
2.
▲
by
parable
1mo ago
This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be
3.
▲
by
parable
1mo ago
Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ulti
4.
▲
by
parable
1mo ago
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I&
5.
▲
Klue OAuth breach victim list grows as Icarus hackers claim attack
(bleepingcomputer.com)
3 points
by
parable
3mo ago
|
0 comments
6.
▲
by
parable
3mo ago
I've had a similar thought in the past. I was thinking about the feasibility of a law being introduced where each company making over a certain amount of money per year must begin a VDP (and optionally a BBP) so that security flaws can
7.
▲
by
parable
3mo ago
Companies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate. IANAL, but the law seems a bit vague to me, and it appears that companies use that vaguen
8.
▲
by
parable
3mo ago
> Otherwise, just assume everything you do online is public and act accordingly. This is such a depressing reality. It's also what governments want you to believe. If you aren't able to speak your mind about anything anonymousl
9.
▲
by
parable
3mo ago
I use Snusbase ( https://snusbase.com ). They've been around since around 2016 and haven't had any issues legally - they're the longest-standing data breach search engine besides HIBP, as far as I know. (This is not
10.
▲
by
parable
3mo ago
Hashes can be cracked, and end users won't understand how to create password hashes to check which one was leaked. Plus, salts exist. Passwords shouldn't matter anyways. Use a password manager and be done with it. The real issue i
11.
▲
by
parable
3mo ago
I wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder. Make it a huge risk to store data, then companies wi
12.
▲
by
parable
3mo ago
I'd also add a third issue to this list: data retention. Too many companies I've dealt with have privacy policies that state something to the tune of "we'll hold onto your data for as long as required" without givin
13.
▲
by
parable
4mo ago
I find it very hard to trust any email service that claims to be E2EE without an audit by a reputable firm like Cure53 or Trail of Bits. I signed up to give it a brief test and immediately noticed that emails are returned from the server in
14.
▲
by
parable
4mo ago
I'm not sure how I haven't heard of this yet. There have been too many times I've wished I could convert a command-line script to a native application easily for me not to try this.
15.
▲
by
parable
4mo ago
Kudos for the public disclosure. Too many people haven't been happy with MSRC and it's starting to boil over (see the Nightmare Eclipse situation, too). Maybe all of these disclosures will cause them to do some introspection and r
16.
▲
by
parable
4mo ago
It seems pretty trivial to just add a check in the agent's tool call to determine if the email is actually the one on file (or one that has previously been on file). I'm not sure why it's taking them so long to remediate.
17.
▲
by
parable
4mo ago
The bug still exists - two of my friends have lost access to their accounts as of an hour ago. They've partially recovered but are unable to change their passwords, so their accounts are still technically in the hands of the attacker(s
18.
▲
by
parable
4mo ago
It appears the exploit hasn't been patched: https://x.com/vxunderground/status/2061636614267273332 I've heard the new "method" has to do with setting your location to Singapore or something, bu
19.
▲
by
parable
4mo ago
The original 2FA did not get thoroughly bypassed, because otherwise I would've lost my username, so that's false - at least, based on my experience. However, there are separate vulnerabilities that allow for 2FA to be bypassed on
20.
▲
by
parable
4mo ago
I suggest you try signing into your Instagram account via the app or website to check if you've been compromised. It could very well be a bot trying to obtain your recovery method hints but you could've also fallen victim to this
21.
▲
by
parable
4mo ago
If there's no recovery email address set, or that email has expired, there are no recovery methods to verify with. The account is locked "for good". I use quotes because in some cases I've been able to recover Gmail acco
22.
▲
by
parable
4mo ago
This still happens. Meta doesn't do much to protect against this, they just fire more people and hire new agents when they find out one was bribed.
23.
▲
by
parable
4mo ago
It's against Meta's terms to buy and sell accounts, thus the bank would never do such a deal unless you structured it a certain way: create a business, the account becomes property of the business, then Chase buys the business and
24.
▲
by
parable
4mo ago
Meta's aware and tries their best to act on it, but the real solution is simply not hiring outsourced support workers. It's really that simple. They have the money to hire people in-house for good wages, which would solve the root
25.
▲
by
parable
4mo ago
Correct, which is the problem here - they don't want to, and you can't force them to.
26.
▲
by
parable
4mo ago
Likely a bot spamming the reset endpoint to fetch your recovery method hints. Happens all the time. I'd ignore and just sign into your account via the app or website to make sure everything's fine. WhatsApp is indeed used to send
27.
▲
by
parable
4mo ago
Your account might be rate limited from performing additional password resets. Try the hacked account flow by selecting "Can't reset your password" (or whatever the app says) when trying to do a password reset. That's ho
28.
▲
by
parable
4mo ago
You're lucky you weren't affected by this. Several people I know with three-letter usernames had theirs stolen over the last few days. When I recovered my account that had been stolen through this exploit (luckily, my username had
29.
▲
by
parable
4mo ago
Or sell it, and pocket some cash for yourself. If this person has a short or otherwise valuable username, they could sell it for possibly thousands or tens of thousands of dollars.
30.
▲
by
parable
4mo ago
Meta has the capability to find out who authorized the change to this person's account. They log every change done in their administrator panel with a scary level of granularity, as far as I know, and they're able to take actions
More ›