Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raesene3
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
raesene3
10y ago
Ah yes, so the threat model for developer signing is compromise of the repository. So here we're looking at the OpSec of the repository owner (e.g. PyPI, npm, Rubygems etc), and also the risk of deliberate compromise by the repo. owne
2.
▲
by
raesene3
10y ago
On the flip-side how is someone who's using a package from one of these repository meant to validate that it's secure and non-malicious? without central validation, each user would have to do it, and that's frankly impractica
3.
▲
by
raesene3
10y ago
Well if there's no central validation, that leaves all individual users to validate packages before use (which is a huge amount of work)... The problem is that companies are using these packages as though they are trusted (i.e. not val
4.
▲
by
raesene3
10y ago
Yep it's a really nasty problem for any package manager that operates at scale. The problem is that without any centralized validation of packages, it leaves checking to each developer who uses the libraries and obviously from an effor
5.
▲
by
raesene3
10y ago
nope and not only that it's not even supported AFAIK
6.
▲
by
raesene3
10y ago
This is very true, but execution at install time (sometimes with root privileges) is a bad idea from a security perspective, especially when it happens with dependencies, which makes it very hard to check all packages that you're insta
7.
▲
by
raesene3
10y ago
One of the problems is that npm (and others) put their credentials or some form of API token into dotfiles in the developers home directory, meaning that if you can execute code as the user (via social engineering or malware) you can push n
8.
▲
by
raesene3
10y ago
Indeed package signing is not the holy grail and won't solve all problems, but it is a part of a secure system. For the problem this blog post talks about, I personally think that keybase is the right solution. You can tie a key to a
9.
▲
by
raesene3
10y ago
Kind of amusing that this is considered to need a new vuln. report, I kind of assumed it was common knowledge. Most of the programming language package repositories (e.g. npm, rubygems, PyPi, NuGet) have this kind of installation process an
10.
▲
by
raesene3
10y ago
Unfortunately I don't think that many/any of the Programming language package repositories have manual review processes, or even automated checking for things like known malware... Linux package managers are a different story of c
11.
▲
by
raesene3
11y ago
I must admit I don't really see this products major benefits over other ways of achieving the same thing (a secondary phone with call forwarding from the main smartphone). Their price is $100 and with that there's the usual risks
12.
▲
by
raesene3
12y ago
I don't think EV SSL certificates have been a big success (though that's just a personal opinion rather something backed with specific data) For me the differentiation in the browser presentation of EV against ordinary SSL doesn&#
13.
▲
by
raesene3
12y ago
on your second point, I'd be careful before making that assumption. Without evidence there's no reason to believe that a supplier company will have better security than your own and it's entirely possible they don't. Als
14.
▲
by
raesene3
12y ago
The Video is also up on Youtube and adds quite a bit to the slides including some good demos https://www.youtube.com/watch?v=nuruzFqMgIw&list=UUJ6q9Ie29a...
15.
▲
Finding Security
(raesene.github.io)
1 points
by
raesene3
12y ago
|
0 comments
16.
▲
by
raesene3
12y ago
However, Micropayments are not the only alternative to Advertising, subscriptions are another choice which only need to be done once rather than repeatedly. I'd like to see more site offer an ad-free subscription, in the way that Ars T
17.
▲
by
raesene3
12y ago
sure but depending on who's paying and how many subscribers you have it can be a decent sized up front expense. I'd argue it's well worth it in the long run but a lot of companies would prefer something which is less expensi
18.
▲
by
raesene3
12y ago
Interesting article, I've always thought that phones are one of the weaker links in the 2FA chain (but a lot cheaper than dedicated tokens). The general use of SMS/voice mail has another potential weak point which is where people
19.
▲
by
raesene3
12y ago
Some of this kind of system won't actually hash the password but encrypt it and use an HSM to secure the keys. Wherever you see a password prompt where the ask for specific characters of the password, they're either doing this or
20.
▲
by
raesene3
12y ago
Very likely to be a legacy back-end system. Doesn't excuse it at all, but that's one I've seen limit banking systems in the past either in password length, complexity or case sensitivity (I've seen some systems automati
21.
▲
by
raesene3
12y ago
That's different to the PIN. CVV is for cardholder not present transactions, PIN is for one's where you're there. Also CVV needs the 16 digit card number, card holder name and expiry as well.. I'd almost guarantee that
22.
▲
by
raesene3
12y ago
What makes you say that? Microsoft have been providing warning of XP going End of life for years now, and (AFAIK) they already supported it for longer than other OS vendors do for desktop OSs. It hasn't been the current offering for t
23.
▲
by
raesene3
12y ago
What I think is interesting about this is more the general case than this specific example. I'd say that people's social media handles are becoming more and more important to them, so loss of them becomes increasingly bad. A lot o
24.
▲
by
raesene3
12y ago
Interesting to see this hit big companies like google. The problem, I think, stems from the idea that most people treat XML parsers as a "black box" and don't enquire too closely as to all the functionality that they support
25.
▲
by
raesene3
12y ago
Hopefully one positive thing that will come out of this whole Heartbleed thing is that companies making extensive use of Open Source software for security critical purposes will consider contributing to ensure that security reviews are carr
26.
▲
by
raesene3
13y ago
If you're worried about not being able to get access to "security people", I'd recommend looking at OWASP ( http://www.owasp.org ) which has a lot of good free information and also chapter meet-ups which are fr
27.
▲
by
raesene3
13y ago
An interesting point, but if interpreted by the wrong person, using wpscan (which makes a load of requests to the site) could be considered dubious under the CMA (I definitely wouldn't run in against a site which I wasn't authori
28.
▲
by
raesene3
13y ago
One thing that to consider is that in UK company cars provided to employees as benefits are taxed heavily based on emissions, which is what drives a large number of customer to small engine diesels (hence the popularity of the BMW 520d amon
29.
▲
by
raesene3
13y ago
Sure in a consumer scenario 2 years is the norm. What I was thinking of is that corporates are not used to 2 year lifecycles so there's likely going to be problems for them if they don't budget for that.
30.
▲
by
raesene3
13y ago
This is a great illustration of why Android is likely to face problems in corporate deployments. Lack of security updates less than 2 years after release is likely to prove a serious problem for companies who operate a 3-5 year device refr
More ›