Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rainonmoon
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
rainonmoon
8mo ago
Yeah, I’m fully in support of a decentralised web but the internet is old enough now that being naive about this stuff has become equivalent to being maliciously incompetent. Without designing for things like community or self-governance an
2.
▲
by
rainonmoon
8mo ago
This isn’t an Obsidian thing, it’s just the next iteration of the GTD mania of the aughts or the Atomic Habits people or whatever other trend. There will always be people trying to optimise their organisational workflow to no end. Some of t
3.
▲
by
rainonmoon
8mo ago
And also just… misguided? I don’t particularly think of neo-Nazis when I think of people who advocate against CSAM.
4.
▲
by
rainonmoon
8mo ago
Those were always my favourite episodes too! Enough to get into a career doing social engineering and physical intrusions. It's very tense! You're right to think it's insane; the nature of these jobs is that unlike most kinds
5.
▲
by
rainonmoon
8mo ago
But I’m responding to the notion that they should’ve had signed documentation with the scope with them. They did. The fact that their own company hung them out to dry by not informing everyone on that list is not the pentesters’ fault.
6.
▲
by
rainonmoon
8mo ago
> If we were testing security for something like a courthouse we would've had a card on each of us with the personal cell phone number of the county clerk along with a statement of work that described exactly what we were authorized
7.
▲
by
rainonmoon
8mo ago
The best use? Probably not. But if I built a website that let people generate extremely convincing unlimited photos of you wearing an SS uniform and forcing your dog to smoke meth and sent them to everyone you’ve ever met, this might seem l
8.
▲
by
rainonmoon
8mo ago
That’s really interesting extra context, thanks!
9.
▲
by
rainonmoon
8mo ago
Absolutely nothing in this article is related to feds using conversation metadata to map participants, so, no they weren’t.
10.
▲
by
rainonmoon
8mo ago
A society which took psychological safety seriously would never have created ChatGPT in the first place. But of course seriously advocating for safety would cost one their toys, and for one unwilling to pay that cost, empowering the surveil
11.
▲
by
rainonmoon
8mo ago
Using any variant of NTLM is insecure, which is why Microsoft is phasing it out in Windows 11/Server 2025. Which means we should be free of it some time around 2060.
12.
▲
by
rainonmoon
8mo ago
Yes. This is no more pernicious than releasing a multiplication table.
13.
▲
by
rainonmoon
8mo ago
Some citations would help your case a lot.
14.
▲
by
rainonmoon
8mo ago
A lot of good information for infra teams to internalise, although I worry that it gets a bit lost in the structure of the piece (there's kind of like 3-5 separate essays here but nothing a good edit couldn't fix.) One thing I
15.
▲
by
rainonmoon
8mo ago
The gutless liberals that dominate your country’s preconceptions of “the left” are not your anti-police state faction, but you do their work for them by conflating the two. The anti-police state faction are the ones habitually being physica
16.
▲
by
rainonmoon
8mo ago
I just registered CVEs in several platforms in a related industry, the founders of whom likely all asked themselves a similar question. And yet, it's the wrong question. The right one is, "Does this company need to exist?" I
17.
▲
by
rainonmoon
8mo ago
I'm also Australian and some of these comments have really made me re-appreciate what we have in Medicare. Damn, it's got its issues, but the American attitudes towards their healthcare system are downright bleak. Deeply worrying
18.
▲
by
rainonmoon
8mo ago
Yeah man, when would technology ever be abused to monitor health data. https://www.mirror.co.uk/news/health/period-tracking-apps-ou...
19.
▲
by
rainonmoon
8mo ago
It doesn't have to get to your employer, it just has to get to the enormous industry of grey-market data brokers who will supply the information to a third-party who will supply that information to a third-party who perform recruitme
20.
▲
by
rainonmoon
9mo ago
Start with your threat model. Who is the “someone” you’re imagining attacking you? What are the most likely risks to occur? What are the most damaging? Where do those two lists overlap? Prioritise addressing those first. There’s no point wo
21.
▲
by
rainonmoon
9mo ago
It's always worth being skeptical when someone appeals with the term "good". I'm sure there are people who run large tech companies who want to deliver "good software", but it's such a meaninglessly vague
22.
▲
by
rainonmoon
9mo ago
Microsoft is currently a target of BDS, which calls it "perhaps the most complicit tech company in Israel’s illegal apartheid regime and ongoing genocide against 2.3 million Palestinians in Gaza." This isn't about some hobbyi
23.
▲
by
rainonmoon
9mo ago
I really like Rustfully on YouTube. Every video is under 10 minutes long and he goes over one concept and where it would be used in practice. Great for reinforcement learning.
24.
▲
by
rainonmoon
9mo ago
This would make this blog notable as the first AI company to proactively respect trademark.
25.
▲
by
rainonmoon
9mo ago
How does a camera make it harder to commit a crime? If I bash your skull in on camera, did the camera make that more difficult? Would your family be less aggrieved?
26.
▲
by
rainonmoon
9mo ago
What content generation would not fall under “what artists and designers normally do”?
27.
▲
by
rainonmoon
9mo ago
As an Australian, this is broadly my take too. People may have explicable concerns about TikTok but at least China can’t systematically deny a foreign citizen access to digital society entirely as the US has done to Nicolas Guillou. If youn
28.
▲
by
rainonmoon
9mo ago
Go to Discord and paste that into your console. None of us will hold it against you if you come back and delete these comments once you learn about Content Security Policy.
29.
▲
by
rainonmoon
9mo ago
Show me where you can "open a tunnel" using the XSS in this post. > Anything the user can do, you can do via an XSS attack. I just explained why this isn't a reasonable assumption. You seem to have multiple fundamental mis
30.
▲
by
rainonmoon
9mo ago
Except discord.com doesn't execute JavaScript, the user's browser does. These are meaningful distinctions that delineate the impact. You aren't "discord.com" if you target someone with an XSS exploit, you've
More ›