Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rtev
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
rtev
2y ago
Solarwinds is still dealing with the reputation damage and fallout today from that breach. People don’t forget about this stuff. the lawsuits will likely be hitting crowdstrike for years to come
2.
▲
by
rtev
2y ago
About to be acquired by Google for $23 billion as well!
3.
▲
by
rtev
2y ago
It’s supposedly only accessible to LocalSystem. If they were to encrypt it, it could just be decrypted anyway. Still, it’s a huge liability and a major blunder by Microsoft.
4.
▲
by
rtev
2y ago
Sam is a very famous security researcher, so I would be shocked if he wasn’t making upwards of $350,000 a year. These articles he writes make him a significant amount of money via reputation boost.
5.
▲
by
rtev
3y ago
This appears to be what happens when rich people that don’t need houses buy them anyway as investments. There should be laws preventing a person from owning more than three houses in the United States.
6.
▲
by
rtev
3y ago
Yahoo returns thousands of results for dorking queries where Kagi and Google return an identical list of 5-6 results. Pretty disappointing for me as a paying customer to learn that Kagi is basically a Google wrapper
7.
▲
by
rtev
3y ago
Anyone know why this is happening? error: subprocess-exited-with-error python3 setup.py egg_info did not run successfully.
8.
▲
by
rtev
3y ago
A vendor pays to have their software included in this competition, where many of the world’s best offensive security pros compete.
9.
▲
by
rtev
3y ago
Looks like the “hack” on Twitter was just a botched rollout as suspected?
10.
▲
by
rtev
3y ago
Weeks after defcon, I saw they had a job listing asking for someone with Bluetooth experience and experience preventing denial of service attacks. Sounds like they finally hired someone that knew what was going on here.
11.
▲
by
rtev
3y ago
Lucidrains also created the much-missed EpicMafia, which still doesn’t have a good replacement after shutting down. Exceptionally skilled person!
12.
▲
by
rtev
3y ago
This is the most sus thing I’ve read in a long time
13.
▲
by
rtev
3y ago
i don’t feel that this is true in the slightest. so many critical exploits use the same characters and lengths as intended inputs. Also, if firewalls were a replacement for secure code, no one would be talking about memory safety.
14.
▲
by
rtev
3y ago
I don’t think it is. Microsoft has a track record for delaying fixes and marking important issues as “not a bug”, so I’m less impressed with their security. As terrible a corporation as Oracle is, their security response team has been one o
15.
▲
by
rtev
3y ago
The reason you see so many critical Gitlab security fixes is because they take security so seriously. They pay huge bounties for security vulnerabilities in their products, so they get the best researchers responsibly disclosing bugs.
16.
▲
by
rtev
3y ago
Typescript applications suffer from many of these vulnerabilities. JS apps have a specific class of critical vulnerabilities as well, prototype pollution. If I had to write a web application with security in mind, I personally would pick Py
17.
▲
by
rtev
4y ago
It’s very weird that out of 95 comments in this thread (at the time of writing), practically half of them are one person.
18.
▲
by
rtev
4y ago
LastPark has child predators under the bridge that the park officials haven’t noticed yet
19.
▲
by
rtev
4y ago
I should have added “/s”
20.
▲
by
rtev
4y ago
This is all just a scam run by Big Cow to get some tasty Asian flavors in the trough.
21.
▲
by
rtev
4y ago
While I generally agree with this, it totally misses the mark by leaving out Chrome. As long as Chrome dominates the web, Google stays on top
22.
▲
by
rtev
4y ago
I have yet to hear a convincing threat model for this actually representing a vulnerability. I don’t think there is one.
23.
▲
by
rtev
4y ago
Tavis Ormandy is one of the leading security experts in the world. Here’s a blog post that highlights a number of the risks related to password manager extensions: https://lock.cmpxchg8b.com/passmgrs.html
24.
▲
by
rtev
4y ago
Taking it down doesn’t make flight tracking infeasible, just moderately less accessible. Any sufficiently motivated attacker is going to be able to get the information without a problem. Isn’t it better to have the information more public t
25.
▲
by
rtev
4y ago
Much of the risk associated with password managers is only applicable when using the browser extensions. I know it’s a minor inconvenience, but I would advise sticking with the lack of extension.
26.
▲
by
rtev
4y ago
Very cool, thank you for sharing! Not only does ROP facilitate traditional binary exploitation, but it’s also used in cutting-edge evasive techniques. By abusing ROP instead of direct calls, red teamers are able to heavily obfuscate activit
27.
▲
by
rtev
4y ago
Sounds like you’ve landed on the wrong path of the last of Erikson’s stages.
28.
▲
by
rtev
4y ago
Did you read the article?
29.
▲
by
rtev
4y ago
Reading quickly with deep comprehension is a superpower. Arts and culture of reading aside, kids that don’t read much limit themselves in the pace they can learn and advance.
30.
▲
by
rtev
4y ago
This is awesome.
More ›