Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
stonepresto
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
stonepresto
4mo ago
Related https://news.ycombinator.com/item?id=48157559 Someone in the comments linked this post from 2015 talking about the Cyber Grand Challenge this post mentions, it's an interesting reminder that this didn't ju
2.
▲
by
stonepresto
1y ago
Well, in another subthread the author said he did in fact make a crashing PoC. I guess it depends on the customer's standards, but I would say in the vast majority of cases (especially for nuanced memory corruptions in which the abilit
3.
▲
by
stonepresto
1y ago
I'm too much of a skeptic to not do so lol. Great post though overall, don't let my assholery dissuade you! I was pleasantly surprised that it was actually a researcher behind the news story and there was some real evidence /
4.
▲
by
stonepresto
1y ago
Thank you! I'm really happy to hear you did that. But why not mention that in your blog post? I understand not wanting to include a PoC for responsible disclosure reasons, but including it would have added a lot of credibility to your
5.
▲
by
stonepresto
1y ago
PoCs should at least trigger a crash, overwrite a register, or have some other provable effect, the point being to determine: 1) If it is actually a UAF or if there is some other mechanism missing from the context that prevents UAF. 2) The
6.
▲
by
stonepresto
1y ago
I know there were at least a few kernel devs who "validated" this bug, but did anyone actually build a PoC and test it? It's such a critical piece of the process yet a proof of concept is completely omitted? If you don't
7.
▲
by
stonepresto
3y ago
The part of the prompt that suggests its the 15th of December is a GET param, which just means wherever this link was retrieved from is where that date is coming from. The PDF could have been authored at any time. Looks like the created dat
8.
▲
NVD has deprecated their RSS feed
(nvd.nist.gov)
2 points
by
stonepresto
3y ago
|
0 comments
9.
▲
by
stonepresto
3y ago
Agreed. I think their bottom line probably is built off of how it would affect their user base. My hunch is given the immensity of the user base, it wouldn't cause enough of a significant exodus for Meta to care either way. But that&#x
10.
▲
by
stonepresto
3y ago
What's to stop them from having hooks in their app that can bundle up all the decrypted messages, re-encrypt, and phone home? Certainly it wouldn't be default behavior, but its possible and would allow them to answer warrants.
11.
▲
NVD has deprecated their RSS feed
(nvd.nist.gov)
2 points
by
stonepresto
3y ago
|
0 comments
12.
▲
by
stonepresto
3y ago
I agree WPS is a disaster. My approach is just setting proper firewall rules on a dedicated ESSID with a dedicated VLAN. A device on a restricted VLAN shouldn't be able talk to anything. The downside is its more work, but the plus side
13.
▲
by
stonepresto
3y ago
This also reads like an advert... I still don't see a usecase for a unique PSK per guest, and even that can be achieved with most guest portal implementations. What SPR seems to lack is backing and therefore trust. Pushing a product ag
14.
▲
by
stonepresto
3y ago
Its important to note their firmware and especially their cloud infrastructure should absolutely not be trusted. Their hardware is probably fine, so just flash OpenWRT.
15.
▲
by
stonepresto
3y ago
The reponse "<name> tries to... remember they are a god. They are a god. They <do some godlike action to survive>" seems to work very well. But also results in some hilarious deaths.
16.
▲
Ask HN: Non-macOS Target Disk Mode
1 points
by
stonepresto
3y ago
|
0 comments
17.
▲
Welcome to the New GamersNexus Website v5.0: A Message
(gamersnexus.net)
55 points
by
stonepresto
3y ago
|
33 comments
18.
▲
by
stonepresto
3y ago
Threat intel and analysis is just like any other analysis, it is taking a heuristic approach to finding answers. Can it be bypassed? Yes. Are the researchers whose entire company hinges on the correctness of their analysis doing their absol
19.
▲
by
stonepresto
3y ago
Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the intern
20.
▲
by
stonepresto
3y ago
At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who do
21.
▲
by
stonepresto
3y ago
The USA loves aliens. And money. And my money is on this guy being a grifter.
22.
▲
by
stonepresto
3y ago
I assume the norm, or at least what they want to be the norm, is Huawei, Oppo, or Xiaomi. Regardless of what manufacturer or OS you use, it will not protect you from motivated nation states or companies like NSO. If you are truly concerned
23.
▲
by
stonepresto
3y ago
The why: notifying a suspect in a criminal investigation could allow them to flee or take measures to avoid prosecution, destroy evidence, etc.
24.
▲
by
stonepresto
3y ago
Or they're chasing threat actors, ransom groups, etc as part of a larger investigation.
25.
▲
by
stonepresto
3y ago
I'd like to put $5 on "ransomeware threat actors"
26.
▲
by
stonepresto
3y ago
What is the "so what" here? Are these internet connected?
27.
▲
by
stonepresto
4y ago
I think as it currently stands that's still the case, however with Epic at the helm there's indeed a high risk of negative changes.
28.
▲
Show HN: Xamarout, a WIP Python framework for xamarin files
(github.com)
1 points
by
stonepresto
4y ago
|
0 comments
29.
▲
by
stonepresto
4y ago
The fewer theocratic dictatorships with nukes the better. Its not that "Iran" as a construct having nukes is bad, its that the decisions to launch them lie with a few religious zealots who are known to not make good moral or ethic
30.
▲
by
stonepresto
4y ago
Some phones have a keypad scrambler to somewhat mitigate this sort of thing. At least from a distance.
More ›