Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
technion
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
technion
7d ago
The purchase of Tumblr was basically Elon purchasing Twitter without the political gain. I'm amazed the purchase decision was ever made, and more amazed that it still exists after the hit to the user base.
2.
▲
by
technion
8d ago
This might depend what you mean by code. In the sysadmin space I ask a web interface for poweshell to generate specific information multiple times a day, and pasting it into a terminal is really the cleanest workflow on a corporate machine
3.
▲
by
technion
9d ago
Vmware vsphere is not at all in the consumer space where virtualbox exists.
4.
▲
by
technion
13d ago
Ai cant make a static HTML page sitting on something like cloudflare pages have an rce bug.
5.
▲
by
technion
13d ago
Every static HTML pages built this way with ai is another WordPress site that wont get built by contractors just to be neglected, compromised, and used to launch phishing and ransomware attacks.
6.
▲
by
technion
16d ago
To give my example, if you search for locksmiths or plumbers or any sorts of trades you'll land on a page for "small family locksmith in your small suburb name". Except the site has thousands of urls with the same exact conte
7.
▲
by
technion
16d ago
It's not just elderly parents. I've sat in on many an incident where skilled people in accounts or HR similarly saw and ad and thought "I have to do this thing", leading to compromise.
8.
▲
by
technion
28d ago
In the last twelve months ive had electricians, plumbers, kitchen renovators all work in my home while I was wfh. In an age gone by I would burn annual leave to deal with this. I dont know how I could handle the logistics of full in office
9.
▲
by
technion
1mo ago
On one hand yes, but on the other hand just configuring your server to refuse connections by IP address rather than server name seemed to drop roughly half the bots I ever see.
10.
▲
by
technion
1mo ago
I'm confused at the way they promoted it. Is there any way someone outside the company reading a Twitter post would consider this a positive thing for the product to be told what incentives the sales team get?
11.
▲
by
technion
1mo ago
Im supposed to be doing endpoint work with people working in this field amd basically have to convince compliance they'll need to be local administrators to do their job. They get onsite and dont know what app they'll need until t
12.
▲
by
technion
1mo ago
Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those dom
13.
▲
by
technion
1mo ago
As someone managing dns for a lot of orgs, the part that kills me is the amount of crappy sass'es that demand you add a big include to your spf. If they already have a skim record thats plenty to get mail through, except their validato
14.
▲
by
technion
2mo ago
Companies make this hard, a bit like various email scams where legit company communication comes from seemingly random domains (hello paypal). Often the company is legit, but theres no public contact that knows anything about the recruiter
15.
▲
by
technion
2mo ago
Compromising a crappy wordpress site means compromising mailbox credentials. https://lolware.net/blog/2020-09-02-autodiscover-circus/
16.
▲
by
technion
2mo ago
This isn't LinkedIn specific - the easily misclickable "one click to logon with Google" button showing up in browsers was a huge mistake and should never have existed. Reddit has started prompting too if you're not curre
17.
▲
by
technion
2mo ago
Making them "fashionable" seems to be a selling point, as seen woth the last advertising positioning largely to the woman's fashion industry. They are definitely aiming to not look like nerdy tech.
18.
▲
by
technion
2mo ago
There's an astounding amount of .DS_Store showing up - I hadn't realised how common it apparently is for people to accidentally upload this.
19.
▲
by
technion
3mo ago
Our helpdesk deals with 2-300 users per day that logon every single day yet forgot their password. This type of thinking doesn't work in large enough orgs dealing with end users.
20.
▲
by
technion
3mo ago
Vulnerable dependencies are very different to compromised or backdoored dependencies though. Noone's taking over Solarwinds because their build tools had a ReDOS involving input from their own config files.
21.
▲
by
technion
3mo ago
I'm reading the ZeroBounce docs and it seems very relevant. Look at this step: "We recheck all unknown emails using IPs from different geographical locations". This matches exactly what this article describes as getting these
22.
▲
by
technion
3mo ago
All of them. My personal tax agent only accepts forms and sends them back via email. I had a conversation with him about using password protected zips and he just told me he won't accept them. My hospital sent me a PDF that I was to fi
23.
▲
by
technion
3mo ago
Yeah, it did always get me as a design issue. I get that "there's more to ask them" is valid. But there's never an indication of "OK I've said everything now". You only find out when they start repeating t
24.
▲
by
technion
3mo ago
If they run a mortgage broking business, they should have a very different experience to what's described in this post about setting up like a personal machine. They presumably have business managed Microsoft accounts, none of that set
25.
▲
by
technion
3mo ago
As an Australian.. politically I need to worry about business data touching China. It will come up at a Risk Advisory Committee meeting as a serious issue. In actual personal practice, no. China having my data presents no actual impact to m
26.
▲
by
technion
3mo ago
You can find the link to the victims leaks page and screenshots of it working right here: https://www.ransomlook.io/group/the%20gentlemen They appear genuinely prolific.
27.
▲
by
technion
3mo ago
A lot of those same people seemed perfectly capable of insisting on 60 day password rotation back when they could use nist guidance as an authority to appeal to (for about five years after the recommendation changed too).
28.
▲
by
technion
3mo ago
Claude, for my non Gmail domain, expects me to click a magic link on every device I wish to use it. Its wild that a product like that cannot take a password, or a passkey.
29.
▲
by
technion
4mo ago
Ten times shorter just means "readable without losing an excess of time on ramble" and I feel like someone's comeback to this will be "you should ask an AI to summarise".
30.
▲
by
technion
4mo ago
The researcher's own statements note that the zero days were not found with AI. And honestly I think that's the part that Microsoft is most upset about, because every internal partner conversation I've had has been about need
More ›