Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
troyhunt
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
troyhunt
4y ago
Not at all, I continued writing a lot on Twitter and still love the product. I don’t like the way they’re handling this situation though, more in this vid from a few days ago: https://www.troyhunt.com/weekly-update-289/
2.
▲
Stupid security things
(troyhunt.com)
609 points
by
troyhunt
9y ago
|
159 comments
3.
▲
Where the Apple accounts hackers are threatening to wipe came from
(troyhunt.com)
3 points
by
troyhunt
9y ago
|
0 comments
4.
▲
by
troyhunt
13y ago
Try this: http://www.troyhunt.com/2013/12/working-with-154-million-rec...
5.
▲
by
troyhunt
13y ago
This might answer your question: haveibeenpwned.com/HowFastIsAzureTableStorage/?email=foo@foo.com I'm writing up how the back end is done and will post it in the next day or two, IMHO it's massively impressive but also v
6.
▲
by
troyhunt
13y ago
Oh hey, welcome back :)
7.
▲
by
troyhunt
13y ago
The viable alternative is in the sentence you quoted: "Ultimately, password hints are evil and they add nothing to an online system that can’t be achieved with a secure password reset feature." Secure password reset.
8.
▲
by
troyhunt
13y ago
Hey, thanks for pointing that out, that's the second time I've heard that recently. I think Ghoetery is getting a little over-excited and hiding the parent element containing Disqus which also contains the body of the post. I'
9.
▲
Disassembling the privacy implications of LinkedIn Intro
(troyhunt.com)
1 points
by
troyhunt
13y ago
|
0 comments
10.
▲
Your corporate network is compromised: are your internal apps ready for attack?
(troyhunt.com)
3 points
by
troyhunt
13y ago
|
0 comments
11.
▲
For your security, please email your credit card and driver’s license
(troyhunt.com)
84 points
by
troyhunt
13y ago
|
67 comments
12.
▲
Everything you wanted to know about SQL injection (but were afraid to ask)
(troyhunt.com)
4 points
by
troyhunt
13y ago
|
0 comments
13.
▲
Your website has never been hacked (except for all the times that it has)
(troyhunt.com)
2 points
by
troyhunt
13y ago
|
0 comments
14.
▲
How to build (and how not to build) a secure “remember me” feature
(troyhunt.com)
253 points
by
troyhunt
13y ago
|
64 comments
15.
▲
Understanding the risk of mixed content warnings
(troyhunt.com)
1 points
by
troyhunt
13y ago
|
0 comments
16.
▲
Your login form posts to HTTPS, but you blew it when you loaded it over HTTP
(troyhunt.com)
4 points
by
troyhunt
13y ago
|
0 comments
17.
▲
by
troyhunt
13y ago
It's harder to detect the framework when ASP.NET MVC is used. No view state in the source code, no .aspx extensions and the server response headers identifying IIS and ASP.NET can be removed. There's always HTTP server fingerprinting but yo
18.
▲
by
troyhunt
13y ago
There's a good NuGet package for dealing with this now: http://brendanforster.com/blog/custom-server-headers-bad-for...
19.
▲
by
troyhunt
13y ago
What it shows is that the server is not configured to return a custom error page when an exception occurs. Beyond the obvious usability issue, this may be used by an attacker to identify sites that leak internal information. It's not a vuln
20.
▲
by
troyhunt
13y ago
Because rightly or wrongly, there's evidence that it increases consumer confidence and results in more purchases / subscribers / customer love. It's an empty promise, but people buy it anyway.
21.
▲
Your Mac, iPhone or iPad may have left Apple with a serious security risk
(troyhunt.com)
17 points
by
troyhunt
13y ago
|
3 comments
22.
▲
by
troyhunt
13y ago
If there was something worth protecting on a personal blog site, it might be a different story. 1 is very on-topic - there's no way that data should be sent in the clear. HSTS is good, but unfortunately only partially supported. Agree on th
23.
▲
by
troyhunt
13y ago
Years and years of experience? Often not, and that's speaking from years and years of experience! Vast sums of money? Yes, at least the outsourcing vendors who churn this sort of thing out. Unfortunately you're the exception Mark so good on
24.
▲
Are we ready to do our banking via Facebook?
(troyhunt.com)
1 points
by
troyhunt
14y ago
|
0 comments
25.
▲
Should websites be required to publicly disclose password storage strategies?
(troyhunt.com)
5 points
by
troyhunt
14y ago
|
2 comments
26.
▲
Lousy ABC cryptography cracked in seconds as Aussie passwords are exposed
(troyhunt.com)
3 points
by
troyhunt
14y ago
|
0 comments
27.
▲
Operating system SmackDown: Windows 8 blitzes XP on 7 year old hardware
(troyhunt.com)
22 points
by
troyhunt
14y ago
|
1 comments
28.
▲
The ghost who codes: how anonymity is killing your programming career
(troyhunt.com)
3 points
by
troyhunt
14y ago
|
0 comments
29.
▲
What is LOIC and can I be arrested for DDoS'ing someone?
(troyhunt.com)
1 points
by
troyhunt
14y ago
|
0 comments
30.
▲
by
troyhunt
14y ago
Which bit was that Toshio? I can't see any MS defending, the post essentially said "This is what's happening, here's what to expect, these are some of the considerations". Whether what MS has done around OS and browser integration is wrong
More ›