Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xyzeva
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Friend.com's encryption is just plaintext
(twitter.com)
23 points
by
xyzeva
11mo ago
|
2 comments
2.
▲
How to gain code execution on hundreds of millions of people and popular apps
(kibty.town)
1156 points
by
xyzeva
2y ago
|
319 comments
3.
▲
Gaining access to anyones Arc browser without them even visiting a website
(kibty.town)
1469 points
by
xyzeva
2y ago
|
498 comments
4.
▲
by
xyzeva
2y ago
i think you're missing the fact that that indeed is not a security email, and the engineering/security email i found bounced. i had no ill intentions. stop pretending i did.
5.
▲
How to pwn a billion dollar VC firm using inspect element
(kibty.town)
11 points
by
xyzeva
2y ago
|
1 comments
6.
▲
You Suck at Securing S3, Here's Why
(env.fail)
5 points
by
xyzeva
2y ago
|
0 comments
7.
▲
by
xyzeva
3y ago
It is for the sites, not Firebase.
8.
▲
by
xyzeva
3y ago
Sadly, most developers don't know this and continue to write from frontend, almost all of the apps and websites we found did this.
9.
▲
by
xyzeva
3y ago
I agree for the most, but there was some good apples (even though very few) that were very thankful and fixed it fast.
10.
▲
by
xyzeva
3y ago
True, but also better than threat actors getting to it and dumping the DB, causing more problems for the customers.
11.
▲
by
xyzeva
3y ago
What'd you expect, its google!
12.
▲
by
xyzeva
3y ago
I agree! Supabase does it pretty good.
13.
▲
by
xyzeva
3y ago
I agree, but I also disagree. The concept with firebase DB's is flawed IMO, I never got the point of directly accessing a DB in the frontend, or allowing that even with security rules, it just seems like it would cause problems.
14.
▲
by
xyzeva
3y ago
We believe the gambling ring is based in Indonesia, which is uncommon to use Line, but they seem to be using it here for all of their customer support across all sites.
15.
▲
by
xyzeva
3y ago
I really doubt that this will be google's downfall, theyre too big to fall right now. I think it will be laws.
16.
▲
by
xyzeva
3y ago
Yeah, funny how that works. Services as time goes on makes making websites easier, and abstracts more stuff, which makes devs oblivious to what they have to configure.
17.
▲
by
xyzeva
3y ago
Thank you! Means a lot, helps us keep going.
18.
▲
by
xyzeva
3y ago
Must've used the twitch chat dataset
19.
▲
by
xyzeva
3y ago
Python just isn't the language for this, really. Rewriting it is the only real solution, I don't know your exact problem.
20.
▲
by
xyzeva
3y ago
Setting up firebase security rules: https://firebase.google.com/docs/rules/
21.
▲
by
xyzeva
3y ago
Would work! If you're willing to write something, go for it. I'm personally way too exhausted right now.
22.
▲
by
xyzeva
3y ago
We confirmed that the gambling site is not fake data, I dont know about the lead one. Why we are saying its more is there is likely other services not in our scan list that could be vulnerable.
23.
▲
by
xyzeva
3y ago
Sadly, this is true, and theres probably much more. We did our best, sent customized emails to each of them, telling what was affected, how to fix it, and how to get in contact.
24.
▲
by
xyzeva
3y ago
It would, except if you have a f'ed up schema like most of these companies had.
25.
▲
by
xyzeva
3y ago
We decided to make a shared blog because we will likely have other projects we will do together, so all of us posting on our personal blogs on the same topic would be counterproductive
26.
▲
by
xyzeva
3y ago
On certain databases, yes We only scanned for firestore, which is a NoSQL database, conversion tools may still be possible, a good firebase alternative would be https://supabase.com , but please set up RLS, its IMO much easier th
27.
▲
by
xyzeva
3y ago
We tried to contact google, via support to try to help or for them to help disclose the issues to the websites. We got no response other then a response telling us that they will be creating a feature request on our behalf if we wanted inst