Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ylk
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
1.
▲
AI agents imperiled by critical vulnerability in open source package
(arstechnica.com)
7 points
by
ylk
4mo ago
|
0 comments
2.
▲
by
ylk
4mo ago
The URL was meant to be https://badhost.org , the site accidentally still has the old canonical meta tag.
3.
▲
BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
(badhost.org)
126 points
by
ylk
4mo ago
|
51 comments
4.
▲
by
ylk
5mo ago
You're correct, thank you. Sadly I can't edit my comment anymore. Sorry for the confusion.
5.
▲
by
ylk
5mo ago
There are (illegal) marketplaces initial access brokers sell session cookies on. Some companies try to defend against that by e.g. checking whether it's even possible that you travelled from place A to place B within a certain timefram
6.
▲
by
ylk
5mo ago
For reference, this is how Google says Chrome stores passwords encrypted in memory and uses an elevated service to prevent other processes from impersonating Chrome and gaining access to the plain text passwords: https://security
7.
▲
by
ylk
7mo ago
This is not how CVEs work at all. You can be pretty vague when registering it. In fact they’re usually annoyingly so and some companies are known for copy and pasting random text into the fields that completely lead you astray when trying t
8.
▲
by
ylk
7mo ago
> The baseband can do a lot, it has dma There's an IOMMU: > Is the baseband isolated? > Yes, the baseband is isolated on all of the officially supported devices. Memory access is partitioned by the IOMMU and limited to interna
9.
▲
by
ylk
1y ago
fwiw, they're using CVSSv3. In CVSSv4, it's probably an 8.7: https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L...
10.
▲
by
ylk
1y ago
> Android 16 no longer provides device trees for Pixels as part of the Android Open Source Project. It's important to note it doesn't provide those for any other devices. There are no other OEMs providing similar AOSP support.
11.
▲
by
ylk
1y ago
The screen is a 16:10 screen with some extra pixels added next to the notch. By default, the system uses a resolution of 1512x982 (14"), which you can change to 1512x945 (16:10) to move the menu bar below the notch and end up with blac
12.
▲
by
ylk
1y ago
You don’t have to assume, the docs in the repo tell you that it does run a Linux kernel in each VM. It’s one container per VM.
13.
▲
by
ylk
1y ago
Not trying to argue that this happens regularly, but some recent (last 6 months or so) minted update contained breaking changes.
14.
▲
by
ylk
2y ago
> a feature that can only be appreciated by a subculture of people (privacy advocates) Just because it can’t be “appreciated” by all users doesn’t mean it’s only “for” a small sub-group. It seems to me they’re just trying to minimise the
15.
▲
by
ylk
2y ago
What you write sounds plausible at first, but then there’s this example from the German KSK: „In 2018, the German Federal Criminal Police Office uncovered a plot involving unknown KSK soldiers to murder prominent German politicians such as
16.
▲
by
ylk
2y ago
It’s recommended to have at least two anyway, to still have access to your accounts in case one is lost. That means you can keep one key at your desktop and you’d only need to go up to get your keys when adding them to an account.
17.
▲
by
ylk
2y ago
I agree that it's annoying that there's now a limit on the amount of credentials you can store on hardware keys. But while older Yubikeys only support 25 resident keys, models with firmware 5.7 onwards support 100. That probably m
18.
▲
by
ylk
2y ago
Just use a password manager that doesn't sync by itself then https://keepassxc.org/docs/KeePassXC_UserGuide#_passkeys
19.
▲
by
ylk
2y ago
I’m saying most people who do phishing likely don’t care to implement passkey detection to display a relevant error message to the user, as it’s not worth the effort, as of now
20.
▲
by
ylk
2y ago
There are syncable and hardware-bound passkeys and you are free to use a password manager that syncs your passkeys. iPhones don’t even let you create a passkey with the built in password manager if you have synchronisation disabled. I don’t
21.
▲
by
ylk
2y ago
Register a passkey on a different device or get a hardware key or whatever. Or call Microsoft support and complain to them. This doesn’t feeling like an honest discussion anymore.
22.
▲
by
ylk
2y ago
Honestly don’t care to spend time on looking up the various states of 2fa proxies. But I’ve learnt so far that attackers don’t build/use the most advanced tooling you can think of at all times. They often use the simplest thing that ge
23.
▲
by
ylk
2y ago
Find your phone: https://www.icloud.com/find/ Scanning a QR code: https://support.apple.com/en-us/102680 The time investment could even be worth it, since "Signing in with a passkey is three
24.
▲
by
ylk
2y ago
> In the case of those services you mention, passkeys are nothing but convenience; they provide no extra security. They do provide extra security, in that they ensure that you're on the correct domain instead of a phishing site.
25.
▲
Security Audit of Backstage
(x41-dsec.de)
1 points
by
ylk
2y ago
|
0 comments
26.
▲
by
ylk
2y ago
That’s for accessing the website, not for sending your traffic via TOR to Mullvad. I don’t think they have a built-in way to send traffic to them via TOR without going through an exit node.
27.
▲
by
ylk
2y ago
You can also mail them cash
28.
▲
by
ylk
2y ago
Link to Mullvad's blog post: https://mullvad.net/en/blog/the-report-for-the-2024-security...
29.
▲
Review of Mullvad VPN
(x41-dsec.de)
476 points
by
ylk
2y ago
|
203 comments
30.
▲
by
ylk
2y ago
> You certainly can run distros without systemd Does it then become not a full OS anymore? Mirage is what I linked to above.
More ›