HN user

Magicstatic

415 karma
Posts43
Comments34
View on HN
security.googleblog.com 2y ago

Android Goes All-In on Fuzzing

Magicstatic
2pts0
twitter.com 4y ago

Security researcher receives $1M bug bounty for saving company from $350M bug

Magicstatic
53pts5
www.eff.org 5y ago

EFF's reply to cease-&-desist letter – “Virtual Coachella” parody video

Magicstatic
230pts35
www.startuptucson.com 5y ago

City of Tucson, AZ invites remote workers with over $7,500 in benefits

Magicstatic
3pts0
imgur.com 7y ago

Gmail conversation between Steve Chen and an early YouTube user (2005)

Magicstatic
2pts0
twitter.com 8y ago

Ethical hacker makes $120k USD in one week hacking EOS smart contracts

Magicstatic
25pts0
www.jonbottarini.com 8y ago

Abusing Internal API to Achieve IDOR in New Relic

Magicstatic
1pts0
twitter.com 9y ago

HackerOne passes $18M in bounties paid out to hackers

Magicstatic
3pts0
storage.googleapis.com 9y ago

Google Widevine DRM 2017 Architecture Overview [pdf]

Magicstatic
2pts0
www.jonbottarini.com 9y ago

(SFW) Penetrating Pornhub – Hacking PornHub for $$$ and Tshirts

Magicstatic
1pts0
www.jonbottarini.com 9y ago

Bypassing Apple's iOS 10 Parental Restrictions – Twice

Magicstatic
1pts0
workplace.stackexchange.com 9y ago

How does one politely decline a handshake due to religious reasons?

Magicstatic
2pts0
pages.payments.amazon.com 9y ago

Amazon Payments Becomes Amazon Pay – Rebranding

Magicstatic
4pts0
www.unmannedsystemssource.com 9y ago

Apple May Harness Drone Technology to Improve Maps Accuracy

Magicstatic
2pts0
ftp.arl.army.mil 9y ago

Ftp.arl.army.mil – One of the first 50 web servers on the internet

Magicstatic
2pts0
support.google.com 9y ago

Google lets users see pictures of cats instead of ads using Contributor program

Magicstatic
2pts0
www.deepmind.com 10y ago

Google DeepMind (Formerly Known as DeepMind Technologies)

Magicstatic
1pts0
medium.com 10y ago

Apple Music and Siri are being used by fake artists to collect music royalties

Magicstatic
2pts0
www.autodialerauthority.com 10y ago

Uber hit with potential class action lawsuit due to TCPA violations

Magicstatic
1pts0
www.wiyre.com 10y ago

SpyFu Keyword Research Tool – Complete Review (2016 Edition)

Magicstatic
2pts0
www.wiyre.com 10y ago

A Guide for Webmasters: How to Disable Ad Blockers from Your Site

Magicstatic
2pts1
www.wiyre.com 10y ago

List of Cheapest Domain Name Renewals

Magicstatic
2pts0
www.wiyre.com 10y ago

The Anatomy of a Craigslist Cashiers Check Scam

Magicstatic
1pts0
en.wikipedia.org 10y ago

Wikipedia editor states that Hillary Clinton never attended Bilderberg Meetings

Magicstatic
3pts0
www.wiyre.com 10y ago

Huge list of free stock photo websites

Magicstatic
1pts0
www.wiyre.com 10y ago

Review of Coin 2.0 – The electronic credit card from onlycoin.com

Magicstatic
1pts0
www.reddit.com 10y ago

“I hate being referred to as an entrepreneur” (/r/entrepreneur)

Magicstatic
1pts0
www.freepatentsonline.com 11y ago

Apple Inc. Patent #9059950 “Delivering and tracking viral invitational content” [pdf]

Magicstatic
3pts1
www.autodialerauthority.com 11y ago

FCC Approves new autodialer restrictions to protect consumers

Magicstatic
2pts0
www.google.com 11y ago

Bank of America Patent Application #20140229239 – “Face Retirement Tool”

Magicstatic
51pts48

This is the craziest part of the whole article - imagine you wanted to own something like "555-FOOD" - to have this vanity number work in every area code, you'd be looking at hundreds of thousands of dollars (annually?) if you used Verizon to route the calls

Anecdote: Out of every bank and financial institution I have ever tried hacking (ethically, as part of bug bounty programs) Goldman Sachs is hands down, without a doubt, the most secure externally. By a long shot. They have what basically amounts to a central authentication service that 95% of their public facing IP’s resolve to. Their sub domains are locked down, they have a reasonably good patch schedule, they swiftly denylist your IP after running light scanners - it’s not a joke. I challenge you to find a vulnerability - when you do - get some money for it: https://hackerone.com/goldmansachs

Many of us including myself are unable to fathom living a life like this, but I imagine this man will die in peace with a flock of sheep to his name, listening to the cuckoos.

And he will be just as happy (if not happier) as any of us reading this article.

Sincere question - not meant to be inflammatory: Do you actually believe that most employees in the United States are coerced/forced to sign employment contracts, or are you simply playing devil's advocate?

My favorite part of this response is in the footnote on page two, which states:

If your client sincerely fears that this depiction is too realistic to be perceived as parody, Krazam’s video should be the least of its reputational concerns.

Followed by screenshots from the video showing the DocuSign "Docustage" and Meme Center (Sponsored by GE). At the end of the video itself, the Coachella participant is banned from the event because their "vibes are not compliant with the Coachella policy".

Glad EFF stepped in here to protect small creators such as this one.

Is this a security problem? Depends on who you ask - but I'm willing to bet it would fall into the "accepted risk" category for the Facebook security team if they had to evaluate this.

The reality is that phone number lookup services are available all over the web which provide even more information (first+last name, address, zip code, social media profile links, etc etc etc) for free (https://www.bestfreephonelookup.com/phone-number/ as an example) - these services get their info from data aggregators and usually - your carrier! I don't see how Facebook exposing (in _limited_, very specific circumstances) the first name of a persons phone number being a security issue.

All the people in this thread screaming GDPR violation don't understand that if someone decides to stop using Facebook and delete their account, this method to lookup someone will not work. Sidenote: If you're really paranoid about having your phone number expose your real name when you're using any type of service online, just sign up for a Google Voice (voice.google.com) account and link it to your cell phone - I use this whenever I sign up for anything online and it saves me a ton of spam and scam calls.

EDIT: Facebook removed the ability to use the in-app search box in Facebook to find people based on just a phone number, this has been removed for at least 2 years.

I don’t even know where to start with this post:

- This isn’t even necessarily a hack. At best, this is a mild inconvenience to the user accounts that you are locking out, on what appears to be a legacy system, due to a quasi-brute force.

- You are “hacking” this company, without their permission, because you want “payback” that Amazon didn’t hire you for what you perceive to be a racially opinionated interviewer. Despite whether this theory (yes, it is purely speculation) is true or not, I would imagine this is HR 101 and a company as large as Amazon would go to great lengths to ensure that this is not the case.

- Your sense of entitlement goes even further, despite having illegally “hacked” a company, after all of this you expect a payment from them?

If anything, this post reaffirms that they made the right decision in not hiring you for the role you were being considered for, and guarantees that you won’t have an opportunity to interview again.

As a researcher, I am incredibly, incredibly excited to see H1 grow and more companies come online. I pay a good portion of my rent through bug bounties and I have to admit the gamification and ease of working with H1 makes it fantastic for someone like me.

As with most events that have occurred since Trump took the presidency, I am concerned, but optimistic. She has my full support, I hope she makes great changes to a system that desperately needs it.

I usually have them for other projects I am working on - rarely do I purchase a domain just to let it sit there, but that's just me.

Not in the market to domain squat... gotta put them to use somehow.

Probably around 20.

My best one: Legal18s.com

I totally want to create a portal for "young professionals who want to study the intricacies of law and legal issues that we face today as a nation" just as a joke. I have no real plans for the domain.

I think what's interesting is that Sacks was put into this position at the request of the board and shareholders. For the most part, this will be a interesting transition for Zenefits as they deal with the wave after wave of bad news...

So disappointed that when I visit reddit.horse now it doesn't show a badly photoshopped picture of Snoo riding a horse...

Here is a message I received from Gandi.net regarding the .blog domain:

-----------------

Hello,

You are getting this email because you have performed a pre-order with your handle {redacted} for the domain name {redacted}.

Unfortunately, this order is currently in error, because the domain name in question has been defined as Premium by the registry. This decision is of course beyond our control and frequently corresponds to a list of common and/or connotative words that allow registered to apply special rates to them.

This means that in your case, we have placed the order in error, because the price that you initially paid is no longer the price that the registry is charging for it.

If you would like to know the price, in order to eventually purchase it, then reply to this email, so that our support team can obtain that for you from the registry.

As long as you are considering this, do not cancel your order, since this will cause you to lose your place in the waiting list.

If, however, you no longer wish to register the domain, you can cancel it from the link provided below, and your prepaid account will be refunded for the order: