HN user

Shamiq

1,251 karma

Security

Posts76
Comments497
View on HN
patchworksecurity.com 10y ago

Pain in the PaaS: The Problem of Lagging Security Updates at Heroku

Shamiq
4pts2
patchworksecurity.com 10y ago

Show HN: Patchwork – Real-time notifications for OSS vulnerabilities

Shamiq
122pts49
www.activistpost.com 12y ago

TRO LLC: Hacktivist Hedge Fund Seeks Crowdfunding

Shamiq
3pts0
beust.com 12y ago

The pitfalls of Test-Driven Development

Shamiq
4pts0
arxiv.org 12y ago

An empirical study of passive 802.11 Device Fingerprinting

Shamiq
1pts0
h30499.www3.hp.com 12y ago

Double-Dip: Using the latest IE 0-day to get RCE and an ASLR Bypass

Shamiq
1pts0
insanecoding.blogspot.gr 12y ago

LibreSSL: The good and the bad

Shamiq
3pts0
www.defriendalert.com 15y ago

Defriend Alert

Shamiq
2pts2
www.scientificamerican.com 16y ago

Robot Pack Mule for G.I.s on the Move (Big Dog, Act 2)

Shamiq
1pts0
www.scientificamerican.com 16y ago

Bees Can Recognize Human Faces

Shamiq
4pts0
sethgodin.typepad.com 16y ago

Seth's Blog: Jumping the gun

Shamiq
9pts3
news.ycombinator.com 16y ago

Ask HN: Any junior Project Managers from MSFT here?

Shamiq
1pts0
www.wired.com 16y ago

MySpace/Imeem Deal Leaves Thousands of Artists Unpaid

Shamiq
17pts6
www.csmonitor.com 16y ago

Global warming: Indians decide to make their own glaciers

Shamiq
3pts0
news.ycombinator.com 16y ago

Ask HN: What's it take to start a telecom?

Shamiq
2pts0
news.nationalgeographic.com 16y ago

Googling Fights Dementia, Study Suggests

Shamiq
9pts1
www.perian.org 16y ago

Perian: QuickTime plugin for codecs

Shamiq
1pts1
www.wired.com 16y ago

Why Eggs Could Be Getting Harder to Peel

Shamiq
24pts15
www.nature.com 16y ago

Researchers [kinda] create portable black hole

Shamiq
1pts1
www.engadget.com 16y ago

OpenMoko branches out with new $99 WikiReader device

Shamiq
17pts10
www.wired.com 16y ago

Judge Refuses to Punish Lawyer for Anti-RIAA Blogging

Shamiq
12pts0
news.nationalgeographic.com 16y ago

"Surreal" Vegetarian Spider Found -- A First

Shamiq
1pts0
gizmodo.com 16y ago

Bloomframe Window That Transforms Into a Balcony

Shamiq
1pts0
news.nationalgeographic.com 16y ago

A Third of Dinosaur Species Never Existed?

Shamiq
49pts15
www.popsci.com 16y ago

Tool Smackdown: Pocket Multimeters

Shamiq
1pts0
en.wikipedia.org 16y ago

Graph coloring

Shamiq
2pts1
blogs.discovermagazine.com 16y ago

The next [Stephen] Hawking

Shamiq
3pts1
hackaday.com 16y ago

Just for fun: Barcode challenge

Shamiq
1pts0
www.scientificamerican.com 16y ago

Abruptly Forgotten: Working Memory Disappears in a Blink

Shamiq
1pts0
chargen.matasano.com 16y ago

Ruby For Pentesters - WIN32OLE

Shamiq
18pts3

Yea, I'm thinking about cases similar to HTTP parameter pollution, and what the program expectations are. You'd be right to argue environment variables should not be user controlled. :)

Will need to double check some machines to make sure these two don't bite me:

On Unix systems the environment variables SSL_CERT_FILE and SSL_CERT_DIR can now be used to override the system default locations for the SSL certificate file and SSL certificate files directory, respectively.

The os/exec package now prevents child processes from being created with any duplicate environment variables. If Cmd.Env contains duplicate environment keys, only the last value in the slice for each duplicate key is used.

That could be a decent hack to get started. Ideally, I'd like for it to be a feature of hackerone et al, assuming security@ as a service providers become the point of interaction with the external security community.

I would love a Marauder's Map for bug bounty programs: Show me who is working on what, where they're finding bugs, and help me identify where I can most efficiently spend my time. Lots of 'feel bads' if I report a bug that's already been reported, and thus don't get a payout.

You've got a point there, but I'd ask why not remove the packages that aren't being used? Here's some of the raw data about which system libraries are lagging in security patches:

  liblwres90 1:9.9.5.dfsg-3ubuntu0.6
  mysql-common 5.5.46-0ubuntu0.14.04.2
  libmysqlclient-dev 5.5.46-0ubuntu0.14.04.2
  libmysqlclient18 5.5.46-0ubuntu0.14.04.2
  rsync 3.1.0-2ubuntu0.1
  bind9-host 1:9.9.5.dfsg-3ubuntu0.6
  libisccc90 1:9.9.5.dfsg-3ubuntu0.6
  libisc95 1:9.9.5.dfsg-3ubuntu0.6
  dnsutils 1:9.9.5.dfsg-3ubuntu0.6
  linux-libc-dev 3.13.0-74.118
  libbind9-90 1:9.9.5.dfsg-3ubuntu0.6
  libxml2 2.9.1+dfsg1-3ubuntu4.6
  libdns100 1:9.9.5.dfsg-3ubuntu0.6
  libxml2-dev 2.9.1+dfsg1-3ubuntu4.6
  libisccfg90 1:9.9.5.dfsg-3ubuntu0.6

Cool idea -- I'll go get the golf clubs!

We'd love to be at the point where Patchwork notifications are ahead of public releases, and get you patched before the vulnerability is widely exploited. In fact, one of the crazy ideas we've been kicking around is how to detect 0days without installing an agent on production machines.

Sure thing! The service pivots around machines as it's core pilar. On a more fundamental level, we consider a machine to be the set of unique packages tracked together. So for your case, you'd spin up a pilot, run the script, then post the data to us. Since it's a new machine, we'll issue it a UUID, and track billing against that UUID. If you change the packages on a machine? That's a-okay! We'll use the same UUID, and bill accordingly :). When it's time to sunset a machine, use our soon to be released API to remove it, and billing stops!

To be totally honest, we're still working out all the wrinkles of how billing would work, what's fair to users, and how to track your usage, so feedback is greatly appreciated!

Great idea! We're looking to build out and extend a callback API so you can have it post data to whichever end point you want. Some integrations I've been toying with are: alerts in a slack channel, SMS notifications, push issues to git, get continuous integration to block unless it's 'ok', have it call my mom and have her yell at me till I patch my servers!

Hi all! I’m Shamiq, ex-Matasano and co-founder of Patchwork Security. David and I built Patchwork as a devops tool to help manage Open Source Vulnerabilities. We want to drive the time between an available fix and patched infrastructure to zero. We’d love for you to try it out, and let us know what you think!

We’ll be here all day answering comments or you can reach us at shamiq@patchworksecurity.com or david@patchworksecurity.com.

submit a pull request? find the dev who wrote it and ask if you can help get it patched? file an bug? same thing as finding any other type of bug, really. Just avoid sounding like an ass and you might make traction.

As a corollary: consider creating a better PoC for the bug.

I'm afraid of the security implications of another automated, hard to control, hard to see attack surface. I'm all for better infrastructure, but infrastructure is what historical comes under attack first when "shit hits the fan", and this seems like a great target and pipeline.

If you can help me make it secure, I'd love to help you design it.