HN user

a1a

549 karma
Posts18
Comments154
View on HN
blog.truesec.com 5y ago

How the Kaseya VSA Zero Day Exploit Worked

a1a
2pts0
stevetabernacle.github.io 7y ago

Open redirects – a vulnerability class no one but attackers cares about

a1a
154pts42
protonvpn.com 9y ago

ProtonVPN: VPN developed by the ProtonMail team

a1a
2pts0
www.reuters.com 9y ago

White House says Trump to sign broadband privacy repeal

a1a
3pts0
stevetabernacle.github.io 9y ago

Hacking static hosting services

a1a
2pts0
stevetabernacle.github.io 9y ago

Automated i3wm setups for Kali Linux

a1a
1pts0
stevetabernacle.github.io 9y ago

Duck Hacking – for fun and profit

a1a
1pts0
stevetabernacle.github.io 9y ago

JS trickery for in-browser HTML templating

a1a
1pts0
stevetabernacle.github.io 9y ago

GitHub as a free blogging platform with paywall functionality

a1a
4pts1
password-hashing.net 12y ago

Password Hashing Competition: Candidates wiki

a1a
1pts0
ideum.com 12y ago

Multitouch Coffee Tables

a1a
1pts0
live.wsj.com 12y ago

High Definition: What Is TV's Problem?

a1a
1pts0
blogs.gentoo.org 12y ago

Gentoo Monthly Newsletter: December 2013

a1a
1pts0
www.engadget.com 12y ago

HDMI 2.0 officially announced: 18Gbps bandwidth, 60fps 4K, 32 channel audio

a1a
2pts1
www.idsc.ethz.ch 13y ago

Individual vehicles self-assemble, coordinate, and take flight

a1a
2pts0
www.sciencedaily.com 13y ago

Just How Secure Is Quantum Cryptography?

a1a
1pts0
seclists.org 13y ago

Another XSS vulnerability and Paypal shows no response

a1a
18pts4
news.ycombinator.com 13y ago

Discuss: Should tattooing the correct answers on yourself be considered chating?

a1a
1pts0

I didn't mean to trivialize the issue. You describe a problem that arise when multiple parties share data with "presumptions of trustworthiness" i.e. do not perform proper input validation. No?

1) Is that really a bad thing? Isn't it generally a good thing that law enforcement finds law-breakers?

2) So do drunk drivers that crash.

3) You're arguing against yourself. Yes, it's bad that bad guys get notified so they can avoid checkpoints.

4) Shouldn't law enforcement spend their time enforcing the law? It's well spent time IMO. As you say in (1), they also solve other more serious crimes (e.g. finding wanted criminals)

Author here. Thanks for your comment. I think you have a valid point about users clicking anything. However I would only say that's the case if you send around 20 phishing mails. In a targeted attack you want to send one or two phishing mails and you wanna maximize your chances of success to avoid a reaction from the blue team.

I agree that the impact is low compared to other vulnerabilities. It is definitely the case that you get a t-shirt (at best) for it. Though, my point is that they could be critical for the users, not for the website itself. An attacker that don't really care about the vulnerable website can still exploit the trust in the vulnerable website to perform attacks on the user he is interested in (e.g. hash stealing or malicious redirects). In fact, I believe malicious redirects is a really common payload of XSS flaws.

Firstly, it is not possible to opt out of facebook. [1] And they do indeed collect private data that we didn't choose to share (shadow accounts, third party website trackers, etc).

Facebook have broken "actual laws". There are so many cases were facebook have broken the law. [2] [3]

Also, please read up on Fallacy of relative privation ("not as bad as").

[1] https://boingboing.net/2017/11/08/involuntary-profiling.html

[2] https://www.theguardian.com/technology/2018/feb/12/facebook-...

[3] https://techcrunch.com/2018/02/19/facebooks-tracking-of-non-...

Benford's Law 9 years ago

So that's why there is no gravity over there?

Seriously though, the statement is ignorant at best. Please help me understand the point of posting it?

I'd recommend deleting all content associated with the account and removing the address from any third party site (recovery etc).

I would however never actually delete the account.

My concern with deleting the account is that it exposes you to some really nasty impersonation attacks. It is free to keep. Just keep it.

That's one of the main takeaways from the story tho. In an open office those who need silence cannot get it, even if there are private rooms available: "Some of us even feel that escaping to a quiet room is a sign of weakness" and "it can feel as if we’re not pulling our weight if we’re not present"

Firefox 50.0 10 years ago

I don't think they are comparable. I run both. NoScript is a security suite – besides blocking java, webgl, flash, silverlight, javascript, etc – it has additional defenses against XSS, ABE, clickjacking etc.

uBlock was to my knowledge never developed to securely stop scripts and deter drive-by attacks etc. It should be used for adblocking, not for security.

To be fair, if it was a con

1/2) Hijack identity of someone reputable

3) Create scam device

4) Film a video that looks like a DEFCON speech. Some simple video editing should fix the face. Voice likely doesn't matter. Start speech by saying "oh this talk is not listed, we changed topic last second"

5) Hack blog and post bogus article

6) Profit

TLDR still not likely

I really dig the login system!

I thought it should be vulnerable to 1. find hash on victim's profile, 2. login using the hash + username

But it seems the hash is never actually submitted to the server, neither through the login form nor later on by cookie. That is good news! The implied hurdle is that you'll need to update the hash on each login.

I just wrote a comment in another thread about bug bounties being cheap. Assuming you work 8 hours a day, your hourly salary would be $83,3. Wow!

Do you think your frequency is somewhat maintainable? I myself dream about working full time with bug hunting but have only gotten to a point where I report a few bugs on a hobby basis. To me it feels weird skipping my consultant salary for small payments and sometimes even a "good job dude, here's a t-shirt".

These programs are great in the sense that companies are starting to accept security research and appreciate responsible disclosure instead of non/full disclosure.

However, and I know this is not a popular opinion and that most people argue they do it "just for fun". But in my mind the "just for fun" argument is nothing more than an excuse for letting large corporations* use you. Seriously, swag? Your hourly salary is minimal wage. What about all the time you spend studying? You should get payed like everyone else. Even if you really think it is that much fun, why wouldn't you want to be able to make a living out of it? Your knowledge should be (and are!) valuable.

I don't really have a solution. Maybe time is the answer. Globalization does not make it easier as the bounties are quite large from the perspective of some countries.

What do you guys think? I think it is time we start valuing our knowledge. No one will do it for us.

* If it is a start-up, non-profit, or a corporation you believe makes the world a better place the situation is different, obviously. Nothing wrong with volunteering your knowledge.

In theory it would be great to if the fine was based on the extra profit generated from using the super cookie (compared to using a legal cookie). Next thing to take in to account is the degree/duration of the privacy violation and multiply this number by the number of users who have had their privacy violated.

Deciding this number is beyond my economics skills -- and quite beyond my point -- because I want to say that it is more reasonable to base the fine on the actual violation and not the business as a whole.

>If so, I'm expecting the same reaction in the future about google analytics.

1) Google analytics is a service for tracking your visitors behavior.

2) Facebook like button is a like button.

You would be surprised if the "like button" silently tracked your visitors behavior -- just as you would be surprised if the "analytics script" silently liked googles own facebook page.

>From the other hand, {facebook,google,random company} did not force someone to put the appropriate {buttons,code} in their site.

They are not getting sued for forcing someone. They are getting sued for adding unwanted/unadvertised functionality that undermines the right to privacy into their service.

I disagree. I believe education is an excellent way to free the north korean people from the brainwashing machine that is the DPRK.

More DPRK people with the hacker mindset (e.g. not just accepting answers but asking questions, a hunger for knowledge, etc) would in the long term be a really great thing for everyone but the leaders of DPRK.