I didn't mean to trivialize the issue. You describe a problem that arise when multiple parties share data with "presumptions of trustworthiness" i.e. do not perform proper input validation. No?
HN user
a1a
Wow, this is a Hyper-V breakout! I am amazed that it's 2024 and we still have problems with basic input validation.
I looked briefly at the encoder and it looks like the ad names are truncated on the size 32. Not sure why the threat actor would do that do. I guess they need some size limitation and just picked an arbitrary number
Yes, if I interpret your suggestion correctly. How would you know that the attacker have not manipulated the size parameter?
That's the best case. Worst case you end up with a memory vulernability (see heartbleed https://xkcd.com/1354/)
Think there is a need for a clarification. It says _member states_ of EU have trackers on their websites. Not EU itself.
1) Is that really a bad thing? Isn't it generally a good thing that law enforcement finds law-breakers?
2) So do drunk drivers that crash.
3) You're arguing against yourself. Yes, it's bad that bad guys get notified so they can avoid checkpoints.
4) Shouldn't law enforcement spend their time enforcing the law? It's well spent time IMO. As you say in (1), they also solve other more serious crimes (e.g. finding wanted criminals)
Author here. Thanks for your comment. I think you have a valid point about users clicking anything. However I would only say that's the case if you send around 20 phishing mails. In a targeted attack you want to send one or two phishing mails and you wanna maximize your chances of success to avoid a reaction from the blue team.
I agree that the impact is low compared to other vulnerabilities. It is definitely the case that you get a t-shirt (at best) for it. Though, my point is that they could be critical for the users, not for the website itself. An attacker that don't really care about the vulnerable website can still exploit the trust in the vulnerable website to perform attacks on the user he is interested in (e.g. hash stealing or malicious redirects). In fact, I believe malicious redirects is a really common payload of XSS flaws.
Firstly, it is not possible to opt out of facebook. [1] And they do indeed collect private data that we didn't choose to share (shadow accounts, third party website trackers, etc).
Facebook have broken "actual laws". There are so many cases were facebook have broken the law. [2] [3]
Also, please read up on Fallacy of relative privation ("not as bad as").
[1] https://boingboing.net/2017/11/08/involuntary-profiling.html
[2] https://www.theguardian.com/technology/2018/feb/12/facebook-...
[3] https://techcrunch.com/2018/02/19/facebooks-tracking-of-non-...
So that's why there is no gravity over there?
Seriously though, the statement is ignorant at best. Please help me understand the point of posting it?
I'd recommend deleting all content associated with the account and removing the address from any third party site (recovery etc).
I would however never actually delete the account.
My concern with deleting the account is that it exposes you to some really nasty impersonation attacks. It is free to keep. Just keep it.
Just had to test what the other keys did.
What i found:
t = search file
j/k = move down/down (selected file)
w = select branch
s = focus search field
y = expands url
Anyone know any more?
EDIT: Found this https://help.github.com/articles/using-keyboard-shortcuts/
That's one of the main takeaways from the story tho. In an open office those who need silence cannot get it, even if there are private rooms available: "Some of us even feel that escaping to a quiet room is a sign of weakness" and "it can feel as if we’re not pulling our weight if we’re not present"
Most definitely. In my experience ideas are rarely valuable by themselves. Rather an idea is valuable when implemented by someone who have what it takes to see it through.
Simply put, not a lot of people have what it takes just because they filed a patent.
How? I bet most commercial VPN services rotates on billions of different IPv6 addresses (from completely different subnets that is).
Better keep your real laptop at a safe distance unless you want VM escape --> Bluetooth propagation --> pwned.
Any reliable source? This is quite the accusation
I don't think they are comparable. I run both. NoScript is a security suite – besides blocking java, webgl, flash, silverlight, javascript, etc – it has additional defenses against XSS, ABE, clickjacking etc.
uBlock was to my knowledge never developed to securely stop scripts and deter drive-by attacks etc. It should be used for adblocking, not for security.
"Any headline that ends in a question mark can be answered by the word no."
https://en.wikipedia.org/wiki/Betteridge%27s_Law_of_Headline...
To be fair, if it was a con
1/2) Hijack identity of someone reputable
3) Create scam device
4) Film a video that looks like a DEFCON speech. Some simple video editing should fix the face. Voice likely doesn't matter. Start speech by saying "oh this talk is not listed, we changed topic last second"
5) Hack blog and post bogus article
6) Profit
TLDR still not likely
Technically speaking they could target VPN users by infecting uploaded files with a simple trojan that pings home to a server, I assume you disable VPN after the download is complete.
I really dig the login system!
I thought it should be vulnerable to 1. find hash on victim's profile, 2. login using the hash + username
But it seems the hash is never actually submitted to the server, neither through the login form nor later on by cookie. That is good news! The implied hurdle is that you'll need to update the hash on each login.
I just wrote a comment in another thread about bug bounties being cheap. Assuming you work 8 hours a day, your hourly salary would be $83,3. Wow!
Do you think your frequency is somewhat maintainable? I myself dream about working full time with bug hunting but have only gotten to a point where I report a few bugs on a hobby basis. To me it feels weird skipping my consultant salary for small payments and sometimes even a "good job dude, here's a t-shirt".
These programs are great in the sense that companies are starting to accept security research and appreciate responsible disclosure instead of non/full disclosure.
However, and I know this is not a popular opinion and that most people argue they do it "just for fun". But in my mind the "just for fun" argument is nothing more than an excuse for letting large corporations* use you. Seriously, swag? Your hourly salary is minimal wage. What about all the time you spend studying? You should get payed like everyone else. Even if you really think it is that much fun, why wouldn't you want to be able to make a living out of it? Your knowledge should be (and are!) valuable.
I don't really have a solution. Maybe time is the answer. Globalization does not make it easier as the bounties are quite large from the perspective of some countries.
What do you guys think? I think it is time we start valuing our knowledge. No one will do it for us.
* If it is a start-up, non-profit, or a corporation you believe makes the world a better place the situation is different, obviously. Nothing wrong with volunteering your knowledge.
I assume they would implement a white-list allowing "some non-intrusive adds" similar to Adblock.
In theory it would be great to if the fine was based on the extra profit generated from using the super cookie (compared to using a legal cookie). Next thing to take in to account is the degree/duration of the privacy violation and multiply this number by the number of users who have had their privacy violated.
Deciding this number is beyond my economics skills -- and quite beyond my point -- because I want to say that it is more reasonable to base the fine on the actual violation and not the business as a whole.
Schneier's Law comes to mind
"Anyone, from the most clueless amateur to the best cryptographer, can create an algorithm that he himself can't break."
https://www.schneier.com/blog/archives/2011/04/schneiers_law...
>If so, I'm expecting the same reaction in the future about google analytics.
1) Google analytics is a service for tracking your visitors behavior.
2) Facebook like button is a like button.
You would be surprised if the "like button" silently tracked your visitors behavior -- just as you would be surprised if the "analytics script" silently liked googles own facebook page.
>From the other hand, {facebook,google,random company} did not force someone to put the appropriate {buttons,code} in their site.
They are not getting sued for forcing someone. They are getting sued for adding unwanted/unadvertised functionality that undermines the right to privacy into their service.
US is not the highest paying country. Not in the absolute sense -- and definitely not in a relative to living cost sense.
http://www.bloomberg.com/visual-data/best-and-worst//highest...
I disagree. I believe education is an excellent way to free the north korean people from the brainwashing machine that is the DPRK.
More DPRK people with the hacker mindset (e.g. not just accepting answers but asking questions, a hunger for knowledge, etc) would in the long term be a really great thing for everyone but the leaders of DPRK.