HN user

elnerd

18 karma
Posts2
Comments21
View on HN

I once got a wildly inaccurate billing estimate shortly after I created my AWS account. I could not find a out which resources that would cost me so dearly, and saw no other option to delete the entire account.

A few hours later, I got a mail saying the estimate was wrong.

Now, I cannot create an AWS account using my email address because you cannot create a new account using the same email address…

I’m using Postgres for my DNS log service. I only store data for 90 days. To delete data, my strategy is to use partitions based on month. At the start of every month, I drop one partition.

I am not sure of this is the best way to do this, but it works for me.

I changed from Gmail to proton many years ago.

The only pain point I have is the search. Understandable, the emails are encrypted and search has to be done on the client. That works when using the web hi as you have the option to index all emails.

I do not find this option in the iOS app :(

Would it be be trivial to have a init container to do CA injection? Maybe though mutating admission controller? Then some CNI magic to redirect outbound traffic to do transparent proxying?

One domain parking actor is responsible for nearly 10% of all issued ssl certificates. 185.53.178.99. This is just one of many bad actors.

Just because you cannot see how a vulnerability can be exploited does not mean that others can. As you describe, people seem to assume that the only way the config file ends up on the server is «physically» editing it.

An anecdote: I have been struggling with exploiting a product that relies on MongoDb, I can replace the configuration file, but gaining RCE is not supported «functionality» in the embedded version as the __exec option came in a newer version.

A parser bug would be most welcome here.

./watch 9 months ago

What’s the emulator he used when designing the firmware?

You are actually more likely to buy a car just after you have bought a car than the 10 years you did not need to buy a car. Maybe not cars, but I’ve heard this argument for kitchen appliances. If you for some reason return the item you just bought, you may buy what you get ads for. Maybe you regret you did not get the premium one, especially when they shove it in your face afterwards…

Getting the rug pulled under you does not qualify as an experience you need. It happens, but should not be in the curriculum for kids.

I am sure that being forced to spend time on this steals time from more interesting projects.

After thinking of it for a while, I do not think it is such a big issue. The threat actor was probably an adversary to existing huntress customers and the EDR probably reacted to his tooling and mistakes.

When doing red team engagements, we do the same, install same security solutions as the customer and work around it. It could be what happened here?

That the analysts spotted him and were able to connect it to existing cases is just good craftsmanship.

I no longer feel that it’s relevant to discuss a red line here. Huntress just did their job.