HN user

flotwig

166 karma
Posts7
Comments30
View on HN

Before reading this, I assumed the method would involve rewriting large parts of the game's graphics code. But it sounds like the author is intercepting draw calls and changing them to use color instead! Looking forward to the rest of this series.

Looks like cURL and SQLite have the same woes: https://www.sqlite.org/cves.html

Previously I worked on an open source project that pulled in many third party libraries. Users would run their corpo vulnerability scanners on the project and find dependencies with open CVEs and demand fixes, not understanding that in our usage of the libraries, the vulnerability is not exposed.

I think in 4 years, we had users open roughly 50 issues like this, which corresponded to exactly 0 real world exploitable issues.

A central vuln DB makes sense for sysadmins, but too many make it the end-all-be-all.

It sounds like the DOD already does block emails to .ml because of this issue:

Lt. Cmdr Tim Gorman [...] said that emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients”.

I think the issue is people sending emails from personal accounts that the DOD cannot control. The article also mentions travel agents as another source of the email.

I felt the same way, which is why I started a recurring donation to WikiMedia. After about a year, they e-mailed me trying to convince me to write WikiMedia into my will. Check out this transparent attempt at manipulation:

Many supporters like you who understand the usefulness of planning ahead have chosen to include a gift to Wikipedia in their will. They want to do more to protect free knowledge and are invested in building a legacy with Wikipedia to ensure their values live on for many years to come.

"If you understood the importance of planning ahead, you'd already have WikiMedia in your will, bozo"

The truth is no one really sells your email – at least no legitimate companies.

`xfinity2@mydomain.com` is the only email that I've ever caught being sold via my catch-all email. I get a decent amount of phishing, scams, malware, etc. to that address. But I guess the author is still correct, since Xfinity/Comcast are sometimes less than legitimate.

[dead] 6 years ago

It wasn't my intent to imply that. However, it would be possible for a trusted CA to issue a certificate like this, which would allow anyone holding it to intercept any SSL traffic without raising alarms.

IBM Outages 6 years ago

I saw that all notifications/alerts are disabled anyway, and yet I end up getting a bunch of alert spam!

Yup, that matches my experience, that's (partially) why I called the site "unusable"

IBM Outages 6 years ago

I STILL can't figure out how to unsubscribe from those incident alerts. There's no link in the email to manage notification settings, and their website is unusable, so I just send them to spam now.

I do think that they were being "more honest" than other cloud providers, since I've noticed that almost every PAAS or SAAS will have brief outages for small sections of the userbase that aren't mentioned on their status page, either out of laziness or for the PR.

Rocket Mail 7 years ago

I wonder if that's where they got the name in the first place. I can't even remember my old rocketmail address anymore.