HN user

hexadec

375 karma

Security nerd & breaker of many things.

Posts11
Comments59
View on HN

I am not seeing the long term, what is the value of this over a Shodan API key? They both crawl public IPs and explore subdomains for exposed resources.

Short term, if you have limited the view to companies only with bug bounty programs, it seems useful if you want to complete a bug bounty but don't know where to start. But the mapping of public resources has already been done.

I think showing URLs with sensitive params exposed, services using default creds, or some extra value add over a commodity scanner would be valuable. But then you would just be running a bug bounty/ pentesting AI service for bigger enterprises.

It is a deliberate oversight, the author picked metrics and test based on the result not the other way around. Even the first test (# of jobs per location) should be adjusted to jobs per population or something else since most people value diversity in their social circles.

This is the inverse of accurate, uBlock Origin already has a MV3 extension in progress (beta at https://ublockorigin.com/ top middle of the page). As others have noted, uBO is not even named in the Google releases, this applies to all MV2 extensions.

Annoyed they are barrelling ahead with this still, but not an attack on uBO or ad-blockers directly. Seems like they even made some changes to service workers to enable ad-blockers as well.

Perhaps gorhill will weigh in with more comments if he sees this. Curious if any of their changes to MV3 actually moved the needle on the issues previously identified.

I am not sure the ideal solution here. I do not like data caps in theory or practice, but I can see the CSPs thinking here: get paid for network usage somehow.

It just seems absurd since they are monetizing every part they can (insert capitalism is to drive revenue to shareholders rant here) that is wholly owned by each customer. VMs, IPs, disks, and databases are easy enough to say who owns what. But after that, the networking should be a shared service that is amortized by other product billables.

There is no real incremental cost to sending data in/out of CSPs so this feels like pure profiteering. They need networking for stuff to work, the fiber is already there, and they are billing for network resources. It is getting blood from a stone and reducing ability to flea, errrrm, migrate.

Maybe we return to the old days of mobile service and texting schemes. Free data ingress/egress on nights and weekends (or whenever traffic is less).

As a internal security person (now a consultant for third parties): your approach is interesting, but still fails where all security tools do, who is going to install the agent on every box. The reason why every asset tracking solution is incomplete is because they are trying to correlate agent data and platform data. This is exacerbated by cloud computing since resources are much more transient and new servers lack gating by a governance org.

Complex AV tools are cool but they are so far down the chain of actually exploited vulns, they are not super useful most of the time. Usually the vulns used are old and just unpatched (check the latest DBIR data to see average age of exploited vuln). So a lot of time and effort goes into cajoling teams to update packages and having them say "we don't even call the vulnerable function."

My biggest issues: -Asset inventory (SANS Top 20 #1)

-Software inventory (SANS Top 20 #2)

-Tagging of ownership (what does this box do and who do I call if it goes bump in the night)

To answer your other questions: -Yes, but that is because we created it

-Yes, but only because we have tooling to do it across cloud envs

-No, we only look at deployed bins

-Signature based

-Getting useful code deployed to a box is hard enough, unless there a RCE this is so far down the list of threats on our threat model

-No idea, I assume pretty good since we use MITRE references, but making sure those are accurate to what we find is tough

-Yes, all of them (Fedora, Ubuntu, Arch, Alpine)

The only possible purpose of making laws like this is so that the state can try to enforce some remedy whereby we're told how much we have to or are allowed to pay someone. Who in their right mind wants to sign up for that kind of risk?

How is this the logical conclusion you arrive at? Do you as a company not have a salary range for headcount? Do you not expect prices to be posted by your vendors leading to a lack in informational symmetry and haggling during every routine interaction?

Imagine if your landlord could arbitrarily raise your rent an untold amount with no notice. You of course have options, move or negotiate. But the informational asymmetry means it is harder for you to know if you are getting a good deal if every other landlord is listing their rent as $1-100000 per month or not telling you until after you spent the time checking out the property only to find it is way outside your budget.

The time cost of candidates finding your job, doing some basic research, prepping for X rounds of interviews, possible homework, dealing with hiring managers/ recruiters is insane once you figure folks usually apply to multiple jobs. Why not just tell them up front the salary like you do for role expectations and company culture drivel? Posting honest salary bands is fine to me, say seniors will get $100-150k or whatever, but the article shows clear malice towards any legitimate transparency up front.

during the GPU shortage where gamers who build systems with AMD chips were left unable to use their PC

This comment baffles me, both AMD and Intel have CPUs with onboard graphics and those without. You even noted the integrated graphics a sentence later.

If anything, this is more evidence that AMD is following the Intel playbook by having that integrated CPU/ GPU architecture plan.

I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data).

The webinar tomorrow should be fascinating if they allow questions.

I do appreciate the fine and the fact that the city will stop tracking citizens but I have to play devil's advocate: is this actually a privacy risk?

I have been playing around with passive wifi tracking for a personal project and found that most devices (including iOS and recent Android) all have MAC randomization turned on. Even in mesh wifi like this, the MAC rotates when a new base station is picked up. So while annoying and against GDPR rules, I am not sure if this is a true loss of privacy.

No, freedom of speech is about the government censoring your ability of speech. You are free to stand on a street corner and yell to the world but it does not require anyone to listen to you.

This person is advocating for a non-governmental website that is for enabling free speech since they see some voices as being silenced. But with that comes the ability for people you disagree with the speak as well. No government censored Parler, it was people who disagreed. What if this new service is overrun with people who disagree, will it be swept away in shadow posts or will people who say disagreeable things actually see that.

This begs the question, which is the default: light or full. You cannot claim to support freedom of speech and have this capacity in my opinion. It is implicitly saying some voices are less valid.

It is an interesting project technically, but I do not think it will replace the *chan model for edgy people to be edgy on the internet. If your opinions are so extreme that you feel that you must be anonymous and free from repercussions, they may be terrible opinions in the eyes of society.

Don't we have a marketplace already? If we take the game example we have Steam, Origin, Epic, and other stores competing to sell games. There are differences in offerings but they all still do a healthy business.

On the streaming video side it is even harder since we never license or pay for videos, just the ability to watch as long as the service persists.

Insert surprised Pikachu face

That aside, I do not think this is a bad move at all. None of the titles they were working on were that appealing, hopefully it will mean they pivot to integrate more into a shared licensing model. I would pay $5 a month to be able to import my current Steam games and play remotely, but this fractured model is incredibly reminiscent of video streaming.

We had a first mover (Steam/ Netflix) come in and now all the stragglers are saturating the market with similar but slightly differentiated products (Stadia/ Peacock). I am curious what the next evolution of this model will look like.

I went with dual AMD for a lot of the reasons discussed (ability to drop into my Proxmox server later) but for a more salient one to me: ray tracing.

Personally I did not think it would change that much gameplay-wise when I picked up my RX5700XT since there were so few games in the pipeline. I decided it was not worth the premium. I can still do most any game at 1440p and 100 fps or more without the headache. Why should I pay the premium for GPU features I will never use?

Curious to see how the new administration will handle this. They will need to gather personal identity information to determine if you are a US citizen which is scary. Will certainly enable AWS/GCP/Azure to curtail all my free trial accounts I imagine.

On the other hand, they do not define US IaaS very well, so I am curious if GCP/AWS will be exempt since I think they are technically shell companies registered in Jersey or Isle of Man or offshored on paper.

No the parent, but I did this a bunch as we grew up poor. I got an oooooold IBM PS2 notebook with 6 Windows 3.1.2 floppies from the school IT discard pile. My friends and I also created the cheapest PC we could. It was a cardboard box with a small box fan and then all the Pentium 4 guts duct taped inside.

What political statement are they making aside from saying 'I would like to vote'?

Even the densest election board recognizes this year is not based on historical trends and that early voting (which has been touted on national news) is one way to solve the issue.

What is the alternative to acceptance? My state has closed hundreds of polling places over the past decade or so. Mostly in poor area, college towns, or cities. What should we do if our option for making our voices heard are removed?

I hope we just make voting compulsory and a national holiday, but I won't hold my breath.

This is pretty good material. There is always the struggle of where to go in security it feels. It is easy to get pigeonholes working with a very specific area or set of tools unless you are ok with jumping to new roles/companies every few years. A different challenge the software engineering where some languages span across roles, but similar in the need to keep on top of continuing education (which fewer and fewer places help with, unless you want to spend all you free time learning).