HN user

iancarroll

3,378 karma

ian[@]ian[.]sh, seats.aero

Posts63
Comments969
View on HN
ian.sh 21d ago

Backstage access: an unauthenticated SQL injection in Front Gate Tickets

iancarroll
3pts0
ian.sh 1y ago

Bypassing airport security via SQL injection

iancarroll
2004pts440
unsaflok.com 1y ago

Unsaflok: Unlocking Hotel Locks [pdf]

iancarroll
3pts0
security.googleblog.com 2y ago

Entrust Certificate Distrust

iancarroll
278pts111
hackcompute.com 3y ago

Hacking root EPP servers to take control of zones

iancarroll
159pts26
github.com 4y ago

PNR.sh: view hidden information in airline reservations

iancarroll
2pts0
aws.amazon.com 5y ago

Resolved: Application Load Balancer Session Ticket Issue

iancarroll
1pts0
stripe.ian.sh 8y ago

Extended Validation is Broken

iancarroll
17pts0
en.wikipedia.org 9y ago

Northeast blackout of 2003

iancarroll
28pts13
www.admin.ch 10y ago

All smartphones sold in Switzerland will use a standard charging port in 2017

iancarroll
3pts3
www.symantec.com 10y ago

Raising the Bar for Security and Trust on the Web

iancarroll
1pts0
blog.ian.sh 11y ago

Free TLS in 2015

iancarroll
1pts0
certly.io 11y ago

Show HN: Certly lets you easily issue and manage certificates

iancarroll
2pts0
www.softlayer.com 11y ago

SoftLayer Catalyst

iancarroll
2pts0
ian.sh 11y ago

Certificate Transparency restrictions soon in effect

iancarroll
2pts0
blog.ian.sh 11y ago

Trivia Crack(ed) – Why you shouldn't trust the client

iancarroll
1pts0
blog.circleci.com 11y ago

CircleCI now has a free plan

iancarroll
10pts0
blog.ian.sh 11y ago

TLS over Tor

iancarroll
10pts2
blog.ian.sh 11y ago

Bypass Admin Password on Netgear Routers

iancarroll
3pts0
blog.ian.sh 11y ago

Why 4096-bit SSL certificates are pointless

iancarroll
7pts0
azure.microsoft.com 11y ago

Azure Signifgantly Drops Some Service Pricing (makes CDN Pricing Competitive)

iancarroll
4pts0
azure.microsoft.com 11y ago

Azure announces SSD-backed instances

iancarroll
9pts1
blog.ian.sh 11y ago

SGC is useless

iancarroll
1pts0
blog.ian.sh 11y ago

Evading Lastline's “Unbeatable” Protection

iancarroll
3pts0
www.globalsign.com 12y ago

Free SSL Certificate for Open Source Projects

iancarroll
165pts64
www.google.com 12y ago

Google Glass taking orders the 15th

iancarroll
9pts7
hackerone.com 12y ago

TLS Triple Handshake Attack

iancarroll
2pts0
www.google.com 12y ago

What happens when you Google "santa"

iancarroll
1pts0
www.godaddy.com 12y ago

GoDaddy issues free SSL certificates to OSS projects

iancarroll
12pts21
updates.intercom.io 12y ago

Intercom.IO Database Accessed

iancarroll
3pts0

In Shenzhen, they told me that I can take the full test on any visa if my permitted length of stay is 90 days or more. Supposedly the US embassies now issue 90 day visas for Americans, so I am hoping to try that route soon as I have already been through two temporary licenses...

Surprised to see this here but happy to answer any questions! Driving across China and getting to use the latest EVs has been quite fun and I hope to do it even more in the future.

Deno Desktop 1 month ago

Most apps (on desktop or mobile) open third party auth flows inside the user's default browser, which makes this a non-issue. For one, if you embed the Google login flow into your app then I can't reuse my existing session in my browser. But it also exposes my full credentials to your app for no reason, which is a good thing to avoid.

My Cloudflare enterprise order form has costs for overages for Workers and the following language about everything else:

If Customer exceeds any of the Total Quantity for the Services below, Cloudflare will invoice Customer in arrears at a rate that corresponds to the rate set forth in the table after this one labeled “Excess Usage Pricing.” If no such Excess Usage Pricing table has been added by the Parties to this order form or if such table does not include the Service(s) for which Customer has exceeded the Total Quantity, then the Parties will negotiate in good faith an increase in the Fees for such Service(s). Should the Parties fail to reach an agreement on an increase within thirty (30) days of Customer’s receipt of notice from Cloudflare that Customer has exceeded its usage cap for the Service(s), Cloudflare will have the right to immediately terminate such Service for its convenience, and without liability to Customer or any third party.

I know plenty of security researchers who exclusively use Claude Code and other tools for blackbox testing against sites they don’t have the source code for. It seems like shutting down the entire product is the only safe decision here!

A bit skeptical of how this article is written as it seems to be mostly written by AI. Out of curiosity, I downloaded the app and it doesn't request location permissions anywhere, despite the claims in the article.

I've noticed Claude Code is happy to decompile APKs for you but isn't very good at doing reachability analysis or figuring out complex control flows. It will treat completely dead code as important as a commonly invoked function.

Although I don’t like Flock, I’m a bit skeptical of the claims in the article. Most screenshots appear to be client-side JavaScript snippets, not API responses from this key.

In the bug bounty community, Google Maps API key leaks are a common false positive, because they are only used for billing purposes and don’t actually control access to any data. The article doesn’t really prove ArcGIS is any different.

I don't think there is any reason to assume they would allow forced code execution just because they allow data residency for mainland accounts. And unfortunately, China is likely a much larger and more profitable consumer market than India - presumably they can still export phones produced inside India without this.

Not an expert but my understanding is that active authentication only occurs after the basic “I can see the MRZ data” authentication passes first. You can’t skip proving you can read the MRZ in any scenario.

Looks like garbage "vulnerabilities" generated by ChatGPT from a random sample of log messages. None of it looks even remotely substantiated and I have no idea how this made it to the front page so quickly.