HN user

itscrush

103 karma
Posts0
Comments64
View on HN
No posts found.
Signal Secure Backups 11 months ago

Monetize first is their strategy given this included statement:

Our future plans include letting you save a secure backup archive to the location of your choosing

Wiz is closer to the CNAPP field instead of the software composition analysis tools you mention, Snyk would fit here for SCA.

Sysdig, Palo Alto's Prisma Cloud, or a few others compete with Wiz's CNAPP offering. Wiz also strays into some SCA and SCA-alike tooling for containers, code or XDR with their CDR/XDR products log ingest and agents available for response/quarantine.

Wiz uses various API's via read access in your accounts/orgs/subscriptions to assess risk of configuration.

They also snapshot your disks, cloning them to Wiz accounts to provide secrets scanning / vuln scanning / etc against your infra.

These resulting risks / findings are scored and provided in their SAAS Wiz console via dashboards / APIs / integrations with remediation guidance.

Bitwarden for usability. Vaultwarden if you can and prefer to self host. Being on the internet you'll have to trust someone at some point. Can reduce risk by combining strong 2FA (not SMS/Email) alongside backing up your vault.

Ensure all your passwords get reset at some point after vaulting, long randomly generated from Bitwarden extension/app is easy enough. Ensure you enable strong 2FA at each service you have an account at too.

https://bitwarden.com/help/setup-two-step-login/ https://bitwarden.com/resources/guide-how-to-create-and-stor...

I am using CloudFlare for my DNS.

Based on this it sounds like you exposed your resource and advertised it for others. Reverse dns, get IP, scan IP.

Probably simpler, you exposed resource on IPV4 publicly, if it exists, it'll be scanned. There's probably 100s of companies scanning entire 0.0.0.0/0 space at all times.

1. Is github the best place to report bugs / issues for Waterfox?

2. When (not in your lifetime obviously) Waterfox is broken, what canaries do you have deployed that we can archive now, like Mozilla's tell here?

3. What keeps waterfox afloat? Where/how do you accept funds?

4. How do I find a sync alternative or provide my own? Such that, I'm not reliant on Mozilla sync/backend? ... If none exists, how much would it cost for you to embed one? Would you accept a serious bounty for it assuming the focus is self hosted / no Waterfox backend services?

Is the best counter here to acquire a brand tld to operate themselves (setting aside all the linkrot it generates)? They've certainly got the resources when you compare against other brand tlds that this could have been an option.

Thanks, FF fork here with ubo, most lists, and medium settings enabled ... somehow this is not the case for me. I'm not being served a page with any overlays / modals, just this redirect to login page.

I know exactly what you're referring to those "content hovers". Like the substack highlight, sign up overlays on immediate visit, or upsells in shopping cart flows.

Thanks for the response, somehow this is not the case for me. Like past times, I always hit the walled garden unless it's Facebook's actual Blog pages.

The provided link of https://m.facebook.com/story.php?story_fbid=1015993413146151... redirects me to https://www.facebook.com/login/?next=https%3A%2F%2Fwww.faceb... which is a hard auth page. No modals, no pop-overs, no X / bypass on the redirected page.

I tried the archive.is for content a work around on the share link, also didn't work.

Free labor that you're handing away. Saw your edits, sounds like you've got start carving boundaries in stone and letting colleagues know it's their loss and fault for not eyeing timezones / after hours.

Load Balancing && WAF or CDN enablement usually suggests at least a decrypt step or two in the HTTP(s) chain. WAF for layer7 payload inspection, or the default wildcard cert'ing your Cloudflare site for instance.

There's also significant aggregation of traffic at handfuls of service providers amongst service categories, all generally HTTP(s) type services too ... Mail, CDN, Video, Voice, Chat, Social, etc. Each of these are still likely to employ Load Balancing & WAF.

Most WAF/Load Balancing providers have documentation about when/where to perform decrypt in your architecture.

How many Cloudflare sites are just using the Cloudflare wildcard cert?

From there, plenty of 3 letter agency space to start whiteboarding how they might continue to evolve their attack chain.