HN user
jsploit
Software Engineer and security enthusiast
If you visit a link right now, it will be kept.
No, only those that were deemed "active" in 2024 will be kept.
It's still being abused by people registering expired domains.
The lack of concurrent access support in the official HDF5 library (the only implementation with full format support) can be a major drawback. There is ongoing work on that front [1] though it's unclear when it will land.
Previous discussion: https://news.ycombinator.com/item?id=42239607
"Jia Tan" does not sound Russian
It's not a real name.
Original content: https://web.archive.org/web/20090502094347/http://www.textfi...
estimate in points (relative size to something you've already done), emphasis on consistent estimates for each dev.
capture total velocity every 2 weeks and eventually use the avg for future planning
This aspect of scrum has never made sense to me. Planning with average velocity turns points into an obfuscated time estimate - why use points at all?
Research shows that 95% of the permissions granted to users aren't used which creates huge problems and is a reason for spending millions in security tools.
It'd potentially cost millions more to recover from a GPT-4 disaster.
Two months ago, Rumor: Google Stadia May Be Getting Shut Down https://news.ycombinator.com/item?id=32276188
they were going to redirect donations intended for Canadian protesters to other (likely left leaning) causes
Per the article you linked, donors have two weeks to request a refund, and any remaining funds will be redirected to causes chosen by the Freedom Convoy organizers:
Donors have until Feb. 19 to ask for a refund, and the rest of the money the group raised would be allocated to “credible and established charities” chosen by Freedom Convoy organizers, the site said.
I was able to use them to enumerate a bunch of storage, dig out more keys
That's unethical and likely criminal without explicit testing authorization (which it appears you didn't have).
I wonder if there are any examples of "researchers" being sued/prosecuted for stunts like this.
Previous S-1 discussion (this is an amendment): https://news.ycombinator.com/item?id=28912799
These rules only apply to Federal Reserve staff. Were you confused by the title?
It explains their course of action, as Jorge was not flexible in his "my way or highway" approach.
I don't understand where this conclusion is coming from as it doesn't seem Andrey raised any concerns with colorette prior to his aggressive actions.
The Firefox profile directory also contains sensitive things like its file cache and trusted CA database, so you don't need to plant a malicious extension to achieve significant impact when you only have write access.
That does not at all explain their overly aggressive approach and (initial) lack of attribution.
If malware has that level of access on your machine, chances are your browser is already fully compromised.
After waiting for a long while, I gave up and switched to the Developer Edition so I can use my own add-on.
I find it very frustrating that they now force users into Nightly / Developer Edition if they want to permanently install unsigned add-ons. What's the harm in simply locking that functionality with a config option?
I agree that it shouldn't be "too easy" as a fraud deterrent, but making it impossible seems like an overreach of consumer protection.
If you own the hardware, why shouldn't you be able to control what data it stores?
Reminded me of this classic recording [0] of Verizon Customer Service failing to understand the difference between cents and dollars.
Isn't that exactly what browser PDF viewers (e.g. PDF.js [0]) already do?
Perhaps I missed it, but that only seems to mention YouTube revenue - not profit.
They were banned after "repeated warnings". It's possible that those warnings began before these market movements.
What differences are there between rysolv and bountysource?
I'm guessing they bank on a small % of "whale" consumers using all their allowance and everyone else being way under the limit
Reminded me of this story [0] of a team with a 500TB account serving as a database and VCS.
[0] https://www.reddit.com/r/sysadmin/comments/eaphr8/a_dropbox_...
Any metric is nonsense if used improperly.
CVSS being used as a basis for bounty payments is certainly evidence that it is taken seriously. Of course there are details that have to be factored in after that calculation, since CVSS is simplified for general usage.
I'm not aware of any programs on HackerOne that don't follow this practice, so it's not "super uncommon".
The authenticated one-click social engineering aspect of this significantly lowers exploit probability and overall risk.