Research analysis logs to answer the question of quality leads.
HN user
perezbox
One of the biggest shortcomings, besides audience, is discoverability. If there was a way for all instances to consume that search content and make it easily accessible inside your instance that'd be awesome.
Think the biggest issue we have in the tech community is this belief that all content should be accessible to all people with no conditions. All things are equal.
Unfortunately, that is not the case. Ask any parent, and I would wager that they feel really strong about what content their kids should be able to access.
Yes, there are aways to bypass, but that doesn't mean we should not deploy some controls to help reduce, limit, its ease of access.
How will it work?
You make very good points here. Thanks
I run many of my own websites, on my own servers. Thanks for your feedback.
I agree, I could have done a better job of tying it together.
How are those questions intensely political?
Thanks for sharing the spec, I'll give it a read.
I am curious how you believe it's misleading? In its simplest form, is that not how it's going to work in Phase I? User has to input their information, platform will do what it does, health organizations will consume some aspect of that data. It will then be used for notifications when in proximity of others?
In the link you shared, in the intro:
"Exposure Notification makes it possible to combat the spread of the coronavirus — the pathogen that causes COVID-19 — by alerting participants about possible exposure to someone they have recently been in contact with, who has subsequently been positively diagnosed as having the virus. The Exposure Notification Service is the vehicle for implementing exposure notification and uses the Bluetooth Low Energy wireless technology for proximity detection of nearby smartphones, and for the data exchange mechanism. "
The last sentence was "Building a web of social behavior information." Is that in essence what is happening? I am not saying that controls are not going to be implemented, and that data is not going to be protected. I am also not denying the social frameworks that another commentator alluded too.
I am, however, implying that regardless of what you find in documentation, I have been around technology long enough, and at the most senior levels of tech companies, to understand there is a difference between what you read and what a platform can, and can't, do.
Why is that misleading? Is it simplified for users to understand, sure, but dismissing it because it doesn't reference technical specs is a bit shortsighted.
You're right, my article does lean towards a potential dark future. You're also right that it is subjective; it is, by design, an opinion piece not an academic one.
Those sharing links don't go to any company, they simply integrate with platforms to facilitate sharing. It's one of the few tools available to disseminate. I find it odd that sharing links made you question the article. I would personally focus on the content of the article, not the ability to share content.
"We need to bring back RSS which will improve discoverability of self hosted content."
I couldn't agree more. It's really tough to write and share on your own platforms because exposure and dissemination is not what it used to be.
consumer web is done, its owned by private companies, which control discoverability (google ads let’s say) then monetization (google ads) the Platform itself (android which gains data), membership and enforcement (google dev account)
I sadly, also, agree with this. This is another article I plan to write.
I didn't go back further because there was enough to say about what is happening now. I allude that this is not just something that is happening now, but figured for everyone's sanity it was important to focus on the now. :)
< The biggest surprise about this is that there was a constant public rhetoric about the Internet that argued that it would be the most naturally competitive ecosystem ever invented, the one most resistant to monopoly, but in fact the opposite happened -- it consolidated much more quickly than any other major industry, certainly much faster than the examples that Drucker gives
This is a great great point!
Hi
I'm the GM for Security Products at GoDaddy, responsible for the GoDaddy CA. I have checked with the team and do not see any certificates issued to: http://myetherwallet.com/ (including DV).
If someone has an image of what was seen, please send it to me at tperez@godaddy.com so that we can investigate further.
Thanks
Tony
Yup
What you're referring to is Conditional Malware. We actually do very well with that, but there are no 100% solutions. There are also things that are hard, like Defacements and environments used for Phishing Lures..
All great points
Hi Sujan
Can we get a list of the domains you scanned that weren't recognized?
Thanks
Hey @josefresco
Do you have any samples? One of the biggest reasons for this is if it's endpoint malware, versus website malware. Two very different things as you might know. Regardless, would love some samples if you any.
Tony
I'm curious, what security tools did you have in place that were failing to stop the attacks?
Just a bit more..
This was a collaborative research effort with our friends at ESET, here is their breakdown of what they saw: http://www.welivesecurity.com/2013/04/26/linuxcdorked-new-ap...
Congrats guys
Nope, haven't heard anything yet. They might just be delayed trying to catch up as more people submit.
Thanks for the heads up. Updated.
Hi JD
You're right on the GET requests.. :) ..
Any attacker, pentesters, worth their salt would be able to garner some good info from this.
See reference to vulnerable soft in the post published.
Cheers.
Thanks for the update withe link.
Yeah, not sure I'd agree with it not being a big deal. Especially with the type of recon you can do on this information as an attacker.
TP
It's back up now.
When was it last on HN? Don't remember seeing it.
This is a classic case of bad security posture by larger enterprises.
Hi All
Happy to release our new PHP obfuscation Decoder. What's unique about it is that it will decode all the various levels of obfuscation. Most tools will do one layer at a time and you, the user, would have to manually go through the process.
Go ahead, give it a whirl.
http://blog.sucuri.net/2012/10/sucuri-decoding-obfuscated-ph...
Cheers
Tony Sucuri