HN user

pizzalife

420 karma
Posts1
Comments154
View on HN
Knoppix 22 days ago

I remember using knoppix on some machine in the school computer room, to sniff everyone's logins using ettercap (pre https adoption). Good times.

  See the AT&T/iPad data leak, where AT&T were leaking private information on the internet with no security checks at all. Someone found it, told the press, who in turn told AT&T, but the FBI still investigated it as a "crime", raided their home, charged them with "conspiracy to access a computer without authorization." AT&T go no punishment at all.
I think you are missing some nuance here. They found a vulnerability where they could just increment an "id" and get access to another user's information. They then went ahead and scraped as much as they could. Also this person (iProphet / weev / Andrew Auernheimer) is awful and certainly not a victim. AT&T did not leak the information, Andrew did!

Should they have had better security? Yes. Was the vulnerability extremely basic? Yes. Doesn't change much, a vulnerability was used to dump a bunch of private data.

This blog post has a really verbose format.

TLDR; White lights are used during the daytime, red lights at night (less annoying), towers under 200 feet don't need blinking lights.

There is a market for capabilities, i.e zerodays in widely used software. It has value, sometimes in the millions.

No one will buy some shitty XSS on a public website.

If you work at a startup, sometimes you have to do extremely mundane and boring things unrelated to your expertise (“wear many hats”). AI is especially useful in those cases so you can quickly go back to working on things you enjoy.