HN user

technion

6,954 karma
Posts93
Comments1,480
View on HN
lolware.net 5mo ago

Meta has an answer to YouTube Face

technion
3pts0
azure-enum.lolware.net 2y ago

Show HN: Enumerate Office365/Azure Domains

technion
33pts6
github.com 3y ago

Show HN: Rust Port of Pwnpasswordsdownloader

technion
3pts1
github.com 3y ago

ByteDance open sources g3 proxy (Rust)

technion
2pts0
lolware.net 3y ago

Time to Shutdown CT Advisor

technion
1pts0
meshcentral2.blogspot.com 3y ago

Starting work at Microsoft (Meshcentral possible shutdown)

technion
2pts0
www.theguardian.com 3y ago

Australian government considering right to be forgotten laws

technion
3pts0
github.com 3y ago

React Monkeypatches Patches Fetch()

technion
1pts0
twitter.com 3y ago

Microsoft font parser ported to rust

technion
2pts0
github.com 4y ago

Show HN: Vssshield, a Rust project to mitigate Windows ransomware

technion
5pts0
gist.github.com 4y ago

Datto founder shares thoughts on kaseya acquisition

technion
29pts7
lolware.net 4y ago

Encoding Neil Madden's Psychic Signatures

technion
1pts0
doublepulsar.com 4y ago

Follina – a Microsoft Office code execution vulnerability

technion
2pts0
lolware.net 4y ago

Using Microsoft Sentinel to roll honey tokens on Windows

technion
1pts0
old.reddit.com 4y ago

Nurses told to BYOD after IT lay off

technion
37pts14
flattsecurity.medium.com 4y ago

Finding an unseen SQL Injection by bypassing escape functions in mysqljs/MySQL

technion
1pts0
old.reddit.com 4y ago

Microsoft Exchange stops passing mail due to bug on 1/1/22

technion
711pts358
f.hubspotusercontent10.net 4y ago

Crown Sterling final Whitepaper [pdf]

technion
2pts0
lolware.net 4y ago

Using Azure MFA for on Premises Active Directory

technion
1pts1
github.com 4y ago

Server overload by enforcing DHE key exchange using minimal bandwidth

technion
19pts1
github.com 4y ago

Microsoft Wont-Fix-List

technion
3pts0
github.com 4y ago

Show HN: A rust application to assist with Windows Scripting Host security

technion
2pts0
blog.truesec.com 5y ago

How the Kaseya VSA Zero Day Exploit Worked

technion
1pts0
lolware.net 5y ago

React XSS Protection

technion
1pts0
passwordfromhell.com 5y ago

A puzzle game of password requirements

technion
2pts0
www.wsj.com 5y ago

Microsoft Probes Whether Leak Played Role in Suspected Chinese Hack

technion
3pts1
www.mcafee.com 5y ago

McAfee Announces Sale of Enterprise Business to Symphony Technology Group $4BN

technion
1pts0
mssecurityadventure.com 5y ago

Microsoft Security Adventures Game

technion
29pts7
github.com 5y ago

Sunburst Evasion simulation and demonstration script

technion
2pts0
github.com 5y ago

Show HN: Revoke the Impacted Solarwinds Certificate

technion
2pts0

This isn't LinkedIn specific - the easily misclickable "one click to logon with Google" button showing up in browsers was a huge mistake and should never have existed. Reddit has started prompting too if you're not currently logged in, to just suddenly be logged in with Google.

Vulnerable dependencies are very different to compromised or backdoored dependencies though. Noone's taking over Solarwinds because their build tools had a ReDOS involving input from their own config files.

I'm reading the ZeroBounce docs and it seems very relevant. Look at this step:

"We recheck all unknown emails using IPs from different geographical locations". This matches exactly what this article describes as getting these emails from a range of locations.

The step before that is just "Proprietary Technology", which sounds like a good cover for what's going on here. How else are you testing an email address after between "real time SMTP server check"?

All of them.

My personal tax agent only accepts forms and sends them back via email. I had a conversation with him about using password protected zips and he just told me he won't accept them.

My hospital sent me a PDF that I was to fill in and email back with cleartext credit card information filled in to pay bills. Screenshot:

https://infosec.exchange/@jsmall/116745959468132388

I recently deal with an inheritance and the Super Fund would only accept legal documents by email. I could go on, this is normal.

Yeah, it did always get me as a design issue. I get that "there's more to ask them" is valid. But there's never an indication of "OK I've said everything now". You only find out when they start repeating themselves.

"Make the person repeat what they just told you" as a process is very immersion breaking.

If they run a mortgage broking business, they should have a very different experience to what's described in this post about setting up like a personal machine. They presumably have business managed Microsoft accounts, none of that setup happens, and most of setup prompts are totally automated away from you after logging into such an account.

A lot of those same people seemed perfectly capable of insisting on 60 day password rotation back when they could use nist guidance as an authority to appeal to (for about five years after the recommendation changed too).

Ripgrep AI Policy 2 months ago

Ten times shorter just means "readable without losing an excess of time on ramble" and I feel like someone's comeback to this will be "you should ask an AI to summarise".

The researcher's own statements note that the zero days were not found with AI.

And honestly I think that's the part that Microsoft is most upset about, because every internal partner conversation I've had has been about needing to buy Security Copilot because all the advanced attacks are coming from AI, and just suggesting vulnerabilities existed before AI seems to make salespeople uncomfortable continuing the conversation.

Note that despite being named here as "Azure Linux" and being described as a "General purpose Linux OS for Azure", once you go to the product documentation it's referred to as "Microsoft Azure Linux Container Host for AKS", and the Quickstart guide is about how to deploy a Kubernetes cluster. It doesn't seem very capable of general use.

I guess I woukd say youre fortunate to have not worked in a "we cannot use github.com because we take security very seriously" environment. Because always tells me you'll be running a on prem product that might get updated once a year.

Yes this is what im confused about. They described it as a parking domain, but the old strategy of "buy a popular domain and put ads on a one pager" hasn't been something that pays substantively for a long time. Ads sales have plummeted in general but not being able to use adsense would make it worse.

The first example I looked at was haute-sorne.ch, which is reported by this tool as "Self hosted/other". Whilst it's true that they appear to self host, https://mails.haute-sorne.ch will land you on a Microsoft Exchange server, patch level 15.2.1748.39.

This is better than typical, being an October 2025 patch. But that leaves open CVE-2025-64667, CVE-2025-64666 and CVE-2026-21527. Which are vulnerabilities with patches out going back months.

Now are these RCEs? No, but this was also the first example I looked at.

There's more to it. Signed desktop software can be signed by any CA.

Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines.

In general this isn't your problem.