HN user

zelivans

195 karma
Posts16
Comments6
View on HN
news.ycombinator.com 3y ago

Ask HN: Why does the CA Pay Transparency Law only address base pay?

zelivans
1pts0
unit42.paloaltonetworks.com 4y ago

FabricScape: Escaping Service Fabric and Taking over the Cluster

zelivans
1pts0
unit42.paloaltonetworks.com 4y ago

New Linux vulnerability affecting cgroups: can containers escape?

zelivans
123pts82
www.twistlock.com 6y ago

Non-root containers, Kubernetes CVE-2019-11245 and why you should care

zelivans
8pts1
www.twistlock.com 7y ago

Golang fuzzing found a vulnerability in NATS server

zelivans
2pts0
www.twistlock.com 7y ago

Vulnerabilities found in rkt still open

zelivans
1pts0
techcrunch.com 7y ago

Palo Alto Networks acquires Twistlock for $410M

zelivans
1pts0
www.twistlock.com 7y ago

Disclosing a directory traversal vulnerability in Kubernetes copy

zelivans
14pts4
www.twistlock.com 7y ago

Breaking Out of Docker via RunC

zelivans
116pts20
www.twistlock.com 7y ago

Demystifying Kubernetes CVE-2018-1002105 (and a dead simple exploit)

zelivans
5pts0
www.twistlock.com 7y ago

Buffer Overflows in QEMU: Disclosing Four New CVEs

zelivans
2pts0
www.twistlock.com 8y ago

Jenkins GitHub Pull Request Builder Vulnerability (CVE-2018-1000142)

zelivans
3pts0
www.twistlock.com 8y ago

Dear Developers, Beware of DNS Rebinding: DNS Rebinding and CSRF with Etcd

zelivans
5pts3
www.twistlock.com 8y ago

CVE-2017-16544: A Busybox autocompletion vulnerability

zelivans
49pts14
www.twistlock.com 9y ago

Exploiting Alpine Linux

zelivans
91pts22
www.twistlock.com 9y ago

Exploitable buffer overflows found in apk (Alpine Linux's package manager)

zelivans
19pts0

Unfortunately these days it is really difficult, borderline impossible to control what images of you are uploaded to the internet. This is discussed in the "Real World Limitations" section of the paper. Even assuming you have no identifying photos online, non-public photos are still analyzed by big companies like Google, Facebook, and Apple, who have access to them through their cloud services (e.g. photos you, your friends or family sync with Google Photos, Apple Cloud). Having just one image correlate to your identification details and you lose anonymity.

Hi, I'm the author of the article. To stress your point, there really are so many embedded devices using Busybox, and most of them were never designed to be updated (or nobody cares enough to update them).

Also I never got to fuzzing networking applets (wget is the most obvious) but this is definitely something I plan to look into, if no one did that before, there are definitely vulnerabilities there too.