HNHacker News
TopNewBestAskShowJobs

Bnshsysjab

325 karma · joined September 4, 2019

submissionscomments
Bnshsysjab··on Opensnitch, application level interactive firewall, heading into Debian
How does this work on a technical level? What stops an app bypassing the firewall?
Bnshsysjab··on Samsung Ads – Demand-Side Platform
Because TVs rapidly get outdated and die. If nothing else the 2inch thick bezels are an eye sore.

Just because I don’t care about 4K doesn’t mean I don’t care about image quality. I’d prefer 1080p@60 over 4k@30.

Bnshsysjab··on Samsung Ads – Demand-Side Platform
720 to 4K is not the same as 480p to 720. The latter is far more noticeable. Most of the world hasn’t moved to 4K, I don’t see a huge amount of value in it personally.
Bnshsysjab··on Luna – Cloud gaming service
You’re missing the point. Most people don’t want to download a video instead of streaming directly, which is a far lower barrier than procuring equipment, dealing with compatibility issues, doing system updates etc. I doubt competitive gamers will ever move across but it hugely reduces the barriers for casual or time poor gamers.
Bnshsysjab··on MalwareBazaar – Malware Sample Exchange
That’s a fair point.
Bnshsysjab··on MalwareBazaar – Malware Sample Exchange
As a side note, and I’ll create a separate thread: say my host is comprised by super sophisticated malware, aside from a reformat what other sanitisation practices can I do? Can I ever trust the hardware again? I don’t think we’re at a point where a firmware compromised graphics card can’t reinfect the processor?
Bnshsysjab··on MalwareBazaar – Malware Sample Exchange
If you wanna go a little bit more paranoid, use a dedicated host to virtualise those machines and connect to the host via RDP/whatever, that should create another layer of safety.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
No the risk is that somebody has decided to disregard security and general security process and create shadow IT, which if left unchecked will create massive problems within the organisation long term. If the culture is to disregard security, throw a waf infront and call it a day then they’ll pay for it financially (and possibly legally) in the long run and not something I’d want to associate with at all.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
Nah you pull it offline and tell them to follow correct procurement and development practices. If your development teams aren’t talking to your security teams you have bigger problems than Wordpress.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
You need to tweet your view of security requirements if you want to provide IT functions to users. Yes they are a nice to have, yes the cost of a data breach either to you or the user are highly damaging.

There’s nothing stopping most industries doing something stupid in the current state of things but I’m sure there will be in the future, you should be legally liable for your consumer data, irrespective of if you’re ‘nontechnical people running old versions of off the shelf software’ or not, mistakes happen, but failing the most obvious stuff in infosec is, IMO, criminally negligent. Waf or not.

Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
See comment on parent.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
I think ‘stop wasting time on dumb stuff and focus on actual security’ is a good take home for the HN crowd. Time and money is finite, so spend it wisely.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
No it’s not recommending snake oil and telling them to do things properly instead I don’t. Care if that makes the security industry dry up, my only hope is that if it does the snake oil salespeople die with it.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
I’ll ignore your condescending dribble but:

> Let’s also not forget that there is good money to be made off consulting for those companies that are “fucked”

Where the hell are your ethics?

Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
Or maybe I’m just not scraping bottom of the barrel when it comes to security assessments. If the software is at that point the organisation is well and truly fucked, waf or not.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
What if the payload is ‘a,b’ which renders as

Select a, b from foo;

Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
Right but I’m the context of antivirus you’re executing unconstrained data in an unconstrained environment, in appsec you can handle data correctly rather than rely on a third party product that can’t contextualise or assess the impact of a payload on your application. I work in appsec and think WAF filtering is snake oil.
Bnshsysjab··on How I bypassed Cloudflare's SQL Injection filter
I hate these kind of defenses. If your application is vulnerable to sqli, select is one of many tools an attacker can use and you’re pretty much screwed anyway.

Instead, use sane tooling, like modern ORMs and parameter izers, with some data sanitation if you’re really paranoid.

Bnshsysjab··on Super Mario Bros. 3 in 3 Minutes – World Record Speedrun Explained [video]
Also be sure to check out the super Mario world flappy bird code injection:

https://youtu.be/hB6eY73sLV0

Bnshsysjab··on The Unix timestamp will begin with 16 this Sunday
2037 is a potential overflow, I believe. I imagine only pre 2000 systems would likely be affected.
Bnshsysjab··on List of All Current TLDs
I’d love $myhandle.sucks but alas the domain registrar decided to charge extortion rates in the hopes that large companies register their own domain to prevent hate sites >_>
Bnshsysjab··on Emacs is special regarding UIs
Esoteric hardware won’t work first, then maybe browsers. I’d estimate 15 years.

I was not using pulse or systemd until early this year, having used Linux since 2008 thats a pretty decent lifespan. It was finally required for Bluetooth headphones which weren’t really around in the age of alsa.

Bnshsysjab··on Emacs is special regarding UIs
I’m not an X hater but just know you’ve given that server access to your display socket which is effectively remote command execution.

In most cases this could be solved with a good web user interface, but you can rest assured X won’t be dead in the next 5-15 years, and you can use an intermediary box w/VNC if security is that much of a concern.

Bnshsysjab··on Confessions of an ID Theft Kingpin
The beauty of public key cryptography is they don’t need to hold your private key, ever :)
Bnshsysjab··on Confessions of an ID Theft Kingpin
I regularly wonder why we don’t have some form of physical verification token which signs things with our identity, the whole system is broken in that regard.
Bnshsysjab··on BitTorrent v2
Yeah but your hardware requirements are driven by software bloat.
Bnshsysjab··on Ultimate Python Study Guide
I’ve recently tried to pickup Go having coded python since 2007.

I find the ideologies behind the language awkward, particularly explicit error object returns, but ultimately I feel upset with what boils down to ‘it’s not python’

Am I destined to hate Go? Some python limitations get to me, namely multiprocessor support and dynamically types fuzziness (typehint sugar is nice but I’d like my compiler to explicitly fail thanks).

Bnshsysjab··on Islamic State: Giant library of group's online propaganda discovered
I generally don’t try and engage in such conversations. In the case of matrix, terrorism existed long before its existence and other encrypted services were available. Unless you block them all, terrorists will just follow the path of least resistance.
Bnshsysjab··on Islamic State: Giant library of group's online propaganda discovered
Based on that logic we should ban all forms of crypto and just live in clear text. It won’t stop the boogeymen, but it’ll make us feel safer.
Bnshsysjab··on Islamic State: Giant library of group's online propaganda discovered
100% of terrorists actively consume water on a regular basis, too.
Page 1 of 8Next →