HNHacker News
TopNewBestAskShowJobs

Dyaz17

32 karma · joined December 2, 2015

submissionscomments
Dyaz17··on Launch HN: Feroot (YC W21) – security scanner for front-end JavaScript code
This is just awesome... Congrats on the launch. This product seems to protect really well websites that include many third party JavaScript. On the other hand ,if you are one of the third party offering the JS, I would advise you to implement Subressource integrity. Or, if not possible to monitor constantly any modifications made to your JS file. I developped a service that does that and there is a free plan : https://www.guardscript.com/
Dyaz17··on Please stop using CDNs for external JavaScript libraries
Regarding the security aspect, I created GuardScript to help catch malicious 3rd party (or 1st party) javascript changes: https://www.guardscript.com/ . You should use if you own a SaaS service that require your clients to include your Javascript library in their page, and when you can't use Subresource Integrity.
Dyaz17··on Confidential VMs
You can login to your instances from the admin console according to this : https://cloud.google.com/compute/docs/instances/connecting-t... So Google has a way to login to your instances...
Dyaz17··on Confidential VMs
What is the attack Vector that this solution prevent ?

Am I missing something obvious ?

Will it prevent Google from being able to have a Root access to the VM?

From my understanding it does not seem to protect from Google. If they are still able to have a Root Access to the VM it does not matter if the memory is encrypted or not.

The only thing that I see, is in case of a spectre/meltdown vulnerabilty where the isolation of the RAM fails...

Dyaz17··on Show HN: Write a private diary using good old email
Great job. Here is what I propose to make it more secure and prevent you from being able to read anyone diary...

I propose that each day a link/token is sent to your email. The link then ask for a password that is handled only with client side javascript and does the encryption of the data before sending it do the server. Look at what Blockhain.info or myetherwallet is doing for client side encryption. Maybe also propose provide all the front end as opensource and provide a way for people to host their own front (a few HTML, JS files where you input the link or token sent to you by email...)

Dyaz17··on Ask HN: Any “Git diff”-like service but for when terms of conditions changes?
You can also use https://www.guardscript.com that does this for free and send you a diff in your email.
Dyaz17··on Show HN: Ciao – HTTP checks and tests monitoring
Nice product! And thank you for making it opensource. Any particular reason why you chose Ruby?

A little plug : I have developed https://www.guardscript.com. It is a service that detect any modification made to static files hosted on your website. The goal is to detect any unwanted modification and revert them as soon as possible.

Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
You are right, for now all the analysis should be done by the owner of the script. I'll think about adding a runbook...
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Thank you, I have corrected it
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Thanks for the suggestion.
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
No it does not include the headers. Only the js file downloaded.
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
For now, Guardscript Goal is for the different SaaS services to use it, not for the individual website owners to use it to monitor the JS of SaaS services.
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
You are right. SRI is the best solution and I mention it in the FAQ. Unfortunately, it can't always be implemented. See my previous comment :

Well many companies that offer you a service don't include the Subresource integrity Tag. Check for instance Stripe : <script src="https://js.stripe.com/v3"></script> or Facebook : <script async defer src="https://connect.facebook.net/en_US/sdk.js"></script>

If they offer you a javascript and it has to change frequently to fix bugs, for instance, they don't want to be bothered with having to coordinate with all their customers to change the subresource integrity tag...

In this case, our service could be an alternative.

Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Exactly.
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Thanks for the suggestion
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Thank you! I have changed it.
Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Well many companies that offer you a service don't include the Subresource integrity Tag.

Check for instance Stripe : <script src="https://js.stripe.com/v3"></script> or Facebook : <script async defer src="https://connect.facebook.net/en_US/sdk.js"></script>

If they offer you a javascript and it has to change frequently to fix bugs, for instance, they don't want to be bothered with having to coordinate with all their customers to change the subresource integrity tag...

In this case our service could be an alternative.

Dyaz17··on Show HN: Guardscript – Detect any changes made to your JavaScript files
Hey HN!

I created GuardScript because in my previous company we started to include more and more third-party Javascript from SaaS services on our homepage, and this created security risks for us [1] [2].

In order to reassure us, a few of these companies created independently what is essentially GuardScript: a service that monitors every few minutes any changes made to your Javascript files and sends you a notification with the changes made. You can then detect any malicious modification by analyzing these results.I decided to build it for a broader audience.

I'd love feedback and suggestions on how to make it better.

Thanks!

[1] https://www.theregister.co.uk/2018/09/12/feedify_magecart_ja [2] https://www.zdnet.com/article/hackers-breach-statcounter-to-...