HNHacker News
TopNewBestAskShowJobs

altharaz

209 karma · joined March 4, 2013

French InfoSec Engineer

https://www.cyberwatch.fr - Vulnerability Monitoring Software

submissionscomments
altharaz··on Ask HN: What are you working on? (June 2026)
I built an Automated Pigeon Deterrent Water Turret.

Everything has been built with Claude, even the bill of materials for the hardware.

The project is open source and now protects my raspberries. You can see a demo here: https://www.reddit.com/r/ClaudeAI/comments/1u03rja/automated...

altharaz··on Ion engines could take us to the solar gravitational lens in less than 13 years
There is a very high quality video about how Solar Gravitational Lens could be used to map exoplanets, and full explanations about the images reconstruction and engineering challenges: https://youtu.be/NQFqDKRAROI
altharaz··on A closer look at CVSS scores
Very great article.

At the moment IMHO the major issue comes from that people use only the Basic Score of the CVSS 3.1, issued by the NVD.

Indeed, if you also take the Temporal Score (with CTI feeds for example), and if you add the Environmental Score, then you can have very good results to help prioritizing the vulnerabilities on your assets and reflect the real threat.

I would also like, however, to see the CVSS4 with a "cost to patch" component: in OT environments, CISO like to use the SSVC because it’s the easiest way to say "wait" instead of "patch now". But since SSVC is not really recognized by all auditors, it generates conflicts. Bringing a component in the CVSS to reflect the cost of remediation on very complex devices, where deploying a KB requires to stop a full factory, could help getting the same results (aka "don’t patch now and wait") but with a more respected scoring system.

From my perspective, that’s the only missing component for a good CVSS system :).

altharaz··on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)
The hardcoded password seems to be:

Gitlab::Password.test_default(21) => "123qweQWE!@#000000000"

altharaz··on The YC Winter 2022 Batch
https://sievedata.com seems very promising, a search engine for videos, with specific tags, sounds like a very good idea.

I'd like the same for all my photos and videos: that would be so much easier to find specific pictures by keywords

altharaz··on HiveNightmare a.k.a. SeriousSAM – anybody can read the registry in Windows 10
TL;DR:

Some Windows configuration have bad permissions on their SAM database. If a standard user has access to shadow copies (VSS), this can lead to privilege escalation.

Microsoft recommends to [1]:

1) Restrict access to the contents of %windir%\system32\config: - Command Prompt (Run as administrator): icacls %windir%\system32\config*.* /inheritance:e - Windows PowerShell (Run as administrator): icacls $env:windir\system32\config*.* /inheritance:e

2) Delete Volume Shadow Copy Service (VSS) shadow copies: - Delete any System Restore points and Shadow volumes that existed prior to restricting access to %windir%\system32\config. - Create a new System Restore point (if desired).

--

Also, please note that some authorities seem to adress this subject carefully. The French national cybersecurity agency (ANSSI) has for instance published a News bulletin [2] but no "real" Security bulletin of this vulnerability [3].

In its News bulletin, the ANSSI specifies that it also affects Windows Vista RTM :).

However, the ANSSI also says that deleting VSS entries (step 2 of Microsoft recommendations) "must be decided after evaluating the advantages and disadvantages with regard to the risks, in particular because there may be other possibilities for privilege escalation depending on the level of security of your information system."

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...

[2] https://www.cert.ssi.gouv.fr/actualite/CERTFR-2021-ACT-031/

[3] https://www.cert.ssi.gouv.fr/alerte/

altharaz··on Unity Software Inc S-1
Unity has also a lot of potential in the Cybersecurity industry, for people that wants to train themselves on Industrial Systems.

The only thing that makes industrial Cybersecurity really hard for students is the industrial systems laboratory requirements.

With Unity, some people are trying to build completely virtual pentest labs on industrial systems, such as GRFICS (https://github.com/Fortiphyd/GRFICSv2).

altharaz··on Show HN: I made a macOS app to let me draw on the screen while on video calls
Great app, I just bought it and I will try it on the next WebEx conference calls :).

Some remarks:

- the "Highlight cursor at app launch" has a "Start sdf sdfsdf" tooltip

- I can not change the keyboard shortcuts (when I click on the button to configure them, nothing happens)

- the default keyboard shortcut "Control + Option + A" presented in the menu does not work on French keyboards and requires instead to push "Control + Option + Q", which looks like a AZERTY / QWERTY configuration issue?

altharaz··on Ad.watch – Breaking open Facebook's machine of political persuasion
From my understanding, it's a dataviz of Facebook ads linked to politics.

For instance, if we select "Browse per country" and then "France", you can see political ads, with their political party, their content, their settings, etc.

altharaz··on Ask HN: What are your favorite books or essays written at least 100 years ago?
Meditations, Marcus Aurelius => A lot of wisdom on how to lead and live

On The Shortness of Life, Seneca => An essay about how to handle life and how to see what is really important

On War, Clausewitz => An important essay about strategy and war, politics and management

The Prince, Machiavelli => A little bit cynical but quite realistic about the nature of power in the hands of humans

Thirty-Six Stratagems, multiple authors => A list of strategies that can be used in any situation, whether when winning or losing

altharaz··on Ask HN: How do I make sure my non-technical parents are safe online?
From my experience, the password manager is just another issue to solve for this kind of people: it’s another software to use and these users do not like to use software.

As a result, paper is sort of natural for them, and the only way I found to impeach them from writing down their passwords is to make them use passphrases instead of passwords.

They do remember the passphrases they typed in, however the issue is that some websites still refuse passphrases because they are too long :(.

altharaz··on Ask HN: How do I make sure my non-technical parents are safe online?
My recipe is AdBlocks + automated updates enabled + firewall enabled + desktop shortcut for web browser + regular antimalware check.

Regarding phishing, I set them up with a GMail account and their filter is quite good against this.

So far, not anything bad happened, some minor malware were installed through malicious web browser extensions, but no financial damage or identity theft.

altharaz··on Security for Elasticsearch is now free
Is it also opensource? Or just free?
altharaz··on $50M CTF from Hackerone – Writeup
Blind-querying is a common technique and is even tested by tools such as SQLMap (https://github.com/sqlmapproject/sqlmap/wiki/Usage#sql-injec...).

You have full details on what these requests look like here: https://www.owasp.org/index.php/Blind_SQL_Injection

altharaz··on Launch HN: Latchel (YC W19) – Rental Property Maintenance as a Service
In France, this kind of work is proposed by a lot of real estate agencies. Real estate agencies can even collect the rent for you and “guarantee” you the amount you will get each month. This point is very important as it is a nightmare to evict a bad tenant.

Do you have the same issues in the US? If so, do you plan to manage the rent payment as well?

altharaz··on What Was the Happiest Day on the Internet This Decade?
I would have said “the day Pokémon Go had been released”.

I remember people from different generations walking in the streets, talking and laughing together without knowing each other. Something very rare for Paris :).

altharaz··on Solving My Email Problem
From my experience, it seems that the daily digest is not enough :). And they still seem to blacklist WebEx invitations, which is really weird as it is definitely a "standard" in web-conferences.
altharaz··on Solving My Email Problem
> I haven't used WebEx, but what is the problem exactly? Are you concerned you won't see the invite or that the sender will get an annoying automatic response?

Basically, WebEx sends invites from their own email address. If your customer has not white-listed the WebEx domain, they will not receive the WebEx invitation. The only solution we found for our sales team is to "double" the invitation with a manual email sent separately, with the link to the WebEx invitation...

Also, I just realized that I was not very clear in my comment: my company does NOT use MailInBlack :). However, a lot of our customers do, and this has been a nightmare for our WebEx invitations process.

altharaz··on Solving My Email Problem
In France we have a software vendor called MailInBlack.

Their solution is exactly the one proposed in this article, where the sender has to solve a “challenge” to get in your mailbox.

If I think this approach is really effective, it also creates a huge pain for a lot of tools relying on emails such as WebEx invites or when you want to contact someone for sales.

As a result I think that this approach might be better if it was for instance triggered only on emails with an “Unsubscribe” link, or on emails with specific keywords.

altharaz··on Show HN: Simplified music notation
I didn’t know about Hummingbird. This is really cool.

I think I prefer Hummingbird’s approach to OP’s because it makes deciphering the notes way easier with its symbol mnemonic, and I think deciphering the notes is the hardest part.

altharaz··on Ask HN: Recommendations on books and documentaries on tech companies/people?
There is an excellent book about that: "Bienvenue dans le nouveau monde : comment j'ai survécu à la coolitude des startups" from Mathilde Ramadier.

It's an analysis of the startups world, with its downside.

This book is not yet in English, but here is a summary: http://www.startup-book.com/2017/05/02/how-i-survived-the-co...

altharaz··on Macron Vowed to Make France a ‘Startup Nation.’ Is It Getting There?
Actually we have two common cases which make it harder to work with contractor.

1. If your contractor has just you as a client for a long time, if you stop the mission he can sue you for « economical dependance »

2. The real estate market does not let you rent without a solid employee contract, making it very hard to independent contractors to find a house.

The important market is not in contractors but rather in « contractors supporters », basically buying contractors time and selling it to big corporations.

These « middlemen » take the juridical risk, which make the big corporations accepting the contractors, and help the contractors finding missions.

These middlemen also take fees on missions.

altharaz··on Macron Vowed to Make France a ‘Startup Nation.’ Is It Getting There?
The "glass ceiling" statement is true in big corporations (you'll never get to the top if you have not graduated from the top Engineering Schools, even if you have the skills).

However, in Small & Medium Businesses, the startup movement has changed that a bit and the diploma is way less important than before.

In terms of mindset, it seems that it is an important part of our culture: Philippe d'Iribarne calls it "The logic of Honor" [1].

To sum up the differences between French and US management (at least, according to Iribarne)[2]:

- French relies on the concept of honor and duty. French employees consider that their honor and rank is way more important than their contract. You must manage with this in mind, and accept to be flexible in order to show consideration. You must also explain what are the limits so that employees will not go over them. Managers must give free space to their employees, being "invisible" when everything works out, respecting their honor, but must also go on the field when it goes wrong in order to show "how it's supposed to be done" and to inspire respect by example.

- US relies on honesty, and on the transparency of a work contract. Managers must control the work on their contractors on a periodic base in order to show interest and respect, as part of the contractual relationship.

=> In France, according to this study, the "Us vs Them" should be accepted by management as long as the companies goes well.

[1] https://www.ecole.org/fr/662/VA021205-ENG.pdf

[2] http://lirsa.cnam.fr/medias/fichier/diribarne2html__12633047...

altharaz··on Macron Vowed to Make France a ‘Startup Nation.’ Is It Getting There?
To those who talk about the administrative & HR issues in France: these are definitely true.

However, the government is running two programs that will try to improve these elements[1][2].

For instance:

- the French Public Investment Bank (BPI) will receive more money in order to create a better leverage for fund raising, co-investing with private funds in startups;

- France will work with European Union to create the european equivalent of the DARPA challenges;

- France Expérimentation will provide exemptions to some startups trying new business models;

- new APIs will be provided to help accomplishing administrative tasks automatically;

- public contracts will have lower entry barriers;

- public aids (which are really important in France) will be simplified;

- the HR thresholds will be reviewed in order to promote startup growth;

- a study will be conducted on "renting contracts" for startups (most contracts have a 3/6/9-years engagement clause, which is not adapted to startup growth);

- corporate tax will be lowered;

- ...

This is not perfect and we are indeed accustomed to a lot of rules and administrative work, but still: it is good and motivating to see that the government is trying to do something.

Moreover, we have great landscapes and food, so let's give France a try :).

[1] https://www.numerique.gouv.fr/actions-startups/elements-de-p... (in French)

[2] https://www.pacte-entreprises.gouv.fr/

[edit] styling

altharaz··on Ask HN: How did you start your business?
I started a first company with some friend. I was in charge of the IT, he was in charge on Sales. However, things were catastrophic as I was selling more than him. A huge conflict occurred and I closed the company. => I lost some money in the process, but I learnt a lot.

Then, a friend from Engineering school just graduated. We had previously worked together on side-projects, and we had a common passion for cybersecurity. We decided to launch our company.

After three years of hard work, we are now profitable and really happy about this choice :).

altharaz··on Quiver – The Programmer's Notebook
I use Quiver every day. I really like the way I can organize my notes and projects. However the main issue I have with this software is the absence of synchronisation between devices: I can’t browse on my iPhone what I wrote on my Mac.
altharaz··on Snips Uses Rust to Build an Embedded Voice Assistant
I agree.

Their IA assistant seems really interesting, and I would really love to give it a try, but I don't want to invest energy if there is a high risk that the service shuts down soon.

I remember the Tranquilien app [0], which was also developed by Snips. There was a lot of media talking about it, but it has been quickly stopped :(.

[0] https://www.digital.sncf.com/store/applications/tranquilien-...

altharaz··on GitHub acquires AppCanary
I met Max just before his YC interview. The fun fact there was that we both have the same firstname, came from the same region (Europe), and work on the same product family (Vulnerability Management).

AppCanary went to YC, and Cyberwatch went back to France.

However, for us that was for the best! Most of our customers indeed really liked the fact that we are a 100% French company.

We are now profitable and provide a complete Server Vulnerability Management + Patch Management solution.

Different paths to glory, but the world is small and I'm sure we'll meet again someday :)

=> I wish you the best at GitHub!

altharaz··on Ask HN: How can I learn computer security?
"Is there any link between data science and cyber security?"

Data Science might be useful if you want to work in Security Information Management or in malware analysis: big companies try to identify "weird behavior" in their networks, based on "normal behavior" records.

"Where can I learn cyber security stuff?"

Well, that depends on the stuff you are interested in...

You should focus at first on learning "system administration" and at least a programming language like Python or Ruby. Network protocols would also be a bonus.

Then, if you want to learn "offensive techniques" or "penetration testing", I suggest that you try websites like RootMe https://www.root-me.org/?lang=en or Cryptopals cryptopals.com.

Once you'll have resolved by yourself some of these challenges, you'll be able to try the "industrialized approach" of penetration testing. For this, this book is quite cool: https://www.nostarch.com/pentesting.

If you're more interested in "defensive techniques", you have tons of resources online.

For instance:

Secure Coding Best Practices: - https://www.owasp.org/index.php/OWASP_Secure_Coding_Practice... - https://security.berkeley.edu/secure-coding-practice-guideli...

=> These documents will help you to understand what are the main risks in your apps

For "general" cybersecurity: - ISO27001 standard - The NIST Cybersecurity Framework https://www.nist.gov/cybersecurity-framework - PCI/DSS - https://www.us-cert.gov/

=> These documents will help you to understand what are the main risks in an organization based on their assets.

altharaz··on SQL Injection Wiki
You should take a look at https://sqlmap.org : this tool runs SQL attacks with « raw data output » as you say, but also without outputs (Blind SQL injections).
Page 1 of 3Next →