HNHacker News
TopNewBestAskShowJobs

aviCC

53 karma · joined March 29, 2022

submissionscomments
aviCC··on Salt-Labs Claims: XSS protections can be bypassed when social sign-in is used
Wow if that's true and affects more websites, then it's super cool and huge
aviCC··on ChatGPT Plugin Flaw – attackers could access private GitHub repos of others
And a link, if you want to read the official blog post: https://salt.security/blog/security-flaws-within-chatgpt-ext...
aviCC··on ChatGPT Plugin Flaw – attackers could access private GitHub repos of others
Technical details: "The plugin does not authenticate the request, which means that the attacker can insert another memberId (aka the victim) and get a code that represents the victim. With that code, he can use ChatGPT and access the GitHub of the victim."
aviCC··on Ask HN: If you were suddenly Financially free, what would you do next?
Invest money on companies who want to improve our life
aviCC··on Can we create a thread for some of the best materials on CS available online?
https://platform.intervee.io/

Provides practical challenges with guidance for graduates in various subjects including Linux, Network, Security, and more..

Computer Science can sometimes be theoretical and learning from practical example is a must.

aviCC··on Ask HN: Why is OAuth still hard in 2023?
Actually, the CVE-2023-283131 vulnerability was published with the full details just two days ago. In April Expo published a short post but without too much technical information. You can find more details about CVE-2023-283131 in the link I shared here:

https://salt.security/blog/a-new-oauth-vulnerability-that-ma....

Thank you for bringing up the distinction, and I agree that OpenID can help address some of the issues, but not all of them...

aviCC··on Social sign-in is not secured: ATO on Booking.com, Codecademy and 100 more Apps
TLDR: A direct link to the interesting technical information: https://salt.security/blog/a-new-oauth-vulnerability-that-ma...
aviCC··on Booking.com account takeover shows possible pitfalls in OAuth implementations
Original article: https://salt.security/blog/traveling-with-oauth-account-take...
aviCC··on Researchers took over Booking.com accounts using a legitimate Facebook link
https://salt.security/blog/traveling-with-oauth-account-take...

Video: https://youtu.be/IK_AV1UFS-0

aviCC··on Researchers took over Booking.com accounts using a legitimate Facebook link
This is the link to the research, you provided a link to Reddit: https://salt.security/blog/traveling-with-oauth-account-take...
aviCC··on Ask HN: Programmers – do you still buy/read technical books?
Makes sense. They are very useful as a monitor stand.
aviCC··on Ask HN: Programmers – do you still buy/read technical books?
Lol, absolutely not
aviCC··on How and why I stopped buying new laptops
I use an 11 years old desktop computer, with a few upgrades (memory, SSD). It is good enough for my virtual machines and other heavy programs.

I don't see a reason to invest in a laptop if 90% of the time you work in the same place. For the other 10% - buy a cheap laptop.

aviCC··on Ask HN: How do you train developer fundamentals?
I'm going to add a code design course to: https://platform.intervee.io/courses

with challenges that very similar to the problems you described. But it will take a few weeks to be ready.

For your question: Maybe they undervalue a well design code because it's hard to be measured. At the end of the day, you judge them based on their tasks and not quality. Try to give them a motivation to think like architects. What would happen if you ask them to be reviewed by a team member, before pushing it to your review?

aviCC··on Undeclared swimming pools in France uncovered by AI
Sounds great for Pool Roofing companies
aviCC··on Show HN: Interactive realistic challenges (CTF) with an AI-Based assistance
Sorry, temporary bug with some function, please refresh the page
aviCC··on Show HN: Interactive realistic challenges (CTF) with an AI-Based assistance
Advantages of this platform compared to other challenging sites:

1. For hiring: instead of only relying on the final solution, we analyze the entire solution pathway to get visibility similar to a frontal interview. (for example: where the candidate got stuck, how long each step took them, detect cheating using anomaly detection, and more)

2. A new experience: during the challenge, there is a virtual assistant (interviewer) that gives you hints when needed (for example, if it recognizes that you are stuck). This feature has a lot of advantages, both for practice(learning) and also for recruiters who want to give their candidates a full chance.

3. The challenges: most of the challenges are more realistic and simulate real day-to-day skills.

Take for example the challenge "repache" (https://platform.interway.ai/#/get/play_/ch/repache):

You get a web server with a "bug" in the configuration, and you try different ways to tackle it, while the virtual interviewer sees your progress and makes sure you are on the right track.

Thanks. Would appreciate feedback :)

aviCC··on Ask HN: How do you stop bad design decisions?
I had this problem too as a team leader. Most of the time employees are aware of this bad decision but still want to make their own engine/library because it's more fun and they think they can get more credit by building their own library.

Instead of telling them what to do (nobody like it) try to give them a clear deadline for the whole project.