HNHacker News
TopNewBestAskShowJobs

gregclermont

75 karma · joined March 1, 2011

submissionscomments
gregclermont··on Home Depot GitHub token exposed for a year, granted access to internal systems
As an example, there is a hacking group tracked as "Atlas Lion" that has been persistently targeting large retailers' internal systems to steal gift cards that they resell on gray markets for a profit.

I don't believe exploiting GitHub repos for initial access is part of their playbook, but there have been plenty of examples in recent years of attackers gaining access to internal infrastructure via secrets exposed in GitHub (whether in code or Actions workflows). Just this year, attackers got into Salesloft's GitHub, pivoted to their AWS environment, and stole OAuth tokens that gave them access to hundreds of Salesforce customers.

gregclermont··on New Science on Building Great Teams
You might like https://www.diigo.com/
gregclermont··on A new Microsoft browser?
I've heard once or twice that, after one of the IE-related antitrust cases, Microsoft has been imposed a pretty heavy official procedure to release a new version of IE, that contributes to the slowness of the release cycle. If that's real, I wonder if this fork could have the additional benefit of circumventing this procedure.
gregclermont··on Twitter Tweet Button URL randomly resolves to a .torrent file
This visualization of the domain name resolution for platform.twitter.com might help to understand the issue. I don't know how to interpret it however. http://dnsviz.net/d/platform.twitter.com/dnssec/
gregclermont··on Tell HN: Add ?share=1 to Quora URLs to display content without login
They actually officially communicated about this method:

  Open any Quora URL. If you come across a Quora link
  anywhere and you want to read it without being asked to
  join Quora, you can add the text "?share=1" to the end
  of the URL.
http://blog.quora.com/Making-Sharing-Better