HNHacker News
TopNewBestAskShowJobs

jagracey

93 karma · joined September 12, 2013

JS Dev CEO @ https://getwisdom.io
submissionscomments
jagracey··on Unicode Is Awesome
Commented above, but to follow up from yesterday, here is the next post.

"Hacking GitHub with Unicode" https://news.ycombinator.com/item?id=21693550

jagracey··on Unicode Is Awesome
Just posted another Unicode article to HN. "Hacking GitHub with Unicode"

https://news.ycombinator.com/item?id=21693550

jagracey··on [dead]
211 of the top 500 domains (https://moz.com/top500) contain the letter 'i' within them. It may be worth checking out if they are also susceptible to the Turkish dotless 'i' problem.
jagracey··on Unicode Is Awesome
I agree. I'll be releasing an article about this tomorrow. There are in-fact many security ramifications that have not been solved in practice.
jagracey··on Unicode Is Awesome
Static Version: https://wisdom.engineering/awesome-unicode/amp/
jagracey··on Unicode Is Awesome
Thanks for catching. It's a fairly complex subject matter- and particularly hard get extra eye balls willing to check for typos.

- String length is typically measured in code units. - Funny enough, with Unicode normalization, multiple diacritics can be reduced into a single code point.

jagracey··on Unicode Is Awesome
For exploration, additionally I'd recommend http://shapecatcher.com/ It allows you to draw the shape you are looking for, and with some form of ML, sorts by similarity. It has come in handy a few times for finding the characters I'm unable to describe.
jagracey··on Unicode Is Awesome
Just a quick and scrappy "Ghost" blog running on a $5 Digital Ocean droplet with the usual analytics.
jagracey··on Unicode Is Awesome
The Emoji emoji modifiers are pretty cool. - Skin color modifiers - Character combiners: - man [ZWJ] woman [ZWJ] boy [ZWJ] girl === family of 4
jagracey··on Unicode Is Awesome
Unicode reverse character:

'hello \u{202e} world'; 'hello dlrow' // Visual equivalent

jagracey··on Show HN: Open source JavaScript library to record and replay the web
I got one about bypassing GitHub's authentication using Unicode on the company blog: https://blog.getwisdom.io/hacking-github/

I've wanted to write a deep dive on JS defense for a while now. Lots of cool stuff learned I'd love to share- maybe in the next few weeks.

jagracey··on Show HN: Open source JavaScript library to record and replay the web
I might be alone on this one, but I feel the Freedom-to-Tinker report was unfair to the analytics providers. I know the folks in the industry work really hard towards privacy and security. They go out of their way to make it clear that not everything is automatically censored, and provide easy tools to limit data and visualize what is and isn't recorded. Holding PII and other sensitive data truly is a liability- nobody wants it.

Companies like Walgreens should be entirely to blame.

I really do appreciate how they author(s) in that report uncovered how those services where used in practice.

[I'm not with any party listed in the report]

jagracey··on Show HN: Open source JavaScript library to record and replay the web
Great work yz-yu. Hope you've learned a lot- I've personally found the session replay space to be incredibly rewarding.

However, as a session replay industry competitor and a former security researcher for most industry players, I caution anyone thinking of using a side-project like this on production applications to proceed slowly with care.

Security and Privacy are extremely hard to get right here. The tricky thing about session replay analytics is that attackers have a huge attack vector, and compromise means gaining a treasure trove of all user data. The nature of replay is in a way a form of XSS. Modern security features help (like CSPs, iframe Sandbox attribute) but browser changes can cause issues.

Some of the challenges: - CSPs can often be bypassed using Google API libraries, <Object/>, <SVG> - Blacklisting <SCRIPT/> tags can often be bypassed with an XML namespace - CSS based data or password exfiltration. - Clickjacking, "data:" urls etc. - Could you imagine a web request proxy server deploying Service Workers? - postMsg() from further nested frames

Substantial work goes into sandboxing replay environments and limiting PII. Defense in depth is particularly important here. Enterprise level research, auditing, monitoring and care should be taken seriously.

jagracey··on Variable identifiers can effectively include whitespace
Don't forget to redefine numbers!
jagracey··on HTTP Status Code XSS
Approximately 3/4 of the top 30 status code checking tools are all vulnerable against basic XSS. Thought I'd share this rather fun method. Checkout "netcat security.gracey.ca 1500" for details.