HNHacker News
TopNewBestAskShowJobs

jsploit

357 karma · joined September 30, 2019

Software Engineer and security enthusiast
submissionscomments
jsploit··on Tesla said it didn't have key data in a fatal crash, then a hacker found it
https://www.youtube.com/watch?v=uSH63KuK01U&t=30s 0:30-0:34
jsploit··on Enlisting in the Fight Against Link Rot
> If you visit a link right now, it will be kept.

No, only those that were deemed "active" in 2024 will be kept.

jsploit··on Enlisting in the Fight Against Link Rot
It's still being abused by people registering expired domains.
jsploit··on 21 GB/s CSV Parsing Using SIMD on AMD 9950X
The lack of concurrent access support in the official HDF5 library (the only implementation with full format support) can be a major drawback. There is ongoing work on that front [1] though it's unclear when it will land.

[1] https://github.com/LifeboatLLC/MT-HDF5

jsploit··on Redis Inc seeks control over future of Rust redis-rs client library
Previous discussion: https://news.ycombinator.com/item?id=42239607
jsploit··on XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable."
> "Jia Tan" does not sound Russian

It's not a real name.

jsploit··on Textfiles
Original content: https://web.archive.org/web/20090502094347/http://www.textfi...
jsploit··on Scrum Sucks
> estimate in points (relative size to something you've already done), emphasis on consistent estimates for each dev.

> capture total velocity every 2 weeks and eventually use the avg for future planning

This aspect of scrum has never made sense to me. Planning with average velocity turns points into an obfuscated time estimate - why use points at all?

jsploit··on Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP
> Research shows that 95% of the permissions granted to users aren't used which creates huge problems and is a reason for spending millions in security tools.

It'd potentially cost millions more to recover from a GPT-4 disaster.

jsploit··on Google is shutting down Stadia
Two months ago, Rumor: Google Stadia May Be Getting Shut Down https://news.ycombinator.com/item?id=32276188
jsploit··on Florida governor to investigate GoFundMe over Canada trucker donations
> they were going to redirect donations intended for Canadian protesters to other (likely left leaning) causes

Per the article you linked, donors have two weeks to request a refund, and any remaining funds will be redirected to causes chosen by the Freedom Convoy organizers:

> Donors have until Feb. 19 to ask for a refund, and the rest of the money the group raised would be allocated to “credible and established charities” chosen by Freedom Convoy organizers, the site said.

jsploit··on Sega Europe suffers major security breach
> I was able to use them to enumerate a bunch of storage, dig out more keys

That's unethical and likely criminal without explicit testing authorization (which it appears you didn't have).

I wonder if there are any examples of "researchers" being sued/prosecuted for stunts like this.

jsploit··on Backblaze IPO
Previous S-1 discussion (this is an amendment): https://news.ycombinator.com/item?id=28912799
jsploit··on Fed to ban policymakers from owning individual stocks
These rules only apply to Federal Reserve staff. Were you confused by the title?
jsploit··on A notable JavaScript developer shamelessly copied one of my most downloaded nod
> It explains their course of action, as Jorge was not flexible in his "my way or highway" approach.

I don't understand where this conclusion is coming from as it doesn't seem Andrey raised any concerns with colorette prior to his aggressive actions.

jsploit··on Firefox Addons Unable to Update, Undisclosed AMO Issues
The Firefox profile directory also contains sensitive things like its file cache and trusted CA database, so you don't need to plant a malicious extension to achieve significant impact when you only have write access.
jsploit··on A notable JavaScript developer shamelessly copied one of my most downloaded nod
That does not at all explain their overly aggressive approach and (initial) lack of attribution.
jsploit··on Firefox Addons Unable to Update, Undisclosed AMO Issues
If malware has that level of access on your machine, chances are your browser is already fully compromised.
jsploit··on Firefox Addons Unable to Update, Undisclosed AMO Issues
> After waiting for a long while, I gave up and switched to the Developer Edition so I can use my own add-on.

I find it very frustrating that they now force users into Nightly / Developer Edition if they want to permanently install unsigned add-ons. What's the harm in simply locking that functionality with a config option?

jsploit··on Chia Coin Miners Are Reselling Used SSDs as New
I agree that it shouldn't be "too easy" as a fraud deterrent, but making it impossible seems like an overreach of consumer protection.
jsploit··on Chia Coin Miners Are Reselling Used SSDs as New
If you own the hardware, why shouldn't you be able to control what data it stores?
jsploit··on The time Pepsi got sued for a $33M fighter jet
Reminded me of this classic recording [0] of Verizon Customer Service failing to understand the difference between cents and dollars.

[0] https://www.youtube.com/watch?v=MShv_74FNWU

jsploit··on Everything has changed in iOS 14, but Jailbreak is eternal [pdf]
Isn't that exactly what browser PDF viewers (e.g. PDF.js [0]) already do?

[0] https://mozilla.github.io/pdf.js/

jsploit··on Google Stadia shuts down internal studios, changing business focus
Perhaps I missed it, but that only seems to mention YouTube revenue - not profit.
jsploit··on Where do we go from here and who is going to step up to help us?
They were banned after "repeated warnings". It's possible that those warnings began before these market movements.
jsploit··on Ask HN: What are you working on?
What differences are there between rysolv and bountysource?
jsploit··on Dropbox to cut 11% of its global workforce
> I'm guessing they bank on a small % of "whale" consumers using all their allowance and everyone else being way under the limit

Reminded me of this story [0] of a team with a 500TB account serving as a database and VCS.

[0] https://www.reddit.com/r/sysadmin/comments/eaphr8/a_dropbox_...

jsploit··on Remote Code Execution in Slack desktop apps
Any metric is nonsense if used improperly.
jsploit··on Remote Code Execution in Slack desktop apps
CVSS being used as a basis for bounty payments is certainly evidence that it is taken seriously. Of course there are details that have to be factored in after that calculation, since CVSS is simplified for general usage.

I'm not aware of any programs on HackerOne that don't follow this practice, so it's not "super uncommon".

jsploit··on Remote Code Execution in Slack desktop apps
The authenticated one-click social engineering aspect of this significantly lowers exploit probability and overall risk.
Page 1 of 2Next →