HNHacker News
TopNewBestAskShowJobs

michaelermer

60 karma · joined June 14, 2016

submissionscomments
michaelermer··on Are We Idiocracy Yet?
And he even missed crocs... https://www.youtube.com/watch?v=bmSkqybtwBk
michaelermer··on Apple parental controls have more holes than Swiss cheese
This is crazy, friends told me apple was good on this, before we had to get a phone for our self, I now think they simply don't understand whats happening. It looks fine to non-tech parents i guess. The question is, what can be used as an alternative? I had first tried an old Android phone, but theres no way to disable app store, so kid figured out he can watch app store videos with no limit...
michaelermer··on Comparing Docusaurus and Starlight and why we made the switch
Same here, funadocs also integrates OpenAPI seamlessly and you can use blocks of the OpenAPI operations in your actual documentation which is perfect for writing developer guides.
michaelermer··on CVE-2022-23529 – node-jsonwebtoken
I am trying this on GitHub https://github.com/github/advisory-database/pull/1595
michaelermer··on CVE-2022-23529 – node-jsonwebtoken
This CVE is a joke, there is no attack vector. If an attacker is able to create an object with an executable function in the scope claimed in the CVE, he may just run the malicious code himself.
michaelermer··on Vulnerability in the Mac Zoom client allows malicious websites to enable camera
This is crazy, heres a video what happens after deleting and opening your URL. https://www.youtube.com/watch?v=DMY7Z9Fe0ic Before testing that I had the app itself removed months ago...
michaelermer··on Apple Cancels AirPower Product
Or a credit card ;)
michaelermer··on The death of Google
They don't tell if it was exploited, all they said was "we have no logs".
michaelermer··on Chrome 67 – Cookies hidden in developer tools network tab
Yes, all of them
michaelermer··on PhantomJS: Archiving the project, suspending development
Also look at stuff like this... https://github.com/SeleniumHQ/selenium/pull/5468
michaelermer··on Blizzard games were vulnerable to DNS rebinding attack
I call BS, it's the responsibility of the server to check Host headers and implement CORS. All browser provide these security measurements. There are valid use cases for having domain aliases for local ips.
michaelermer··on Blizzard games were vulnerable to DNS rebinding attack
And/or simply implement CORS headers.
michaelermer··on Reading privileged memory with a side-channel
Google's post is newer and has more insights, the registry article is now outdated.
michaelermer··on Linux page table isolation is not needed on AMD processors
Full Story https://www.theregister.co.uk/2018/01/02/intel_cpu_design_fl...