HNHacker News
TopNewBestAskShowJobs

packtreefly

86 karma · joined December 20, 2024

submissionscomments
packtreefly··on Ask HN: Why didn't the Chrome Web Store team detect Honey's cookie hijacking?
All it is doing is opening a new tab when the user clicks a button, then closing that tab. The JavaScript that replaces the cookie comes from the site itself. I'm sure there's an API call that happens inside the extension to look up the affiliate link to load, but that's probably it.

They wrap all their magic behind that single click, but to be fair, that's exactly how the traditional coupon code sites (e.g. retailmenot) have always worked. Honey just wrapped it into a browser extension and promoted the hell out of it.

packtreefly··on Why we use our own hardware
> although I was worried that folks are too locked in to SaaS stuff

For some people the cloud is straight magic, but for many of us, it just represents work we don't have to do. Let "the cloud" manage the hardware and you can deliver a SaaS product with all the nines you could ask for...

> teaching a course on how to do all this ... there might be interest in that after all?

Idk about a course, but I'd be interested in a blog post or something that addresses the pain points that I conveniently outsource to AWS. We have to maintain SOC 2 compliance, and there's a good chunk of stuff in those compliance requirements around physical security and datacenter hygiene that I get to just point at AWS for.

I've run physical servers for production resources in the past, but they weren't exactly locked up in Fort Knox.

I would find some in-depth details on these aspects interesting, but from a less-clinical viewpoint than the ones presented in the cloud vendors' SOC reports.

packtreefly··on How to lose a fortune with one bad click
There are some obvious, significant benefits I can think of off the top of my head:

- Passkeys give the website no secret to keep.

Breach of the passkey public key is not an event worthy of credential rotation.

- Passkey authentication is submitted via a rigorously-defined mechanism intended for machine-to-machine communication.

Ever had your password manager try to fill the wrong field with your login credentials? Passkeys cannot make that mistake. There's no heuristic mechanism at play trying to figure out where to insert the passkey.

- Passkeys are immune to credential theft via MITM

Sure the MITM could hijack the session, but not the credential. (I know this one is a stretch, but you asked for anything)

packtreefly··on How to lose a fortune with one bad click
The glaring common denominator here is that the attacker has the ability to send an unprompted, unblockable request to the victim's phone. Pressing the safe-looking green button that shows up, even accidentally, is digital suicide.

Google Prompt is supposed to be a safety feature. The account recovery process lets a hostile actor turn Google Prompt into a loaded gun, and Google puts it directly into the victim's hand, aimed straight at their own head.

There's absolutely no way to shut off Google Prompt that doesn't involve removing every Google app from your mobile devices.

← PreviousPage 2 of 2