HNHacker News
TopNewBestAskShowJobs

pgraf

136 karma · joined August 6, 2023

long time lurker
submissionscomments
pgraf··on How to Replace Your CPAP in Only 666 Days
Might have been useful to establish a paper trail instead of calling them. Have a look at the great article by patio11 for ideas how to establish one: https://www.kalzumeus.com/2017/09/09/identity-theft-credit-r...
pgraf··on FSRS: A modern, efficient spaced repetition algorithm
I would be very interested in that thing :-) Do you already have something you can share or a page where we can track your progress?
pgraf··on BCHS software stack: BSD, C, httpd, SQLite
“BCHS is a stable, developer-oriented platform. Get used to minimalism and security”

With all the memory-safety issues you can introduce by improperly using C, is this page meant to be taken sarcastically or are they really serious about this claim?

pgraf··on TikTok is making users give their iPhone passwords for unclear reasons
No, because if there was the app could either brute-force your pin or lock you out by trying it too often :-) If there was a way this would be a pretty big vulnerability from Apple’s side. Even in the unlikely event that there is some private API, there is no chance you could pass an App Store review with that in your code
pgraf··on Choose the browser that best suits your privacy needs
If you just like the mental separation but don‘t want Chrome, you could also create Firefox profiles with different themes. You can even tweak the browser icon, so I found that sufficient for mental separation
pgraf··on I accidentally saved my company half a million dollars
In my opinion this red tape is why startups are more successful than large organisations… At least in the beginning
pgraf··on Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
Great to hear from you firsthand! While the issue was not reproducable for you, wouldn‘t it have been easy to have a look in the source code if the open-redirect was at all possible?
pgraf··on Using Goatse to Stop App Theft
Omg! One random comment that did not only made my day, but my WEEK :-P
pgraf··on Stocketa – An app I designed, built and never launched
Really impressive for a side project! However, it also feels wasteful to just let go of it after so many work hours invested… How about open-sourcing it? Even if only one person picks it up for personal use it’s better than just rotting-bits on your hard drive
pgraf··on SSH-audit: SSH server and client security auditing
For those wondering, TOFU means “trust on first use” here
pgraf··on Rack Attack – Rails Tricks
Could you please explain how sending a 404 to clients sending too many requests would adhere to the HTTP standards? I’m not against the blocking itself.

For reference: https://datatracker.ietf.org/doc/html/rfc7231#section-6.5.4

pgraf··on Rack Attack – Rails Tricks
Why not adhere to the HTTP standard for once and return a 429 Too many requests or 403 Forbidden? 404 Not Found should only be used for “Not Found” errors. If adhered to this posts advice, you can really screw your search ranking if a major web crawler gets blocked and de-lists all of your pages because of 404
pgraf··on Linux from Scratch Version 12.0
Does anyone know if anything similar exists for Windows? Of course it would be hard due to the closed nature of it, but a similar in-deth look into Windows internals would be much appreciated for a UNIX guy like me.
pgraf··on Data accidentally exposed by Microsoft AI researchers
As in every industry there are cheapskates, and especially in pentesting it is often hard for the customer to tell the good ones from the bad ones. Nevertheless, I think that you have never worked with a credible pentesting vendor. I am doing these tests for a living and would be ashamed to deliver anything coming near your description :-)
pgraf··on F-35 can’t be found after pilot ejected
They should have placed an Apple AirTag under the pilots seat… *sarcasm off*
pgraf··on Zero Effort Private Key Compromise: Abusing SSH-Agent for Lateral Movement
Nice article, although the title is slightly off. The private key is not compromised (as described agent forwarding uses a challenge-response method) and the attacker can only initiate connections as long as the agent is being forwarded.
pgraf··on Bypassing Bitlocker using a cheap logic analyzer on a Lenovo laptop
Same technique described in 2021: https://dolosgroup.io/blog/2021/7/9/from-stolen-laptop-to-in...
← PreviousPage 2 of 2